NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #3535 most downloaded on Packagist
Pure-PHP implementation to read and write TAR and ZIP archives
Last release 1 months ago
19 Aug 2026
Release timing varies
gaps range from 2 weeks to 2.7 years
Some releases are documented
notes for 8 of 23 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
23 releases · first in 2015
Zip::extract() trusted the sizes and the compression method from an entry's headers before checking that the data was there.
Zip::extract() trusted the sizes and the compression method from an
entry's headers before checking that the data was there.
The copy loops padded short reads with pack('a'.$read_size, $buffer), so
a small archive could make extraction write a much larger file:
Entries using neither store nor deflate ended up in the output as their
raw compressed data. zlib answers the faked gzip header of an unknown
method with the bytes unchanged instead of an error.
Incomplete headers reached unpack(), which warned about the missing
input before the exception was thrown.
Extraction now checks that an entry's data lies in front of the central
directory, fails on a short read instead of padding it, and rejects
unsupported compression methods. Entries that the include and exclude
filters skip stay unchecked, because their data is never read. All
headers are read through readRecord(), which refuses a short read.
Regression tests cover each of these archives.
One column per quarter.
Adding a directory produced an entry that no reader recognized as one, because its name was stored without the trailing slash readers look for. Adding
Adding a directory produced an entry that no reader recognized as one, because its name was
stored without the trailing slash readers look for. Adding one through addFile() also tried
to read its content, which raised a notice and left a stray deflate remnant in the entry.
Directories are now stored with a trailing slash and without content, so empty directories
survive a round trip and keep their mode.
writebytesAt() back-patches the CRC and sizes into a streamed local file header. The in-memory branch appended the patched buffer to itself and omitte
writebytesAt() back-patches the CRC and sizes into a streamed local file
header. The in-memory branch appended the patched buffer to itself and
omitted the replacement length, so it duplicated data and left the header
fields at zero instead of overwriting them in place. This corrupted any
in-memory archive where an addFile() entry followed another entry; the
fault stayed hidden because the library and several tools read those
values from the central directory rather than the local header.
Now the in-memory branch overwrites the header bytes in place, matching
the file-backed branch.
When a corrupt zip file is read, an exception should be thrown without any previous notices and warnings leaking.
When a corrupt zip file is read, an exception should be thrown without
any previous notices and warnings leaking.
This also introduces constants for a few magic numbers in the zip
format.
add tests for testing file property preservation
add tests for testing file property preservation
Nothing published for this version
Nothing published for this version
moved constant definition to top
moved constant definition to top
Existing tests didn't 100% make sure a zero byte file was correctly added and extracted. It was. Now we also have the tests to prove it.
Existing tests didn't 100% make sure a zero byte file was correctly
added and extracted. It was. Now we also have the tests to prove it.
In PHP8, match is a reserved keyword. In preparation this renames the method. A fallback via __call() is provided which will trigger a E_USER_NOTICE.
In PHP8, match is a reserved keyword. In preparation this renames the
method. A fallback via __call() is provided which will trigger a
E_USER_NOTICE.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →