Skip to content

Commit aa15621

Browse files
Bump adm-zip and @wordpress/env (#300)
Bumps [adm-zip](https://github.com/cthackers/adm-zip) to 0.6.1 and updates ancestor dependency [@wordpress/env](https://github.com/WordPress/gutenberg/tree/HEAD/packages/env). These dependencies need to be updated together. Updates `adm-zip` from 0.5.18 to 0.6.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/cthackers/adm-zip/releases">adm-zip's releases</a>.</em></p> <blockquote> <h2>v0.6.1</h2> <p><strong>Full Changelog</strong>: <a href="https://github.com/cthackers/adm-zip/compare/v0.6.0...v0.6.1">https://github.com/cthackers/adm-zip/compare/v0.6.0...v0.6.1</a></p> <ul> <li>Updated dev dependencies</li> <li>Fixed uncaught crash in async decompression on malformed DEFLATE data</li> <li>Fixed addLocalFolder following symlinks out of the archived folder</li> <li>Stripped setuid/setgid/sticky bits from extracted file permissions</li> <li>Enforced the decompression size cap on the async path and for size 0</li> <li>Rejected archives with duplicate entry names</li> <li>Blocked extraction from writing through symlinks inside the target</li> <li>Routed malformed-header parse errors through the async callback</li> <li>Rejected zip entries whose declared data extent runs past the buffer</li> <li>Fixed addLocalFolderPromise hanging on empty folders and swallowing errors</li> <li>Fixed addLocalFolderAsync2 mangling local paths on Windows</li> </ul> <h2>v0.6.0</h2> <p><strong>Full Changelog</strong>: <a href="https://github.com/cthackers/adm-zip/compare/v0.5.18...v0.6.0">https://github.com/cthackers/adm-zip/compare/v0.5.18...v0.6.0</a></p> <p>This release fixes a security vulnerability (CVE-2026-39244), resolves several long-standing bugs, ships built-in TypeScript types, and includes two behavior changes worth reading before you upgrade.</p> <ul> <li>extractEntryTo(dirEntry, target, maintainEntryPath = false) now preserves subdirectories instead of flattening files into the target folder by basename (which also silently overwrote same-named files). (<a href="https://redirect.github.com/cthackers/adm-zip/issues/306">#306</a>)</li> <li>Extraction no longer fails when the modification time can't be set — utimes is now best-effort. (<a href="https://redirect.github.com/cthackers/adm-zip/issues/379">#379</a>)</li> <li>Minimum Node.js is now 14 (the code already required it; engines was incorrectly &gt;=12).</li> <li>CVE-2026-39244 — a crafted archive declaring a huge uncompressed size could force an unbounded Buffer.alloc and OOM the process; allocation is now bounded by the data actually present. Reported by Daniel Púa (devploit), Anh Hong, and José Antonio Zamudio Amaya. (<a href="https://redirect.github.com/cthackers/adm-zip/issues/568">#568</a>)</li> <li>Hardened entry-name lookup against object injection (<strong>proto</strong> names). Prototype-less table.</li> <li>Data-descriptor regression rejecting valid archives (<a href="https://redirect.github.com/cthackers/adm-zip/issues/548">#548</a>, <a href="https://redirect.github.com/cthackers/adm-zip/issues/533">#533</a>, <a href="https://redirect.github.com/cthackers/adm-zip/issues/554">#554</a>)</li> <li>Directory permissions not restored on extract (<a href="https://redirect.github.com/cthackers/adm-zip/issues/530">#530</a>)</li> <li>Infinite recursion on symlink loops in addLocalFolder (<a href="https://redirect.github.com/cthackers/adm-zip/issues/541">#541</a>)</li> <li>Uncaught process crash in writeFileToAsync on write failure (<a href="https://redirect.github.com/cthackers/adm-zip/issues/470">#470</a>, <a href="https://redirect.github.com/cthackers/adm-zip/issues/459">#459</a>, <a href="https://redirect.github.com/cthackers/adm-zip/issues/402">#402</a>)</li> <li>Empty name on directory entries (<a href="https://redirect.github.com/cthackers/adm-zip/issues/466">#466</a>)</li> <li>test() always returned false for archives with files</li> <li>~6× faster entry sorting for large archives</li> <li>Built-in TypeScript definitions (types.d.ts) — you can drop <code>@​types/adm-zip</code></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/cthackers/adm-zip/blob/master/history.md">adm-zip's changelog</a>.