Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[rush] Medium - <CVE-2024-28863> -6.5 - Vulnerability in ‘tar6.1.15’ #4645

Open
davidabap opened this issue Apr 15, 2024 · 1 comment
Open

Comments

@davidabap
Copy link
Contributor

Summary

rush-lib is dependent on tar(~6.1.1) There is a CVE link recommending an update. I also create a PR: #4644

Repro steps

Expected result:

Actual result:

Details

Standard questions

Please answer these questions to help us investigate your issue more quickly:

Question Answer
@microsoft/rush globally installed version? 5.120.2
rushVersion from rush.json? 5.120.2
useWorkspaces from rush.json? Yes
Operating system? Mac
Would you consider contributing a PR? Yes
Node.js version (node -v)? 18.18.1
@pwbriggs
Copy link

@davidabap @iclanton since #4644 is merged, I think you can close this issue now. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: In Progress
Development

No branches or pull requests

2 participants