-
Notifications
You must be signed in to change notification settings - Fork 135
Open
Description
Your package.json has "tar": "^6.1.11" which has security vulnerabilities. I install @railway/cli in my repo so i can run it via pnpm exec ... which allows my developers to all have the same version of railway. This transitive dependency on a vulnerable version of tar is causing security findings in my project. Thanks!
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels