Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: upgrade lerna to fix CVE with tar dependency #4555

Merged
merged 2 commits into from
Jun 26, 2024

Conversation

mrgrain
Copy link
Contributor

@mrgrain mrgrain commented Jun 26, 2024

See GHSA-f5x3-32g6-xq36
The affected version of tar is only used in build tooling, i.e. no risk to published packages.


By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@mergify mergify bot added the contribution/core This is a PR that came from AWS. label Jun 26, 2024
Copy link
Contributor

mergify bot commented Jun 26, 2024

Thank you for contributing! ❤️ I will now look into making sure the PR is up-to-date, then proceed to try and merge it!

@mergify mergify bot added the pr/ready-to-merge This PR is ready to be merged. label Jun 26, 2024
Copy link
Contributor

mergify bot commented Jun 26, 2024

Merging (with squash)...

@mergify mergify bot merged commit 7b91e7a into main Jun 26, 2024
37 checks passed
@mergify mergify bot deleted the mrgrain/chore/update-tar branch June 26, 2024 11:13
@mergify mergify bot removed the pr/ready-to-merge This PR is ready to be merged. label Jun 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
contribution/core This is a PR that came from AWS.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants