Commit aa15621
authored
Bump adm-zip and @wordpress/env (#300)
Bumps [adm-zip](https://github.com/cthackers/adm-zip) to 0.6.1 and
updates ancestor dependency
[@wordpress/env](https://github.com/WordPress/gutenberg/tree/HEAD/packages/env).
These dependencies need to be updated together.
Updates `adm-zip` from 0.5.18 to 0.6.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/cthackers/adm-zip/releases">adm-zip's
releases</a>.</em></p>
<blockquote>
<h2>v0.6.1</h2>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/cthackers/adm-zip/compare/v0.6.0...v0.6.1">https://github.com/cthackers/adm-zip/compare/v0.6.0...v0.6.1</a></p>
<ul>
<li>Updated dev dependencies</li>
<li>Fixed uncaught crash in async decompression on malformed DEFLATE
data</li>
<li>Fixed addLocalFolder following symlinks out of the archived
folder</li>
<li>Stripped setuid/setgid/sticky bits from extracted file
permissions</li>
<li>Enforced the decompression size cap on the async path and for size
0</li>
<li>Rejected archives with duplicate entry names</li>
<li>Blocked extraction from writing through symlinks inside the
target</li>
<li>Routed malformed-header parse errors through the async callback</li>
<li>Rejected zip entries whose declared data extent runs past the
buffer</li>
<li>Fixed addLocalFolderPromise hanging on empty folders and swallowing
errors</li>
<li>Fixed addLocalFolderAsync2 mangling local paths on Windows</li>
</ul>
<h2>v0.6.0</h2>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/cthackers/adm-zip/compare/v0.5.18...v0.6.0">https://github.com/cthackers/adm-zip/compare/v0.5.18...v0.6.0</a></p>
<p>This release fixes a security vulnerability (CVE-2026-39244),
resolves several long-standing bugs, ships built-in TypeScript types,
and includes two behavior changes worth reading before you upgrade.</p>
<ul>
<li>extractEntryTo(dirEntry, target, maintainEntryPath = false) now
preserves subdirectories instead of flattening files into the target
folder by basename (which also silently overwrote same-named files). (<a
href="https://redirect.github.com/cthackers/adm-zip/issues/306">#306</a>)</li>
<li>Extraction no longer fails when the modification time can't be set —
utimes is now best-effort. (<a
href="https://redirect.github.com/cthackers/adm-zip/issues/379">#379</a>)</li>
<li>Minimum Node.js is now 14 (the code already required it; engines was
incorrectly >=12).</li>
<li>CVE-2026-39244 — a crafted archive declaring a huge uncompressed
size could force an unbounded Buffer.alloc and OOM the process;
allocation is now bounded by the data actually present. Reported by
Daniel Púa (devploit), Anh Hong, and José Antonio Zamudio Amaya. (<a
href="https://redirect.github.com/cthackers/adm-zip/issues/568">#568</a>)</li>
<li>Hardened entry-name lookup against object injection
(<strong>proto</strong> names). Prototype-less table.</li>
<li>Data-descriptor regression rejecting valid archives (<a
href="https://redirect.github.com/cthackers/adm-zip/issues/548">#548</a>,
<a
href="https://redirect.github.com/cthackers/adm-zip/issues/533">#533</a>,
<a
href="https://redirect.github.com/cthackers/adm-zip/issues/554">#554</a>)</li>
<li>Directory permissions not restored on extract (<a
href="https://redirect.github.com/cthackers/adm-zip/issues/530">#530</a>)</li>
<li>Infinite recursion on symlink loops in addLocalFolder (<a
href="https://redirect.github.com/cthackers/adm-zip/issues/541">#541</a>)</li>
<li>Uncaught process crash in writeFileToAsync on write failure (<a
href="https://redirect.github.com/cthackers/adm-zip/issues/470">#470</a>,
<a
href="https://redirect.github.com/cthackers/adm-zip/issues/459">#459</a>,
<a
href="https://redirect.github.com/cthackers/adm-zip/issues/402">#402</a>)</li>
<li>Empty name on directory entries (<a
href="https://redirect.github.com/cthackers/adm-zip/issues/466">#466</a>)</li>
<li>test() always returned false for archives with files</li>
<li>~6× faster entry sorting for large archives</li>
<li>Built-in TypeScript definitions (types.d.ts) — you can drop
<code>@types/adm-zip</code></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/cthackers/adm-zip/blob/master/history.md">adm-zip's
changelog</a>.</em></p>
<blockquote>
<h1>0.6.0 / 2026-07-10</h1>
<p>Security</p>
<ul>
<li>Fixed CVE-2026-39244: a crafted archive declaring a huge
uncompressed size could force an unbounded <code>Buffer.alloc</code>
(memory exhaustion / DoS) before any validation. Allocation is now
bounded by the data actually present — STORED output is sized from the
real bytes, DEFLATED output is grown by the inflater and capped at the
declared size (<a
href="https://redirect.github.com/cthackers/adm-zip/issues/568">#568</a>)</li>
<li>Hardened the internal entry-name lookup table against object
injection: entry names come from untrusted archives, and a name such as
<code>__proto__</code> previously resolved to
<code>Object.prototype</code>, crashing <code>addFile</code> and hiding
the entry from <code>getEntry</code>/<code>readFile</code>. The table is
now prototype-less</li>
</ul>
<p>Bug fixes</p>
<ul>
<li>Fixed a regression (0.5.15) that rejected valid archives using a
data descriptor (general-purpose bit 3). The payload is now validated
against the authoritative central-directory CRC instead of
requiring/parsing the trailing descriptor (<a
href="https://redirect.github.com/cthackers/adm-zip/issues/548">#548</a>,
<a
href="https://redirect.github.com/cthackers/adm-zip/issues/533">#533</a>,
<a
href="https://redirect.github.com/cthackers/adm-zip/issues/554">#554</a>)</li>
<li>Fixed <code>extractAllTo</code>/<code>extractAllToAsync</code> not
restoring directory permissions with
<code>keepOriginalPermission</code>; directory modes are applied after
their contents are written, deepest path first, and no longer lock the
extractor out of a restrictive directory (<a
href="https://redirect.github.com/cthackers/adm-zip/issues/530">#530</a>)</li>
<li>Fixed infinite recursion in <code>addLocalFolder</code> when a
folder contains a symlink pointing back to an ancestor (e.g. workspace
<code>node_modules</code>); the walk now tracks resolved real paths and
skips already-visited directories (<a
href="https://redirect.github.com/cthackers/adm-zip/issues/541">#541</a>)</li>
<li>Fixed an uncaught exception (<code>ERR_INVALID_ARG_TYPE</code>) that
crashed the process when <code>writeFileToAsync</code> could not open
the target file (bad permissions, invalid filename, exhausted file
descriptors); write failures are now reported through the callback and
write errors are no longer silently swallowed (<a
href="https://redirect.github.com/cthackers/adm-zip/issues/470">#470</a>,
<a
href="https://redirect.github.com/cthackers/adm-zip/issues/459">#459</a>,
<a
href="https://redirect.github.com/cthackers/adm-zip/issues/402">#402</a>)</li>
<li>Fixed directory entries reporting an empty <code>name</code> (e.g.
<code>a/b/c/</code> now returns <code>c</code>) (<a
href="https://redirect.github.com/cthackers/adm-zip/issues/466">#466</a>)</li>
<li>Fixed <code>extractEntryTo</code> flattening subdirectories when
<code>maintainEntryPath</code> is false; the structure below the
extracted directory is now preserved instead of collapsing (and
overwriting) files by basename (<a
href="https://redirect.github.com/cthackers/adm-zip/issues/306">#306</a>)</li>
<li>Fixed a failed <code>utimes</code> aborting extraction; setting the
modification time is now best-effort and never fails extraction of
already-written content (<a
href="https://redirect.github.com/cthackers/adm-zip/issues/379">#379</a>)</li>
<li>Fixed <code>test()</code> always returning false for any archive
containing a file (it indexed the entries array with an entry object
instead of reading the entry); it now correctly verifies each entry's
CRC</li>
</ul>
<p>Performance</p>
<ul>
<li>Faster entry sorting when writing archives with many entries: names
are decoded once instead of on every comparison (about 6× faster sort
for large archives)</li>
</ul>
<p>Added</p>
<ul>
<li>Bundled TypeScript type definitions (<code>types.d.ts</code>), so
<code>@types/adm-zip</code> is no longer required</li>
</ul>
<p>Notes</p>
<ul>
<li>Behavior change: <code>extractEntryTo(dir, target, /*
maintainEntryPath */ false)</code> now preserves subdirectories beneath
the extracted directory rather than flattening them</li>
<li>Behavior change: extraction no longer fails when the modification
time cannot be set</li>
</ul>
<h1>0.5.4 / 2021-03-08</h1>
<ul>
<li>Fixed relative paths</li>
<li>Added zipcrypto encryption</li>
<li>Lower verMade for macOS when generating zip file</li>
</ul>
<h1>0.5.3 / 2021-02-07</h1>
<ul>
<li>Fixed filemode when unzipping</li>
</ul>
<h1>0.5.2 / 2021-01-27</h1>
<ul>
<li>Fixed path traversal issue (GHSL-2020-198)</li>
</ul>
<h1>0.5.1 / 2020-11-27</h1>
<ul>
<li>Incremented version (cthackers)</li>
<li>Fixed outFileName (cthackers)</li>
</ul>
<h1>0.5.0 / 2020-11-19</h1>
<ul>
<li>Added extra parameter to extractEntryTo so target filename can be
renamed (cthackers)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/cthackers/adm-zip/commit/cb2cf9ba4c7c865db426e2de1997cb41194d9872"><code>cb2cf9b</code></a>
Fixed addLocalFolderAsync2 mangling local paths on Windows</li>
<li><a
