Skip to content

chore: bump tar#2542

Merged
jakehobbs merged 1 commit into
mainfrom
jake/update-tar-7-5-16
Jun 16, 2026
Merged

chore: bump tar#2542
jakehobbs merged 1 commit into
mainfrom
jake/update-tar-7-5-16

Conversation

@jakehobbs

@jakehobbs jakehobbs commented Jun 16, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • chore: bump tar

Test plan

  • fnm exec --using=22.20.0 pnpm install --frozen-lockfile --lockfile-only

PR-Codex overview

This PR updates the version of the tar package from 7.5.15 to 7.5.16 in both the .vitest/package.json and pnpm-lock.yaml files to address security vulnerabilities present in older versions.

Detailed summary

  • Updated tar version in .vitest/package.json from 7.5.15 to 7.5.16.
  • Updated tar specifier and version in pnpm-lock.yaml from 7.5.15 to 7.5.16.
  • Changed integrity hash for tar@7.5.16 in pnpm-lock.yaml.

✨ Ask PR-Codex anything about this PR by commenting with /codex {your question}

Co-Authored-By: Codex <noreply@openai.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR bumps the tar dependency from 7.5.15 to 7.5.16 for the local Vitest workspace, updating the lockfile accordingly to pick up the patched version.

Changes:

  • Updated .vitest devDependency on tar to ^7.5.16.
  • Updated pnpm-lock.yaml entries (importer, package resolution, snapshot) to tar@7.5.16 with the new integrity hash.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
.vitest/package.json Bumps tar devDependency to ^7.5.16.
pnpm-lock.yaml Updates lockfile records to resolve tar at 7.5.16 (including integrity and snapshot entries).
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

@jakehobbs jakehobbs enabled auto-merge (squash) June 16, 2026 18:05
@jakehobbs jakehobbs merged commit 6d0c5cb into main Jun 16, 2026
10 checks passed
@jakehobbs jakehobbs deleted the jake/update-tar-7-5-16 branch June 16, 2026 18:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants