Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

tar security issue #690

Closed
nworden opened this issue May 16, 2019 · 1 comment
Closed

tar security issue #690

nworden opened this issue May 16, 2019 · 1 comment

Comments

@nworden
Copy link
Contributor

nworden commented May 16, 2019

We're getting a warning from GitHub saying that we should upgrade the tar JS library to 4.4.2 or later. However, node-gyp (which we indirectly depend on) specifically requires tar v2.x, apparently for good but complicated reasons. The tar fix has been backported to the 2.x line and is in v2.2.2, which is what we use.

I'm not sure why GH's still complaining about it (maybe the alerting system just doesn't handle backports well), but npm audit passes so I don't think we need to be concerned. I'm just going to leave this issue open FTR until GH stops warning us about it.

@nworden
Copy link
Contributor Author

nworden commented Jun 7, 2019

The GitHub warning is gone.

@nworden nworden closed this as completed Jun 7, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant