yarnpkg / yarn

The 1.x line is frozen - features and bugfixes now happen on https://github.com/yarnpkg/berry
https://classic.yarnpkg.com
Other
41.37k stars 2.72k forks source link

Update dependency tar-fs to v1.16.2 [SECURITY] #9063

Open renovate[bot] opened 1 month ago

renovate[bot] commented 1 month ago

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
tar-fs 1.16.0 -> 1.16.2 age adoption passing confidence

[!WARNING] Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

GitHub Vulnerability Alerts

CVE-2018-20835

A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content.


Release Notes

mafintosh/tar-fs (tar-fs) ### [`v1.16.2`](https://togithub.com/mafintosh/tar-fs/compare/v1.16.1...v1.16.2) [Compare Source](https://togithub.com/mafintosh/tar-fs/compare/v1.16.1...v1.16.2) ### [`v1.16.1`](https://togithub.com/mafintosh/tar-fs/compare/v1.16.0...v1.16.1) [Compare Source](https://togithub.com/mafintosh/tar-fs/compare/v1.16.0...v1.16.1)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

â™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Mend Renovate. View repository job log here.