</em></p> <blockquote> <h1>0.6.0 / 2026-07-10</h1> <p>Security</p> <ul> <li>Fixed CVE-2026-39244: a crafted archive declaring a huge uncompressed size could force an unbounded <code>Buffer.alloc</code> (memory exhaustion / DoS) before any validation. Allocation is now bounded by the data actually present — STORED output is sized from the real bytes, DEFLATED output is grown by the inflater and capped at the declared size (<a href="https://redirect.github.com/cthackers/adm-zip/issues/568">#568</a>)</li> <li>Hardened the internal entry-name lookup table against object injection: entry names come from untrusted archives, and a name such as <code>__proto__</code> previously resolved to <code>Object.prototype</code>, crashing <code>addFile</code> and hiding the entry from <code>getEntry</code>/<code>readFile</code>. The table is now prototype-less</li> </ul> <p>Bug fixes</p> <ul> <li>Fixed a regression (0.5.15) that rejected valid archives using a data descriptor (general-purpose bit 3). The payload is now validated against the authoritative central-directory CRC instead of requiring/parsing the trailing descriptor (<a href="https://redirect.github.com/cthackers/adm-zip/issues/548">#548</a>, <a href="https://redirect.github.com/cthackers/adm-zip/issues/533">#533</a>, <a href="https://redirect.github.com/cthackers/adm-zip/issues/554">#554</a>)</li> <li>Fixed <code>extractAllTo</code>/<code>extractAllToAsync</code> not restoring directory permissions with <code>keepOriginalPermission</code>; directory modes are applied after their contents are written, deepest path first, and no longer lock the extractor out of a restrictive directory (<a href="https://redirect.github.com/cthackers/adm-zip/issues/530">#530</a>)</li> <li>Fixed infinite recursion in <code>addLocalFolder</code> when a folder contains a symlink pointing back to an ancestor (e.g. workspace <code>node_modules</code>); the walk now tracks resolved real paths and skips already-visited directories (<a href="https://redirect.github.com/cthackers/adm-zip/issues/541">#541</a>)</li> <li>Fixed an uncaught exception (<code>ERR_INVALID_ARG_TYPE</code>) that crashed the process when <code>writeFileToAsync</code> could not open the target file (bad permissions, invalid filename, exhausted file descriptors); write failures are now reported through the callback and write errors are no longer silently swallowed (<a href="https://redirect.github.com/cthackers/adm-zip/issues/470">#470</a>, <a href="https://redirect.github.com/cthackers/adm-zip/issues/459">#459</a>, <a href="https://redirect.github.com/cthackers/adm-zip/issues/402">#402</a>)</li> <li>Fixed directory entries reporting an empty <code>name</code> (e.g. <code>a/b/c/</code> now returns <code>c</code>) (<a href="https://redirect.github.com/cthackers/adm-zip/issues/466">#466</a>)</li> <li>Fixed <code>extractEntryTo</code> flattening subdirectories when <code>maintainEntryPath</code> is false; the structure below the extracted directory is now preserved instead of collapsing (and overwriting) files by basename (<a href="https://redirect.github.com/cthackers/adm-zip/issues/306">#306</a>)</li> <li>Fixed a failed <code>utimes</code> aborting extraction; setting the modification time is now best-effort and never fails extraction of already-written content (<a href="https://redirect.github.com/cthackers/adm-zip/issues/379">#379</a>)</li> <li>Fixed <code>test()</code> always returning false for any archive containing a file (it indexed the entries array with an entry object instead of reading the entry); it now correctly verifies each entry's CRC</li> </ul> <p>Performance</p> <ul> <li>Faster entry sorting when writing archives with many entries: names are decoded once instead of on every comparison (about 6× faster sort for large archives)</li> </ul> <p>Added</p> <ul> <li>Bundled TypeScript type definitions (<code>types.d.ts</code>), so <code>@types/adm-zip</code> is no longer required</li> </ul> <p>Notes</p> <ul> <li>Behavior change: <code>extractEntryTo(dir, target, /* maintainEntryPath */ false)</code> now preserves subdirectories beneath the extracted directory rather than flattening them</li> <li>Behavior change: extraction no longer fails when the modification time cannot be set</li> </ul> <h1>0.5.4 / 2021-03-08</h1> <ul> <li>Fixed relative paths</li> <li>Added zipcrypto encryption</li> <li>Lower verMade for macOS when generating zip file</li> </ul> <h1>0.5.3 / 2021-02-07</h1> <ul> <li>Fixed filemode when unzipping</li> </ul> <h1>0.5.2 / 2021-01-27</h1> <ul> <li>Fixed path traversal issue (GHSL-2020-198)</li> </ul> <h1>0.5.1 / 2020-11-27</h1> <ul> <li>Incremented version (cthackers)</li> <li>Fixed outFileName (cthackers)</li> </ul> <h1>0.5.0 / 2020-11-19</h1> <ul> <li>Added extra parameter to extractEntryTo so target filename can be renamed (cthackers)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/cthackers/adm-zip/commit/cb2cf9ba4c7c865db426e2de1997cb41194d9872"><code>cb2cf9b</code></a> Fixed addLocalFolderAsync2 mangling local paths on Windows</li> <li><a href="https://github.com/cthackers/adm-zip/commit/54902b60f0f1d6d6e8157e81e0f18c5001941ccc"><code>54902b6</code></a> Fixed addLocalFolderPromise