Skip to content

chore(deps): bump tar from 7.5.19 to 7.5.21 - #27

Merged
jhfnetboy merged 1 commit into
masterfrom
dependabot/npm_and_yarn/tar-7.5.21
Oct 2, 2026
Merged

jhfnetboy merged 1 commit into
masterfrom
dependabot/npm_and_yarn/tar-7.5.21

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 30, 2026 •

Copy link
Copy Markdown
Contributor

Bumps tar from 7.5.19 to 7.5.21.

Commits

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.19 to 7.5.21.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v7.5.19...v7.5.21)

---
updated-dependencies:
- dependency-name: tar
  dependency-version: 7.5.21
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 30, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 30, 2026

@clestons clestons left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PR-Daemon Review (2-round, pure dependency bump)

Change: tar 7.5.19→7.5.21

Diff is limited to lockfile/manifest (or a single pinned-version bump in a workflow file, YAML-validated) — no source/logic/config touched. Per pr-daemon-loop policy, pure version bumps skip the Codex PK round.

Verdict: APPROVE

@clestons clestons left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Multi-round review (DeepSeek R1 + Opus R2/R4 + Codex R3 PK)

Verdict below is from the pr-daemon-loop v4 pipeline.

VERDICT: APPROVE

TOP FINDINGS:

  • [Low] package-lock.json:16365 — registry flip npmmirror→npmjs for tar only; rest of lockfile stays npmmirror (consistency/cosmetic, non-blocking — npmjs is the canonical registry; NOT a supply-chain concern since integrity verified)
  • [Verify-OK] tar 7.5.21 integrity sha512-XdhtCvl...== matches npm registry exactly
  • [Verify-OK] No transitive drift — tar dep set unchanged (@isaacs/fs-minipass, chownr, minipass, minizlib, yallist, same ranges)
  • [Verify-OK] tar used only in data-tools.service.ts (own-data export/import), not untrusted archive parsing

MODELS ACTUALLY RAN:
R1=deepseek-v4-flash (R1a full + R1b security, both real, parallel)
R2=N/A R3=N/A R4=N/A
(2-round path: Sonnet-executor verdict only. NO real Opus R2/R4, NO real Codex R3 — deliberately, per honest triage of a trivial dep bump. If you specifically want the real-Anthropic R2/R4 backend exercised, point this validation at a code-touching PR.)
ROUNDS: 2 — pure dependabot version bump + lockfile only, no src/ logic, no security surface; 2-round is the honest call and forcing 4 would be fabrication.

@clestons clestons left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE — #27 @ ef90abf [2-round]

tar 7.5.19→7.5.21。不只是常规 bump:master 当前 npm audit 报 tar <=7.5.20(high,GHSA-r292-9mhp-454m,mapHas/filesFilter 无界递归导致栈溢出 DoS,构造超长路径 tar 触发),此 bump 恰好越过该版本边界——本 PR 分支 npm audit 已不再出现这条。同样的 registry 切换(npmmirror→npmjs,无仓库级镜像固定,非阻塞)。CI 14/14 全绿,未锁定。批准,建议优先合并(真实 CVE 修复)。

@clestons clestons left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

R1a (DeepSeek, full diff)

Triage: trivial — dependency version bump only, no core logic change.
tar 7.5.19→7.5.21. No application source code touched (package.json/package-lock.json only). CI all green (Build/Test/TypeCheck/CodeQL/Trivy/Security Audit all pass on this PR's head).

Verdict

2-round (pure dependency-manifest bump, no source change — Codex PK skipped per standing policy for pure version bumps).

APPROVE — lockfile/manifest-only change, CI clean, no blocking findings.

@jhfnetboy
jhfnetboy merged commit c877034 into master Oct 2, 2026
14 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/tar-7.5.21 branch October 2, 2026 13:31
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 2, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants