Skip to content

chore: upgrade tar to ^7.5.20 to address CVE-2026-59874#1472

Draft
linear-code[bot] wants to merge 2 commits into
mainfrom
linear/sou-1554-sourcebot-devsourcebot-cve-2026-59874-tar-node-tar-56dc
Draft

chore: upgrade tar to ^7.5.20 to address CVE-2026-59874#1472
linear-code[bot] wants to merge 2 commits into
mainfrom
linear/sou-1554-sourcebot-devsourcebot-cve-2026-59874-tar-node-tar-56dc

Conversation

@linear-code

@linear-code linear-code Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1554

Refreshes the yarn.lock entry for tar from 7.5.16 to 7.5.20 to address CVE-2026-59874 (Denial of Service via malformed tar archive header, fixed in 7.5.18).

tar is a transitive dependency (via cacache and node-gyp), both requesting ^7.4.3, which already admits the patched version. No package.json or resolutions change was needed, just a lockfile refresh (yarn up -R tar).

@github-actions

Copy link
Copy Markdown
Contributor

License Audit

❌ Audit failed to produce results. Check the workflow logs for details.

@linear-code linear-code Bot reopened this Jul 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant