Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump sharp for security vulnerability in tar-fs #12007

Draft
wants to merge 2 commits into
base: main
Choose a base branch
from

Conversation

denolfe
Copy link
Member

@denolfe denolfe commented Apr 5, 2025

Sharp 0.32.6 had a dependency on tar-fs, which reported a vulnerability: GHSA-pq67-2wwv-3xjx

We haven't bumped sharp it quite some time, so we'll need to be diligent on testing.

@denolfe denolfe force-pushed the chore/bump-sharp-sec-vuln branch from f9c6ed1 to 90c2268 Compare April 5, 2025 02:28
@denolfe denolfe marked this pull request as draft April 5, 2025 02:35
@denolfe denolfe force-pushed the chore/bump-sharp-sec-vuln branch from 90c2268 to 4c6cf3d Compare April 8, 2025 18:21
@denolfe denolfe force-pushed the chore/bump-sharp-sec-vuln branch from 4c6cf3d to 070c4f7 Compare April 11, 2025 17:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant