Skip to content

fix(deps): Patch critical tar archive vulnerability - #157

Merged
sds merged 1 commit into
mainfrom
centaur/fix-tar-security-advisories-1790652900
Sep 29, 2026
Merged

sds merged 1 commit into
mainfrom
centaur/fix-tar-security-advisories-1790652900

Conversation

@decofe

@decofe decofe commented Sep 29, 2026

Copy link
Copy Markdown
Member

CI dependency installation fails because Aegis rejects tar@7.5.16 with criticalCVE, as seen in PR #156's failed install. The installed version is affected by CVE-2026-59873 / GHSA-23hp-3jrh-7fpw, which permits resource exhaustion while extracting archives.

Pin the transitive tar dependency to 7.5.22 and regenerate the lockfile. This version also covers the newer GHSA-r292-9mhp-454m fix. The dependency comes from the development-only @yao-pkg/pkg packager, which uses tar to extract downloaded Node.js archives. Include a non-release changelog entry for this toolchain update.

This PR targets main independently of #156; merge this first, then update that PR from main. Existing security enforcement is unchanged.

Validation:

  • Frozen-lockfile install and dependency tree check: only tar 7.5.22 resolves.
  • Lint, application/test type checks, TypeScript build, CLI bundle, changed-file formatting, and changelog validation passed.
  • Created and extracted a small gzip archive using tar resolved through the packager; content matched.
  • Full unit tests and standalone binary generation were not rerun. The prior unit run was limited by the sandbox's missing sqlite3 executable. The CLI bundle retains its existing import.meta/CommonJS warning.
  • The live Aegis-protected CI install must confirm the policy block is cleared.

Prompted by: @sds

Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
@sds
sds merged commit 3989430 into main Sep 29, 2026
9 checks passed
@sds
sds deleted the centaur/fix-tar-security-advisories-1790652900 branch September 29, 2026 03:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants