Skip to content

Bump adm-zip to 0.6.1 to fix security alerts - #526

Merged
juliasilge merged 1 commit into
mainfrom
bump-adm-zip-for-snyk
Sep 23, 2026
Merged

juliasilge merged 1 commit into
mainfrom
bump-adm-zip-for-snyk

Conversation

@juliasilge

Copy link
Copy Markdown
Member

This PR updates adm-zip from 0.5.16 to 0.6.1 in the VS Code extension (editors/code). Version 0.6.1 corrects the two high-severity Dependabot alerts for adm-zip. These are showing up as "high" in our Snyk reporting so we need to get this fixed and then also released in a timely fashion.

Why the extension version changed in package-lock.json

The version field at the top of package-lock.json changed from 0.2.0 to 0.28.0, although this is not a new release of the extension, and the version of Air itself does not change. The lockfile had an old value. The value was 0.2.0 from the first commit of the extension, and later version bumps changed only package.json. When npm install ran, npm wrote the current version from package.json into the lockfile. Now the two files agree!

Risks

The risk here is very low.

  • The extension uses adm-zip in one function only: zipFileRepresentations() in src/commands.ts. This function uses new AdmZip(), addFile(), and writeZip(), and the types for these calls did not change in 0.6.x.
  • adm-zip 0.6.x requires Node 14 or later (0.5.x required Node 12 or later). VS Code and Positron use a much newer Node version, so this change has no effect on users.
  • adm-zip is a 0.x package, so a minor version bump can include breaking changes. The type check, the webpack build, and the linter all pass.

Testing

  • npx tsc --noEmit -p . passes.
  • npm run compile passes. Webpack shows one warning from vscode-languageserver-types, but the same warning occurs on main.
  • npm run lint passes.

To do a manual test, open one or more of the Air tree views (tree-sitter, syntax tree, or format tree). Then use the command that zips the file representations, and make sure that the zip file contains the expected files.

The other open high-severity alerts (js-yaml, brace-expansion, browserslist, minimatch, flatted, serialize-javascript) unfortunately do not have a supported fix at this time so this PR does not change them.

@juliasilge
juliasilge requested a review from lionel- September 23, 2026 00:35
@juliasilge
juliasilge merged commit 070656a into main Sep 23, 2026
6 checks passed
@juliasilge
juliasilge deleted the bump-adm-zip-for-snyk branch September 23, 2026 13:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants