Skip to content

chore(deps): bump fast-uri to 3.1.4, tar to 7.5.22, drop 8 exclusions#9355

Open
github-actions[bot] wants to merge 1 commit into
masterfrom
osv-scanner-prune/20260727-automated-prune
Open

chore(deps): bump fast-uri to 3.1.4, tar to 7.5.22, drop 8 exclusions#9355
github-actions[bot] wants to merge 1 commit into
masterfrom
osv-scanner-prune/20260727-automated-prune

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Summary

  • Bumped fast-uri from 3.1.3 to 3.1.4 to resolve GHSA-v2hh-gcrm-f6hx
  • Upgraded tar resolutions to 7.5.22 across swarm-js, yeoman-generator, pacote paths
  • Removed 8 stale osv-scanner exclusions that are now fixed by the dependency upgrades

Removed exclusions

GHSA ID Package Vulnerability Fix Version
GHSA-v2hh-gcrm-f6hx fast-uri Host confusion via literal backslash 3.1.4+
GHSA-8qq5-rm4j-mr97 tar Symlink/hardlink extraction CVE 7.5.3+
GHSA-r6q2-hw4h-h46w tar Extraction CVE 7.5.4+
GHSA-34x7-hfp2-rc4v tar Crafted archives CVE 7.5.4+
GHSA-83g3-92jg-28cx tar Crafted archives CVE 7.5.4+
GHSA-qffp-2rhf-9h96 tar Hardlink path traversal 7.5.7+
GHSA-9ppj-qmqm-q256 tar Extraction CVE N/A
GHSA-23hp-3jrh-7fpw tar Decompression DoS 7.5.19+
GHSA-8x88-c5mf-7j5w tar Infinite loop via negative entry size 7.5.18+

Verification

OSV Scanner: All removed exclusions no longer flagged
check-deps: Cross-workspace version consistency verified
Dependencies: All resolutions upgraded successfully

Still blocked

These exclusions remain in place due to compatibility constraints:

🤖 Generated with Claude Code

… from osv-scanner.toml

- fast-uri: 3.1.3 → 3.1.4 (resolves GHSA-v2hh-gcrm-f6hx host confusion vulnerability)
- tar resolutions: 6.2.1 → 7.5.22 for swarm-js, yeoman-generator, and pacote paths
- Remove 8 stale osv-scanner exclusions:
  • GHSA-v2hh-gcrm-f6hx (fast-uri host confusion, fixed in 3.1.4)
  • GHSA-8qq5-rm4j-mr97 (tar symlink/hardlink, fixed in 7.5.3+)
  • GHSA-r6q2-hw4h-h46w (tar extraction CVE, fixed in 7.5.4+)
  • GHSA-34x7-hfp2-rc4v (tar crafted archives, fixed in 7.5.4+)
  • GHSA-83g3-92jg-28cx (tar crafted archives, fixed in 7.5.4+)
  • GHSA-qffp-2rhf-9h96 (tar hardlink traversal, fixed in 7.5.7+)
  • GHSA-9ppj-qmqm-q256 (tar extraction CVE)
  • GHSA-23hp-3jrh-7fpw (tar decompression DoS, fixed in 7.5.19+)
  • GHSA-8x88-c5mf-7j5w (tar infinite loop, fixed in 7.5.18+)

All fixes verified with osv-scanner and check-deps passes.

Ticket: HSM-429
@github-actions
github-actions Bot requested review from a team as code owners July 27, 2026 07:25
@github-actions github-actions Bot added automated Automated changes dependencies Updates to dependencies security Security-related changes labels Jul 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Automated changes dependencies Updates to dependencies security Security-related changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants