Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
From https://nodesecurity.io/advisories/57: The tar module earlier than version 2.0.0 allow for archives to contain symbolic links that will overwrite targets outside the expected path for extraction. PR-URL: #797 Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
- Loading branch information
f5d86eb
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Awesome!