Skip to content

chore: upgrade lerna to fix CVE with tar dependency#4555

Merged
mergify[bot] merged 2 commits intomainfrom
mrgrain/chore/update-tar
Jun 26, 2024
Merged

chore: upgrade lerna to fix CVE with tar dependency#4555
mergify[bot] merged 2 commits intomainfrom
mrgrain/chore/update-tar

Conversation

@mrgrain
Copy link
Copy Markdown
Contributor

@mrgrain mrgrain commented Jun 26, 2024

See GHSA-f5x3-32g6-xq36
The affected version of tar is only used in build tooling, i.e. no risk to published packages.


By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@mergify mergify Bot added the contribution/core This is a PR that came from AWS. label Jun 26, 2024
@mergify
Copy link
Copy Markdown
Contributor

mergify Bot commented Jun 26, 2024

Thank you for contributing! ❤️ I will now look into making sure the PR is up-to-date, then proceed to try and merge it!

@mergify mergify Bot added the pr/ready-to-merge This PR is ready to be merged. label Jun 26, 2024
@mergify
Copy link
Copy Markdown
Contributor

mergify Bot commented Jun 26, 2024

Merging (with squash)...

@mergify mergify Bot merged commit 7b91e7a into main Jun 26, 2024
@mergify mergify Bot deleted the mrgrain/chore/update-tar branch June 26, 2024 11:13
@mergify mergify Bot removed the pr/ready-to-merge This PR is ready to be merged. label Jun 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contribution/core This is a PR that came from AWS.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants