Skip to content

Conversation

@matz3
Copy link
Member

@matz3 matz3 commented Jan 26, 2026

Resolves alerts for several security advisories such as: GHSA-r6q2-hw4h-h46w GHSA-8qq5-rm4j-mr97

As per our assessment those vulnerabilities are not exploitable in the context of UI5 CLI.

The override for tar is specifically defined where necessary in order to not downgrade tar in case a new major version is being used by other dependencies.

Resolves alerts for several security advisories such as:
GHSA-r6q2-hw4h-h46w
GHSA-8qq5-rm4j-mr97

As per our assessment those vulnerabilities are not exploitable in the context of UI5 CLI.

The override for tar is specifically defined where necessary in order to not downgrade tar
in case a new major version is being used by other dependencies.
@matz3 matz3 requested a review from a team January 26, 2026 08:29
@matz3 matz3 merged commit ea4e521 into v4 Jan 26, 2026
8 checks passed
@matz3 matz3 deleted the v4-override-tar-version branch January 26, 2026 08:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants