[v24.x] deps: patch npm/tar to not return uninitialized mem#60430
[v24.x] deps: patch npm/tar to not return uninitialized mem#60430ChALkeR wants to merge 1 commit intonodejs:v24.xfrom
Conversation
|
Review requested:
|
|
Fast-track has been requested by @nodejs-github-bot. Please π to approve. |
aduh95
left a comment
There was a problem hiding this comment.
Shouldn't we apply this diff also to
node/deps/corepack/dist/lib/corepack.cjs
Lines 15506 to 15508 in 82fc81c
|
@aduh95 this PR targets 24.x branch. |
|
If |
|
@aduh95 is there a reason to bypass the regular procedure in main? |
|
@aduh95 also pls fell free to retarget this to the correct branch / force-push to my branch, I'm out of context of the staging branches |
The regular procedure is for changes to first land upstream, then it can be cherry-picked to |
Only if we we want to merge the non zero-filling behavior to 24 asap. It's not needed otherwise |
|
See #60012 (comment) I also rechecked the usage (so it was now checked by 2 people), |
This goes against the npm update procedure but we don't have much time before LTS to revert zero-filling to wait for isaacs/node-tar#446,
tarandnpmreleasesAn alternative is to force
.allocinstead of.allocUnsafethereRefs:
js/file-system-race(CWE-367) security issueΒ isaacs/node-tar#444