NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
A Zstandard (Zstd) compression library for Dart. Supports native platforms via FFI and the web platform via an Emscripten-compiled WASM module.
Last release 1 months ago
24 Aug 2026
Too new to tell
only 2 release windows
Nearly every release is documented
notes for 1 of 1 stable releases
Nothing withdrawn
no release was ever pulled
3 months old
5 releases · first in 2026
One column per month.
Bump the version to 0.1.0 and open its CHANGELOG section
Co-Authored-By: Claude Opus 5 noreply@anthropic.com
First stable release. No functional changes to the compression API since
0.1.0-dev.4.
code_assets constraint to ^1.2.0; it had been relaxed to
^1.1.0 unintentionally and shipped that way in 0.1.0-dev.4.Security: bounded decompress's allocation against an attacker-controlled declared frame size (KMDB finding S-2). decompress now takes an optional maxO
decompress's allocation against an attacker-controlled
declared frame size (KMDB finding S-2). decompress now takes an optional
maxOutputBytes parameter (default defaultMaxOutputBytes, 64 MiB) and
throws the new ZstdLimitExceededException — before allocating anything for
the declared size — when a frame's declared decompressed size is negative or
exceeds the limit. There is no unbounded/opt-out mode; callers that need to
decompress something larger pass a larger explicit value. bin/dartz.dart
passes an explicit 1 << 40 cap, since a locally-selected file is trusted
input.compress: a failure allocating
the destination buffer could previously leak the already-allocated source
buffer (KMDB finding F-1). Each allocation is now guarded by its own nested
try/finally, matching the structure already used on web._malloc helper now throws ZstdException when the underlying WASM
malloc returns a null pointer (0), instead of silently proceeding to write
at heap offset 0 on allocation failure.Further publishing fixes
Further publishing fixes
Fix .pubignore incorrectly excluding lib/src/ from the published package.
.pubignore incorrectly excluding lib/src/ from the published package.hooks to ^2.0.0, native_toolchain_c to ^0.19.0, code_assets^1.2.0.Fixes to repair poor pub.dev score:
.pubignore incorrectly excluding lib/src/ from the published package.hooks to ^2.0.0, native_toolchain_c to ^0.19.0, code_assets
to ^1.2.0.- Initial version.
Your coding agent can read these notes before it upgrades. Set up the MCP server →