Skip to content

fix: updates node-gyp and ssh2 to fix vulnerable transitive dependencies#3528

Open
tlowrimore-heroku wants to merge 1 commit intomainfrom
tl/fix-node-tar-vuln-pt-2
Open

fix: updates node-gyp and ssh2 to fix vulnerable transitive dependencies#3528
tlowrimore-heroku wants to merge 1 commit intomainfrom
tl/fix-node-tar-vuln-pt-2

Conversation

@tlowrimore-heroku
Copy link
Contributor

Summary

This PR updates node-gyp and ssh2 to fix a vulnerability in node-tar.

Type of Change

Breaking Changes (major semver update)

  • Add a ! after your change type to denote a change that breaks current behavior

Feature Additions (minor semver update)

  • feat: Introduces a new feature to the codebase

Patch Updates (patch semver update)

  • fix: Bug fix
  • deps: Dependency upgrade
  • revert: Revert a previous commit
  • chore: Change that does not affect production code
  • refactor: Refactoring existing code without changing behavior
  • test: Add/update/remove tests

Related Issues

Dependabot Issues: 208, 205, and 202

@tlowrimore-heroku tlowrimore-heroku marked this pull request as ready for review February 13, 2026 22:57
@tlowrimore-heroku tlowrimore-heroku requested a review from a team as a code owner February 13, 2026 22:57
Copy link
Contributor

@michaelmalave michaelmalave left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants