Skip to content

chore(deps): bump fast-uri to 3.1.4, tar to 7.5.22, drop 8 exclusions#9355

Open
github-actions[bot] wants to merge 1 commit into
masterfrom
osv-scanner-prune/20260727-automated-prune
Open

chore(deps): bump fast-uri to 3.1.4, tar to 7.5.22, drop 8 exclusions#9355
github-actions[bot] wants to merge 1 commit into
masterfrom
osv-scanner-prune/20260727-automated-prune

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Summary

  • Bumped fast-uri from 3.1.3 to 3.1.4 to resolve GHSA-v2hh-gcrm-f6hx
  • Upgraded tar resolutions to 7.5.22 across swarm-js, yeoman-generator, pacote paths
  • Removed 8 stale osv-scanner exclusions that are now fixed by the dependency upgrades

Removed exclusions

GHSA ID Package Vulnerability Fix Version
GHSA-v2hh-gcrm-f6hx fast-uri Host confusion via literal backslash 3.1.4+
GHSA-8qq5-rm4j-mr97 tar Symlink/hardlink extraction CVE 7.5.3+
GHSA-r6q2-hw4h-h46w tar Extraction CVE 7.5.4+
GHSA-34x7-hfp2-rc4v tar Crafted archives CVE 7.5.4+
GHSA-83g3-92jg-28cx tar Crafted archives CVE 7.5.4+
GHSA-qffp-2rhf-9h96 tar Hardlink path traversal 7.5.7+
GHSA-9ppj-qmqm-q256 tar Extraction CVE N/A
GHSA-23hp-3jrh-7fpw tar Decompression DoS 7.5.19+
GHSA-8x88-c5mf-7j5w tar Infinite loop via negative entry size 7.5.18+

Verification

OSV Scanner: All removed exclusions no longer flagged
check-deps: Cross-workspace version consistency verified
Dependencies: All resolutions upgraded successfully

Still blocked

These exclusions remain in place due to compatibility constraints:

🤖 Generated with Claude Code

… from osv-scanner.toml

- fast-uri: 3.1.3 → 3.1.4 (resolves GHSA-v2hh-gcrm-f6hx host confusion vulnerability)
- tar resolutions: 6.2.1 → 7.5.22 for swarm-js, yeoman-generator, and pacote paths
- Remove 8 stale osv-scanner exclusions:
  • GHSA-v2hh-gcrm-f6hx (fast-uri host confusion, fixed in 3.1.4)
  • GHSA-8qq5-rm4j-mr97 (tar symlink/hardlink, fixed in 7.5.3+)
  • GHSA-r6q2-hw4h-h46w (tar extraction CVE, fixed in 7.5.4+)
  • GHSA-34x7-hfp2-rc4v (tar crafted archives, fixed in 7.5.4+)
  • GHSA-83g3-92jg-28cx (tar crafted archives, fixed in 7.5.4+)
  • GHSA-qffp-2rhf-9h96 (tar hardlink traversal, fixed in 7.5.7+)
  • GHSA-9ppj-qmqm-q256 (tar extraction CVE)
  • GHSA-23hp-3jrh-7fpw (tar decompression DoS, fixed in 7.5.19+)
  • GHSA-8x88-c5mf-7j5w (tar infinite loop, fixed in 7.5.18+)

All fixes verified with osv-scanner and check-deps passes.

Ticket: HSM-429
@github-actions
github-actions Bot requested review from a team as code owners July 27, 2026 07:25
@github-actions github-actions Bot added automated Automated changes dependencies Updates to dependencies security Security-related changes labels Jul 27, 2026

Copy link
Copy Markdown
Contributor

NACK — CI is failing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Automated changes dependencies Updates to dependencies security Security-related changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants