mapbox / node-pre-gyp

Node.js tool for easy binary deployment of C++ addons
BSD 3-Clause "New" or "Revised" License
1.11k stars 260 forks source link

security vulnerability in tar v6.1.11 #716

Closed abhilashaSingh4042 closed 1 month ago

abhilashaSingh4042 commented 2 months ago

there is security vulnerability in v @mapbox/node-pre-gyp@1.0.11 because of tar version 6.1.11

for more information: https://github.com/advisories/GHSA-f5x3-32g6-xq36

cclauss commented 1 month ago

Fixed in #738 (merged)