Skip to content

Bump adm-zip and web-ext - #292

Merged
freshstrangemusic merged 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-25e141c5f9
Sep 19, 2026
Merged

freshstrangemusic merged 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-25e141c5f9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Bumps adm-zip to 0.6.1 and updates ancestor dependency web-ext. These dependencies need to be updated together.

Updates adm-zip from 0.5.16 to 0.6.1

Release notes

Sourced from adm-zip's releases.

v0.6.1

Full Changelog: cthackers/adm-zip@v0.6.0...v0.6.1

  • Updated dev dependencies
  • Fixed uncaught crash in async decompression on malformed DEFLATE data
  • Fixed addLocalFolder following symlinks out of the archived folder
  • Stripped setuid/setgid/sticky bits from extracted file permissions
  • Enforced the decompression size cap on the async path and for size 0
  • Rejected archives with duplicate entry names
  • Blocked extraction from writing through symlinks inside the target
  • Routed malformed-header parse errors through the async callback
  • Rejected zip entries whose declared data extent runs past the buffer
  • Fixed addLocalFolderPromise hanging on empty folders and swallowing errors
  • Fixed addLocalFolderAsync2 mangling local paths on Windows

v0.6.0

Full Changelog: cthackers/adm-zip@v0.5.18...v0.6.0

This release fixes a security vulnerability (CVE-2026-39244), resolves several long-standing bugs, ships built-in TypeScript types, and includes two behavior changes worth reading before you upgrade.

  • extractEntryTo(dirEntry, target, maintainEntryPath = false) now preserves subdirectories instead of flattening files into the target folder by basename (which also silently overwrote same-named files). (#306)
  • Extraction no longer fails when the modification time can't be set — utimes is now best-effort. (#379)
  • Minimum Node.js is now 14 (the code already required it; engines was incorrectly >=12).
  • CVE-2026-39244 — a crafted archive declaring a huge uncompressed size could force an unbounded Buffer.alloc and OOM the process; allocation is now bounded by the data actually present. Reported by Daniel Púa (devploit), Anh Hong, and José Antonio Zamudio Amaya. (#568)
  • Hardened entry-name lookup against object injection (proto names). Prototype-less table.
  • Data-descriptor regression rejecting valid archives (#548, #533, #554)
  • Directory permissions not restored on extract (#530)
  • Infinite recursion on symlink loops in addLocalFolder (#541)
  • Uncaught process crash in writeFileToAsync on write failure (#470, #459, #402)
  • Empty name on directory entries (#466)
  • test() always returned false for archives with files
  • ~6× faster entry sorting for large archives
  • Built-in TypeScript definitions (types.d.ts) — you can drop @​types/adm-zip

v0.5.18

What's Changed

New Contributors

Full Changelog: cthackers/adm-zip@v0.5.17...v0.5.18

v0.5.17

... (truncated)

Changelog

Sourced from adm-zip's changelog.

0.6.0 / 2026-07-10

Security

  • Fixed CVE-2026-39244: a crafted archive declaring a huge uncompressed size could force an unbounded Buffer.alloc (memory exhaustion / DoS) before any validation. Allocation is now bounded by the data actually present — STORED output is sized from the real bytes, DEFLATED output is grown by the inflater and capped at the declared size (#568)
  • Hardened the internal entry-name lookup table against object injection: entry names come from untrusted archives, and a name such as __proto__ previously resolved to Object.prototype, crashing addFile and hiding the entry from getEntry/readFile. The table is now prototype-less

Bug fixes

  • Fixed a regression (0.5.15) that rejected valid archives using a data descriptor (general-purpose bit 3). The payload is now validated against the authoritative central-directory CRC instead of requiring/parsing the trailing descriptor (#548, #533, #554)
  • Fixed extractAllTo/extractAllToAsync not restoring directory permissions with keepOriginalPermission; directory modes are applied after their contents are written, deepest path first, and no longer lock the extractor out of a restrictive directory (#530)
  • Fixed infinite recursion in addLocalFolder when a folder contains a symlink pointing back to an ancestor (e.g. workspace node_modules); the walk now tracks resolved real paths and skips already-visited directories (#541)
  • Fixed an uncaught exception (ERR_INVALID_ARG_TYPE) that crashed the process when writeFileToAsync could not open the target file (bad permissions, invalid filename, exhausted file descriptors); write failures are now reported through the callback and write errors are no longer silently swallowed (#470, #459, #402)
  • Fixed directory entries reporting an empty name (e.g. a/b/c/ now returns c) (#466)
  • Fixed extractEntryTo flattening subdirectories when maintainEntryPath is false; the structure below the extracted directory is now preserved instead of collapsing (and overwriting) files by basename (#306)
  • Fixed a failed utimes aborting extraction; setting the modification time is now best-effort and never fails extraction of already-written content (#379)
  • Fixed test() always returning false for any archive containing a file (it indexed the entries array with an entry object instead of reading the entry); it now correctly verifies each entry's CRC

Performance

  • Faster entry sorting when writing archives with many entries: names are decoded once instead of on every comparison (about 6× faster sort for large archives)

Added

  • Bundled TypeScript type definitions (types.d.ts), so @types/adm-zip is no longer required

Notes

  • Behavior change: extractEntryTo(dir, target, /* maintainEntryPath */ false) now preserves subdirectories beneath the extracted directory rather than flattening them
  • Behavior change: extraction no longer fails when the modification time cannot be set

0.5.4 / 2021-03-08

  • Fixed relative paths
  • Added zipcrypto encryption
  • Lower verMade for macOS when generating zip file

