Skip to content

npm(deps): bump adm-zip, @wordpress/env and @wordpress/scripts - #1055

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/multi-24959be723
Closed

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/multi-24959be723

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Bumps adm-zip to 0.6.1 and updates ancestor dependencies adm-zip, @wordpress/env and @wordpress/scripts. These dependencies need to be updated together.

Updates adm-zip from 0.5.16 to 0.6.1

Release notes

Sourced from adm-zip's releases.

v0.6.1

Full Changelog: cthackers/adm-zip@v0.6.0...v0.6.1

  • Updated dev dependencies
  • Fixed uncaught crash in async decompression on malformed DEFLATE data
  • Fixed addLocalFolder following symlinks out of the archived folder
  • Stripped setuid/setgid/sticky bits from extracted file permissions
  • Enforced the decompression size cap on the async path and for size 0
  • Rejected archives with duplicate entry names
  • Blocked extraction from writing through symlinks inside the target
  • Routed malformed-header parse errors through the async callback
  • Rejected zip entries whose declared data extent runs past the buffer
  • Fixed addLocalFolderPromise hanging on empty folders and swallowing errors
  • Fixed addLocalFolderAsync2 mangling local paths on Windows

v0.6.0

Full Changelog: cthackers/adm-zip@v0.5.18...v0.6.0

This release fixes a security vulnerability (CVE-2026-39244), resolves several long-standing bugs, ships built-in TypeScript types, and includes two behavior changes worth reading before you upgrade.

  • extractEntryTo(dirEntry, target, maintainEntryPath = false) now preserves subdirectories instead of flattening files into the target folder by basename (which also silently overwrote same-named files). (#306)
  • Extraction no longer fails when the modification time can't be set — utimes is now best-effort. (#379)
  • Minimum Node.js is now 14 (the code already required it; engines was incorrectly >=12).
  • CVE-2026-39244 — a crafted archive declaring a huge uncompressed size could force an unbounded Buffer.alloc and OOM the process; allocation is now bounded by the data actually present. Reported by Daniel Púa (devploit), Anh Hong, and José Antonio Zamudio Amaya. (#568)
  • Hardened entry-name lookup against object injection (proto names). Prototype-less table.
  • Data-descriptor regression rejecting valid archives (#548, #533, #554)
  • Directory permissions not restored on extract (#530)
  • Infinite recursion on symlink loops in addLocalFolder (#541)
  • Uncaught process crash in writeFileToAsync on write failure (#470, #459, #402)
  • Empty name on directory entries (#466)
  • test() always returned false for archives with files
  • ~6× faster entry sorting for large archives
  • Built-in TypeScript definitions (types.d.ts) — you can drop @​types/adm-zip

v0.5.18

What's Changed

New Contributors

Full Changelog: cthackers/adm-zip@v0.5.17...v0.5.18

v0.5.17

... (truncated)

Changelog

Sourced from adm-zip's changelog.

0.6.0 / 2026-07-10

Security

  • Fixed CVE-2026-39244: a crafted archive declaring a huge uncompressed size could force an unbounded Buffer.alloc (memory exhaustion / DoS) before any validation. Allocation is now bounded by the data actually present — STORED output is sized from the real bytes, DEFLATED output is grown by the inflater and capped at the declared size (#568)
  • Hardened the internal entry-name lookup table against object injection: entry names come from untrusted archives, and a name such as __proto__ previously resolved to Object.prototype, crashing addFile and hiding the entry from getEntry/readFile. The table is now prototype-less

