Skip to content

chore(deps): bump adm-zip from 0.6.0 to 0.6.1 - #368

Merged
psiinon merged 1 commit into
masterfrom
dependabot/npm_and_yarn/adm-zip-0.6.1
Sep 19, 2026
Merged

psiinon merged 1 commit into
masterfrom
dependabot/npm_and_yarn/adm-zip-0.6.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 19, 2026

Copy link
Copy Markdown
Contributor

Bumps adm-zip from 0.6.0 to 0.6.1.

Release notes

Sourced from adm-zip's releases.

v0.6.1

Full Changelog: cthackers/adm-zip@v0.6.0...v0.6.1

  • Updated dev dependencies
  • Fixed uncaught crash in async decompression on malformed DEFLATE data
  • Fixed addLocalFolder following symlinks out of the archived folder
  • Stripped setuid/setgid/sticky bits from extracted file permissions
  • Enforced the decompression size cap on the async path and for size 0
  • Rejected archives with duplicate entry names
  • Blocked extraction from writing through symlinks inside the target
  • Routed malformed-header parse errors through the async callback
  • Rejected zip entries whose declared data extent runs past the buffer
  • Fixed addLocalFolderPromise hanging on empty folders and swallowing errors
  • Fixed addLocalFolderAsync2 mangling local paths on Windows
Commits
  • cb2cf9b Fixed addLocalFolderAsync2 mangling local paths on Windows
  • 54902b6 Fixed addLocalFolderPromise hanging on empty folders and swallowing errors
  • 73131bd Fixed CI
  • 758898d Rejected zip entries whose declared data extent runs past the buffer
  • 74b6e9f Routed malformed-header parse errors through the async callback
  • eaa35fa Blocked extraction from writing through symlinks inside the target
  • 1e015e3 Increment version
  • 05101d4 Rejected archives with duplicate entry names
  • 4916006 Enforced the decompression size cap on the async path and for size 0
  • 6a63c33 Stripped setuid/setgid/sticky bits from extracted file permissions
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [adm-zip](https://github.com/cthackers/adm-zip) from 0.6.0 to 0.6.1.
- [Release notes](https://github.com/cthackers/adm-zip/releases)
- [Changelog](https://github.com/cthackers/adm-zip/blob/master/history.md)
- [Commits](cthackers/adm-zip@v0.6.0...v0.6.1)

---
updated-dependencies:
- dependency-name: adm-zip
  dependency-version: 0.6.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 19, 2026
@psiinon

psiinon commented Sep 19, 2026

Copy link
Copy Markdown
Member

Logo
Checkmarx One – Scan Summary & Details – 6a179253-9163-4279-90b0-3ad53d033d12


New Issues (5 out of 5) Checkmarx found the following issues in this Pull Request

Severity: 4 High · 1 Medium

# Severity Issue Source File / Package Checkmarx Insight
1 HIGH CVE-2026-93687 Npm-braces-3.0.3
detailsDescription: braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply neste...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
2 HIGH CVE-2026-93690 Npm-uri-js-4.4.1
detailsDescription: uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins ...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
3 HIGH CVE-2026-93748 Npm-http-cache-semantics-4.2.0
detailsDescription: http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing u...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
4 HIGH CVE-2026-93750 Npm-http-cache-semantics-4.2.0
detailsDescription: http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary he...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package
5 MEDIUM CVE-2026-93751 Npm-uri-js-4.4.1
detailsDescription: uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package

Fixed Issues (1) Great job! The following issues were fixed in this Pull Request

Severity: 1 Medium

Severity Issue Source File / Package
MEDIUM CVE-2026-76845 Npm-adm-zip-0.6.0

Use @Checkmarx to take action directly from this PR:

  • Rescan the PR

Try it: @Checkmarx how can you help? · @Checkmarx rescan this PR

@psiinon
psiinon merged commit 64822a3 into master Sep 19, 2026
7 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/adm-zip-0.6.1 branch September 19, 2026 08:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Development

Successfully merging this pull request may close these issues.

2 participants