Skip to content

Conversation

@rafaellehmkuhl
Copy link
Member

Problem

The tar package has a high-severity vulnerability (CVE-2026-23950) affecting all versions before 7.5.4. The yarn.lock currently has two vulnerable versions:

tar@6.2.1 - used by @electron/rebuild, electron-builder, node-gyp, cacache
tar@7.4.3 - used by @kmamal/sdl

Solution

Add a yarn resolution to force all tar dependencies to version 7.5.4 or later.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants