This repository has been archived by the owner on Aug 11, 2021. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 39
Tar package vulnerability on install #28
Comments
The underlying issue has been patched in the source of |
This can be resolved with either updating to a node-gyp@4 here or doing a patch release of |
Created a PR to update node-gyp@4 here. #31 |
When can we expect a release? lerna depends on this package, so all users of lerna are currently exposed to the tar vulnerability. |
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
npm-lifeycycle
is using a version ofnode-gyp
which is pointing to a version oftar
that has a vulnerability. See https://www.npmjs.com/advisories/803.The text was updated successfully, but these errors were encountered: