Skip to content

Fix CVE-2025-59343#215

Open
Pomax wants to merge 1 commit intoprebuild:masterfrom
Pomax:patch-1
Open

Fix CVE-2025-59343#215
Pomax wants to merge 1 commit intoprebuild:masterfrom
Pomax:patch-1

Conversation

@Pomax
Copy link

@Pomax Pomax commented Oct 12, 2025

The high severity security vulnerability (8.7/10) GHSA-vj76-c3g6-qr5v was fixed in tar-fs v2.1.4, and as such all projects relying on tar-fs v2 should pin this version as lowest allowed version.

@vweevers if you have the power to merge this in and kick off a new patch version release, that would be really good.

GHSA-vj76-c3g6-qr5v was fixed in tar-fs v2.1.4, all projects relying on tar-fs v2 should pin this version as lowest allowed semver.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant