Bump adm-zip to 0.6.1 to fix security alerts - #526
Merged
Merged
Conversation
lionel-
approved these changes
Sep 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR updates
adm-zipfrom 0.5.16 to 0.6.1 in the VS Code extension (editors/code). Version 0.6.1 corrects the two high-severity Dependabot alerts foradm-zip. These are showing up as "high" in our Snyk reporting so we need to get this fixed and then also released in a timely fashion.Why the extension version changed in
package-lock.jsonThe
versionfield at the top ofpackage-lock.jsonchanged from0.2.0to0.28.0, although this is not a new release of the extension, and the version of Air itself does not change. The lockfile had an old value. The value was0.2.0from the first commit of the extension, and later version bumps changed onlypackage.json. Whennpm installran, npm wrote the current version frompackage.jsoninto the lockfile. Now the two files agree!Risks
The risk here is very low.
adm-zipin one function only:zipFileRepresentations()insrc/commands.ts. This function usesnew AdmZip(),addFile(), andwriteZip(), and the types for these calls did not change in 0.6.x.adm-zip0.6.x requires Node 14 or later (0.5.x required Node 12 or later). VS Code and Positron use a much newer Node version, so this change has no effect on users.adm-zipis a 0.x package, so a minor version bump can include breaking changes. The type check, the webpack build, and the linter all pass.Testing
npx tsc --noEmit -p .passes.npm run compilepasses. Webpack shows one warning fromvscode-languageserver-types, but the same warning occurs onmain.npm run lintpasses.To do a manual test, open one or more of the Air tree views (tree-sitter, syntax tree, or format tree). Then use the command that zips the file representations, and make sure that the zip file contains the expected files.
The other open high-severity alerts (
js-yaml,brace-expansion,browserslist,minimatch,flatted,serialize-javascript) unfortunately do not have a supported fix at this time so this PR does not change them.