Skip to content

fix(deps): update astral-tokio-tar to 0.6.0#2171

Merged
bug-ops merged 1 commit intomainfrom
fix/4-astral-tokio-tar
Mar 23, 2026
Merged

fix(deps): update astral-tokio-tar to 0.6.0#2171
bug-ops merged 1 commit intomainfrom
fix/4-astral-tokio-tar

Conversation

@bug-ops
Copy link
Owner

@bug-ops bug-ops commented Mar 23, 2026

Resolves Dependabot alert #4.

Advisory: astral-tokio-tar insufficiently validates PAX extensions during extraction (low severity).
Fixed in: 0.6.0
Change: Cargo.lock updated — no Cargo.toml changes required (transitive dependency bump).

Resolves low-severity advisory: astral-tokio-tar insufficiently
validated PAX extensions during extraction. Fixed in 0.6.0.
@github-actions github-actions bot added rust Rust code changes dependencies Dependency updates bug Something isn't working size/M Medium PR (51-200 lines) labels Mar 23, 2026
@bug-ops bug-ops enabled auto-merge (squash) March 23, 2026 18:48
@bug-ops bug-ops merged commit 9f2adbe into main Mar 23, 2026
25 checks passed
@bug-ops bug-ops deleted the fix/4-astral-tokio-tar branch March 23, 2026 18:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working dependencies Dependency updates rust Rust code changes size/M Medium PR (51-200 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant