Package
saf
Component
tar
Latest update
Fixed version
1.7.0-r0
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
1.7.0-r0Status
Impact
saf uses npm-11 which bundles the vulnerable version of tar. Upstream maintainers of npm will need to release a fixed version of npm-11 or saf will need to migrate to npm-12 to fix this vulnerability.
Status