Skip to content

Conversation

@Pr0methean
Copy link
Contributor

Due to GHSA-94vh-gphv-8pm8, the zip crate should be updated to 2.4.x immediately, to prevent specially-crafted templates from writing files outside the destination directory.

Make sure these boxes are checked! 📦✅

  • You have the latest version of rustfmt installed
$ rustup component add rustfmt-preview --toolchain nightly
  • You ran cargo fmt on the code base before submitting
  • You reference which issue is being closed in the PR text

✨✨ 😄 Thanks so much for contributing to binary-install! 😄 ✨✨

Due to GHSA-94vh-gphv-8pm8, the zip crate should be updated to 2.4.x immediately, to prevent specially-crafted templates from writing files outside the destination directory.
Copy link
Owner

@drager drager left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks

@drager drager merged commit 985580c into drager:master Aug 6, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants