diff --git a/CHANGELOG.md b/CHANGELOG.md index 7323551..41a9f6b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,6 +3,7 @@ ## [Unreleased] - Process: each 9.x minor gets an Announcements GitHub Discussion linked from the GitHub Release (`.github/announcements/vX.Y.md`, RNZA-28). [9.5 Discussion](https://github.com/mockingbot/react-native-zip-archive/discussions/389) +- SECURITY.md: 7.x install line is **7.1.3** (`maintenance-7`). 7.1.2 has the Zip Slip backport but does not compile on Android (#390). ## [9.5.1] - 2026-09-05 diff --git a/SECURITY.md b/SECURITY.md index 2da836a..2259110 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -9,7 +9,7 @@ | **7.x** | Security fixes only through **2027-02-19**. After that, 7.x is unsupported. Stay on 7.x if you are on React Native < 0.70 until you upgrade RN. 7.x will not be deleted or unpublished. | | **< 7** | Unsupported except for critical issues | -Zip Slip / symlink fixes shipped in 9.x will be **evaluated for 7.x backports**. If a patch is warranted, it will be published as `7.x.y`. **7.1.2** (`maintenance-7` dist-tag) backports Zip Slip validation and symlink skipping for Android and iOS extract paths. 7.x stays on security-only support through the EOL date above; it is not unpublished. +Zip Slip / symlink fixes shipped in 9.x will be **evaluated for 7.x backports**. If a patch is warranted, it will be published as `7.x.y`. **7.1.3** (`maintenance-7` dist-tag) is the 7.x release to install: it includes the Zip Slip / symlink backport from 7.1.2 and the Android compile fix for `compressionLevel` (#390). 7.1.2 has the security backport but does not compile on Android. 7.x stays on security-only support through the EOL date above; it is not unpublished. ## Reporting a vulnerability