Skip to content

fix(deps): [release-1.8] bump tar from 7.4.3 to 7.5.15#4858

Merged
openshift-merge-bot[bot] merged 1 commit into
redhat-developer:release-1.8from
jonkoops:fix-tar-v6-1.8
May 25, 2026
Merged

fix(deps): [release-1.8] bump tar from 7.4.3 to 7.5.15#4858
openshift-merge-bot[bot] merged 1 commit into
redhat-developer:release-1.8from
jonkoops:fix-tar-v6-1.8

Conversation

@jonkoops
Copy link
Copy Markdown
Contributor

Bumps tar from 7.4.3 to 7.5.15 in both the root and dynamic-plugins lockfiles. The previous version was resolved by yarn-lockfile-surgeon to the minimum satisfying version, but 7.4.3 is deprecated and flagged for known vulnerabilities. This is a lockfile-only change with no package.json modifications.

Remaining tar v6 (6.2.1) references will be addressed separately.

@openshift-ci openshift-ci Bot requested review from invincibleJai and kim-tsao May 19, 2026 16:45
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@josephca
Copy link
Copy Markdown
Member

/retest

@github-actions
Copy link
Copy Markdown
Contributor

The container image build workflow finished with status: failure.

tar 7.4.3 is deprecated and contains known vulnerabilities. Bumps to
7.5.15, the latest non-deprecated release.

Signed-off-by: Jon Koops <jonkoops@gmail.com>
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@josephca
Copy link
Copy Markdown
Member

/lgtm

@openshift-ci openshift-ci Bot added the lgtm label May 25, 2026
@openshift-merge-bot openshift-merge-bot Bot merged commit 30492f5 into redhat-developer:release-1.8 May 25, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants