Releases: codehaus-plexus/plexus-archiver
Releases Β· codehaus-plexus/plexus-archiver
4.10.0
- Change Snappy compressor to io.airlift:aircompressor (#339) @slachiewicz
- Fix modular jar final permissions (#333) @laurentgo
π¦ Dependency updates
- Update dependencies (#341) @slachiewicz
- Bump org.apache.commons:commons-compress from 1.26.1 to 1.26.2 (#337) @dependabot
- Bump org.assertj:assertj-core from 3.25.3 to 3.26.0 (#338) @dependabot
- Bump org.codehaus.plexus:plexus from 17 to 18 (#335) @dependabot
- Bump com.github.luben:zstd-jni from 1.5.6-2 to 1.5.6-3 (#331) @dependabot
- Bump commons-codec:commons-codec from 1.16.1 to 1.17.0 (#334) @dependabot
- Bump org.codehaus.plexus:plexus-utils from 4.0.0 to 4.0.1 (#330) @dependabot
- Bump com.github.luben:zstd-jni from 1.5.6-1 to 1.5.6-2 (#328) @dependabot
- Bump commons-io:commons-io from 2.16.0 to 2.16.1 (#329) @dependabot
- Bump commons-io:commons-io from 2.15.1 to 2.16.0 (#327) @dependabot
- Bump com.github.luben:zstd-jni from 1.5.5-11 to 1.5.6-1 (#326) @dependabot
4.9.2
π¦ Dependency updates
- Bump org.apache.commons:commons-compress from 1.26.0 to 1.26.1 (#325) @dependabot
- Bump org.codehaus.plexus:plexus from 16 to 17 (#324) @dependabot
- Bump org.apache.commons:commons-compress from 1.25.0 to 1.26.0 (#323) @dependabot
- Bump org.assertj:assertj-core from 3.25.2 to 3.25.3 (#322) @dependabot
- Bump org.assertj:assertj-core from 3.25.1 to 3.25.2 (#320) @dependabot
- Bump org.assertj:assertj-core from 3.24.2 to 3.25.1 (#319) @dependabot
- Bump org.codehaus.plexus:plexus-io from 3.4.1 to 3.4.2 (#317) @dependabot
π» Maintenance
- Bump release-drafter/release-drafter from 5 to 6 (#321) @dependabot
4.9.1
π New features and improvements
π¦ Dependency updates
- Bump org.codehaus.plexus:plexus from 15 to 16 (#316) @dependabot
- Bump com.github.luben:zstd-jni from 1.5.5-10 to 1.5.5-11 (#314) @dependabot
- Bump commons-io:commons-io from 2.15.0 to 2.15.1 (#313) @dependabot
- Bump org.apache.commons:commons-compress from 1.24.0 to 1.25.0 (#309) @dependabot
π» Maintenance
- Reuse plexus-pom action for CI (#315) @slachiewicz
4.9.0
π New features and improvements
- Allow copy all files without timestamp checking by DirectoryArchiver (#304) @slawekjaranowski
π¦ Dependency updates
- Bump com.github.luben:zstd-jni from 1.5.5-6 to 1.5.5-10 (#307) @dependabot
- Bump commons-io:commons-io from 2.14.0 to 2.15.0 (#303) @dependabot
- Bump org.codehaus.plexus:plexus from 14 to 15 (#302) @dependabot
- Bump com.github.luben:zstd-jni from 1.5.5-5 to 1.5.5-6 (#301) @dependabot
- Bump commons-io:commons-io from 2.13.0 to 2.14.0 (#300) @dependabot
- Bump org.apache.commons:commons-compress from 1.23.0 to 1.24.0 (#298) @dependabot
π» Maintenance
- Update info about release notes in README, ReleaseNotes (#308) @slawekjaranowski
4.8.0
π New features and improvements
- Add tzst alias for tar.zst archiver/unarchived (#274) @slawekjaranowski
π Bug Fixes
π¦ Dependency updates
- Bump org.codehaus.plexus:plexus from 13 to 14 (#296) @dependabot
- Bump zstd-jni from 1.5.5-4 to 1.5.5-5 (#295) @dependabot
- Bump Eclipse Sisu and from 0.3.5 to 0.9.0.M2 (#289) @slachiewicz
- Bump commons-io from 2.12.0 to 2.13.0 (#288) @dependabot
- Bump zstd-jni from 1.5.5-3 to 1.5.5-4 (#287) @dependabot
- Bump plexus-utils from 3.5.1 to 4.0.0 (#283) @dependabot
- Bump commons-io from 2.11.0 to 2.12.0 (#277) @dependabot
- Bump zstd-jni from 1.5.5-2 to 1.5.5-3 (#284) @dependabot
- Bump guice from 5.1.0 to 6.0.0 (#278) @dependabot
- Bump plexus from 10 to 13 (#280) @dependabot
π» Maintenance
- Remove public modifier from JUnit 5 tests (#294) @slawekjaranowski
- Use https in scm/url (#291) @slawekjaranowski
- Remove junit-jupiter-engine from project dependencies (#292) @slawekjaranowski
- Remove parent and reports menu from site (#282) @slawekjaranowski
- Cleanup after "veryLargeJar" test (#281) @slachiewicz
- Override project.url (#279) @slawekjaranowski
Plexus Archiver 4.7.1
Plexus Archiver 4.7.0
π New features and improvements
- add umask support and use 022 in RB mode (#271) @hboutemy
- Use NIO Files for creating temporary files (#270) @slawekjaranowski
- Deprecate the JAR Index feature (JDK-8302819) (#268) @jorsol
- Add Archiver aliases for tar.* (#266) @slawekjaranowski
π¦ Dependency updates
- Bump junitVersion from 5.9.2 to 5.9.3 (#267) @dependabot
- Bump zstd-jni from 1.5.5-1 to 1.5.5-2 (#265) @dependabot
- Bump zstd-jni from 1.5.4-2 to 1.5.5-1 (#263) @dependabot
- Bump commons-compress from 1.22 to 1.23.0 (#262) @dependabot
π» Maintenance
- Use JUnit TempDir to manage temporary files in tests (#269) @slawekjaranowski
- Override uId and gId for Tar in test (#264) @slawekjaranowski
- Bump maven-resources-plugin from 2.7 to 3.3.1 (#223) @dependabot
Plexus Archiver 4.6.3
π New features and improvements
- Fix path traversal vulnerability (#261) @plamentotev Thanks to @Fewword for reporting the vulnerability and suggesting a fix. The vulnerability affects only directories whose name begins with the same prefix as the destination directory. For example malicious archive may extract file in
/opt/directory
instead of/opt/dir
.
π¦ Dependency updates
- Bump plexus-utils from 3.5.0 to 3.5.1 (#257) @dependabot
Plexus Archiver 4.6.2
π Bug Fixes
- Fix regression in handling symbolic links. See codehaus-plexus/plexus-io#89
π¦ Dependency updates
- Bump plexus-io from 3.4.0 to 3.4.1 (#256) @dependabot
- Bump zstd-jni from 1.5.2-5 to 1.5.4-2 (#254) @dependabot, (#255) @dependabot
Plexus Archiver 4.6.1
π Bug Fixes
- Normalize file separators before warning about equal archive entries (#249) @Bananeweizen
π¦ Dependency updates
- Bump commons-compress from 1.21 to 1.22 (#243) @dependabot