Skip to content

fix(deps): vuln tar (major → 7.5.20) - #183

Closed
gh-worker-campaigns-3e9aa4[bot] wants to merge 2 commits into
mainfrom
engraver-auto-version-upgrade/major/npm/0-1784608286
Closed

gh-worker-campaigns-3e9aa4[bot] wants to merge 2 commits into
mainfrom
engraver-auto-version-upgrade/major/npm/0-1784608286

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor

Summary: Critical-severity security update — 1 package upgraded (MAJOR changes included)

Manifests changed:

  • . (npm)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
tar 6.1.11 7.5.20 major Direct 2 CRITICAL, 14 HIGH, 8 MEDIUM

Warning

Major Version Upgrade

This update includes major version changes that may contain breaking changes. Please:

  • Review the changelog/release notes for breaking changes
  • Test thoroughly in a staging environment
  • Update any code that depends on changed APIs
  • Ensure all tests pass before merging

Security Details

🚨 Critical & High Severity (16 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
tar GHSA-23hp-3jrh-7fpw CRITICAL node-tar: Decompression/parse DoS via unlimited input 6.1.11 7.5.19 -
tar CVE-2026-59873 CRITICAL node-tar: Decompression/parse DoS via unlimited input 6.1.11 - -
tar GHSA-8qq5-rm4j-mr97 HIGH node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization 6.1.11 7.5.3 -
tar CVE-2026-26960 HIGH node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction 6.1.11 - -
tar GHSA-8x88-c5mf-7j5w HIGH node-tar: Negative tar entry size causes infinite loop in archive replace 6.1.11 7.5.18 -
tar CVE-2026-59874 HIGH node-tar: Negative tar entry size causes infinite loop in archive replace 6.1.11 - -
tar GHSA-r6q2-hw4h-h46w HIGH Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS 6.1.11 7.5.4 -
tar CVE-2026-23745 HIGH node-tar Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization 6.1.11 - -
tar GHSA-qffp-2rhf-9h96 HIGH tar has Hardlink Path Traversal via Drive-Relative Linkpath 6.1.11 7.5.10 -
tar CVE-2026-23950 HIGH node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS 6.1.11 - -
tar GHSA-9ppj-qmqm-q256 HIGH node-tar Symlink Path Traversal via Drive-Relative Linkpath 6.1.11 7.5.11 -
tar CVE-2026-31802 HIGH node-tar Symlink Path Traversal via Drive-Relative Linkpath 6.1.11 - -
tar GHSA-83g3-92jg-28cx HIGH Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction 6.1.11 7.5.8 -
tar CVE-2026-29786 HIGH node-tar: Hardlink Path Traversal via Drive-Relative Linkpath 6.1.11 - -
tar GHSA-34x7-hfp2-rc4v HIGH node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal 6.1.11 7.5.7 -
tar CVE-2026-24842 HIGH node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal 6.1.11 - -
ℹ️ Other Vulnerabilities (8)
Package CVE Severity Summary Unsafe Version Fixed In Case
tar GHSA-gvwx-54wh-qm9j MODERATE node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records 6.1.11 7.5.17 -
tar CVE-2026-53655 MODERATE node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling) 6.1.11 - -
tar GHSA-vmf3-w455-68vh MODERATE node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling) 6.1.11 7.5.16 -
tar CVE-2024-28863 MODERATE node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation 6.1.11 - -
tar GHSA-f5x3-32g6-xq36 MODERATE Denial of service while parsing a tar file due to lack of folders count validation 6.1.11 6.2.1 -
tar CVE-2026-59875 MODERATE node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records 6.1.11 - -
tar GHSA-w8wr-v893-vjvp MODERATE node-tar: Process crash via PAX numeric path type confusion 6.1.11 7.5.18 -
tar CVE-2026-59871 MODERATE node-tar: Process crash via PAX numeric path type confusion 6.1.11 - -

Review Checklist

Extra review is recommended for this update:

  • Review changes for compatibility with your code
  • Check release notes for breaking changes
  • Run integration tests to verify service behavior
  • Test in staging environment before production
  • Monitor key metrics after deployment
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

dd-octo-sts Bot and others added 2 commits July 28, 2026 10:23
Co-authored-by: gh-worker-campaigns-3e9aa4[bot] <244854796+gh-worker-campaigns-3e9aa4[bot]@users.noreply.github.com>
Co-authored-by: gh-worker-campaigns-3e9aa4[bot] <244854796+gh-worker-campaigns-3e9aa4[bot]@users.noreply.github.com>
@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor Author

Auto-rebase complete

Branch is up to date with main — rebased onto 3a5cc60.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts
dd-octo-sts Bot force-pushed the engraver-auto-version-upgrade/major/npm/0-1784608286 branch from 166b0f0 to b5f9a43 Compare July 28, 2026 10:23
@dd-octo-sts
dd-octo-sts Bot marked this pull request as ready for review July 28, 2026 12:00
@dd-octo-sts
dd-octo-sts Bot requested a review from a team as a code owner July 28, 2026 12:00
@gh-worker-campaigns-3e9aa4
gh-worker-campaigns-3e9aa4 Bot deleted the engraver-auto-version-upgrade/major/npm/0-1784608286 branch August 3, 2026 20:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants