{"_id":"@electron-internal/extract-zip","_rev":"5-6e2c5c9334fe3890a124324c8aadd37a","name":"@electron-internal/extract-zip","dist-tags":{"latest":"1.0.4"},"versions":{"0.0.0":{"name":"@electron-internal/extract-zip","version":"0.0.0","author":"","license":"ISC","_id":"@electron-internal/extract-zip@0.0.0","maintainers":[{"name":"marshallofsound","email":"samuel.r.attard@gmail.com"},{"name":"electron-cfa","email":"info+cfa-npm@electronjs.org"},{"name":"electronhq","email":"marshallofsound+electronhqnpm@electronjs.org"}],"dist":{"shasum":"2b24e41cec3b69235e1f21a44286331159acccf0","tarball":"https://registry.npmjs.org/@electron-internal/extract-zip/-/extract-zip-0.0.0.tgz","fileCount":1,"integrity":"sha512-ILTly8mcmpQ04NYR4Bd/eC7vTPVhjFotU5AdWRjbJyfml5ksDmbEH6h1OZ//Ktg9n8DhWwxsJRNO1vNYsWsCUQ==","signatures":[{"sig":"MEUCIQDnqngG3BjJ3luOTkUvg6XBq5obuZnHZ23tFI+F9pFTEwIgKL4czcUeY+kHrajvLJY/s8xQ0I5uykMOns2owgBTlIY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":248},"main":"index.js","type":"commonjs","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"electronhq","email":"marshallofsound+electronhqnpm@electronjs.org"},"_npmVersion":"11.12.1","description":"","directories":{},"_nodeVersion":"24.15.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/extract-zip_0.0.0_1780599462555_0.047224217356127474","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@electron-internal/extract-zip","version":"1.0.1","keywords":["zip","unzip","extract","native","fast"],"license":"BSD-2-Clause","_id":"@electron-internal/extract-zip@1.0.1","maintainers":[{"name":"marshallofsound","email":"samuel.r.attard@gmail.com"},{"name":"electron-cfa","email":"info+cfa-npm@electronjs.org"},{"name":"electronhq","email":"marshallofsound+electronhqnpm@electronjs.org"}],"homepage":"https://github.com/electron/extract-zip#readme","bugs":{"url":"https://github.com/electron/extract-zip/issues"},"dist":{"shasum":"60a491edba28416a2f3a043b798966aa1700e4a2","tarball":"https://registry.npmjs.org/@electron-internal/extract-zip/-/extract-zip-1.0.1.tgz","fileCount":13,"integrity":"sha512-rdlxalBCtnzr9+MFptygKrrEB5rmCv0rKAAAfuaqEWVu4m5ZIxVZeh5b1zPZy2/mLvAL3VHlo+xSaC5ZUSZzeg==","signatures":[{"sig":"MEYCIQDj798hH3FVhPJQCODPLHjikQj2u40Qge+rgVFMGeExUwIhAN5Z8Fh/jTFKoh7wi4v37aLJcaMadcrJIrhmpg6GR3Ba","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@electron-internal%2fextract-zip@1.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":5932067},"napi":{"targets":["x86_64-apple-darwin","aarch64-apple-darwin","universal-apple-darwin","x86_64-pc-windows-msvc","aarch64-pc-windows-msvc","x86_64-unknown-linux-gnu","aarch64-unknown-linux-gnu","x86_64-unknown-linux-musl","aarch64-unknown-linux-musl"],"binaryName":"index","packageName":"@electron-internal/extract-zip"},"type":"module","types":"./index.d.ts","engines":{"node":">=22.12.0"},"exports":{".":{"types":"./index.d.ts","default":"./index.js"}},"gitHead":"d1ba072d6194cbaf4247d028b39d74e74d4311a5","scripts":{"test":"node --test test/*.test.js","bench":"node bench/bench.js","build":"napi build --platform --release --esm --output-dir . --js binding.js --dts binding.d.ts && node scripts/strip-binding-fallbacks.js","universal":"napi universalize --output-dir .","build:debug":"napi build --platform --esm --output-dir . --js binding.js --dts binding.d.ts && node scripts/strip-binding-fallbacks.js","bench:electron":"node bench/electron.js","prepublishOnly":"node scripts/check-prebuilds.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b94c0082-7ba1-445e-99f5-0c584402b526"}},"repository":{"url":"git+https://github.com/electron/extract-zip.git"},"_npmVersion":"11.6.2","description":"Fast, safe, native zip extraction for Node.js. Drop-in replacement for extract-zip.","directories":{},"_nodeVersion":"24.10.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"packageManager":"yarn@4.10.3+sha512.c38cafb5c7bb273f3926d04e55e1d8c9dfa7d9c3ea1f36a4868fa028b9e5f72298f0b7f401ad5eb921749eb012eb1c3bb74bf7503df3ee43fd600d14a018266f","devDependencies":{"yazl":"3.3.1","extract-zip":"2.0.1","@napi-rs/cli":"^3.6.2"},"_npmOperationalInternal":{"tmp":"tmp/extract-zip_1.0.1_1780600471236_0.2497123829742003","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@electron-internal/extract-zip","version":"1.0.2","keywords":["zip","unzip","extract","native","fast"],"license":"BSD-2-Clause","_id":"@electron-internal/extract-zip@1.0.2","maintainers":[{"name":"marshallofsound","email":"samuel.r.attard@gmail.com"},{"name":"electron-cfa","email":"info+cfa-npm@electronjs.org"},{"name":"electronhq","email":"marshallofsound+electronhqnpm@electronjs.org"}],"homepage":"https://github.com/electron/extract-zip#readme","bugs":{"url":"https://github.com/electron/extract-zip/issues"},"dist":{"shasum":"c612e3db45f78261a1e16d577cea9eac8663defc","tarball":"https://registry.npmjs.org/@electron-internal/extract-zip/-/extract-zip-1.0.2.tgz","fileCount":13,"integrity":"sha512-VJuNETNPEhrmQEZezeTZO5TZMV+dobBRyJ7zHjGJWIhMS7m7W1UeClt69u4hkUxv9ZZVxuli/E9Yvc4gDNHGsg==","signatures":[{"sig":"MEUCIBDHvdzAW4YWaVwlOXrqRhchgY3LQUTgwg1bxnKNdnCOAiEArc9lOASxuUXi5vvdW1rYdsHtt+G4jl0Cgklk04fZ3B0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@electron-internal%2fextract-zip@1.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":5934115},"napi":{"targets":["x86_64-apple-darwin","aarch64-apple-darwin","universal-apple-darwin","x86_64-pc-windows-msvc","aarch64-pc-windows-msvc","x86_64-unknown-linux-gnu","aarch64-unknown-linux-gnu","x86_64-unknown-linux-musl","aarch64-unknown-linux-musl"],"binaryName":"index","packageName":"@electron-internal/extract-zip"},"type":"module","types":"./index.d.ts","engines":{"node":">=22.12.0"},"exports":{".":{"types":"./index.d.ts","default":"./index.js"}},"gitHead":"d3f1eafc8ddf49211d72da957f9e68d7112a20b7","scripts":{"test":"node --test test/*.test.js","bench":"node bench/bench.js","build":"napi build --platform --release --esm --output-dir . --js binding.js --dts binding.d.ts && node scripts/strip-binding-fallbacks.js","universal":"napi universalize --output-dir .","build:debug":"napi build --platform --esm --output-dir . --js binding.js --dts binding.d.ts && node scripts/strip-binding-fallbacks.js","bench:electron":"node bench/electron.js","prepublishOnly":"node scripts/check-prebuilds.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b94c0082-7ba1-445e-99f5-0c584402b526"}},"repository":{"url":"git+https://github.com/electron/extract-zip.git"},"_npmVersion":"11.6.2","description":"Fast, safe, native zip extraction for Node.js. Drop-in replacement for extract-zip.","directories":{},"_nodeVersion":"24.10.