[ 
https://issues.apache.org/jira/browse/YUNIKORN-3207?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18054285#comment-18054285
 ] 

Wilfred Spiegelenburg edited comment on YUNIKORN-3207 at 1/26/26 4:31 AM:
--------------------------------------------------------------------------

This is not a candidate for YuniKorn 1.8, targeting for YuniKorn 1.9:
 * Lodash is a test dependency
 * tar: we do not deliver unicode tar files or with hard links
 * tar is introduced as a dependency for the angular-cli which is not shipped 
and only used during the build phase.


was (Author: wifreds):
This is not a candidate for YuniKorn 1.8, targeting for YuniKorn 1.9:
 * Lodash is a test dependency
 * tar: we do not deliver unicode tar files or with hard links

Tar is introduced as a dependency for the angular-cli which is not shipped and 
only used during the build phase.

> Update dependencies for CVE fixes
> ---------------------------------
>
>                 Key: YUNIKORN-3207
>                 URL: https://issues.apache.org/jira/browse/YUNIKORN-3207
>             Project: Apache YuniKorn
>          Issue Type: Improvement
>          Components: security, webapp
>            Reporter: Wilfred Spiegelenburg
>            Priority: Major
>
> Another set of CVE upgrades that cannot be applied by dependabot:
>  * CVE-2025-13465: Lodash has Prototype Pollution Vulnerability in `_.unset` 
> and `_.omit` functions (Moderate)
>  * CVE-2026-23950 Race Condition in node-tar Path Reservations via Unicode 
> Ligature Collisions on macOS APFS (High)
>  * CVE-2026-23745 node-tar is Vulnerable to Arbitrary File Overwrite and 
> Symlink Poisoning via Insufficient Path Sanitization (High)



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to