Skip to content

[Security] tar ≤7.5.10 transitive dependency in uniwind-pro has 7 known vulnerabilities (2 high severity) #474

@dacoto

Description

@dacoto

What happened?

The tar package (≤7.5.10), a transitive dependency of uniwind-pro, has 7 known vulnerabilities (5 low, 2 high severity) flagged by npm audit:

The fix suggested by npm (npm audit fix --force) would install undefined@undefined, indicating no safe upgrade path exists without uniwind-pro updating its own dependency.

Steps to Reproduce

  1. Install uniwind-pro in any project
  2. Run npm audit
  3. Observe 7 vulnerabilities reported in node_modules/tar, pulled in by node_modules/uniwind

Snack or Repository Link

https://github.com/dacoto/transportam-app

Uniwind version

1.0.0-rc.6

React Native Version

0.83.2

Platforms

Android, iOS

Expo

Yes

Additional information

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions