Skip to content

Commit b34aee8

Browse files
committed
chore: add new security advisory GHSA-34x7-hfp2-rc4v to configuration
Ticket: WIN-8746
1 parent e711153 commit b34aee8

1 file changed

Lines changed: 6 additions & 0 deletions

File tree

.iyarc

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,3 +11,9 @@ GHSA-8qq5-rm4j-mr97
1111
# archive PACKING, not extraction,
1212
GHSA-r6q2-hw4h-h46w
1313

14+
# Excluded because:
15+
# - CVE-2026-24842: node-tar hardlink path traversal vulnerability
16+
# - Transitive dependency through lerna and yeoman-generator, which pin tar to < 7.5.7
17+
# - This CVE affects archive EXTRACTION (hardlink escape during unpacking)
18+
# - Lerna only uses tar for PACKING, not extraction
19+
GHSA-34x7-hfp2-rc4v

0 commit comments

Comments
 (0)