href="https://github.com/cthackers/adm-zip/commit/54902b60f0f1d6d6e8157e81e0f18c5001941ccc"><code>54902b6</code></a>
Fixed addLocalFolderPromise hanging on empty folders and swallowing
errors</li>
<li><a
href="https://github.com/cthackers/adm-zip/commit/73131bdce50fa6ed201c48b468082ef456894f2e"><code>73131bd</code></a>
Fixed CI</li>
<li><a
href="https://github.com/cthackers/adm-zip/commit/758898d71508e8a016691d5843b5f7ce2d1b208a"><code>758898d</code></a>
Rejected zip entries whose declared data extent runs past the
buffer</li>
<li><a
href="https://github.com/cthackers/adm-zip/commit/74b6e9f402c4c7cde4e33f3c87ff8f15ddcd6121"><code>74b6e9f</code></a>
Routed malformed-header parse errors through the async callback</li>
<li><a
href="https://github.com/cthackers/adm-zip/commit/eaa35fa73df6108a3d6ebc9b9073371740735265"><code>eaa35fa</code></a>
Blocked extraction from writing through symlinks inside the target</li>
<li><a
href="https://github.com/cthackers/adm-zip/commit/1e015e3e713aee426bf3d5c1bc1b555c90f4f3e6"><code>1e015e3</code></a>
Increment version</li>
<li><a
href="https://github.com/cthackers/adm-zip/commit/05101d47b3b983b705cc3e66fc34366118ba7b99"><code>05101d4</code></a>
Rejected archives with duplicate entry names</li>
<li><a
href="https://github.com/cthackers/adm-zip/commit/491600683dacb6cb9fe0718a0eeb9cb5eb49afa6"><code>4916006</code></a>
Enforced the decompression size cap on the async path and for size
0</li>
<li><a
href="https://github.com/cthackers/adm-zip/commit/6a63c339b83c52915483efacda517660a7a7bf87"><code>6a63c33</code></a>
Stripped setuid/setgid/sticky bits from extracted file permissions</li>
<li>Additional commits viewable in <a
href="https://github.com/cthackers/adm-zip/compare/v0.5.18...v0.6.1">compare
view</a></li>
</ul>
</details>
<br />
Updates `@wordpress/env` from 11.13.0 to 11.15.0
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/WordPress/gutenberg/blob/trunk/packages/env/CHANGELOG.md">@wordpress/env's
changelog</a>.</em></p>
<blockquote>
<h2>11.15.0 (2026-09-10)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Point the apt sources of the bullseye-based WordPress images (PHP
7.4 and 8.0) at <code>archive.debian.org</code>, so building them no
longer fails now that Debian 11 has reached end-of-life and left the
regular mirrors (<a
href="https://redirect.github.com/WordPress/gutenberg/pull/82478">#82478</a>).</li>
</ul>
<h2>11.14.0 (2026-08-26)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Update git sources to the latest commit when <code>--update</code>
is passed. Previously, a source pointing at a branch (such as
<code>"core": "WordPress/WordPress"</code>) stayed
at the commit it was first cloned at, no matter how many times it was
updated.</li>
<li>Do not fail <code>wp-env start</code> when Docker images cannot be
pulled (e.g., the Docker registry is unreachable); fall back to locally
cached images and show a notice instead. (<a
href="https://redirect.github.com/WordPress/gutenberg/issues/81631">#81631</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/WordPress/gutenberg/commit/485f42ae8a1c58ceea18371a507fd4acfa86fbd8"><code>485f42a</code></a>
chore(release): publish</li>
<li><a
href="https://github.com/WordPress/gutenberg/commit/c89dd70a9a10686a07421ad74d9ae01548a5366a"><code>c89dd70</code></a>
Update changelog files</li>
<li><a
href="https://github.com/WordPress/gutenberg/commit/a55a0d7826714af9232883c97a724a55f2610796"><code>a55a0d7</code></a>
Merge changes published in the Gutenberg plugin "release/24.0"
branch</li>
<li><a
href="https://github.com/WordPress/gutenberg/commit/d06b0104c1684b0c78906a62681af7d9deae29a4"><code>d06b010</code></a>
chore(release): publish (<a
href="https://github.com/WordPress/gutenberg/tree/HEAD/packages/env/issues/82084">#82084</a>)</li>
<li><a
href="https://github.com/WordPress/gutenberg/commit/0790fa5321f5f088494330178299a4d9a95ab254"><code>0790fa5</code></a>
Update changelog files</li>
<li><a
href="https://github.com/WordPress/gutenberg/commit/098e3ba18bd7e8054bca4fdd4bcb706af42971a9"><code>098e3ba</code></a>
Merge changes published in the Gutenberg plugin "release/23.9"
branch</li>
<li>See full diff in <a
href="https://github.com/WordPress/gutenberg/commits/@wordpress/env@11.15.0/packages/env">compare
view</a></li>
</ul>
</details>
<br />
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/WordPress/phpdoc-parser/network/alerts).
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>1 parent 03c8a25 commit aa15621
2 files changed
Lines changed: 10 additions & 10 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
28 | | - | |
| 28 | + | |
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
0 commit comments