Skip to content

tar and node-gyp versions bump #1835

Open
@igeto

Description

@igeto

Summary

tar <6.1.11 has denial of service vulnerability, bumping it to v6.2.1 should be enough
also node-gyp 8.* is dependent on tar so that version need bumping too

Proposed implementation

bump tar version to ^6.2.1 or latest
bump node-gyp version to 11

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions