Bump zip4j from 2.11.1 to 2.11.2
Bumps zip4j from 2.11.1 to 2.11.2.
Release notes
Sourced from zip4j's releases.
v2.11.2
Improvements:
Use SecureRandom instead of Random to implement a cryptographically strong random number
Bug fixes:
Fix null check Append file separator to path check only if required Fix endOfCentralDirectory location calculation when setting comment Use Path comparison over String comparison for Path traversal vulnerability Set lastModifiedFileTime for all entries and not just directories Use charset when generating AES vendor id info
Commits
942fe57Release v2.11.2c64f9eb#474 Use charset when generating aes vendor id info4aaa10aCode analysis cleanup and #435 mistake? (#458)5013235vuln-fix: Partial Path Traversal Vulnerability (#466)3eb5867#473 set lastModifiedFileTime to 0 if negative value is passed7a74670#473 set lastModifiedFileTime for all entries and not just directories0ffcaec#462 Append file separator to path check only if required5024127#463 Fix endOfCentralDirectory location calculation when setting comment9c7bb74Use SecureRandom instead of Random to implement a cryptographically strong ra...ce99554Update README.md (#444)- Additional commits viewable in compare view
You can trigger a rebase of this PR by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.