[dev][security-sig] Revisiting tarfile, or "What's old is new again"