Skip to content
This repository was archived by the owner on Aug 27, 2026. It is now read-only.

fix(deps): refresh mintlify to pull tar 7.5.21 - #33

Closed
YushaArif99 wants to merge 1 commit into
mainfrom
fix/dependabot-high-critical-overdue
Closed

fix(deps): refresh mintlify to pull tar 7.5.21#33
YushaArif99 wants to merge 1 commit into
mainfrom
fix/dependabot-high-critical-overdue

Conversation

@YushaArif99

Copy link
Copy Markdown
Member

Clears the open critical Dependabot alert #216 — node-tar <= 7.5.18, CVE-2026-59873 (decompression DoS via unlimited input) — plus the four medium tar alerts (#179, #215, #214, #224, worst range <= 7.5.20). tar arrives transitively through @mintlify/previewing; the current mintlify release pins tar 7.5.21.

Lockfile-only change (root mintlify range ^4.0.195 already permits the new version). Smoke-tested: npx mintlify broken-links runs clean on the refreshed install. Note: the newer CLI auto-upgrades mint.jsondocs.json on first run — deliberately not included here, left for the docs owners.

Vanta: returns packages-checked-for-vulnerabilities-v2-...-github-dependabot-critical to OK (due Aug 26); closes ClickUp G-114.

node-tar <= 7.5.18 is subject to CVE-2026-59873 (decompression DoS via
unlimited input) and older advisories up to <= 7.5.20; tar arrives
transitively through @mintlify/previewing, whose current release pins
7.5.21.
@YushaArif99

Copy link
Copy Markdown
Member Author

Superseded: docs staging already carries this fix (951f766, Mintlify upgrade + transitive overrides, tar at 7.5.21) — promoting staging→main instead per the staging-source guard.

@YushaArif99
YushaArif99 deleted the fix/dependabot-high-critical-overdue branch August 20, 2026 07:33
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant