diff --git a/Frends.Zip.CreateArchive/CHANGELOG.md b/Frends.Zip.CreateArchive/CHANGELOG.md index 05e7f2b..ccb17a1 100644 --- a/Frends.Zip.CreateArchive/CHANGELOG.md +++ b/Frends.Zip.CreateArchive/CHANGELOG.md @@ -1,5 +1,11 @@ # Changelog +## [1.2.0] - 2024-12-13 +### Changed +- Drop DotNetZip in favour of ProDotNetZip because of security reasons +- DotNetZip has a HIGH severity directory traversal vulnerability (CVE reported Nov 2024) affecting versions 1.10.1 through 1.16.0 with no patch available (package is deprecated) +- The migration to ProDotNetZip 1.20.0 addresses this security concern + ## [1.1.0] - 2023-11-27 ### Added - [Breaking] Added Encoding for file and directory names. diff --git a/Frends.Zip.CreateArchive/Frends.Zip.CreateArchive/Frends.Zip.CreateArchive.csproj b/Frends.Zip.CreateArchive/Frends.Zip.CreateArchive/Frends.Zip.CreateArchive.csproj index a78b67f..d2152e8 100644 --- a/Frends.Zip.CreateArchive/Frends.Zip.CreateArchive/Frends.Zip.CreateArchive.csproj +++ b/Frends.Zip.CreateArchive/Frends.Zip.CreateArchive/Frends.Zip.CreateArchive.csproj @@ -8,10 +8,9 @@ Frends frends zip archive MIT - true true - 1.1.0 + 1.2.0 Task for creating ZIP archives. https://frends.com/ https://github.com/FrendsPlatform/Frends.Zip/Frends.Zip @@ -24,7 +23,7 @@ - + diff --git a/Frends.Zip.ExtractArchive/CHANGELOG.md b/Frends.Zip.ExtractArchive/CHANGELOG.md index c61c94f..22172d2 100644 --- a/Frends.Zip.ExtractArchive/CHANGELOG.md +++ b/Frends.Zip.ExtractArchive/CHANGELOG.md @@ -1,5 +1,11 @@ # Changelog +## [1.2.0] - 2024-12-13 +### Changed +- Drop DotNetZip in favour of ProDotNetZip because of security reasons +- DotNetZip has a HIGH severity directory traversal vulnerability (CVE reported Nov 2024) affecting versions 1.10.1 through 1.16.0 with no patch available (package is deprecated) +- The migration to ProDotNetZip 1.20.0 addresses this security concern + ## [1.1.0] - 2024-10-22 ### Fixed - Fixed issue with rename option writing the extracted files to wrong directory. @@ -19,4 +25,4 @@ ## [1.0.0] - 2022-02-23 ### Added -- Initial implementation \ No newline at end of file +- Initial implementation diff --git a/Frends.Zip.ExtractArchive/Frends.Zip.ExtractArchive/Frends.Zip.ExtractArchive.csproj b/Frends.Zip.ExtractArchive/Frends.Zip.ExtractArchive/Frends.Zip.ExtractArchive.csproj index 3c375e1..efdcbfd 100644 --- a/Frends.Zip.ExtractArchive/Frends.Zip.ExtractArchive/Frends.Zip.ExtractArchive.csproj +++ b/Frends.Zip.ExtractArchive/Frends.Zip.ExtractArchive/Frends.Zip.ExtractArchive.csproj @@ -8,10 +8,9 @@ Frends frends zip archive MIT - true true - 1.1.0 + 1.2.0 Task for extracting ZIP archives. https://frends.com/ https://github.com/FrendsPlatform/Frends.Zip/Frends.Zip.ExtractArchive @@ -24,7 +23,7 @@ - +