Skip to content

fix(deps): remove vulnerable tar-fs 3.0.4 (CVE-2024-12905)#7

Open
Leathal1 wants to merge 1 commit into
mainfrom
fix/tar-fs-CVE-2024-12905
Open

fix(deps): remove vulnerable tar-fs 3.0.4 (CVE-2024-12905)#7
Leathal1 wants to merge 1 commit into
mainfrom
fix/tar-fs-CVE-2024-12905

Conversation

@Leathal1

Copy link
Copy Markdown
Owner

Bumps puppeteer-core 21.11.0 → 25.1.0. SMRY does not directly use tar-fs; it came in transitively via @puppeteer/browsers@1.9.1. The newer browsers package (3.0.4) replaces tar-fs with modern-tar, eliminating the CVE. Build passes.

… tar-fs 3.0.4 (CVE-2024-12905)

SMRY never directly imports tar-fs; it was pulled in transitively by
@puppeteer/browsers@1.9.1 via puppeteer-core@21.11.0.  puppeteer-core 25
switches @puppeteer/browsers to 3.0.4, which replaces tar-fs with modern-tar.
Build passes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant