Skip to content

chore(deps): bump tar to ^7.5.10#5777

Merged
antonis merged 1 commit intomainfrom
antonis/bump-tar
Mar 9, 2026
Merged

chore(deps): bump tar to ^7.5.10#5777
antonis merged 1 commit intomainfrom
antonis/bump-tar

Conversation

@antonis
Copy link
Contributor

@antonis antonis commented Mar 5, 2026

Bumps the existing tar resolution from ^7.5.8 to ^7.5.10 to fix a hardlink path traversal vulnerability.

All consumers now resolve to 7.5.10. Dev-only dependency.

https://github.com/getsentry/sentry-react-native/security/dependabot/443

Fixes Dependabot alert for tar hardlink path traversal vulnerability.

https://github.com/getsentry/sentry-react-native/security/dependabot/443

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actions
Copy link
Contributor

github-actions bot commented Mar 5, 2026

Semver Impact of This PR

None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(deps): bump tar to ^7.5.10 by antonis in #5777

🤖 This preview updates automatically when you update the PR.

@github-actions
Copy link
Contributor

github-actions bot commented Mar 5, 2026

Fails
🚫 Pull request is not ready for merge, please add the "ready-to-merge" label to the pull request

Generated by 🚫 dangerJS against 14249f6

@antonis antonis marked this pull request as ready for review March 5, 2026 14:32
Copy link
Collaborator

@lucas-zimerman lucas-zimerman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@antonis antonis merged commit e6f517d into main Mar 9, 2026
56 of 65 checks passed
@antonis antonis deleted the antonis/bump-tar branch March 9, 2026 08:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants