We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 516a0d7 commit 533705eCopy full SHA for 533705e
build-info-extractor-npm/src/main/java/org/jfrog/build/extractor/npm/extractor/NpmPublish.java
@@ -100,7 +100,8 @@ private void readPackageInfoFromTarball() throws IOException {
100
new GzipCompressorInputStream(new BufferedInputStream(new FileInputStream(path.toFile()))))) {
101
TarArchiveEntry entry;
102
while ((entry = inputStream.getNextTarEntry()) != null) {
103
- if (StringUtils.endsWith(entry.getName(), "package.json")) {
+ Path parent = Paths.get(entry.getName()).getParent();
104
+ if (parent != null && StringUtils.equals(parent.toString(), "package") && StringUtils.endsWith(entry.getName(), "package.json")) {
105
npmPackageInfo.readPackageInfo(inputStream);
106
tarballProvided = true;
107
return;
0 commit comments