Skip to content

[Snyk] Upgrade adm-zip from 0.5.10 to 0.5.14#1

Open
Elenore23 wants to merge 1 commit intomainfrom
snyk-upgrade-8ef211a9a72ac706105c150fc87774d5
Open

[Snyk] Upgrade adm-zip from 0.5.10 to 0.5.14#1
Elenore23 wants to merge 1 commit intomainfrom
snyk-upgrade-8ef211a9a72ac706105c150fc87774d5

Conversation

@Elenore23
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)

Snyk has created this PR to upgrade adm-zip from 0.5.10 to 0.5.14.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 4 versions ahead of your current version.

  • The recommended version was released on 2 months ago.

Release notes
Package name: adm-zip
  • 0.5.14 - 2024-06-04

    Fixed an issue introduced on version 0.5.13 requiring a new mandatory parameter on the inflater on nodejs version >= 15

  • 0.5.13 - 2024-06-01
    • Fixed extractAllToAsync callback @ 5saviahv
    • Fixed issue with "toAsyncBuffer" where after that command all entries are gone @ 5saviahv
    • Minor fixes (tests, typos etc) @ 5saviahv
    • Added a an option to specificy the maximum expectedLength of the file to protect against zip bombs or limit memory usage @ undefined-moe
    • Add check for invalid large disk entries @ criyle
  • 0.5.12 - 2024-03-14

    Fixed extraction error

  • 0.5.11 - 2024-03-13
    • Add support for Info-Zip password check spec for ZipCrypto @ lukemalcolm
    • Extraction of password protected zip entries @ Santa77
    • Fixed unnecessary scanning a local file headers (except in the case of corrupted archives) @ likev
    • Added GitHub actions @ kibertoad
    • Fixed cases when extra data was lost @ yfdyh000
    • Fixed throw empty error in extractAllToAsync on operation done @ Autokaka
  • 0.5.10 - 2022-12-20
from adm-zip GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade adm-zip from 0.5.10 to 0.5.14.

See this package in npm:
adm-zip

See this project in Snyk:
https://app.snyk.io/org/elenore23/project/b4631f3f-24dd-402c-ac63-66307ddafb75?utm_source=github&utm_medium=referral&page=upgrade-pr
@socket-security
Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/adm-zip@0.5.14 filesystem 0 105 kB cthackers

🚮 Removed packages: npm/adm-zip@0.5.10

View full report↗︎

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants