Skip to content

chore: add .iyarc exclusion for tar GHSA-9ppj-qmqm-q256#8278

Merged
manojkumar138 merged 1 commit intomasterfrom
chore/iyarc-tar-ghsa-9ppj-qmqm-q256-exclusion
Mar 11, 2026
Merged

chore: add .iyarc exclusion for tar GHSA-9ppj-qmqm-q256#8278
manojkumar138 merged 1 commit intomasterfrom
chore/iyarc-tar-ghsa-9ppj-qmqm-q256-exclusion

Conversation

@manojkumar138
Copy link
Contributor

Security-approved exception. Same risk profile as existing tar exclusions: CVE affects archive extraction (unpacking malicious archives); we only use tar for packing. Unblocks bitgo-beta release.

CECHO-375

@manojkumar138 manojkumar138 requested review from a team as code owners March 11, 2026 17:42
@manojkumar138 manojkumar138 force-pushed the chore/iyarc-tar-ghsa-9ppj-qmqm-q256-exclusion branch from 3f1ceb9 to 427e9ee Compare March 11, 2026 17:43
Security-approved exception. CECHO-375. Same risk profile as existing tar exclusions:
CVE affects archive extraction (unpacking malicious archives); we only use
tar for packing. Unblocks bitgo-beta release.
@manojkumar138 manojkumar138 force-pushed the chore/iyarc-tar-ghsa-9ppj-qmqm-q256-exclusion branch from 427e9ee to 2aba69f Compare March 11, 2026 17:46
@manojkumar138 manojkumar138 merged commit 925df80 into master Mar 11, 2026
22 checks passed
@bhargavirao24
Copy link

JYI - this was approved to merged by AppSec team.

image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants