Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Sep 24, 2025

Coming soon: The Renovate bot (GitHub App) will be renamed to Mend. PRs from Renovate will soon appear from 'Mend'. Learn more here.

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
tar-fs@>=2.0.0 <2.1.3 [>=3.1.0 -> >=3.1.1](https://renovatebot.com/diffs/npm/tar-fs@&gt;&#x3D;2.0.0 <2.1.3/3.1.0/3.1.1) age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2025-59343

Impact

v3.1.0, v2.1.3, v1.16.5 and below

Patches

Has been patched in 3.1.1, 2.1.4, and 1.16.6

Workarounds

You can use the ignore option to ignore non files/directories.

  ignore (_, header) {
    // pass files & directories, ignore e.g. symlinks
    return header.type !== 'file' && header.type !== 'directory'
  }

Credit

Reported by: Mapta / BugBunny_ai


Release Notes

mafintosh/tar-fs (tar-fs@>=2.0.0 <2.1.3)

v3.1.1

Compare Source


Configuration

📅 Schedule: Branch creation - "" in timezone Asia/Tokyo, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the renovate label Sep 24, 2025
@renovate renovate bot requested a review from a team as a code owner September 24, 2025 20:48
@renovate renovate bot requested review from misako0927 and s-sasaki-0529 and removed request for a team September 24, 2025 20:48
@pkg-pr-new
Copy link

pkg-pr-new bot commented Sep 24, 2025

Open in StackBlitz

npm i https://pkg.pr.new/kufu/smarthr-ui@5849

commit: e8a3dc2

@renovate renovate bot changed the title chore: update dependency tar-fs@&gt;&#x3d;2.0.0 &lt;2.1.3 to >=3.1.1 [security] chore: update dependency tar-fs@&gt;&#x3d;2.0.0 &lt;2.1.3 to >=3.1.1 [security] - autoclosed Oct 6, 2025
@renovate renovate bot closed this Oct 6, 2025
@renovate renovate bot deleted the renovate/npm-tar-fs>=2.0.0-<2.1.3-vulnerability branch October 6, 2025 10:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant