Skip to content

[Snyk] Upgrade unzipper from 0.9.15 to 0.12.3 - #111

Open
ryanmcmorrowsnyk wants to merge 1 commit into
masterfrom
snyk-upgrade-d601ea25f766fe44f2dd57c8f711415f
Open

ryanmcmorrowsnyk wants to merge 1 commit into
masterfrom
snyk-upgrade-d601ea25f766fe44f2dd57c8f711415f

Conversation

@ryanmcmorrowsnyk

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to upgrade unzipper from 0.9.15 to 0.12.3.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 21 versions ahead of your current version.

  • The recommended version was released 2 years ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-TAR-1536758
40 No Known Exploit

Breaking Change Risk

Merge Risk: High

Notice: This assessment is enhanced by AI.

Release notes
Package name: unzipper
  • 0.12.3 - 2024-07-31

    Add @ ts-ignore to unblock typescript errors

  • 0.12.2 - 2024-07-14
  • 0.12.1 - 2024-06-08
    • unmaintained fstream replaced with fs-extra
    • empty directories in a zip file will now be created when zip file is extracted
    • big-integer replaced with node-int64 (up to 20x performance increase on large encrypted files)
    • npm deployment added to github actions
  • 0.11.6 - 2024-05-11
  • 0.11.5 - 2024-05-04
  • 0.11.4 - 2024-04-22
  • 0.11.3 - 2024-04-15
  • 0.11.2 - 2024-04-14
    • remove polyfills - no longer supporting ancient node versions
    • use GitHub actions for testing and coverage
    • remove 'binary' dependency
    • break up huge promise chain to minimize memory usage
    • ignore window zip slipped files
    • use pipeline to propagate errors in a chain of streams
  • 0.10.14 - 2023-05-10
  • 0.10.11 - 2020-04-20
  • 0.10.10 - 2020-02-28
  • 0.10.9 - 2020-02-21
  • 0.10.8 - 2020-02-06
  • 0.10.7 - 2020-01-22
  • 0.10.6 - 2020-01-22
  • 0.10.5 - 2019-09-08
  • 0.10.4 - 2019-08-22
  • 0.10.3 - 2019-08-06
  • 0.10.2 - 2019-08-01
  • 0.10.1 - 2019-06-17
  • 0.10.0 - 2019-06-01
    • fix extract, move to a duplex stream to handle events better
    • add extract method to Open
    • add crx options and parsing
    • in Open methods use central directory instead of the local file headers (mainly to determine compressedSize)
  • 0.9.15 - 2019-05-20
from unzipper GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

@ryanmcmorrowsnyk

Copy link
Copy Markdown
Owner Author

Merge Risk: High

This upgrade from unzipper v0.9.15 to v0.12.3 introduces significant breaking changes related to stream handling and Node.js version support.

Key Breaking Changes:

  • Stream Draining: The parser no longer automatically drains entry streams. If you are listening for entry events, you must now manually consume each entry's stream (e.g., by calling entry.autodrain() or piping it) to prevent the main stream from pausing and never finishing. Code that does not handle this will likely hang.
  • Dropped Node.js Support: Starting with v0.11.2, support for "ancient" Node.js versions was removed by eliminating polyfills. While the specific versions are not listed, projects running on very old Node.js runtimes may fail.

Recommendation:
Review all usages of unzipper. For any code that listens to the entry event, ensure you are actively consuming the entry stream. For example:

// Old code might only listen for the event  
stream.on('entry', function (entry) {  
  console.log(entry.path);  
});  
  
// New code MUST consume the entry stream  
stream.on('entry', function (entry) {  
  console.log(entry.path);  
  entry.autodrain(); // or entry.pipe(some_destination)  
});  

Source: GitHub Repository, Release Notes

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@zeropath-ai

zeropath-ai Bot commented Apr 27, 2026

Copy link
Copy Markdown

✅ No security or compliance issues detected. Reviewed everything up to f298b05.

Security Overview
Detected Code Changes
Change Type Relevant files
Configuration changes ► package-lock.json
    Update express-jwt dependency version
    Update unzipper dependency version
    Remove unused dependencies (big-integer, binary, buffer-indexof-polyfill, buffers, chainsaw, listenercount, traverse)
► package.json
    Update unzipper dependency version
Enhancement ► package-lock.json
    Add optional flag to fstream, mkdirp, and rimraf dependencies
    Update fstream dependency to version 1.0.12
    Update mkdirp dependency to version 0.5.5
    Update rimraf dependency to version 2.7.1
    Update unzipper dependencies (bluebird, duplexer2, fs-extra, graceful-fs, node-int64)
    Update fs-extra dependencies (graceful-fs, jsonfile, universalify)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants