Update dependency tar to v7 [SECURITY] - #12
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
January 11, 2025 11:49
a494498 to
ce1dbab
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
January 15, 2025 19:40
ce1dbab to
93267a9
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
January 17, 2025 11:45
93267a9 to
98f71a8
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
January 25, 2025 11:49
98f71a8 to
954e52d
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
January 26, 2025 06:13
954e52d to
1182a60
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
January 31, 2025 19:07
1182a60 to
20778a6
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
February 1, 2025 19:46
20778a6 to
f3d6735
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
February 9, 2025 11:31
f3d6735 to
1c19a60
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
February 12, 2025 07:54
1c19a60 to
62f2f10
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
March 5, 2025 03:44
62f2f10 to
bba3d66
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
March 8, 2025 03:32
bba3d66 to
55a1c46
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
March 13, 2025 08:04
55a1c46 to
9101ad9
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
March 15, 2025 11:18
9101ad9 to
fd6191e
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
March 19, 2025 23:59
fd6191e to
470ca78
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
March 21, 2025 23:49
470ca78 to
f7d2871
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
May 17, 2025 04:02
b8cbfde to
31c00e9
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
May 18, 2025 19:27
31c00e9 to
51342e4
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
May 24, 2025 11:33
51342e4 to
dfb563a
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
May 25, 2025 11:37
dfb563a to
f954d83
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
May 31, 2025 12:12
f954d83 to
d5f706d
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
June 1, 2025 19:14
d5f706d to
ce0c4c9
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
June 6, 2025 18:23
ce0c4c9 to
d48cb88
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
June 8, 2025 10:34
d48cb88 to
520cd9f
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
June 21, 2025 12:03
520cd9f to
c820d3f
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
July 13, 2025 23:55
c820d3f to
609f396
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
August 11, 2025 03:26
609f396 to
3acb651
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
August 16, 2025 11:48
3acb651 to
5c1e390
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
August 21, 2025 04:16
5c1e390 to
13984ff
Compare
renovate
Bot
force-pushed
the
renovate/npm-tar-vulnerability
branch
from
August 24, 2025 04:12
13984ff to
ba0888d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
~0.1.12→~7.5.11Symlink Arbitrary File Overwrite in tar
CVE-2015-8860 / GHSA-gfjr-3jmm-4g9v
More information
Details
Versions of
tarprior to 2.0.0 are affected by an arbitrary file write vulnerability. The vulnerability occurs becausetardoes not verify that extracted symbolic links to not resolve to targets outside of the extraction root directory.Recommendation
Update to version 2.0.0 or later
Severity
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Arbitrary File Overwrite in tar
CVE-2018-20834 / GHSA-j44m-qm6p-hp7m
More information
Details
Versions of
tarprior to 4.4.2 for 4.x and 2.2.2 for 2.x are vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink will overwrite the system's file with the contents of the extracted file.Recommendation
For tar 4.x, upgrade to version 4.4.2 or later.
For tar 2.x, upgrade to version 2.2.2 or later.
Severity
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization
CVE-2021-32804 / GHSA-3jfq-g458-7qm9
More information
Details
Impact
Arbitrary File Creation, Arbitrary File Overwrite, Arbitrary Code Execution
node-taraims to prevent extraction of absolute file paths by turning absolute paths into relative paths when thepreservePathsflag is not set totrue. This is achieved by stripping the absolute path root from any absolute file paths contained in a tar file. For example/home/user/.bashrcwould turn intohome/user/.bashrc.This logic was insufficient when file paths contained repeated path roots such as
////home/user/.bashrc.node-tarwould only strip a single path root from such paths. When given an absolute file path with repeating path roots, the resulting path (e.g.///home/user/.bashrc) would still resolve to an absolute path, thus allowing arbitrary file creation and overwrite.Patches
3.2.2 || 4.4.14 || 5.0.6 || 6.1.1
NOTE: an adjacent issue CVE-2021-32803 affects this release level. Please ensure you update to the latest patch levels that address CVE-2021-32803 as well if this adjacent issue affects your
node-taruse case.Workarounds
Users may work around this vulnerability without upgrading by creating a custom
onentrymethod which sanitizes theentry.pathor afiltermethod which removes entries with absolute paths.Users are encouraged to upgrade to the latest patch versions, rather than attempt to sanitize tar input themselves.
