Skip to content

chore(deps): bump tar to ^7.5.10#5777

Open
antonis wants to merge 1 commit intomainfrom
antonis/bump-tar
Open

chore(deps): bump tar to ^7.5.10#5777
antonis wants to merge 1 commit intomainfrom
antonis/bump-tar

Conversation

@antonis
Copy link
Contributor

@antonis antonis commented Mar 5, 2026

Bumps the existing tar resolution from ^7.5.8 to ^7.5.10 to fix a hardlink path traversal vulnerability.

All consumers now resolve to 7.5.10. Dev-only dependency.

https://github.com/getsentry/sentry-react-native/security/dependabot/443

Fixes Dependabot alert for tar hardlink path traversal vulnerability.

https://github.com/getsentry/sentry-react-native/security/dependabot/443

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actions
Copy link
Contributor

github-actions bot commented Mar 5, 2026

Semver Impact of This PR

None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(deps): bump tar to ^7.5.10 by antonis in #5777

🤖 This preview updates automatically when you update the PR.

@github-actions
Copy link
Contributor

github-actions bot commented Mar 5, 2026

Fails
🚫 Pull request is not ready for merge, please add the "ready-to-merge" label to the pull request

Generated by 🚫 dangerJS against 14249f6

@antonis antonis marked this pull request as ready for review March 5, 2026 14:32
Copy link
Collaborator

@lucas-zimerman lucas-zimerman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants