Dávid Paksy created HBASE-29847:
-----------------------------------

             Summary: Bump tar from 7.5.2 to 7.5.6 in /hbase-website
                 Key: HBASE-29847
                 URL: https://issues.apache.org/jira/browse/HBASE-29847
             Project: HBase
          Issue Type: Task
          Components: website
            Reporter: Dávid Paksy


Dependabot found a new high severity security vulnerability in node-tar:

Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on 
macOS APFS

[https://github.com/apache/hbase/security/dependabot/124]

node-tar is a dependency in the hbase-website.

 

Dependabot created a new automated PR to fix this:

[https://github.com/apache/hbase/pull/7656]

 



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to