actions-runner
Chainguard
Status
Justification
Impact
The vulnerable tar package is included as a transitive dependency of Node.js through npm. However, npm does not utilize the affected code path. For more details, refer to the upstream discussions: https://github.com/nodejs/node/pull/60430#issuecomment-3455536702 and https://github.com/nodejs/node/pull/60012#issuecomment-3452094442
Status