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"packageManager":"yarn@4.10.3+sha512.c38cafb5c7bb273f3926d04e55e1d8c9dfa7d9c3ea1f36a4868fa028b9e5f72298f0b7f401ad5eb921749eb012eb1c3bb74bf7503df3ee43fd600d14a018266f","devDependencies":{"yazl":"3.3.1","extract-zip":"2.0.1","@napi-rs/cli":"^3.6.2"},"_npmOperationalInternal":{"tmp":"tmp/extract-zip_1.0.2_1780620413077_0.7840527862191558","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@electron-internal/extract-zip","version":"1.0.3","keywords":["zip","unzip","extract","native","fast"],"license":"BSD-2-Clause","_id":"@electron-internal/extract-zip@1.0.3","maintainers":[{"name":"marshallofsound","email":"samuel.r.attard@gmail.com"},{"name":"electron-cfa","email":"info+cfa-npm@electronjs.org"},{"name":"electronhq","email":"marshallofsound+electronhqnpm@electronjs.org"}],"homepage":"https://github.com/electron/extract-zip#readme","bugs":{"url":"https://github.com/electron/extract-zip/issues"},"dist":{"shasum":"debf68f415ed7a8416d568cd03cda98109c0eab4","tarball":"https://registry.npmjs.org/@electron-internal/extract-zip/-/extract-zip-1.0.3.tgz","fileCount":15,"integrity":"sha512-OjKpjB7gohtEjZiq6nDx1egqjZJhGPN1iFOIED+NFhB/MMkXw/XRcHjh1DGXKT5z2W9eW7Jy2UKU3gpjvusFTQ==","signatures":[{"sig":"MEUCIQCN9Zo14ngE8odmh6XBIXvjaXB1SVeF4oGW1nbMEAw0CwIgJm6/aD/QJre0EfhWfEVNKqLWpPQ0WAmcQePM6nZ1Sd8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@electron-internal%2fextract-zip@1.0.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7386972},"napi":{"targets":["x86_64-apple-darwin","aarch64-apple-darwin","universal-apple-darwin","x86_64-pc-windows-msvc","aarch64-pc-windows-msvc","x86_64-unknown-linux-gnu","aarch64-unknown-linux-gnu","x86_64-unknown-linux-musl","aarch64-unknown-linux-musl","i686-unknown-linux-gnu","armv7-unknown-linux-gnueabihf"],"binaryName":"index","packageName":"@electron-internal/extract-zip"},"type":"module","types":"./index.d.ts","engines":{"node":">=22.12.0"},"exports":{".":{"types":"./index.d.ts","default":"./index.js"}},"gitHead":"f4a8781fbf813bb066642aac19713973aa5a24df","scripts":{"test":"node --test test/*.test.js","bench":"node bench/bench.js","build":"napi build --platform --release --esm --output-dir . --js binding.js --dts binding.d.ts && node scripts/strip-binding-fallbacks.js","universal":"napi universalize --output-dir .","build:debug":"napi build --platform --esm --output-dir . --js binding.js --dts binding.d.ts && node scripts/strip-binding-fallbacks.js","bench:electron":"node bench/electron.js","prepublishOnly":"node scripts/check-prebuilds.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b94c0082-7ba1-445e-99f5-0c584402b526"}},"repository":{"url":"git+https://github.com/electron/extract-zip.git"},"_npmVersion":"11.6.2","description":"Fast, safe, native zip extraction for Node.js. Drop-in replacement for extract-zip.","directories":{},"_nodeVersion":"24.10.