Commit d74e397
authored
fix(security): upgrade tar to 7.5.3 for GHSA-8qq5-rm4j-mr97 (#298)
Adds npm override to force tar@7.5.3 across all dependencies to fix
path sanitization vulnerability (CVE-2026-23745). Also adds third-party
license notice for Blue Oak Model License 1.0.0.1 parent 9d21508 commit d74e397
3 files changed
Lines changed: 25 additions & 347 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
119 | 119 | | |
120 | 120 | | |
121 | 121 | | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
122 | 128 | | |
123 | 129 | | |
124 | 130 | | |
| |||
0 commit comments