- Properly bundle all dependencies of Bower within package
Unclaimed project
Are you a maintainer of bower? Claim this project to take control of your public changelog and roadmap.
Fix security issue connected to extracting .tar.gz archives
This bug allows to write arbitrary file on filesystem when Bower extracts malicious package
Needlessly to say, please upgrade
Fixes side effect of fix from v1.8.6 that caused improper permissions for extracted folders
https://github.com/bower/bower/issues/2532
Fix Zip Slip Vulnerability of decompress-zip package: https://snyk.io/research/zip-slip-vulnerability
Note: v1.8.5 has been unpublished because of missing files