duckscript
duckscript copied to clipboard
Bump zip from 2.2.3 to 4.0.0
trafficstars
Bumps zip from 2.2.3 to 4.0.0.
Release notes
Sourced from zip's releases.
v4.0.0
🐛 Bug Fixes
- Allow extraction of Zip64 where "Version needed to extract" is higher than "Version made by" (#356)
⚙️ Miscellaneous Tasks
- Revert nt-time upgrade (would increase MSRV)
- Revert constant_time_eq update (would increase MSRV)
- Update fully-qualified names of liblzma imports
v3.0.0
🐛 Bug Fixes
- return correct offset in SeekableTake::seek (#342)
- When only zopfli is available, decompression of deflate should not be possible (#348)
- Specify
flate2dependency of thedeflate-flate2feature. (#345)⚙️ Miscellaneous Tasks
- drop unused crossbeam-utils dependency (#339)
- fix typo
- remove
deflate-flate2dependency on specific backend- [breaking] Drop deprecated
deflate-minizfeature flag (#351)v2.6.1
🐛 Bug Fixes
- avoid scanning through all local file headers while opening an archive (#281)
v2.6.0
🚀 Features
🐛 Bug Fixes
- improve error message for duplicated file (#277)
v2.5.0
🚀 Features
🐛 Bug Fixes
- improve error message for duplicated file (#277)
... (truncated)
Changelog
Sourced from zip's changelog.
4.0.0 - 2025-05-21
🐛 Bug Fixes
- Allow extraction of Zip64 where "Version needed to extract" is higher than "Version made by" (#356)
⚙️ Miscellaneous Tasks
- Revert nt-time upgrade (would increase MSRV)
- Revert constant_time_eq update (would increase MSRV)
- Update fully-qualified names of liblzma imports
3.0.0 - 2025-05-14
🐛 Bug Fixes
- return correct offset in SeekableTake::seek (#342)
- When only zopfli is available, decompression of deflate should not be possible (#348)
- Specify
flate2dependency of thedeflate-flate2feature. (#345)⚙️ Miscellaneous Tasks
- drop unused crossbeam-utils dependency (#339)
- fix typo
- remove
deflate-flate2dependency on specific backend- [breaking] Drop deprecated
deflate-minizfeature flag (#351)2.6.1 - 2025-04-03
🐛 Bug Fixes
- avoid scanning through all local file headers while opening an archive (#281)
2.5.0 - 2025-03-23
🚀 Features
🐛 Bug Fixes
- improve error message for duplicated file (#277)
2.4.2 - 2025-03-18
🐛 Bug Fixes
deep_copy_fileproduced a mangled file header on big-endian platforms (#309)
... (truncated)
Commits
b87a248chore: release v4.0.0 (#357)2514c4cfix: Allow extraction of Zip64 where "Version needed to extract" is higher th...4aadb85docs: Update fuzzing section of README470394dchore: Revert nt-time upgrade (would increase MSRV)e4ab083test(ci): Remove redundant semver checks89fd4ffdeps!: Usedep:to suppress implicit features that may change in the future7d7d265chore: Revert constant_time_eq update (would increase MSRV)2d75b28style: cargo fmt --all3a5094ddeps: Replace lzma-rs with liblzmab93fc34chore: Update fully-qualified names of liblzma imports- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)