Skip to content

Update tar version to avoid CVE-2026-33056#8073

Merged
jamadeo merged 1 commit intoblock:mainfrom
r0x0d:update-tar-version-to-avoid-cve
Mar 23, 2026
Merged

Update tar version to avoid CVE-2026-33056#8073
jamadeo merged 1 commit intoblock:mainfrom
r0x0d:update-tar-version-to-avoid-cve

Conversation

@r0x0d
Copy link
Contributor

@r0x0d r0x0d commented Mar 23, 2026

Summary

We received a CVE report in downstream builds for tar <= 0.4.44 and the fix is present in >= 0.4.45, and to avoid the version being stuck on an old version, this patch updates the Cargo.toml to have tar >= 0.4.45

Testing

Related Issues

Relates to #ISSUE_ID
Discussion: LINK (if any)

Screenshots/Demos (for UX changes)

Before:

After:

@r0x0d r0x0d force-pushed the update-tar-version-to-avoid-cve branch from 3d93ae0 to c313708 Compare March 23, 2026 16:56
Copy link

@chatgpt-codex-connector chatgpt-codex-connector bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c313708683

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

We received a CVE report in downstream builds for tar <= 0.4.44 and the
fix is present in >= 0.4.45, and to avoid the version being stuck on an
old version, this patch updates the Cargo.toml to have tar >= 0.4.45

Signed-off-by: Rodolfo Olivieri <rodolfo.olivieri3@gmail.com>
@r0x0d r0x0d force-pushed the update-tar-version-to-avoid-cve branch from 0853d0d to da7ee3e Compare March 23, 2026 17:05
@jamadeo jamadeo added this pull request to the merge queue Mar 23, 2026
Merged via the queue into block:main with commit 7823a8e Mar 23, 2026
21 checks passed
wpfleger96 added a commit that referenced this pull request Mar 23, 2026
* origin/main:
  fix: handle reasoning content blocks in OpenAI-compat streaming parser (#8078)
  chore(acp): build native packages on latest mac (#8075)
  Display delegate sub agents logs in UI (#7519)
  Update tar version to avoid CVE-2026-33056 (#8073)
  refactor: consolidate duplicated dependencies into workspace (#8041)
  tui: set up for publishing via github actions (#8020)
  feat: feature-gate local inference dependencies (#7976)
  feat: ability to manage sub recipes in desktop ui (#6360)
lifeizhou-ap added a commit that referenced this pull request Mar 24, 2026
* main: (37 commits)
  fix: handle reasoning content blocks in OpenAI-compat streaming parser (#8078)
  chore(acp): build native packages on latest mac (#8075)
  Display delegate sub agents logs in UI (#7519)
  Update tar version to avoid CVE-2026-33056 (#8073)
  refactor: consolidate duplicated dependencies into workspace (#8041)
  tui: set up for publishing via github actions (#8020)
  feat: feature-gate local inference dependencies (#7976)
  feat: ability to manage sub recipes in desktop ui (#6360)
  Tweak the release process: no more merge to main (#7994)
  fix: gemini models via databricks (#8042)
  feat(apps): Pass toolInfo to MCP Apps via hostContext (#7506)
  fix: remove configured marker when deleting oauth provider configuration (#7887)
  docs: add vmware-aiops MCP extension documentation (#8055)
  Show setup instructions for ACP providers in settings modal (#8065)
  deps: replace sigstore-verification with sigstore-verify to kill vulns (#8064)
  feat(acp): add session/set_config and stabilize list, delete and close (#7984)
  docs: Correct `gosoe` typo to `goose` (#8062)
  fix: use default provider and model when provider in session no longer exists (#8035)
  feat: add GOOSE_SHELL env var to configure preferred shell (#7909)
  fix(desktop): fullscreen header bar + always-visible close controls (#8033)
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants