From 4b340e20df7fecdf0bbfaa5dd4aea7c8809b827b Mon Sep 17 00:00:00 2001 From: Convly Date: Wed, 1 Sep 2021 12:01:44 +0200 Subject: [PATCH] Bump tar to 6.1.9, fix security issue --- packages/strapi-generate-new/package.json | 2 +- yarn.lock | 12 ++++++++++++ 2 files changed, 13 insertions(+), 1 deletion(-) diff --git a/packages/strapi-generate-new/package.json b/packages/strapi-generate-new/package.json index 2bcc958bff..258d5680b1 100644 --- a/packages/strapi-generate-new/package.json +++ b/packages/strapi-generate-new/package.json @@ -23,7 +23,7 @@ "node-fetch": "^2.6.1", "node-machine-id": "^1.1.10", "ora": "^5.4.0", - "tar": "6.1.4", + "tar": "6.1.9", "uuid": "^3.3.2" }, "scripts": { diff --git a/yarn.lock b/yarn.lock index 8e24e24e68..8720b834aa 100644 --- a/yarn.lock +++ b/yarn.lock @@ -19569,6 +19569,18 @@ tar@6.1.4: mkdirp "^1.0.3" yallist "^4.0.0" +tar@6.1.9: + version "6.1.9" + resolved "https://registry.yarnpkg.com/tar/-/tar-6.1.9.tgz#5646ef51342ac55456b2466e44da810439978db1" + integrity sha512-XjLaMNl76o07zqZC/aW4lwegdY07baOH1T8w3AEfrHAdyg/oYO4ctjzEBq9Gy9fEP9oHqLIgvx6zuGDGe+bc8Q== + dependencies: + chownr "^2.0.0" + fs-minipass "^2.0.0" + minipass "^3.0.0" + minizlib "^2.1.1" + mkdirp "^1.0.3" + yallist "^4.0.0" + tar@^2.0.0: version "2.2.2" resolved "https://registry.yarnpkg.com/tar/-/tar-2.2.2.tgz#0ca8848562c7299b8b446ff6a4d60cdbb23edc40"