Files
camoufox/.github
Jake WriterandClaude Opus 5.5 b5e56dd0cd fix(ts): adm-zip 0.6.1, and run the CLI as npx @camoufox/camoufox (#831)
adm-zip ^0.5.16 carried three high-severity advisories that every
`npm audit` of a project using the package reported: a crafted archive
could force an unbounded allocation (CVE-2026-39244, fixed in 0.6.0), and
the decompression-bomb protection was incomplete until 0.6.1. Our one call,
extractEntryTo(entry, dir, maintainEntryPath=true, overwrite=true), is not
affected by 0.6's two behaviour changes. 0.6 bundles its own types, so
@types/adm-zip goes. `pnpm audit --prod` now reports nothing.

The README told users to run `npx camoufox fetch`. Without the package
installed in the current project, npx resolves `camoufox` to an unrelated
npm package (camoufox@0.1.19, a third-party port) and runs it. The scoped
name runs ours: `npx @camoufox/camoufox fetch`, and likewise `version` in
the issue templates.

Found while testing 0.5.7-beta.6 on macOS before the 0.5.7 stable tag.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-04 01:29:14 +00:00
..