mapbox / node-pre-gyp

Node.js tool for easy binary deployment of C++ addons
BSD 3-Clause "New" or "Revised" License
1.11k stars 260 forks source link

mapbox / node-pre-gyp #714

Closed kasasusmitha12 closed 1 month ago

kasasusmitha12 commented 2 months ago

We need to upgrade "6.2.1 or later." . We have found a vulnerability in the "tar" package. Please consider upgrading and releasing new release notes for the package. Here I am providing CVE and Vendor Advisories

CVE -https://nvd.nist.gov/vuln/detail/CVE-2024-28863 Vendor Advisories - https://github.com/isaacs/node-tar/security/advisories/GHSA-f5x3-32g6-xq36

cclauss commented 1 month ago

Fixed in #738 (merged)