fix: drop vulnerable decompress dependency (GHSA-mp2f-45pm-3cg9), update tooling - #206
Merged
Merged
Conversation
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YEboe44Fee8PMf9Zv5kbqe
- eslint 9 with flat config, prettier 3, eslint-plugin-prettier 5 - tests migrated from tap to node:test - CI on Node 20/22/24 (16 and 18 are EOL), actions/setup-node v6 - regenerated package-lock.json, which had lost the fsevents entry and made `npm ci` fail in the release workflow Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YEboe44Fee8PMf9Zv5kbqe
This was referenced Sep 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #205.
Security fix
decompress(used only by the Windows postinstall to extract Sysinternals'DU.zip) is affected by GHSA-mp2f-45pm-3cg9 and has no patched release. It is removed.The archive is now read with the
tar.exe(bsdtar) that ships with Windows 10+, called by full path. tar is only used to list the archive (-tf) and to stream individual entries to stdout (-xOf), never to write to disk:du.exe,du64.exe,du64a.exeandEula.txtare written by name intobin/, and nothing else in the archive is touched. Entry paths,..components and symlinks inside the archive therefore cannot decide where anything is written.A first attempt that let
tar -xextract into a temp directory turned out not to be enough: Windows' bsdtar followed a symlink entry and wrote outside the target. The zip-slip fixture includes that case.Tooling (dev only, no effect on the published package)
node:test— supersedes chore(deps-dev): bump tap from 16.3.8 to 21.1.1 #200actions/setup-nodev6 — supersedes chore(deps): bump actions/setup-node from 4 to 6 #202package-lock.json: it had lost thefseventsentry, which madenpm cifail in the release workflow after the recent Dependabot merges🤖 Generated with Claude Code
https://claude.ai/code/session_01YEboe44Fee8PMf9Zv5kbqe