Severity
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization
CVE-2021-37713 / GHSA-5955-9wpr-37jh
More information
Details
Impact
Arbitrary File Creation, Arbitrary File Overwrite, Arbitrary Code Execution
node-tar aims to guarantee that any file whose location would be outside of the extraction target directory is not extracted. This is, in part, accomplished by sanitizing absolute paths of entries within the archive, skipping archive entries that contain
..path portions, and resolving the sanitized paths against the extraction target directory.This logic was insufficient on Windows systems when extracting tar files that contained a path that was not an absolute path, but specified a drive letter different from the extraction target, such as
C:some\path. If the drive letter does not match the extraction target, for exampleD:\extraction\dir, then the result ofpath.resolve(extractionDirectory, entryPath)would resolve against the current working directory on theC:drive, rather than the extraction target directory.Additionally, a
..portion of the path could occur immediately after the drive letter, such asC:../foo, and was not properly sanitized by the logic that checked for..within the normalized and split portions of the path.This only affects users of
node-taron Windows systems.Patches
4.4.18 || 5.0.10 || 6.1.9
Workarounds
There is no reasonable way to work around this issue without performing the same path normalization procedures that node-tar now does.
Users are encouraged to upgrade to the latest patched versions of node-tar, rather than attempt to sanitize paths themselves.
Fix
The fixed versions strip path roots from all paths prior to being resolved against the extraction target folder, even if such paths are not "absolute".
Additionally, a path starting with a drive letter and then two dots, like
c:../, would bypass the check for..path portions. This is checked properly in the patched versions.Finally, a defense in depth check is added, such that if the
entry.absoluteis outside of the extraction taret, and we are not in preservePaths:true mode, a warning is raised on that entry, and it is skipped. Currently, it is believed that this check is redundant, but it did catch some oversights in development.Severity
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Denial of service while parsing a tar file due to lack of folders count validation
CVE-2024-28863 / GHSA-f5x3-32g6-xq36
More information
Details
Description:
During some analysis today on npm's
node-tarpackage I came across the folder creation process, Basicly if you provide node-tar with a path like this./a/b/c/foo.txtit would create every folder and sub-folder here a, b and c until it reaches the last folder to createfoo.txt, In-this case I noticed that there's no validation at all on the amount of folders being created, that said we're actually able to CPU and memory consume the system running node-tar and even crash the nodejs client within few seconds of running it using a path with too many sub-folders insideSteps To Reproduce:
You can reproduce this issue by downloading the tar file I provided in the resources and using node-tar to extract it, you should get the same behavior as the video
Proof Of Concept:
Here's a video show-casing the exploit:
Impact
Denial of service by crashing the nodejs client when attempting to parse a tar archive, make it run out of heap memory and consuming server CPU and memory resources
Report resources
payload.txt
archeive.tar.gz
Note
This report was originally reported to GitHub bug bounty program, they asked me to report it to you a month ago
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
CVE-2026-23745 / GHSA-8qq5-rm4j-mr97
More information
Details
Summary
The
node-tarlibrary (<= 7.5.2) fails to sanitize thelinkpathofLink(hardlink) andSymbolicLinkentries whenpreservePathsis false (the default secure behavior). This allows malicious archives to bypass the extraction root restriction, leading to Arbitrary File Overwrite via hardlinks and Symlink Poisoning via absolute symlink targets.Details
The vulnerability exists in
src/unpack.tswithin the[HARDLINK]and[SYMLINK]methods.1. Hardlink Escape (Arbitrary File Overwrite)
The extraction logic uses
path.resolve(this.cwd, entry.linkpath)to determine the hardlink target. Standard Node.js behavior dictates that if the second argument (entry.linkpath) is an absolute path,path.resolveignores the first argument (this.cwd) entirely and returns the absolute path.The library fails to validate that this resolved target remains within the extraction root. A malicious archive can create a hardlink to a sensitive file on the host (e.g.,
/etc/passwd) and subsequently write to it, if file permissions allow writing to the target file, bypassing path-based security measures that may be in place.2. Symlink Poisoning
The extraction logic passes the user-supplied
entry.linkpathdirectly tofs.symlinkwithout validation. This allows the creation of symbolic links pointing to sensitive absolute system paths or traversing paths (../../), even when secure extraction defaults are used.PoC
The following script generates a binary TAR archive containing malicious headers (a hardlink to a local file and a symlink to
/etc/passwd). It then extracts the archive using standardnode-tarsettings and demonstrates the vulnerability by verifying that the local "secret" file was successfully overwritten.Impact
LinkandSymbolicLinktar entries from extracted packages.)Severity
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS
CVE-2026-23950 / GHSA-r6q2-hw4h-h46w
More information
Details
TITLE: Race Condition in node-tar Path Reservations via Unicode Sharp-S (ß) Collisions on macOS APFS
AUTHOR: Tomás Illuminati
Details
A race condition vulnerability exists in
node-tar(v7.5.3) this is to an incomplete handling of Unicode path collisions in thepath-reservationssystem. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g.,ßandss), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses aPathReservationssystem to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently.In MacOS the
join(normalizeUnicode(p)),FS confuses ß with ss, but this code does not. For example:PoC
Impact
This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using
NFDUnicode normalization (in whichßandssare different), conflicting paths do not have their order properly preserved under filesystems that ignore Unicode normalization (e.g., APFS (in whichßcauses an inode collision withss)). This enables an attacker to circumvent internal parallelization locks (PathReservations) using conflicting filenames within a malicious tar archive.Remediation
Update
path-reservations.jsto use a normalization form that matches the target filesystem's behavior (e.g.,NFKD), followed by firsttoLocaleLowerCase('en')and thentoLocaleUpperCase('en').Users who cannot upgrade promptly, and who are programmatically using
node-tarto extract arbitrary tarball data should filter out allSymbolicLinkentries (as npm does) to defend against arbitrary file writes via this file system entry name collision issue.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal
CVE-2026-24842 / GHSA-34x7-hfp2-rc4v
More information
Details
Summary
node-tar contains a vulnerability where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory.
Details
The vulnerability exists in
lib/unpack.js. When extracting a hardlink, two functions handle the linkpath differently:Security check in
[STRIPABSOLUTEPATH]:Hardlink creation in
[HARDLINK]:Example: An application extracts a TAR using
tar.extract({ cwd: '/var/app/uploads/' }). The TAR contains entrya/b/c/d/xas a hardlink to../../../../etc/passwd.Security check resolves the linkpath relative to the entry's parent directory:
a/b/c/d/ + ../../../../etc/passwd=etc/passwd. No../prefix, so it passes.Hardlink creation resolves the linkpath relative to the extraction directory (
this.cwd):/var/app/uploads/ + ../../../../etc/passwd=/etc/passwd. This escapes to the system's/etc/passwd.The security check and hardlink creation use different starting points (entry directory
a/b/c/d/vs extraction directory/var/app/uploads/), so the same linkpath can pass validation but still escape. The deeper the entry path, the more levels an attacker can escape.PoC
Setup
Create a new directory with these files:
package.json
{ "dependencies": { "tar": "^7.5.0" } }secret.txt (sensitive file outside uploads/)
server.js (vulnerable file upload server)
create-malicious-tar.js (attacker creates exploit TAR)
Run
Impact
An attacker can craft a malicious TAR archive that, when extracted by an application using node-tar, creates hardlinks that escape the extraction directory. This enables:
Immediate (Read Attack): If the application serves extracted files, attacker can read any file readable by the process.
Conditional (Write Attack): If the application later writes to the hardlink path, it modifies the target file outside the extraction directory.
Remote Code Execution / Server Takeover
~/.ssh/authorized_keys/etc/cron.d/*,~/.crontab~/.bashrc,~/.profile.js,.php,.pyfiles/etc/systemd/system/*.service/etc/passwd(if running as root)Data Exfiltration & Corruption
.env, secretsSeverity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction
CVE-2026-26960 / GHSA-83g3-92jg-28cx
More information
Details
Summary
tar.extract()in Nodetarallows an attacker-controlled archive to create a hardlink inside the extraction directory that points to a file outside the extraction root, using default options.This enables arbitrary file read and write as the extracting user (no root, no chmod, no
preservePaths).Severity is high because the primitive bypasses path protections and turns archive extraction into a direct filesystem access primitive.
Details
The bypass chain uses two symlinks plus one hardlink:
a/b/c/up -> ../..a/b/escape -> c/up/../..exfil(hardlink) ->a/b/escape/<target-relative-to-parent-of-extract>Why this works:
Linkpath checks are string-based and do not resolve symlinks on disk for hardlink target safety.
