Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 9 additions & 7 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,16 @@

## [Unreleased]

## [9.5.3] - 2026-10-05

### Fixed
- Android: `zip` / `zipWithPassword` progress stays monotonic. The work total is counted before the first event, so a mix of files and folders no longer moves progress backwards.
- Android: `unzipAssets` progress stays within 0–1 when an entry's compressed size is unknown (`ZipInputStream` reports `-1`). Directory entries in asset archives are created, and traversal paths are rejected.
- Android: full `unzip` / `unzipWithPassword` create directory entries, including empty directories (same as iOS and selective extract). An entry that resolves to the destination directory itself is accepted; sibling prefixes such as `dest-evil` stay rejected.
- Missing archives reject with `ERR_FILE_NOT_FOUND` from Android `unzipWithPassword`, `isPasswordProtected`, and `getUncompressedSize`, and from iOS `getUncompressedSize`.
- Android: an invalid charset name rejects with `ERR_UNSUPPORTED`. A bare `AES` encryption method (or any unknown method) no longer throws; `AES` is AES-128 and unknown methods stay ZipCrypto.
- Android: successful `zip` / `zipWithPassword` fsync the archive before resolving (iOS already did).
- JS: an `AbortSignal` that aborts before the abort listener is attached rejects with `ERR_CANCELLED` and does not start native work or cancel a different in-flight operation.
- Android: `zip` / `zipWithPassword` progress stays monotonic. The work total is counted before the first event, so a mix of files and folders no longer moves progress backwards (#397).
- Android: `unzipAssets` progress stays within 0–1 when an entry's compressed size is unknown (`ZipInputStream` reports `-1`). Directory entries in asset archives are created, and traversal paths are rejected (#397).
- Android: full `unzip` / `unzipWithPassword` create directory entries, including empty directories (same as iOS and selective extract). An entry that resolves to the destination directory itself is accepted; sibling prefixes such as `dest-evil` stay rejected (#397).
- Missing archives reject with `ERR_FILE_NOT_FOUND` from Android `unzipWithPassword`, `isPasswordProtected`, and `getUncompressedSize`, and from iOS `getUncompressedSize` (#397).
- Android: an invalid charset name rejects with `ERR_UNSUPPORTED`. A bare `AES` encryption method (or any unknown method) no longer throws; `AES` is AES-128 and unknown methods stay ZipCrypto (#397).
- Android: successful `zip` / `zipWithPassword` fsync the archive before resolving (iOS already did) (#397).
- JS: an `AbortSignal` that aborts before the abort listener is attached rejects with `ERR_CANCELLED` and does not start native work or cancel a different in-flight operation (#397).

## [9.5.2] - 2026-09-28

Expand Down
7 changes: 6 additions & 1 deletion MIGRATION.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ Working examples: [playground-expo](./playground-expo/) and [playground-rn](./pl

Old-arch proof is compile + link on RN **0.81.6** (`.github/workflows/old-arch.yml`), not device Maestro. See the [README matrix](./README.md#old-architecture-rn-070081).

## Unreleased
## v9.5.3

Native behavior fixes. JavaScript call sites are unchanged. Rebuild the native app after upgrading.

Expand All @@ -38,6 +38,11 @@ Native behavior fixes. JavaScript call sites are unchanged. Rebuild the native a
- **Android `zip` / `zipWithPassword`** fsync the archive before the promise resolves. iOS already did.
- **`AbortSignal`:** if the signal aborts before the listener is attached, the call rejects with `ERR_CANCELLED` and does not start native work.

```bash
npm install react-native-zip-archive@^9.5.3
cd ios && pod install && cd ..
```

## v9.5.1

Android old-architecture load fix. JavaScript call sites are unchanged. Native rebuild required.
Expand Down
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "react-native-zip-archive",
"version": "9.5.2",
"version": "9.5.3",
"description": "Zip and unzip files in React Native and Expo (iOS & Android)",
"main": "index.js",
"types": "index.d.ts",
Expand Down
Loading