fix(security): upgrade tar to 7.5.3 for GHSA-8qq5-rm4j-mr97#298
Conversation
Adds npm override to force tar@7.5.3 across all dependencies to fix path sanitization vulnerability (CVE-2026-23745). Also adds third-party license notice for Blue Oak Model License 1.0.0.
📝 WalkthroughWalkthroughThis pull request adds documentation and adjusts dependency overrides. The README gains a "Third-party licenses" section documenting tar's Blue Oak Model License 1.0.0. In package.json, a new override entry for tar is introduced, and the existing 🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Warning Review ran into problems🔥 ProblemsErrors were encountered while retrieving linked issues. Errors (1)
Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #298 +/- ##
===========================
===========================
🚀 New features to boost your workflow:
|
Adds npm override to force tar@7.5.3 across all dependencies to fix path sanitization vulnerability (CVE-2026-23745). Also adds third-party license notice for Blue Oak Model License 1.0.0.
Summary by CodeRabbit
Documentation
Chores
✏️ Tip: You can customize this high-level summary in your review settings.