Skip to content

chore: bump tar to 7.5.7#5472

Merged
knolleary merged 1 commit intonode-red:masterfrom
bryopsida:patch-tar
Feb 11, 2026
Merged

chore: bump tar to 7.5.7#5472
knolleary merged 1 commit intonode-red:masterfrom
bryopsida:patch-tar

Conversation

@bryopsida
Copy link
Copy Markdown
Contributor

@bryopsida bryopsida commented Jan 31, 2026

Types of changes

  • Bugfix (non-breaking change which fixes an issue)

Proposed changes

Bumps tar from 7.5.6 to 7.5.7 to resolve findings in npm audit --production

Checklist

  • I have read the contribution guidelines
  • For non-bugfix PRs, I have discussed this change on the forum/slack team.
  • I have run npm run test to verify the unit tests pass
  • I have added suitable unit tests to cover the new/changed functionality

Signed-off-by: bryopsida <8363252+bryopsida@users.noreply.github.com>
@knolleary
Copy link
Copy Markdown
Member

Thanks for this, however your PR is also modifying the NR package versions. That is something the release process handles - so in future for similar cases, please just bump the version of the dependency.

As we want to get the 4.1.5 release done today, I am going to merge your PR as-is, but please keep this in mind for the future.

@knolleary knolleary merged commit dc6a86d into node-red:master Feb 11, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants