[Not really a security bug, but let's be more careful rather than less.]
tar <=7.5.3
Severity: high
node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization - https://github.com/advisories/GHSA-8qq5-rm4j-mr97
Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS - https://github.com/advisories/GHSA-r6q2-hw4h-h46w
fix available via `npm audit fix --force`
Will install c12@3.3.3, which is a breaking change
node_modules/tar
giget 0.0.1 - 1.2.5
Depends on vulnerable versions of tar
node_modules/giget
c12 1.1.0 - 2.0.4
Depends on vulnerable versions of giget
node_modules/c12- Landed
- Released
- Users upgraded (search)
- function-evaluator
- function-orchestrator
- eventgate
- eventstreams