Skip to content
This repository has been archived by the owner on Feb 19, 2022. It is now read-only.

Update dependancies to fix tar security vulnerability #49

Closed
synap5e opened this issue May 9, 2019 · 2 comments
Closed

Update dependancies to fix tar security vulnerability #49

synap5e opened this issue May 9, 2019 · 2 comments
Assignees

Comments

@synap5e
Copy link
Collaborator

synap5e commented May 9, 2019

tar before 4.4.2 has a file overwrite issue, so I get this lovely alert whenever I go to github
image

I believe we are currently waiting on nodejs/node-gyp#1714 as this has a dependency on the old tar

@synap5e synap5e self-assigned this May 9, 2019
@benolot
Copy link
Collaborator

benolot commented May 9, 2019

@synap5e this fix may wait a while. You can dismiss the vulnerability alert and mark it as can't currently fix iirc. I've had to do that on a lot of repos until the node ecosystem organises itself.

@synap5e
Copy link
Collaborator Author

synap5e commented May 9, 2019

👍 dismissed - I'll leave the issue up as a reminder though

@synap5e synap5e closed this as completed Jun 8, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants