Technology
GitHub tackles severe vulnerabilities in Node.js packages – ZDNet
Bugs impacting tar and @npmcli/arborist were reported through a bug bounty program.

GitHub has resolved numerous vulnerabilities in Node.js packages tar and @npmcli/arborist, with the worst allowing file overwrites and arbitrary code execution.
On Wednesday, GitHub said the company received reports from Robert Chen and Philip Papurt,…
Continue Reading