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"packageManager":"yarn@4.10.3+sha512.c38cafb5c7bb273f3926d04e55e1d8c9dfa7d9c3ea1f36a4868fa028b9e5f72298f0b7f401ad5eb921749eb012eb1c3bb74bf7503df3ee43fd600d14a018266f","devDependencies":{"yazl":"3.3.1","extract-zip":"2.0.1","@napi-rs/cli":"patch:@napi-rs/cli@npm%3A3.6.2#~/.yarn/patches/@napi-rs-cli-npm-3.6.2-b710c59d43.patch"},"_npmOperationalInternal":{"tmp":"tmp/extract-zip_1.0.3_1781237103876_0.6725476277490103","host":"s3://npm-registry-packages-npm-production"}},"1.0.4":{"name":"@electron-internal/extract-zip","version":"1.0.4","description":"Fast, safe, native zip extraction for Node.js. Drop-in replacement for extract-zip.","type":"module","exports":{".":{"types":"./index.d.ts","default":"./index.js"}},"napi":{"binaryName":"index","packageName":"@electron-internal/extract-zip","targets":["x86_64-apple-darwin","aarch64-apple-darwin","universal-apple-darwin","x86_64-pc-windows-msvc","aarch64-pc-windows-msvc","x86_64-unknown-linux-gnu","aarch64-unknown-linux-gnu","x86_64-unknown-linux-musl","aarch64-unknown-linux-musl","i686-unknown-linux-gnu","armv7-unknown-linux-gnueabihf"]},"scripts":{"build":"napi build --platform --release --esm --output-dir . --js binding.js --dts binding.d.ts && node scripts/strip-binding-fallbacks.js","build:debug":"napi build --platform --esm --output-dir . --js binding.js --dts binding.d.ts && node scripts/strip-binding-fallbacks.js","universal":"napi universalize --output-dir .","test":"node --test test/*.test.js","bench":"node bench/bench.js","bench:electron":"node bench/electron.js","prepublishOnly":"node scripts/check-prebuilds.js"},"keywords":["zip","unzip","extract","native","fast"],"license":"BSD-2-Clause","packageManager":"yarn@4.10.3+sha512.c38cafb5c7bb273f3926d04e55e1d8c9dfa7d9c3ea1f36a4868fa028b9e5f72298f0b7f401ad5eb921749eb012eb1c3bb74bf7503df3ee43fd600d14a018266f","engines":{"node":">=22.12.0"},"publishConfig":{"provenance":true,"access":"public"},"repository":{"url":"git+https://github.com/electron/extract-zip.git"},"devDependencies":{"@napi-rs/cli":"patch:@napi-rs/cli@npm%3A3.6.2#~/.yarn/patches/@napi-rs-cli-npm-3.6.2-b710c59d43.patch","extract-zip":"2.0.1","yazl":"3.3.1"},"gitHead":"3eb9258c8e5205cd522a84bc5872f3d18daba942","types":"./index.d.ts","_id":"@electron-internal/extract-zip@1.0.4","bugs":{"url":"https://github.com/electron/extract-zip/issues"},"homepage":"https://github.com/electron/extract-zip#readme","_nodeVersion":"24.10.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-Zr1Vs7E9tpCNhZHDAbFVXc2gEVCG9RqPDjrno5+bdgB6LRAuvgyMHJut4NCVyYwtAieapMzc3fiQ3CSTi75ARg==","shasum":"00b2c5cbd49fdc074d3ebf8dfef3c7b7b72eb46d","tarball":"https://registry.npmjs.org/@electron-internal/extract-zip/-/extract-zip-1.0.4.tgz","fileCount":15,"unpackedSize":7310166,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@electron-internal%2fextract-zip@1.0.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIF1ZT0/LEea9pKdWDtp+/5cRigCISsDcivI+lgSNlRiCAiEA3v8Uadc/QKyzUzG3xuLo0ajpRb7wKJWzTgf/6AQ5OBg="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b94c0082-7ba1-445e-99f5-0c584402b526"}},"directories":{},"maintainers":[{"name":"marshallofsound","email":"samuel.r.attard@gmail.com"},{"name":"electron-cfa","email":"info+cfa-npm@electronjs.org"},{"name":"electronhq","email":"marshallofsound+electronhqnpm@electronjs.org"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/extract-zip_1.0.4_1782254597050_0.6268593961829703"