0.5.3 / 2021-02-07

  • Fixed filemode when unzipping

0.5.2 / 2021-01-27

  • Fixed path traversal issue (GHSL-2020-198)

0.5.1 / 2020-11-27

  • Incremented version (cthackers)
  • Fixed outFileName (cthackers)

0.5.0 / 2020-11-19

  • Added extra parameter to extractEntryTo so target filename can be renamed (cthackers)

... (truncated)

Commits
  • cb2cf9b Fixed addLocalFolderAsync2 mangling local paths on Windows
  • 54902b6 Fixed addLocalFolderPromise hanging on empty folders and swallowing errors
  • 73131bd Fixed CI
  • 758898d Rejected zip entries whose declared data extent runs past the buffer
  • 74b6e9f Routed malformed-header parse errors through the async callback
  • eaa35fa Blocked extraction from writing through symlinks inside the target
  • 1e015e3 Increment version
  • 05101d4 Rejected archives with duplicate entry names
  • 4916006 Enforced the decompression size cap on the async path and for size 0
  • 6a63c33 Stripped setuid/setgid/sticky bits from extracted file permissions
  • Additional commits viewable in compare view

Updates web-ext from 10.4.0 to 10.6.0

Release notes

Sourced from web-ext's releases.

10.6.0 (2026-08-04)

main changes

  • Added: new Firefox 154.0b4 schema for web-ext lint
  • Fixed: rename default export to webExt (#3789)

dependencies

  • Updated: dependency @devicefarmer/adbkit to 3.3.9 (#3774)
  • Updated: dependency addons-linter to 10.9.0 (#3780)
  • Updated: dependency firefox-profile to 4.7.1 (#3795)

dev dependencies

  • Updated: dependency @babel/cli to 8.0.4 (#3775)
  • Updated: dependency @eslint/eslintrc to 3.3.6 (#3779)
  • Updated: dependency fs-extra to 11.4.0 (#3788)
  • Updated: dependency globals to 17.8.0 (#3791)
  • Updated: dependency prettier to 3.9.6 (#3785)
  • Updated: dependency fast-uri to 3.1.4 (#3784)
  • Updated: dependency fx-runner to 1.6.0 (#3796)

others

  • Add SSDLC and SBOM Actions (#3783)

10.5.0 (2026-07-10)

main changes

  • Added: add a --enterprise CLI flag to the lint command (#3770)
  • Added: log the response data when a PATCH request fails (#3746)
  • Added: new Firefox 153.0b2 schema for web-ext lint

dependencies

  • Updated: dependency @babel/runtime to 8.0.0 (#3749)
  • Updated: dependency addons-linter to 10.8.0 (#3772)
  • Updated: dependency watchpack to 2.5.2 (#3742)
  • Updated: dependencies uuid and istanbul-lib-processinfo (#3745)

dev dependencies

  • Updated: dependency fs-extra to 11.3.6 (#3768)
  • Updated: dependency globals to 17.7.0 (#3761)
  • Updated: dependency prettier to 3.9.4 (#3769)
  • Updated: dependency undici to 7.28.0 (#3743)

others

  • Drop commitlint in this project (#3765)

... (truncated)

Commits
  • 6aeb4b9 10.6.0
  • 8e76d7b chore: rename default export webExt (#3789)
  • a89584c chore(deps-dev): bump @​eslint/eslintrc from 3.3.5 to 3.3.6 (#3779)
  • f40ea4e Bump addons-linter to 10.10.0 (#3797)
  • 8aafbba chore(deps-dev): bump prettier from 3.9.5 to 3.9.6 (#3785)
  • 978d273 chore(deps-dev): bump globals from 17.7.0 to 17.8.0 (#3791)
  • bf72979 chore(deps): bump addons-linter from 10.8.0 to 10.9.0 (#3780)
  • 27054d2 chore(deps-dev): bump fs-extra from 11.3.6 to 11.4.0 (#3788)
  • e5ccd4c Bump fx-runner version to 1.6.0 (#3796)
  • c5c7026 chore(deps): bump mozilla/ssdlc-actions/.github/workflows/code-security-analy...
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 18, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 18, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-25e141c5f9 branch 3 times, most recently from e4a22e2 to 121c58b Compare September 18, 2026 23:14
@freshstrangemusic

Copy link
Copy Markdown
Collaborator

@dependabot rebase

Bumps [adm-zip](https://github.com/cthackers/adm-zip) to 0.6.1 and updates ancestor dependency [web-ext](https://github.com/mozilla/web-ext). These dependencies need to be updated together.


Updates `adm-zip` from 0.5.16 to 0.6.1
- [Release notes](https://github.com/cthackers/adm-zip/releases)
- [Changelog](https://github.com/cthackers/adm-zip/blob/master/history.md)
- [Commits](cthackers/adm-zip@v0.5.16...v0.6.1)

Updates `web-ext` from 10.4.0 to 10.6.0
- [Release notes](https://github.com/mozilla/web-ext/releases)
- [Commits](mozilla/web-ext@10.4.0...10.6.0)

---
updated-dependencies:
- dependency-name: adm-zip
  dependency-version: 0.6.1
  dependency-type: indirect
- dependency-name: web-ext
  dependency-version: 10.6.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-25e141c5f9 branch from 121c58b to bd8a899 Compare September 18, 2026 23:37
@freshstrangemusic
freshstrangemusic merged commit bd8a899 into main Sep 19, 2026
12 checks passed
@freshstrangemusic
freshstrangemusic deleted the dependabot/npm_and_yarn/multi-25e141c5f9 branch September 19, 2026 01:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant