NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #1898 most downloaded on crates.io
A Rust implementation of an async TAR file reader and writer. This library does not currently handle compression, but it is abstract over all I/O readers and writers. Additionally, great lengths are taken to ensure that the entire contents are never required to be entirely resident in memory all at once.
Last release 1 months ago
28 Aug 2026
Release timing varies
gaps range from 2 weeks to 5 months
Nearly every release is documented
notes for 13 of 13 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
14 releases · first in 2025
Bump the github-actions group across 1 directory with 5 updates by @dependabot [bot] in #108
Full Changelog: v0.6.4...v0.7.0
One column per month.
Entry::effective_size returns the effective size of an archive entry,
including any pax size records that apply to itHeader::entry_size is now Header::raw_entry_sizeHeader::size is now Header::raw_file_sizeBump taiki-e/install-action from 2.77.1 to 2.77.6 in the github-actions group by @dependabot [bot] in #84
Full Changelog: v0.6.2...v0.6.4
Reject mixed PAX and GNU path metadata
Full Changelog: v0.6.2...v0.6.3
Avoid desync when mixing extensions #82
This release addresses two advisories:
This release addresses two advisories:
Purely to shake out any issues with #73 .
Purely to shake out any issues with #73.
Signed-off-by: William Woodruff william@astral.sh
This release addresses GHSA-6gx3-4362-rf54 .
This release addresses GHSA-6gx3-4362-rf54.
Full Changelog: v0.5.6...v0.6.0
Fixed a parser desynchronization vulnerability when reading tar archives that contain mismatched size information in PAX/ustar headers.
Fixed a parser desynchronization vulnerability when reading tar archives that
contain mismatched size information in PAX/ustar headers.
This vulnerability is being tracked as GHSA-j5gw-2vrg-8fgx
and CVE-2025-62518.
This is a corrective release for 0.5.4 to fix a debugging artifact that was accidentally left in the release.
Fixed a path traversal vulnerability when using the unpack_in_raw API by @charliermarsh
Fixed a path traversal vulnerability when using the unpack_in_raw API
by @charliermarsh
This vulnerability is being tracked as GHSA-3wgq-wrwc-vqmv.
Release v0.5.3 for astral-sh/uv#15202 (comment) . The Cargo.toml is already bumped, so we only need update the Changelog.
Release v0.5.3 for
astral-sh/uv#15202 (comment). The
Cargo.toml is already bumped, so we only need update the Changelog.
TarError publicly by @konstin in https://github.com/astral-sh/tokio-tar/pull/52Enable opt-in to deny creation of symlinks outside target directory by @charliermarsh in https://github.com/astral-sh/tokio-tar/pull/46
Add test to reproduce issue in impl Stream for Entries causing filename truncation by @charliermarsh in https://github.com/astral-sh/tokio-tar/pull/41
impl Stream for Entries causing filename truncation by @charliermarsh in https://github.com/astral-sh/tokio-tar/pull/41Setting preserve_permissions to false will avoid setting _any_ permissions on extracted files. In `alexcrichton/tar-rs`, setting preserve_permissions
preserve_permissions to false will avoid setting any permissions on extracted files.
In alexcrichton/tar-rs, setting preserve_permissions
to false will still set read, write, and execute permissions on extracted files, but will avoid
setting extended permissions (e.g., setuid, setgid, and sticky bits).alexcrichton/tar-rs#259).unpack_in_raw which memoizes the set of validated paths (and assumes a pre-canonicalized)
unpack target to avoid redundant filesystem operations.Your coding agent can read these notes before it upgrades. Set up the MCP server →