Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
We assessed that node-tar vulnerability does not applicable here since npm that uses node-tar under the hood for tar creation/extracting adds additional stripping of all links in the archives on top of tar's (vulnerable here) sanitizing. Closing.