Skip to content

chore(deps): Bump modern-tar from 0.7.3 to 0.7.5 in /bdist/js#534

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/bdist/js/modern-tar-0.7.5
Open

chore(deps): Bump modern-tar from 0.7.3 to 0.7.5 in /bdist/js#534
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/bdist/js/modern-tar-0.7.5

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Mar 4, 2026

Bumps modern-tar from 0.7.3 to 0.7.5.

Release notes

Sourced from modern-tar's releases.

v0.7.5

Overview

Full Changelog: ayuhito/modern-tar@v0.7.4...v0.7.5

v0.7.4

Overview

A few correctness fixes and security enhancements 🛡️

Full Changelog: ayuhito/modern-tar@v0.7.3...v0.7.4

Commits
  • 79e4d4b fix(options): strip relative hardlink linknames (#118)
  • 98df8be chore: bump version to 0.7.4
  • 857578e fix(fs): strip sticky bits
  • e223bfb fix(tar): prevent prototype pollution in PAX headers (#117)
  • 76efe5c fix: parsing of archives with directories that have type=FILE name=.../ (#115)
  • 0aae183 Fix parsing of archives with type=link entries with size!=0 (#116)
  • b7cd92c chore: bump version to 0.7.3
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [modern-tar](https://github.com/ayuhito/modern-tar) from 0.7.3 to 0.7.5.
- [Release notes](https://github.com/ayuhito/modern-tar/releases)
- [Commits](ayuhito/modern-tar@v0.7.3...v0.7.5)

---
updated-dependencies:
- dependency-name: modern-tar
  dependency-version: 0.7.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Mar 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant