Package
code-server
Component
tar-fs
Latest update
Fixed version
4.105.1-r1
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
4.105.1-r1Status
Impact
The tar-fs vulnerability exists in the vscode submodule at /usr/lib/code-server/lib/vscode/node_modules/tar-fs. npm overrides set in the top-level package.json do not apply to the vscode submodule's dependencies because vscode has its own committed package-lock.json from upstream Microsoft repository. The fix requires upstream vscode to update tar-fs to 3.1.1+.
Status