hanging on empty folders and swallowing errors</li> <li><a href="https://github.com/cthackers/adm-zip/commit/73131bdce50fa6ed201c48b468082ef456894f2e"><code>73131bd</code></a> Fixed CI</li> <li><a href="https://github.com/cthackers/adm-zip/commit/758898d71508e8a016691d5843b5f7ce2d1b208a"><code>758898d</code></a> Rejected zip entries whose declared data extent runs past the buffer</li> <li><a href="https://github.com/cthackers/adm-zip/commit/74b6e9f402c4c7cde4e33f3c87ff8f15ddcd6121"><code>74b6e9f</code></a> Routed malformed-header parse errors through the async callback</li> <li><a href="https://github.com/cthackers/adm-zip/commit/eaa35fa73df6108a3d6ebc9b9073371740735265"><code>eaa35fa</code></a> Blocked extraction from writing through symlinks inside the target</li> <li><a href="https://github.com/cthackers/adm-zip/commit/1e015e3e713aee426bf3d5c1bc1b555c90f4f3e6"><code>1e015e3</code></a> Increment version</li> <li><a href="https://github.com/cthackers/adm-zip/commit/05101d47b3b983b705cc3e66fc34366118ba7b99"><code>05101d4</code></a> Rejected archives with duplicate entry names</li> <li><a href="https://github.com/cthackers/adm-zip/commit/491600683dacb6cb9fe0718a0eeb9cb5eb49afa6"><code>4916006</code></a> Enforced the decompression size cap on the async path and for size 0</li> <li><a href="https://github.com/cthackers/adm-zip/commit/6a63c339b83c52915483efacda517660a7a7bf87"><code>6a63c33</code></a> Stripped setuid/setgid/sticky bits from extracted file permissions</li> <li>Additional commits viewable in <a href="https://github.com/cthackers/adm-zip/compare/v0.5.18...v0.6.1">compare view</a></li> </ul> </details> <br /> Updates `@wordpress/env` from 11.13.0 to 11.15.0 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/WordPress/gutenberg/blob/trunk/packages/env/CHANGELOG.md">@​wordpress/env's changelog</a>.</em></p> <blockquote> <h2>11.15.0 (2026-09-10)</h2> <h3>Bug Fixes</h3> <ul> <li>Point the apt sources of the bullseye-based WordPress images (PHP 7.4 and 8.0) at <code>archive.debian.org</code>, so building them no longer fails now that Debian 11 has reached end-of-life and left the regular mirrors (<a href="https://redirect.github.com/WordPress/gutenberg/pull/82478">#82478</a>).</li> </ul> <h2>11.14.0 (2026-08-26)</h2> <h3>Bug Fixes</h3> <ul> <li>Update git sources to the latest commit when <code>--update</code> is passed. Previously, a source pointing at a branch (such as <code>&quot;core&quot;: &quot;WordPress/WordPress&quot;</code>) stayed at the commit it was first cloned at, no matter how many times it was updated.</li> <li>Do not fail <code>wp-env start</code> when Docker images cannot be pulled (e.g., the Docker registry is unreachable); fall back to locally cached images and show a notice instead. (<a href="https://redirect.github.com/WordPress/gutenberg/issues/81631">#81631</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/WordPress/gutenberg/commit/485f42ae8a1c58ceea18371a507fd4acfa86fbd8"><code>485f42a</code></a> chore(release): publish</li> <li><a href="https://github.com/WordPress/gutenberg/commit/c89dd70a9a10686a07421ad74d9ae01548a5366a"><code>c89dd70</code></a> Update changelog files</li> <li><a href="https://github.com/WordPress/gutenberg/commit/a55a0d7826714af9232883c97a724a55f2610796"><code>a55a0d7</code></a> Merge changes published in the Gutenberg plugin &quot;release/24.0&quot; branch</li> <li><a href="https://github.com/WordPress/gutenberg/commit/d06b0104c1684b0c78906a62681af7d9deae29a4"><code>d06b010</code></a> chore(release): publish (<a href="https://github.com/WordPress/gutenberg/tree/HEAD/packages/env/issues/82084">#82084</a>)</li> <li><a href="https://github.com/WordPress/gutenberg/commit/0790fa5321f5f088494330178299a4d9a95ab254"><code>0790fa5</code></a> Update changelog files</li> <li><a href="https://github.com/WordPress/gutenberg/commit/098e3ba18bd7e8054bca4fdd4bcb706af42971a9"><code>098e3ba</code></a> Merge changes published in the Gutenberg plugin &quot;release/23.9&quot; branch</li> <li>See full diff in <a href="https://github.com/WordPress/gutenberg/commits/@wordpress/env@11.15.0/packages/env">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/WordPress/phpdoc-parser/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent 03c8a25 commit aa15621

2 files changed

Lines changed: 10 additions & 10 deletions

File tree

‎package-lock.json‎

Lines changed: 9 additions & 9 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@
2525
},
2626
"homepage": "https://github.com/wordpress/phpdoc-parser#readme",
2727
"dependencies": {
28-
"@wordpress/env": "^11.13.0",
28+
"@wordpress/env": "^11.15.0",
2929
"npm-run-all": "^4.1.5"
3030
}
3131
}

0 commit comments

Comments
 (0)