Skip to content

Commit 811c326

Browse files
authored
fix(security): Bump tar to 7.5.9 and lerna to 9.0.4 to fix CVE-2026-26960 (#2618)
1 parent fdc31b2 commit 811c326

File tree

4 files changed

+1678
-1001
lines changed

4 files changed

+1678
-1001
lines changed

.circleci/config.yml

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -38,9 +38,6 @@ jobs:
3838
# Define ignored vulnerabilities with comments
3939
IGNORED_VULNS=(
4040
"GHSA-5j98-mcp5-4vw2" # CVE-2025-64756 - glob is not used on the command line
41-
"GHSA-8qq5-rm4j-mr97" # CVE-2026-23745 - limited to build/dev environments
42-
"GHSA-r6q2-hw4h-h46w" # CVE-2026-23950 - limited to build/dev environments
43-
"GHSA-34x7-hfp2-rc4v" # CVE-2026-24842 - limited to build/dev environments
4441
)
4542
4643
# Build ignore flags

0 commit comments

Comments
 (0)