Skip to content

fix: reject path traversal entries when inflating dependency shrinkwraps#9451

Merged
owlstronaut merged 1 commit into
release/v11from
owlstronaut/shrinkwrap-traversal
Jun 1, 2026
Merged

fix: reject path traversal entries when inflating dependency shrinkwraps#9451
owlstronaut merged 1 commit into
release/v11from
owlstronaut/shrinkwrap-traversal

Conversation

@owlstronaut
Copy link
Copy Markdown
Contributor

No description provided.

@owlstronaut owlstronaut requested review from a team as code owners June 1, 2026 15:13
@owlstronaut owlstronaut force-pushed the owlstronaut/shrinkwrap-traversal branch from 1664e2f to 5967330 Compare June 1, 2026 15:44
Comment thread workspaces/arborist/lib/arborist/load-virtual.js
Comment thread workspaces/arborist/lib/arborist/load-virtual.js
Comment thread workspaces/arborist/lib/arborist/load-virtual.js
Comment thread workspaces/arborist/test/arborist/load-virtual.js
Comment thread workspaces/arborist/lib/arborist/load-virtual.js
@owlstronaut owlstronaut force-pushed the owlstronaut/shrinkwrap-traversal branch from 5967330 to 2b473d3 Compare June 1, 2026 20:15
@owlstronaut owlstronaut requested a review from nishantms June 1, 2026 20:18
@owlstronaut owlstronaut merged commit d59c964 into release/v11 Jun 1, 2026
16 checks passed
@owlstronaut owlstronaut deleted the owlstronaut/shrinkwrap-traversal branch June 1, 2026 21:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants