tar-fs
npm
pkg:npm/tar-fs
24,107 Dependabot PRs
2 days ago
14,028 repositories
55 repositories
Security Advisories
tar-fs can extract outside the specified dir with a specific tarball
tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File
Improper Input Validation in tar-fs
tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
Recent PRs
Bump tar-fs from 3.1.0 to 3.1.2 in /js
rmcode-benchmark/clean20260529-2327__keycloak-greptile__rmcode-dev__PR1__20260530 #30
Bump tar-fs from 3.1.0 to 3.1.2 in /js
rmcode-benchmark/clean20260529-1728__keycloak__rmcode-dev__PR40940__20260529 #19
Bump the npm_and_yarn group across 1 directory with 19 updates
NYPL/nypl-library-card-app #745
Bump tar-fs from 3.0.8 to 3.1.2 in /js
rmcode-benchmark/keycloak__keycloak__rmcode-dev__PR37634__20260529 #33
Bump the npm_and_yarn group across 1 directory with 16 updates
ali963git/keycloak-nodejs-connect #11
Bump tar-fs from 2.1.3 to 2.1.4
stephendmann/LeadershipIntel #8
Bump tar-fs from 3.0.8 to 3.1.2 in /js
pr-review-agent-bench/keycloak__keycloak__diffjudge__PR37634__20260527 #65
Bump the npm_and_yarn group across 16 directories with 19 updates
Bump the npm_and_yarn group across 1 directory with 8 updates
Bump the npm_and_yarn group across 9 directories with 19 updates
Surfndez/next.js #15
Bump tar-fs from 3.0.8 to 3.1.2 in /js
CloudSmith-Agent-Benchmark/keycloak__PR37429 #53
Bump the npm-dependencies group across 1 directory with 33 updates
Win1817/keycloak #22
Bump the npm_and_yarn group across 4 directories with 12 updates
chore(deps): bump tar-fs from 2.1.3 to 2.1.4
txpipe-shop/cardano-graphical-tx #273
chore(deps): bump the npm_and_yarn group across 3 directories with 7 updates
chore(deps): bump the npm_and_yarn group across 1 directory with 4 updates
Dargon789/coinbase-wallet-sdk #199
Bump the npm_and_yarn group across 1 directory with 29 updates
Bump tar-fs from 3.0.8 to 3.1.2 in /js
imantubex-create/keycloak__keycloak__prixai__PR37634__20260516 #14
Bump tar-fs from 3.0.6 to 3.1.2
imantubex-create/keycloak__keycloak__prixai__PR32918__20260516 #29
Bump tar-fs from 3.0.6 to 3.1.2
imantubex-create/keycloak__prixai__PR32918__20260516 #10
Bump the npm_and_yarn group across 1 directory with 26 updates
Bump the npm_and_yarn group across 1 directory with 25 updates
Bump the npm_and_yarn group across 1 directory with 26 updates
Bump the npm_and_yarn group across 7 directories with 20 updates
Surfndez/next.js #12
Bump the npm_and_yarn group across 1 directory with 15 updates
drzo/bolt.ceo #28
chore(deps): bump the npm_and_yarn group across 11 directories with 14 updates
chore(deps): bump the npm_and_yarn group across 2 directories with 22 updates
chore(deps): bump the npm_and_yarn group across 11 directories with 13 updates
Bump the npm_and_yarn group across 5 directories with 17 updates
build(deps): bump the npm_and_yarn group across 3 directories with 20 updates
Asper-Beauty-Shop/supabase-js #27
Bump the npm_and_yarn group across 1 directory with 7 updates
RetireJS/retire-site-scanner #7
Bump the npm-dependencies group across 1 directory with 30 updates
Win1817/keycloak #21
Bump the npm-dependencies group across 1 directory with 29 updates
sg-evals/keycloak--6fd372cb #20
Bump the npm-dependencies group across 1 directory with 28 updates
Code-Review-Assessment-2026/test_subset_6__keycloak__claude__PR37634__20260407 #14
Bump the npm-dependencies group across 1 directory with 27 updates
86dh/keycloak #940
Bump the npm-dependencies group across 1 directory with 27 updates
thomasdarimont/keycloak #1232
Bump the npm_and_yarn group across 1 directory with 10 updates
chore(deps): bump the npm_and_yarn group across 2 directories with 20 updates
chore(deps): bump the npm_and_yarn group across 4 directories with 27 updates
chore(deps): bump the npm_and_yarn group across 4 directories with 27 updates
chore(deps): bump the npm_and_yarn group across 2 directories with 7 updates
Bump the npm_and_yarn group across 1 directory with 23 updates
FacePrintPay/npm-documentation #1
chore(deps): Bump the npm_and_yarn group across 6 directories with 14 updates
chore(deps): bump the npm_and_yarn group across 2 directories with 10 updates
build(deps): bump the npm_and_yarn group across 1 directory with 20 updates
Bump the npm_and_yarn group across 5 directories with 26 updates
getflip/swirl #1637
Bump tar-fs from 3.0.6 to 3.1.2
sc-vikvorona-test/keycloak__keycloak__sonar-review__PR32918__20260504 #18
build(deps): bump the npm_and_yarn group across 3 directories with 20 updates
MetaMask/snap-bitcoin-wallet #603
chore(deps): Bump the npm_and_yarn group across 1 directory with 2 updates
SantiagoXOR/pintureria-digital #26
chore(deps): bump the npm_and_yarn group across 2 directories with 25 updates
UNLP-Accesible/unlp-accesible #15
Package Details
| Name: | tar-fs |
| Ecosystem: | npm |
| PURL Type: | npm |
| Package URL: | pkg:npm/tar-fs |
| JSON API: | View JSON |
Security Advisories
Package Information
filesystem bindings for tar-stream
| Repository: | https://github.com/mafintosh/tar-fs |
| Homepage: | https://github.com/mafintosh/tar-fs |
| Latest Release: |
3.0.9
about 1 year ago |
| Dependent Repos: | 404,503 |
| Dependent Packages: | 1,213 |
| Downloads: | 98,992,404 |
| Ranking: | Top 0.0565% by dependent repos Top 0.0247% by downloads Top 0.0588% by dependent pkgs |