deps: bump tar from 7.0.1 to 7.1.0 (#1095)

Bumps [tar](https://github.com/isaacs/node-tar) from 7.0.1 to 7.1.0. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md">tar's changelog</a>.</em></p> <blockquote> <h1>Changelog</h1> <h2>7.1</h2> <ul> <li>Update minipass to v7.1.0</li> <li>Update the type definitions of <code>write()</code> and <code>end()</code> methods on <code>Unpack</code> and <code>Parser</code> classes to be compatible with the NodeJS.WritableStream type in the latest versions of <code>@types/node</code>.</li> </ul> <h2>7.0</h2> <ul> <li>Rewrite in TypeScript, provide ESM and CommonJS hybrid interface</li> <li>Add tree-shake friendly exports, like <code>import('tar/create')</code> and <code>import('tar/read-entry')</code> to get individual functions or classes.</li> <li>Add <code>chmod</code> option that defaults to false, and deprecate <code>noChmod</code>. That is, reverse the default option regarding explicitly setting file system modes to match tar entry settings.</li> <li>Add <code>processUmask</code> option to avoid having to call <code>process.umask()</code> when <code>chmod: true</code> (or <code>noChmod: false</code>) is set.</li> </ul> <h2>6.2</h2> <ul> <li>Add support for brotli compression</li> <li>Add <code>maxDepth</code> option to prevent extraction into excessively deep folders.</li> </ul> <h2>6.1</h2> <ul> <li>remove dead link to benchmarks (<a href="https://redirect.github.com/isaacs/node-tar/issues/313">#313</a>) (<a href="https://github.com/yetzt"><code>@​yetzt</code></a>)</li> <li>add examples/explanation of using tar.t (<a href="https://github.com/isaacs"><code>@​isaacs</code></a>)</li> <li>ensure close event is emited after stream has ended (<a href="https://github.com/webark"><code>@​webark</code></a>)</li> <li>replace deprecated String.prototype.substr() (<a href="https://github.com/CommanderRoot"><code>@​CommanderRoot</code></a>, <a href="https://github.com/lukekarrys"><code>@​lukekarrys</code></a>)</li> </ul> <h2>6.0</h2> <ul> <li>Drop support for node 6 and 8</li> <li>fix symlinks and hardlinks on windows being packed with <code>\</code>-style path targets</li> </ul> <h2>5.0</h2> <ul> <li>Address unpack race conditions using path reservations</li> <li>Change large-numbers errors from TypeError to Error</li> <li>Add <code>TAR_*</code> error codes</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/isaacs/node-tar/commit/ce612d0aa818f93a133a5f76e14fe6eef2abb12f"><code>ce612d0</code></a> 7.1.0</li> <li><a href="https://github.com/isaacs/node-tar/commit/6b61030dacb86eb22f1935b73b6aa09cd2ddc208"><code>6b61030</code></a> update types to comply with NodeJS.WritableStream</li> <li><a href="https://github.com/isaacs/node-tar/commit/79a5c30d7bd836eee0751e2ec6c838767a70ecad"><code>79a5c30</code></a> update minipass</li> <li><a href="https://github.com/isaacs/node-tar/commit/bead873b5c22915b15da72e95b0da6b87eeb384e"><code>bead873</code></a> remove more cruft, format codes</li> <li><a href="https://github.com/isaacs/node-tar/commit/faf9359ca738b2ba8c5527973cd9529c69add15e"><code>faf9359</code></a> remove temlate-oss stuff</li> <li>See full diff in <a href="https://github.com/isaacs/node-tar/compare/v7.0.1...v7.1.0">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=tar&package-manager=npm_and_yarn&previous-version=7.0.1&new-version=7.1.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

dependabot[bot] committed May 6, 2024 at 15:36 UTC fc2250c8fb49c13ec06c616a0b53bc4f5d73590d
1 file changed +7 -23
package-lock.json
+7 -23
@@ -28965,9 +28965,9 @@
28965 }
28966 },
28967 "node_modules/minipass": {
28968 - "version": "7.0.4",
28969 - "resolved": "https://registry.npmjs.org/minipass/-/minipass-7.0.4.tgz",
28970 - "integrity": "sha512-jYofLM5Dam9279rdkWzqHozUo4ybjdZmCsDHePy5V/PbBcVMiSZR97gmAy45aqi8CK1lG2ECd356FU86avfwUQ==",
28968 + "version": "7.1.0",
28969 + "resolved": "https://registry.npmjs.org/minipass/-/minipass-7.1.0.tgz",
28970 + "integrity": "sha512-oGZRv2OT1lO2UF1zUcwdTb3wqUwI0kBGTgt/T7OdSj6M6N5m3o5uPf0AIW6lVxGGoiWUR7e2AwTE+xiwK8WQig==",
28971 "engines": {
28972 "node": ">=16 || 14 >=14.17"
28973 }
@@ -37381,13 +37381,13 @@
37381 }
37382 },
37383 "node_modules/tar": {
37384 - "version": "7.0.1",
37385 - "resolved": "https://registry.npmjs.org/tar/-/tar-7.0.1.tgz",
37386 - "integrity": "sha512-IjMhdQMZFpKsHEQT3woZVxBtCQY+0wk3CVxdRkGXEgyGa0dNS/ehPvOMr2nmfC7x5Zj2N+l6yZUpmICjLGS35w==",
37384 + "version": "7.1.0",
37385 + "resolved": "https://registry.npmjs.org/tar/-/tar-7.1.0.tgz",
37386 + "integrity": "sha512-ENhg4W6BmjYxl8GTaE7/h99f0aXiSWv4kikRZ9n2/JRxypZniE84ILZqimAhxxX7Zb8Px6pFdheW3EeHfhnXQQ==",
37387 "dependencies": {
37388 "@isaacs/fs-minipass": "^4.0.0",
37389 "chownr": "^3.0.0",
37390 - "minipass": "^5.0.0",
37390 + "minipass": "^7.1.0",
37391 "minizlib": "^3.0.1",
37392 "mkdirp": "^3.0.1",
37393 "yallist": "^5.0.0"
@@ -37416,14 +37416,6 @@
37416 "streamx": "^2.15.0"
37417 }
37418 },
37419 - "node_modules/tar/node_modules/minipass": {
37420 - "version": "5.0.0",
37421 - "resolved": "https://registry.npmjs.org/minipass/-/minipass-5.0.0.tgz",
37422 - "integrity": "sha512-3FnjYuehv9k6ovOEbyOswadCDPX1piCfhV8ncmYtHOjuPwylVWsghTLo7rabjC3Rx5xD4HDx8Wm1xnMF7S5qFQ==",
37423 - "engines": {
37424 - "node": ">=8"
37425 - }
37426 - },
37419 "node_modules/tar/node_modules/minizlib": {
37420 "version": "3.0.1",
37421 "resolved": "https://registry.npmjs.org/minizlib/-/minizlib-3.0.1.tgz",
@@ -37436,14 +37428,6 @@
37428 "node": ">= 18"
37429 }
37430 },
37439 - "node_modules/tar/node_modules/minizlib/node_modules/minipass": {
37440 - "version": "7.0.4",
37441 - "resolved": "https://registry.npmjs.org/minipass/-/minipass-7.0.4.tgz",
37442 - "integrity": "sha512-jYofLM5Dam9279rdkWzqHozUo4ybjdZmCsDHePy5V/PbBcVMiSZR97gmAy45aqi8CK1lG2ECd356FU86avfwUQ==",
37443 - "engines": {
37444 - "node": ">=16 || 14 >=14.17"
37445 - }
37446 - },
37431 "node_modules/tar/node_modules/mkdirp": {
37432 "version": "3.0.1",
37433 "resolved": "https://registry.npmjs.org/mkdirp/-/mkdirp-3.0.1.tgz",