From 2b79c253a62667b5773c98c6e3be6bdc4d5addb9 Mon Sep 17 00:00:00 2001 From: Jacalz Date: Wed, 23 Dec 2020 12:02:25 +0100 Subject: [PATCH 1/6] Update github.com/andybalholm/brotli to v1.0.1 The changes between v1.0.0 and v1.0.1 can be found [here](https://github.com/andybalholm/brotli/compare/v1.0.0...v1.0.1). --- go.mod | 2 +- go.sum | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/go.mod b/go.mod index 8d8e4e16..9711c826 100644 --- a/go.mod +++ b/go.mod @@ -3,7 +3,7 @@ module github.com/mholt/archiver/v3 go 1.13 require ( - github.com/andybalholm/brotli v1.0.0 + github.com/andybalholm/brotli v1.0.1 github.com/dsnet/compress v0.0.1 github.com/golang/snappy v0.0.1 github.com/klauspost/compress v1.10.10 diff --git a/go.sum b/go.sum index adf9ee7d..78a98851 100644 --- a/go.sum +++ b/go.sum @@ -1,5 +1,5 @@ -github.com/andybalholm/brotli v1.0.0 h1:7UCwP93aiSfvWpapti8g88vVVGp2qqtGyePsSuDafo4= -github.com/andybalholm/brotli v1.0.0/go.mod h1:loMXtMfwqflxFJPmdbJO0a3KNoPuLBgiu3qAvBg8x/Y= +github.com/andybalholm/brotli v1.0.1 h1:KqhlKozYbRtJvsPrrEeXcO+N2l6NYT5A2QAFmSULpEc= +github.com/andybalholm/brotli v1.0.1/go.mod h1:loMXtMfwqflxFJPmdbJO0a3KNoPuLBgiu3qAvBg8x/Y= github.com/dsnet/compress v0.0.1 h1:PlZu0n3Tuv04TzpfPbrnI0HW/YwodEXDS+oPKahKF0Q= github.com/dsnet/compress v0.0.1/go.mod h1:Aw8dCMJ7RioblQeTqt88akK31OvO8Dhf5JflhBbQEHo= github.com/dsnet/golib v0.0.0-20171103203638-1ea166775780/go.mod h1:Lj+Z9rebOhdfkVLjJ8T6VcRQv3SXugXy999NBtR9aFY= From 22ead49abd7f5eafc634fc8cb05886c9974f84dd Mon Sep 17 00:00:00 2001 From: Jacalz Date: Wed, 23 Dec 2020 12:05:59 +0100 Subject: [PATCH 2/6] Update github.com/golang/snappy to v0.0.2 The changes between v0.0.1 and v0.0.2 can be found [here](https://github.com/golang/snappy/compare/v0.0.1...v0.0.2). --- go.mod | 2 +- go.sum | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/go.mod b/go.mod index 9711c826..dcfa741e 100644 --- a/go.mod +++ b/go.mod @@ -5,7 +5,7 @@ go 1.13 require ( github.com/andybalholm/brotli v1.0.1 github.com/dsnet/compress v0.0.1 - github.com/golang/snappy v0.0.1 + github.com/golang/snappy v0.0.2 github.com/klauspost/compress v1.10.10 github.com/klauspost/pgzip v1.2.4 github.com/nwaples/rardecode v1.1.0 diff --git a/go.sum b/go.sum index 78a98851..773ff5a0 100644 --- a/go.sum +++ b/go.sum @@ -3,8 +3,8 @@ github.com/andybalholm/brotli v1.0.1/go.mod h1:loMXtMfwqflxFJPmdbJO0a3KNoPuLBgiu github.com/dsnet/compress v0.0.1 h1:PlZu0n3Tuv04TzpfPbrnI0HW/YwodEXDS+oPKahKF0Q= github.com/dsnet/compress v0.0.1/go.mod h1:Aw8dCMJ7RioblQeTqt88akK31OvO8Dhf5JflhBbQEHo= github.com/dsnet/golib v0.0.0-20171103203638-1ea166775780/go.mod h1:Lj+Z9rebOhdfkVLjJ8T6VcRQv3SXugXy999NBtR9aFY= -github.com/golang/snappy v0.0.1 h1:Qgr9rKW7uDUkrbSmQeiDsGa8SjGyCOGtuasMWwvp2P4= -github.com/golang/snappy v0.0.1/go.mod h1:/XxbfmMg8lxefKM7IXC3fBNl/7bRcc72aCRzEWrmP2Q= +github.com/golang/snappy v0.0.2 h1:aeE13tS0IiQgFjYdoL8qN3K1N2bXXtI6Vi51/y7BpMw= +github.com/golang/snappy v0.0.2/go.mod h1:/XxbfmMg8lxefKM7IXC3fBNl/7bRcc72aCRzEWrmP2Q= github.com/klauspost/compress v1.4.1/go.mod h1:RyIbtBH6LamlWaDj8nUwkbUhJ87Yi3uG0guNDohfE1A= github.com/klauspost/compress v1.10.10 h1:a/y8CglcM7gLGYmlbP/stPE5sR3hbhFRUjCBfd/0B3I= github.com/klauspost/compress v1.10.10/go.mod h1:aoV0uJVorq1K+umq18yTdKaF57EivdYsUV+/s2qKfXs= From 22a247c46dc4a2e9e459cb329cf43086cd87cbf5 Mon Sep 17 00:00:00 2001 From: Jacalz Date: Wed, 23 Dec 2020 12:17:13 +0100 Subject: [PATCH 3/6] Update github.com/klauspost/compress to v1.11.4 The changelog can be found [here](https://github.com/klauspost/compress/blob/bb5ba3d9301e407bb22d6c5208c2b7625d71185e/README.md#changelog). --- go.mod | 2 +- go.sum | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/go.mod b/go.mod index dcfa741e..7813fb65 100644 --- a/go.mod +++ b/go.mod @@ -6,7 +6,7 @@ require ( github.com/andybalholm/brotli v1.0.1 github.com/dsnet/compress v0.0.1 github.com/golang/snappy v0.0.2 - github.com/klauspost/compress v1.10.10 + github.com/klauspost/compress v1.11.4 github.com/klauspost/pgzip v1.2.4 github.com/nwaples/rardecode v1.1.0 github.com/pierrec/lz4/v4 v4.0.3 diff --git a/go.sum b/go.sum index 773ff5a0..6e858066 100644 --- a/go.sum +++ b/go.sum @@ -6,8 +6,8 @@ github.com/dsnet/golib v0.0.0-20171103203638-1ea166775780/go.mod h1:Lj+Z9rebOhdf github.com/golang/snappy v0.0.2 h1:aeE13tS0IiQgFjYdoL8qN3K1N2bXXtI6Vi51/y7BpMw= github.com/golang/snappy v0.0.2/go.mod h1:/XxbfmMg8lxefKM7IXC3fBNl/7bRcc72aCRzEWrmP2Q= github.com/klauspost/compress v1.4.1/go.mod h1:RyIbtBH6LamlWaDj8nUwkbUhJ87Yi3uG0guNDohfE1A= -github.com/klauspost/compress v1.10.10 h1:a/y8CglcM7gLGYmlbP/stPE5sR3hbhFRUjCBfd/0B3I= -github.com/klauspost/compress v1.10.10/go.mod h1:aoV0uJVorq1K+umq18yTdKaF57EivdYsUV+/s2qKfXs= +github.com/klauspost/compress v1.11.4 h1:kz40R/YWls3iqT9zX9AHN3WoVsrAWVyui5sxuLqiXqU= +github.com/klauspost/compress v1.11.4/go.mod h1:aoV0uJVorq1K+umq18yTdKaF57EivdYsUV+/s2qKfXs= github.com/klauspost/cpuid v1.2.0 h1:NMpwD2G9JSFOE1/TJjGSo5zG7Yb2bTe7eq1jH+irmeE= github.com/klauspost/cpuid v1.2.0/go.mod h1:Pj4uuM528wm8OyEC2QMXAi2YiTZ96dNQPGgoMS4s3ek= github.com/klauspost/pgzip v1.2.4 h1:TQ7CNpYKovDOmqzRHKxJh0BeaBI7UdQZYc6p7pMQh1A= From caec2ec9c70dc4c61e34c5ec284dd7eeef17f1df Mon Sep 17 00:00:00 2001 From: Jacalz Date: Wed, 23 Dec 2020 12:20:01 +0100 Subject: [PATCH 4/6] Update github.com/klauspost/pgzip to v1.2.5 When resetting before reading all content temporary buffers were lost. Make sure to re-add temporary buffers. --- go.mod | 2 +- go.sum | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/go.mod b/go.mod index 7813fb65..c6d9e05d 100644 --- a/go.mod +++ b/go.mod @@ -7,7 +7,7 @@ require ( github.com/dsnet/compress v0.0.1 github.com/golang/snappy v0.0.2 github.com/klauspost/compress v1.11.4 - github.com/klauspost/pgzip v1.2.4 + github.com/klauspost/pgzip v1.2.5 github.com/nwaples/rardecode v1.1.0 github.com/pierrec/lz4/v4 v4.0.3 github.com/ulikunitz/xz v0.5.7 diff --git a/go.sum b/go.sum index 6e858066..73948659 100644 --- a/go.sum +++ b/go.sum @@ -10,8 +10,8 @@ github.com/klauspost/compress v1.11.4 h1:kz40R/YWls3iqT9zX9AHN3WoVsrAWVyui5sxuLq github.com/klauspost/compress v1.11.4/go.mod h1:aoV0uJVorq1K+umq18yTdKaF57EivdYsUV+/s2qKfXs= github.com/klauspost/cpuid v1.2.0 h1:NMpwD2G9JSFOE1/TJjGSo5zG7Yb2bTe7eq1jH+irmeE= github.com/klauspost/cpuid v1.2.0/go.mod h1:Pj4uuM528wm8OyEC2QMXAi2YiTZ96dNQPGgoMS4s3ek= -github.com/klauspost/pgzip v1.2.4 h1:TQ7CNpYKovDOmqzRHKxJh0BeaBI7UdQZYc6p7pMQh1A= -github.com/klauspost/pgzip v1.2.4/go.mod h1:Ch1tH69qFZu15pkjo5kYi6mth2Zzwzt50oCQKQE9RUs= +github.com/klauspost/pgzip v1.2.5 h1:qnWYvvKqedOF2ulHpMG72XQol4ILEJ8k2wwRl/Km8oE= +github.com/klauspost/pgzip v1.2.5/go.mod h1:Ch1tH69qFZu15pkjo5kYi6mth2Zzwzt50oCQKQE9RUs= github.com/nwaples/rardecode v1.1.0 h1:vSxaY8vQhOcVr4mm5e8XllHWTiM4JF507A0Katqw7MQ= github.com/nwaples/rardecode v1.1.0/go.mod h1:5DzqNKiOdpKKBH87u8VlvAnPZMXcGRhxWkRpHbbfGS0= github.com/pierrec/lz4/v4 v4.0.3 h1:vNQKSVZNYUEAvRY9FaUXAF1XPbSOHJtDTiP41kzDz2E= From d5cda147731d1a7ae0e7db0555a0b127cbe832d6 Mon Sep 17 00:00:00 2001 From: Jacalz Date: Wed, 23 Dec 2020 12:24:10 +0100 Subject: [PATCH 5/6] Update github.com/pierrec/lz4/v4 to v4.1.2 The changes between v4.0.3 and v4.1.2 can be found [here](https://github.com/pierrec/lz4/compare/v4.0.3...v4.1.2). --- go.mod | 2 +- go.sum | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/go.mod b/go.mod index c6d9e05d..d2e4a01b 100644 --- a/go.mod +++ b/go.mod @@ -9,7 +9,7 @@ require ( github.com/klauspost/compress v1.11.4 github.com/klauspost/pgzip v1.2.5 github.com/nwaples/rardecode v1.1.0 - github.com/pierrec/lz4/v4 v4.0.3 + github.com/pierrec/lz4/v4 v4.1.2 github.com/ulikunitz/xz v0.5.7 github.com/xi2/xz v0.0.0-20171230120015-48954b6210f8 ) diff --git a/go.sum b/go.sum index 73948659..127ee8c9 100644 --- a/go.sum +++ b/go.sum @@ -14,8 +14,8 @@ github.com/klauspost/pgzip v1.2.5 h1:qnWYvvKqedOF2ulHpMG72XQol4ILEJ8k2wwRl/Km8oE github.com/klauspost/pgzip v1.2.5/go.mod h1:Ch1tH69qFZu15pkjo5kYi6mth2Zzwzt50oCQKQE9RUs= github.com/nwaples/rardecode v1.1.0 h1:vSxaY8vQhOcVr4mm5e8XllHWTiM4JF507A0Katqw7MQ= github.com/nwaples/rardecode v1.1.0/go.mod h1:5DzqNKiOdpKKBH87u8VlvAnPZMXcGRhxWkRpHbbfGS0= -github.com/pierrec/lz4/v4 v4.0.3 h1:vNQKSVZNYUEAvRY9FaUXAF1XPbSOHJtDTiP41kzDz2E= -github.com/pierrec/lz4/v4 v4.0.3/go.mod h1:gZWDp/Ze/IJXGXf23ltt2EXimqmTUXEy0GFuRQyBid4= +github.com/pierrec/lz4/v4 v4.1.2 h1:qvY3YFXRQE/XB8MlLzJH7mSzBs74eA2gg52YTk6jUPM= +github.com/pierrec/lz4/v4 v4.1.2/go.mod h1:gZWDp/Ze/IJXGXf23ltt2EXimqmTUXEy0GFuRQyBid4= github.com/ulikunitz/xz v0.5.6 h1:jGHAfXawEGZQ3blwU5wnWKQJvAraT7Ftq9EXjnXYgt8= github.com/ulikunitz/xz v0.5.6/go.mod h1:2bypXElzHzzJZwzH67Y6wb67pO62Rzfn7BSiF4ABRW8= github.com/ulikunitz/xz v0.5.7 h1:YvTNdFzX6+W5m9msiYg/zpkSURPPtOlzbqYjrFn7Yt4= From 41df2e662af197af79e971bdd3d89b435ec8fb1b Mon Sep 17 00:00:00 2001 From: Jacalz Date: Wed, 23 Dec 2020 12:27:53 +0100 Subject: [PATCH 6/6] Update github.com/ulikunitz/xz to v0.5.9 The changes between v0.5.7 and v0.5.9 can be found [here](https://github.com/ulikunitz/xz/compare/v0.5.7...v0.5.9). The most important part here is that it fixes a security issue. https://github.com/ulikunitz/xz/security/advisories/GHSA-25xm-hr59-7c27 --- go.mod | 2 +- go.sum | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/go.mod b/go.mod index d2e4a01b..f02c8b62 100644 --- a/go.mod +++ b/go.mod @@ -10,6 +10,6 @@ require ( github.com/klauspost/pgzip v1.2.5 github.com/nwaples/rardecode v1.1.0 github.com/pierrec/lz4/v4 v4.1.2 - github.com/ulikunitz/xz v0.5.7 + github.com/ulikunitz/xz v0.5.9 github.com/xi2/xz v0.0.0-20171230120015-48954b6210f8 ) diff --git a/go.sum b/go.sum index 127ee8c9..efc6ff57 100644 --- a/go.sum +++ b/go.sum @@ -18,7 +18,7 @@ github.com/pierrec/lz4/v4 v4.1.2 h1:qvY3YFXRQE/XB8MlLzJH7mSzBs74eA2gg52YTk6jUPM= github.com/pierrec/lz4/v4 v4.1.2/go.mod h1:gZWDp/Ze/IJXGXf23ltt2EXimqmTUXEy0GFuRQyBid4= github.com/ulikunitz/xz v0.5.6 h1:jGHAfXawEGZQ3blwU5wnWKQJvAraT7Ftq9EXjnXYgt8= github.com/ulikunitz/xz v0.5.6/go.mod h1:2bypXElzHzzJZwzH67Y6wb67pO62Rzfn7BSiF4ABRW8= -github.com/ulikunitz/xz v0.5.7 h1:YvTNdFzX6+W5m9msiYg/zpkSURPPtOlzbqYjrFn7Yt4= -github.com/ulikunitz/xz v0.5.7/go.mod h1:nbz6k7qbPmH4IRqmfOplQw/tblSgqTqBwxkY0oWt/14= +github.com/ulikunitz/xz v0.5.9 h1:RsKRIA2MO8x56wkkcd3LbtcE/uMszhb6DpRf+3uwa3I= +github.com/ulikunitz/xz v0.5.9/go.mod h1:nbz6k7qbPmH4IRqmfOplQw/tblSgqTqBwxkY0oWt/14= github.com/xi2/xz v0.0.0-20171230120015-48954b6210f8 h1:nIPpBwaJSVYIxUFsDv3M8ofmx9yWTog9BfvIu0q41lo= github.com/xi2/xz v0.0.0-20171230120015-48954b6210f8/go.mod h1:HUYIGzjTL3rfEspMxjDjgmT5uz5wzYJKVo23qUhYTos=