STRIPABSOLUTEPATHlogic in:../tar-audit-setuid - CVE/node_modules/tar/dist/commonjs/unpack.js:255../tar-audit-setuid - CVE/node_modules/tar/dist/commonjs/unpack.js:268../tar-audit-setuid - CVE/node_modules/tar/dist/commonjs/unpack.js:281Hardlink extraction resolves target as
path.resolve(cwd, entry.linkpath)and then callsfs.link(target, destination).../tar-audit-setuid - CVE/node_modules/tar/dist/commonjs/unpack.js:566../tar-audit-setuid - CVE/node_modules/tar/dist/commonjs/unpack.js:567../tar-audit-setuid - CVE/node_modules/tar/dist/commonjs/unpack.js:703Parent directory safety checks (
mkdir+ symlink detection) are applied to the destination path of the extracted entry, not to the resolved hardlink target path.../tar-audit-setuid - CVE/node_modules/tar/dist/commonjs/unpack.js:617../tar-audit-setuid - CVE/node_modules/tar/dist/commonjs/unpack.js:619../tar-audit-setuid - CVE/node_modules/tar/dist/commonjs/mkdir.js:27../tar-audit-setuid - CVE/node_modules/tar/dist/commonjs/mkdir.js:101As a result,
exfilis created inside extraction root but linked to an external file. The PoC confirms shared inode and successful read+write viaexfil.PoC
hardlink.js
Environment used for validation:
v25.4.07.5.7tar.extract({ file, cwd }))Steps:
Prepare/locate a
tarmodule. Ifrequire('tar')is not available locally, setTAR_MODULEto an absolute path to a tar package directory.Run:
TAR_MODULE="$(cd '../tar-audit-setuid - CVE/node_modules/tar' && pwd)" node hardlink.jsInterpretation:
same_inode=true: extractedexfiland external secret are the same file object.read_ok=true: readingexfilleaks external content.write_ok=true: writingexfilmodifies external file.Impact
Vulnerability type:
Who is impacted:
tardefaults.Potential outcomes:
Severity
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
tar has Hardlink Path Traversal via Drive-Relative Linkpath
CVE-2026-29786 / GHSA-qffp-2rhf-9h96
More information
Details
Summary
tar(npm) can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such asC:../target.txt, which enables file overwrite outsidecwdduring normaltar.x()extraction.Details
The extraction logic in
Unpack[STRIPABSOLUTEPATH]checks for..segments before stripping absolute roots.What happens with
linkpath: "C:../target.txt":/gives['C:..', 'target.txt'], soparts.includes('..')is false.stripAbsolutePath()removesC:and rewrites the value to../target.txt.cwdand escapes one directory up.This is reachable in standard usage (
tar.x({ cwd, file })) when extracting attacker-controlled tar archives.PoC
Tested on Arch Linux with
tar@7.5.9.PoC script (
poc.cjs):Run:
Observed output:
PWNEDconfirms outside file content overwrite. Link count2confirms the extracted file and../target.txtare hardlinked.Impact
This is an arbitrary file overwrite primitive outside the intended extraction root, with the permissions of the process performing extraction.
Realistic scenarios:
Severity
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:H/SA:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
node-tar Symlink Path Traversal via Drive-Relative Linkpath
CVE-2026-31802 / GHSA-9ppj-qmqm-q256
More information
Details
Summary
tar(npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such asC:../../../target.txt, which enables file overwrite outsidecwdduring normaltar.x()extraction.Details
The extraction logic in
Unpack[STRIPABSOLUTEPATH]validates..segments against a resolved path that still uses the original drive-relative value, and only afterwards rewrites the storedlinkpathto the stripped value.What happens with
linkpath: "C:../../../target.txt":stripAbsolutePath()removesC:and rewrites the value to../../../target.txt.../../../target.txt) from nested patha/b/l.../target.txt).This is reachable in standard usage (
tar.x({ cwd, file })) when extracting attacker-controlled tar archives.PoC
Tested on Arch Linux with
tar@7.5.10.PoC script (
poc.cjs):Run:
Observed output:
PWNEDconfirms outside file content overwrite.readlinkandls -lconfirm the extracted symlink points outside the extraction directory.Impact
This is an arbitrary file overwrite primitive outside the intended extraction root, with the permissions of the process performing extraction.
Realistic scenarios:
Severity
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
isaacs/node-tar (tar)
v7.5.11Compare Source
v7.5.10Compare Source
v7.5.9Compare Source
v7.5.8Compare Source
v7.5.7Compare Source
v7.5.6Compare Source
v7.5.5Compare Source
v7.5.4Compare Source
v7.5.3Compare Source
v7.5.2Compare Source
v7.5.1Compare Source
v7.5.0Compare Source
v7.4.4Compare Source
v7.4.3Compare Source
v7.4.2Compare Source
v7.4.1Compare Source
v7.4.0Compare Source
v7.3.0Compare Source
v7.2.0Compare Source
v7.1.0Compare Source
v7.0.1Compare Source
v7.0.0Compare Source
v6.2.1Compare Source
v6.2.0Compare Source
v6.1.15Compare Source
v6.1.14Compare Source
v6.1.13Compare Source
Dependencies
cc4e0dd#343 bump minipass from 3.3.6 to 4.0.0v6.1.12Compare Source
Bug Fixes
57493ee#332 ensuring close event is emited after stream has ended (@webark)b003c64#314 replace deprecated String.prototype.substr() (#314) (@CommanderRoot, @lukekarrys)Documentation
f129929](https:/Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.