Skip to content

chore: upgrade tar to ^7.5.20 to address CVE-2026-59875#1474

Merged
brendan-kellam merged 3 commits into
mainfrom
linear/sou-1555-sourcebot-devsourcebot-cve-2026-59875-node-tar-node-tar-adda
Jul 22, 2026
Merged

chore: upgrade tar to ^7.5.20 to address CVE-2026-59875#1474
brendan-kellam merged 3 commits into
mainfrom
linear/sou-1555-sourcebot-devsourcebot-cve-2026-59875-node-tar-node-tar-adda

Conversation

@linear-code

@linear-code linear-code Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1555

Addresses CVE-2026-59875 (node-tar DoS via crafted archive with NUL bytes in PAX metadata), affecting tar < 7.5.17.

tar is a transitive dependency (via node-gyp / cacache), requested through ^7.4.3, which already admits the patched release. Refreshing the lockfile with yarn up -R tar bumped it from 7.5.16 to 7.5.20 — no package.json change or resolutions override needed. Verified with yarn why tar that no instance of 7.5.16 remains.


Note

Low Risk
Dependency patch with no application code changes; typical low-risk security maintenance.

Overview
Bumps the lockfile-resolved tar package from 7.5.16 to 7.5.20 to address CVE-2026-59875 (DoS via crafted archives with NUL bytes in PAX metadata). package.json is unchangedtar remains a transitive dependency satisfied by the existing ^7.4.3 range.

Documents the fix under Unreleased → Fixed in CHANGELOG.md.

Reviewed by Cursor Bugbot for commit f92d558. Bugbot is set up for automated code reviews on this repo. Configure here.

@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️ Status: PASS

Metric Count
Total packages 2222
Resolved (non-standard) 8
Unresolved 0
Strong copyleft 0
Weak copyleft 39

Weak Copyleft Packages (informational)

Package Version License
@img/sharp-libvips-darwin-arm64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.0.5 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.2.4 LGPL-3.0-or-later
@img/sharp-wasm32 0.33.5 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm32 0.34.5 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm64 0.34.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.33.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.34.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.33.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.34.5 Apache-2.0 AND LGPL-3.0-or-later
axe-core 4.10.3 MPL-2.0
dompurify 3.4.11 (MPL-2.0 OR Apache-2.0)
lightningcss 1.32.0 MPL-2.0
lightningcss-android-arm64 1.32.0 MPL-2.0
lightningcss-darwin-arm64 1.32.0 MPL-2.0
lightningcss-darwin-x64 1.32.0 MPL-2.0
lightningcss-freebsd-x64 1.32.0 MPL-2.0
lightningcss-linux-arm-gnueabihf 1.32.0 MPL-2.0
lightningcss-linux-arm64-gnu 1.32.0 MPL-2.0
lightningcss-linux-arm64-musl 1.32.0 MPL-2.0
lightningcss-linux-x64-gnu 1.32.0 MPL-2.0
lightningcss-linux-x64-musl 1.32.0 MPL-2.0
lightningcss-win32-arm64-msvc 1.32.0 MPL-2.0
lightningcss-win32-x64-msvc 1.32.0 MPL-2.0
Resolved Packages (8)
Package Version Original Resolved Source
codemirror-lang-elixir 4.0.0 UNKNOWN Apache-2.0 npm registry (registry.npmjs.org) - license declared on package
khroma 2.1.0 UNKNOWN MIT GitHub repo (license file: The MIT License)
lezer-elixir 1.1.2 UNKNOWN Apache-2.0 npm registry (registry.npmjs.org) - license declared on package
map-stream 0.1.0 UNKNOWN MIT npm registry root license + GitHub repo (LICENCE file: The MIT License)
memorystream 0.3.1 UNKNOWN MIT GitHub repo (LICENSE file: MIT text)
valid-url 1.0.9 UNKNOWN MIT GitHub repo (LICENSE file: released under the MIT license)
posthog-js 1.369.0 SEE LICENSE IN LICENSE (Apache-2.0 AND MIT) npm registry (registry.npmjs.org) - license declared on package
pause-stream 0.0.11 ["MIT","Apache2"] (MIT OR Apache-2.0) GitHub repo (LICENSE file: Dual Licensed MIT and Apache 2); normalized from array

@brendan-kellam
brendan-kellam marked this pull request as ready for review July 21, 2026 14:06
@brendan-kellam
brendan-kellam merged commit 08cf01d into main Jul 22, 2026
8 checks passed
@brendan-kellam
brendan-kellam deleted the linear/sou-1555-sourcebot-devsourcebot-cve-2026-59875-node-tar-node-tar-adda branch July 22, 2026 17:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant