-
Notifications
You must be signed in to change notification settings - Fork 664
Closed
Labels
effort: easyProbably a quick fix. Want to contribute? :-)Probably a quick fix. Want to contribute? :-)help wantedIf you're looking to contribute, this issue is a good place to start!If you're looking to contribute, this issue is a good place to start!
Description
Summary
rush-lib is still using an old version of tar 6.x:
https://github.com/microsoft/rushstack/blob/main/libraries/rush-lib/package.json#L69
Old versions of tar have a security issue:
Repro steps
Use rush-lib in a repo and run a security scan.
Expected result: No issues
Actual result: 1 security issue
Details
rush-lib should be updated to use the latest version of tar.
Standard questions
Please answer these questions to help us investigate your issue more quickly:
N/A
atsikovCopilot
Metadata
Metadata
Labels
effort: easyProbably a quick fix. Want to contribute? :-)Probably a quick fix. Want to contribute? :-)help wantedIf you're looking to contribute, this issue is a good place to start!If you're looking to contribute, this issue is a good place to start!
Type
Projects
Status
Closed