Skip to content

Upgrade node-sass to resolve tar vulnerability #796

@shawnbot

Description

@shawnbot

See sass/node-sass#2625 (comment) for why this is tricky to fix.

TL;DR: Deep down in our dependency tree (node-sassnode-gypnode-tar) lives an old version of tar that's susceptible to an arbitrary file overwrite vulnerability. We can't resolve it by just installing a newer version of tar; we're stuck waiting on a new node-sass release.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions