mirror of
https://github.com/daijro/camoufox.git
synced 2026-10-05 08:00:21 +00:00
adm-zip ^0.5.16 carried three high-severity advisories that every `npm audit` of a project using the package reported: a crafted archive could force an unbounded allocation (CVE-2026-39244, fixed in 0.6.0), and the decompression-bomb protection was incomplete until 0.6.1. Our one call, extractEntryTo(entry, dir, maintainEntryPath=true, overwrite=true), is not affected by 0.6's two behaviour changes. 0.6 bundles its own types, so @types/adm-zip goes. `pnpm audit --prod` now reports nothing. The README told users to run `npx camoufox fetch`. Without the package installed in the current project, npx resolves `camoufox` to an unrelated npm package (camoufox@0.1.19, a third-party port) and runs it. The scoped name runs ours: `npx @camoufox/camoufox fetch`, and likewise `version` in the issue templates. Found while testing 0.5.7-beta.6 on macOS before the 0.5.7 stable tag. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>