Bug fixes

  • Fixed a regression (0.5.15) that rejected valid archives using a data descriptor (general-purpose bit 3). The payload is now validated against the authoritative central-directory CRC instead of requiring/parsing the trailing descriptor (#548, #533, #554)
  • Fixed extractAllTo/extractAllToAsync not restoring directory permissions with keepOriginalPermission; directory modes are applied after their contents are written, deepest path first, and no longer lock the extractor out of a restrictive directory (#530)
  • Fixed infinite recursion in addLocalFolder when a folder contains a symlink pointing back to an ancestor (e.g. workspace node_modules); the walk now tracks resolved real paths and skips already-visited directories (#541)
  • Fixed an uncaught exception (ERR_INVALID_ARG_TYPE) that crashed the process when writeFileToAsync could not open the target file (bad permissions, invalid filename, exhausted file descriptors); write failures are now reported through the callback and write errors are no longer silently swallowed (#470, #459, #402)
  • Fixed directory entries reporting an empty name (e.g. a/b/c/ now returns c) (#466)
  • Fixed extractEntryTo flattening subdirectories when maintainEntryPath is false; the structure below the extracted directory is now preserved instead of collapsing (and overwriting) files by basename (#306)
  • Fixed a failed utimes aborting extraction; setting the modification time is now best-effort and never fails extraction of already-written content (#379)
  • Fixed test() always returning false for any archive containing a file (it indexed the entries array with an entry object instead of reading the entry); it now correctly verifies each entry's CRC

Performance

  • Faster entry sorting when writing archives with many entries: names are decoded once instead of on every comparison (about 6× faster sort for large archives)

Added

  • Bundled TypeScript type definitions (types.d.ts), so @types/adm-zip is no longer required

Notes

  • Behavior change: extractEntryTo(dir, target, /* maintainEntryPath */ false) now preserves subdirectories beneath the extracted directory rather than flattening them
  • Behavior change: extraction no longer fails when the modification time cannot be set

0.5.4 / 2021-03-08

  • Fixed relative paths
  • Added zipcrypto encryption
  • Lower verMade for macOS when generating zip file

0.5.3 / 2021-02-07

  • Fixed filemode when unzipping

0.5.2 / 2021-01-27

  • Fixed path traversal issue (GHSL-2020-198)

0.5.1 / 2020-11-27

  • Incremented version (cthackers)
  • Fixed outFileName (cthackers)

0.5.0 / 2020-11-19

  • Added extra parameter to extractEntryTo so target filename can be renamed (cthackers)

... (truncated)

Commits
  • cb2cf9b Fixed addLocalFolderAsync2 mangling local paths on Windows
  • 54902b6 Fixed addLocalFolderPromise hanging on empty folders and swallowing errors
  • 73131bd Fixed CI
  • 758898d Rejected zip entries whose declared data extent runs past the buffer
  • 74b6e9f Routed malformed-header parse errors through the async callback
  • eaa35fa Blocked extraction from writing through symlinks inside the target
  • 1e015e3 Increment version
  • 05101d4 Rejected archives with duplicate entry names
  • 4916006 Enforced the decompression size cap on the async path and for size 0
  • 6a63c33 Stripped setuid/setgid/sticky bits from extracted file permissions
  • Additional commits viewable in compare view

Updates @wordpress/env from 11.9.0 to 11.17.0

Changelog

Sourced from @​wordpress/env's changelog.

11.17.0 (2026-10-07)

New Features

  • Add a mariadbVersion option and WP_ENV_MARIADB_VERSION environment variable to choose the MariaDB version used by the Docker runtime, including versions older than 10.4 (#83751).
  • Explain why wp-env start fails when a database was last used by a newer MariaDB version, which MariaDB cannot downgrade from (#83751).
  • Stop wp-env start with an error naming the image when an image cannot be pulled and is not available locally, such as a mariadbVersion that does not exist, instead of reporting that cached images will be used (#83751).
  • Make wp db commands, and so wp-env reset, work with a mariadbVersion older than 11.4. The MariaDB client in the CLI image requires TLS, which those servers do not offer, so the CLI image now runs the client without verifying the server certificate, as WP-CLI does from db-command 3.0 (#83751).

Bug Fixes

  • Reject a phpVersion or WP_ENV_PHP_VERSION that is not only a version number, such as 8.2-apache or abc8, instead of failing later because the Docker image does not exist (#83751).
  • Pass -T to docker compose exec when stdin is not a terminal, so commands run from a Git hook, which has a TTY on stdout but not on stdin, no longer fail with "cannot attach stdin to a TTY-enabled container" (#78374).

Internal

  • Update @wp-playground/cli to 3.1.56, which replaces the fs-ext optional dependency, compiled with node-gyp at install time, with fs-ext-extra-prebuilt, which ships prebuilt binaries and works without running install scripts (#84012).
  • Update simple-git to v4, which has better TypeScript support (#84137).

11.16.0 (2026-09-23)

Bug Fixes

  • Wait for lifecycle script output streams to close before reporting command failures, so their error output is not lost (#82735).

11.15.0 (2026-09-10)

Bug Fixes

  • Point the apt sources of the bullseye-based WordPress images (PHP 7.4 and 8.0) at archive.debian.org, so building them no longer fails now that Debian 11 has reached end-of-life and left the regular mirrors (#82478).

11.14.0 (2026-08-26)

Bug Fixes

  • Update git sources to the latest commit when --update is passed. Previously, a source pointing at a branch (such as "core": "WordPress/WordPress") stayed at the commit it was first cloned at, no matter how many times it was updated.
  • Do not fail wp-env start when Docker images cannot be pulled (e.g., the Docker registry is unreachable); fall back to locally cached images and show a notice instead. (#81631)

11.13.0 (2026-08-12)

11.12.0 (2026-07-29)

11.11.0 (2026-07-14)

11.10.0 (2026-07-01)

Commits
  • 12441e2 chore(release): publish
  • 36c194f Update changelog files
  • 7b99cae Merge changes published in the Gutenberg plugin "release/24.2" branch
  • 56d8058 chore(release): publish
  • 9ff3f0e Update changelog files
  • f905a64 Merge changes published in the Gutenberg plugin "release/24.1" branch
  • 485f42a chore(release): publish
  • c89dd70 Update changelog files
  • a55a0d7 Merge changes published in the Gutenberg plugin "release/24.0" branch
  • d06b010 chore(release): publish (#82084)
  • Additional commits viewable in compare view

Updates @wordpress/scripts from 32.5.1 to 36.1.0

Changelog

Sourced from @​wordpress/scripts's changelog.

36.1.0 (2026-10-07)

Enhancements

  • lint-js: Allow unit-test titles passed through variables (#83995).

Bug Fixes

  • Add the stylelint-scss dependency, a peer of @wordpress/stylelint-config (#83765).
  • build, start and lint-pkg-json: Resolve the default browserslist and npm-package-json-lint configs when dependencies are not hoisted to the project root (npm install-strategy=linked, pnpm). lint-pkg-json now defaults to config/npmpackagejsonlint.js; config/npmpackagejsonlint.json stays for projects that reference it (#83902).
  • lint-js, lint-style and lint-md-docs: a file passed right after --fix is now treated as a file instead of that flag's value, so only the listed files get processed. Same for --require-pragma in format (#83521).

36.0.0 (2026-09-23)

Breaking Changes

  • Switch test-unit-js to consumer-installed Vitest 5 and Vite 7/8 at the 36.0.0 boundary. Run once by default, discover consumer Vitest/Vite config, and use Vitest lint defaults for test/spec files. Keep test-unit-jest as a maintenance-only adapter for consumer-installed Jest, with no scheduled removal. Remove the bundled Jest dependencies, preset config, Babel transformer, and GitHub Actions reporter. Retire the Jest preset and console package source; published versions remain available. Jest projects must install their own dependencies and configure the published preset if needed. See the migration guide. (#82843).

  • Require Node.js ^22.22.2 || ^24.15.0 || >=26.0.0 and update the bundled markdownlint-cli from ^0.31.1 to ^0.49.1, which moves markdownlint from 0.25 to 0.41. lint-md-docs now runs the rules added since then (MD051 through MD060) by default, so projects may see new reports. The header rule aliases (for example header-increment) no longer work in configuration files; use the heading names (#81917).

  • lint-style: Use stylelint's resolveConfig for config detection instead of a static extension list, supporting all current and future config file formats without manual maintenance overhead. Note that resolveConfig also searches ancestor directories and the global config directory (~/.config/stylelint), so a project with no local config may now pick up an unrelated config found there instead of the bundled default (#79280).

Enhancements

  • check-engines: Check only the tools listed in engines, instead of always passing --node and --npm. Without an engines field in the project, it now checks only the Node.js version (#83326).
  • lint-md-docs: Detect .markdownlint.jsonc so the bundled default config is not used when one is present (#81917).
  • format: Format .cjs and .mjs files when expanding a directory (#82731).
  • format: Format .cts and .mts files when expanding a directory (#83071).
  • The default ESLint config now lints .jsx, .ts, .tsx, .mts and .cts files, which ESLint's own file discovery skips (#83071).
  • build and start: Discover .cjs, .cts and .mts entry points, resolve them from extensionless imports, and transpile .cjs and .cts modules (#83071).
  • The bundled wp-prettier dependency has been upgraded from 3.0.3 to 3.9.6 (#82731).

Bug Fixes

  • Update the bundled webpack to ^5.111.0, which fixes a code-generation regression in webpack 5.110.3 that can make production bundles fail at startup (#82698).

35.0.0 (2026-09-10)

Breaking Changes

  • Require Node.js ^20.19.0 || >=22.13.0 and upgrade the bundled Stylelint to ^17.14.1 (#80738).

Bug Fixes

  • test-playwright: Install browsers with the bundled @playwright/test CLI, so they match the Playwright that runs the tests. A bare npx playwright could resolve another version, or download one (#82331).
  • build: Strip JavaScript and TypeScript source extensions from legacy positional entry names so generated output uses names such as index.js instead of index.tsx.js or index.jsx.js (#80990).

Enhancements

  • Include .jsx unit tests in the default lint configuration (#80990).

... (truncated)

Commits
  • 12441e2 chore(release): publish
  • 36c194f Update changelog files
  • 7b99cae Merge changes published in the Gutenberg plugin "release/24.2" branch
  • 56d8058 chore(release): publish
  • 9ff3f0e Update changelog files
  • f905a64 Merge changes published in the Gutenberg plugin "release/24.1" branch
  • 485f42a chore(release): publish
  • c89dd70 Update changelog files
  • a55a0d7 Merge changes published in the Gutenberg plugin "release/24.0" branch
  • d06b010 chore(release): publish (#82084)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added the dependencies Dependency updates label Sep 19, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 19, 2026 04:56
@dependabot dependabot Bot added the dependencies Dependency updates label Sep 19, 2026
Bumps [adm-zip](https://github.com/cthackers/adm-zip) to 0.6.1 and updates ancestor dependencies [adm-zip](https://github.com/cthackers/adm-zip), [@wordpress/env](https://github.com/WordPress/gutenberg/tree/HEAD/packages/env) and [@wordpress/scripts](https://github.com/WordPress/gutenberg/tree/HEAD/packages/scripts). These dependencies need to be updated together.


Updates `adm-zip` from 0.5.16 to 0.6.1
- [Release notes](https://github.com/cthackers/adm-zip/releases)
- [Changelog](https://github.com/cthackers/adm-zip/blob/master/history.md)
- [Commits](cthackers/adm-zip@v0.5.16...v0.6.1)

Updates `@wordpress/env` from 11.9.0 to 11.17.0
- [Release notes](https://github.com/WordPress/gutenberg/releases)
- [Changelog](https://github.com/WordPress/gutenberg/blob/trunk/packages/env/CHANGELOG.md)
- [Commits](https://github.com/WordPress/gutenberg/commits/@wordpress/env@11.17.0/packages/env)

Updates `@wordpress/scripts` from 32.5.1 to 36.1.0
- [Release notes](https://github.com/WordPress/gutenberg/releases)
- [Changelog](https://github.com/WordPress/gutenberg/blob/trunk/packages/scripts/CHANGELOG.md)
- [Commits](https://github.com/WordPress/gutenberg/commits/@wordpress/scripts@36.1.0/packages/scripts)

---
updated-dependencies:
- dependency-name: "@wordpress/env"
  dependency-version: 11.15.0
  dependency-type: direct:development
- dependency-name: "@wordpress/scripts"
  dependency-version: 35.0.0
  dependency-type: direct:development
- dependency-name: adm-zip
  dependency-version: 0.6.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-24959be723 branch from 76394c2 to ebb5f9f Compare October 10, 2026 15:56
@GaryJones

Copy link
Copy Markdown
Contributor

Superseded by #1067, which upgrades @wordpress/scripts to 36 (moving the JS unit tests to Vitest) and folds in these @wordpress/* bumps.

@GaryJones GaryJones closed this Oct 10, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/multi-24959be723 branch October 10, 2026 16:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant