Skip to content

Commit 1bd2919

Browse files
committed
Bump tar-fs devdep to fix vuln warning
1 parent 89bda9d commit 1bd2919

File tree

2 files changed

+28
-15
lines changed

2 files changed

+28
-15
lines changed

package-lock.json

+17-14
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

setup-server.ts

+11-1
Original file line numberDiff line numberDiff line change
@@ -98,7 +98,17 @@ async function insertServer(
9898
});
9999

100100
console.log(`Extracting server to ${buildPath}`);
101-
await extractTarGz({ src: downloadPath, dest: buildPath });
101+
await extractTarGz({
102+
src: downloadPath,
103+
dest: buildPath,
104+
tar: {
105+
ignore (_, header) {
106+
// Extract only files & directories - ignore symlinks or similar
107+
// which can sneak in in some cases (e.g. native dep build envs)
108+
return header!.type !== 'file' && header!.type !== 'directory'
109+
}
110+
}
111+
});
102112
await deleteFile(downloadPath);
103113

104114
console.log('Server download completed');

0 commit comments

Comments
 (0)