From b5e56dd0cd2b77dd210dc1be4cd9e3be73210918 Mon Sep 17 00:00:00 2001 From: Jake Writer Date: Sun, 4 Oct 2026 01:29:14 +0000 Subject: [PATCH] fix(ts): adm-zip 0.6.1, and run the CLI as `npx @camoufox/camoufox` (#831) adm-zip ^0.5.16 carried three high-severity advisories that every `npm audit` of a project using the package reported: a crafted archive could force an unbounded allocation (CVE-2026-39244, fixed in 0.6.0), and the decompression-bomb protection was incomplete until 0.6.1. Our one call, extractEntryTo(entry, dir, maintainEntryPath=true, overwrite=true), is not affected by 0.6's two behaviour changes. 0.6 bundles its own types, so @types/adm-zip goes. `pnpm audit --prod` now reports nothing. The README told users to run `npx camoufox fetch`. Without the package installed in the current project, npx resolves `camoufox` to an unrelated npm package (camoufox@0.1.19, a third-party port) and runs it. The scoped name runs ours: `npx @camoufox/camoufox fetch`, and likewise `version` in the issue templates. Found while testing 0.5.7-beta.6 on macOS before the 0.5.7 stable tag. Co-authored-by: Claude Opus 5.5 --- .github/ISSUE_TEMPLATE/bug-report.md | 2 +- .github/ISSUE_TEMPLATE/camoufox-detected.md | 2 +- typescript/README.md | 2 +- typescript/package.json | 3 +-- typescript/pnpm-lock.yaml | 22 ++++++--------------- 5 files changed, 10 insertions(+), 21 deletions(-) diff --git a/.github/ISSUE_TEMPLATE/bug-report.md b/.github/ISSUE_TEMPLATE/bug-report.md index 4c32f73..0e19382 100644 --- a/.github/ISSUE_TEMPLATE/bug-report.md +++ b/.github/ISSUE_TEMPLATE/bug-report.md @@ -21,4 +21,4 @@ Provide steps or a code snippet that reproduces the bug. ### Version: -Run `python -m camoufox version` (or `npx camoufox version` for the npm package) and paste the output here. \ No newline at end of file +Run `python -m camoufox version` (or `npx @camoufox/camoufox version` for the npm package) and paste the output here. \ No newline at end of file diff --git a/.github/ISSUE_TEMPLATE/camoufox-detected.md b/.github/ISSUE_TEMPLATE/camoufox-detected.md index cd4f8f0..a4aa7af 100644 --- a/.github/ISSUE_TEMPLATE/camoufox-detected.md +++ b/.github/ISSUE_TEMPLATE/camoufox-detected.md @@ -41,4 +41,4 @@ These questions will help me diagnose the issue: ### Version: -Run `python -m camoufox version` (or `npx camoufox version` for the npm package) and paste the output here. \ No newline at end of file +Run `python -m camoufox version` (or `npx @camoufox/camoufox version` for the npm package) and paste the output here. \ No newline at end of file diff --git a/typescript/README.md b/typescript/README.md index d32972d..76531fd 100644 --- a/typescript/README.md +++ b/typescript/README.md @@ -18,7 +18,7 @@ pinned identity presents identically from either language. ```bash npm install @camoufox/camoufox playwright-core # then download the browser -npx camoufox fetch +npx @camoufox/camoufox fetch ``` `playwright-core` is a peer dependency — bring your own version (`<1.63`, diff --git a/typescript/package.json b/typescript/package.json index 4cac49d..86f3306 100644 --- a/typescript/package.json +++ b/typescript/package.json @@ -47,7 +47,7 @@ "//playwright-core": "Range mirrors pythonlib/pyproject.toml's `playwright = \"<1.63\"`: every Playwright minor is free to change Juggler, so the ceiling is bumped deliberately, with a run of `make tests`. The dev pin (1.62.0) is the version the Python venv resolves, so the goldens compare like with like.", "packageManager": "pnpm@10.33.4", "dependencies": { - "adm-zip": "^0.5.16", + "adm-zip": "^0.6.1", "cli-progress": "^3.12.0", "commander": "^14.0.0", "impit": "^0.14.1", @@ -60,7 +60,6 @@ }, "devDependencies": { "@biomejs/biome": "2.4.10", - "@types/adm-zip": "^0.5.7", "@types/cli-progress": "^3.11.6", "@types/language-tags": "^1.0.4", "@types/node": "^24.0.0", diff --git a/typescript/pnpm-lock.yaml b/typescript/pnpm-lock.yaml index 8cad8bc..cbd26ce 100644 --- a/typescript/pnpm-lock.yaml +++ b/typescript/pnpm-lock.yaml @@ -9,8 +9,8 @@ importers: .: dependencies: adm-zip: - specifier: ^0.5.16 - version: 0.5.18 + specifier: ^0.6.1 + version: 0.6.1 cli-progress: specifier: ^3.12.0 version: 3.12.0 @@ -42,9 +42,6 @@ importers: '@biomejs/biome': specifier: 2.4.10 version: 2.4.10 - '@types/adm-zip': - specifier: ^0.5.7 - version: 0.5.8 '@types/cli-progress': specifier: ^3.11.6 version: 3.11.6 @@ -254,9 +251,6 @@ packages: '@tybys/wasm-util@0.10.3': resolution: {integrity: sha512-F3fo1MYrRJYL3zER0OUOmkutjr1Vp23m7OsSgp7nq4SP6OqX6C/56XFIPAl5bt3zaBRjmW7SGz3u/6LwFpYcOg==} - '@types/adm-zip@0.5.8': - resolution: {integrity: sha512-RVVH7QvZYbN+ihqZ4kX/dMiowf6o+Jk1fNwiSdx0NahBJLU787zkULhGhJM8mf/obmLGmgdMM0bXsQTmyfbR7Q==} - '@types/chai@5.2.3': resolution: {integrity: sha512-Mw558oeA9fFbv65/y4mHtXDs9bPnFMZAL/jxdPFUpOHHIXX91mcgEHbS5Lahr+pwZFR8A7GQleRWeI6cGFC2UA==} @@ -307,9 +301,9 @@ packages: '@vitest/utils@4.1.10': resolution: {integrity: sha512-fy9am/HWxbaGt/Sawrp90vt6Y6jQwf1RX77cz3uwoJwJVMli/e1IEwRPnMNJ7vKfPTwo0diXifkpPvwH9v7nGA==} - adm-zip@0.5.18: - resolution: {integrity: sha512-ufJnssQGbxzLNS1Ho9bCtX4rQKCCvoVuDLHoJyc3F9dOGDB4BkWs2Ci0kv53lqocAEQ/Cbi+I2XCsNYGqVYqng==} - engines: {node: '>=12.0'} + adm-zip@0.6.1: + resolution: {integrity: sha512-Xwrja8nx9e5o2N1my4DsKCeKpdrnACyr1wtbPxBDgGzKzKyE9kRtBFA8mWldI+RVlD7CBZNWY/wQ2+ydwOR6kQ==} + engines: {node: '>=14.0'} ansi-regex@5.0.1: resolution: {integrity: sha512-quJQXlTSUGL2LH9SUXo8VwsY4soanhgo6LNSm84E1LBcE8s3O0wpdiRzyR9z/ZZJMlMWv37qOOb9pdJlMUEKFQ==} @@ -882,10 +876,6 @@ snapshots: tslib: 2.8.1 optional: true - '@types/adm-zip@0.5.8': - dependencies: - '@types/node': 24.13.3 - '@types/chai@5.2.3': dependencies: '@types/deep-eql': 4.0.2 @@ -950,7 +940,7 @@ snapshots: convert-source-map: 2.0.0 tinyrainbow: 3.1.1 - adm-zip@0.5.18: {} + adm-zip@0.6.1: {} ansi-regex@5.0.1: {}