[0.80] Bump tar-fs from 3.0.9 to 3.1.1 & 2.1.3 to 2.1.4 for component governance #15201
+6
−6
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Upgraded following packages
tar-fs from 3.0.9 to 3.1.1
tar-fs from 2.1.3 to 2.1.4
Type of Change
Why
Upgraded to tar-fs to fix security vulnerabilities
Resolves #15200
What
Updated the yarn.lock to point to the new versions.
Steps to upgrade:
Delete the older version from yarn.lock file
Execute yarn command so it can fetch the new versions.
Screenshots
Changelog
Should this change be included in the release notes: indicate :no
Microsoft Reviewers: Open in CodeFlow
Microsoft Reviewers: Open in CodeFlow