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-04T18:57:42.366Z","modified":"2026-06-23T22:43:17.619Z","0.0.0":"2026-06-04T18:57:42.689Z","1.0.1":"2026-06-04T19:14:31.494Z","1.0.2":"2026-06-05T00:46:53.328Z","1.0.3":"2026-06-12T04:05:04.131Z","1.0.4":"2026-06-23T22:43:17.304Z"},"bugs":{"url":"https://github.com/electron/extract-zip/issues"},"license":"BSD-2-Clause","homepage":"https://github.com/electron/extract-zip#readme","keywords":["zip","unzip","extract","native","fast"],"repository":{"url":"git+https://github.com/electron/extract-zip.git"},"description":"Fast, safe, native zip extraction for Node.js. Drop-in replacement for extract-zip.","maintainers":[{"name":"marshallofsound","email":"samuel.r.attard@gmail.com"},{"name":"electron-cfa","email":"info+cfa-npm@electronjs.org"},{"name":"electronhq","email":"marshallofsound+electronhqnpm@electronjs.org"}],"readme":"# @electron-internal/extract-zip\n\n> [!WARNING]\n> **Internal to the Electron project.** This package exists to serve Electron's\n> own tooling. Use from non-Electron packages is not supported: the API may\n> change to suit Electron's needs, and bug reports or feature requests from\n> outside use cases may be closed without action. If you need a general-purpose\n> extractor, use [`extract-zip`](https://github.com/max-mapper/extract-zip).\n\nFast, safe, native zip extraction for Node.js. Drop-in replacement for [`extract-zip`](https://github.com/max-mapper/extract-zip).\n\n- **Native**: Rust core via N-API, decompression runs off the event loop.\n- **Fast**: ~2x faster on entry-heavy archives, never slower. See [benchmarks](#benchmarks).\n- **Safe**: hardened against Zip Slip, symlink escapes, absolute paths, NUL injection, Windows reserved names, and zip bombs.\n- **Zero runtime deps**: no `debug`/`yauzl`/`get-stream` in your tree.\n- **Cross-platform**: prebuilt binaries for macOS, Linux (glibc/musl), and Windows (x64/arm64).\n\n## Install\n\n```sh\nyarn add @electron-internal/extract-zip\n```\n\n## Usage\n\nESM only:\n\n```js\nimport extract from '@electron-internal/extract-zip';\n\nawait extract('archive.zip', { dir: '/absolute/output/path' });\n```\n\n`dir` (required, absolute) is the only option. Everything else is fixed: existing\nfiles are overwritten, archive mode bits (masked to `0o777`) and mtimes are\npreserved, symlinks are created (skipped on Windows without symlink privilege),\nand writes are parallelised across `min(cpus, 8)` workers. The original's\n`onEntry`, `defaultDirMode`, and `defaultFileMode` are not supported, since no\nconsumer in the `electron` org uses them.\n\n## Security\n\nEvery entry path is verified to land inside `dir`:\n\n- `..` traversal is rejected and absolute paths are stripped, via the `zip` crate's audited `enclosed_name()`.\n- Directories are created one component at a time without following symlinks; an entry whose path crosses a symlink is rejected.\n- Symlinks are created after all files. Each target is walked against the on-disk tree and the archive's own symlink set, with relative-only hops bounded by `dir` and a hop cap, so a chain resolving outside `dir` is rejected before any link is created.\n- NUL bytes and Windows reserved device names (`CON`, `AUX`, `COM1`, trailing space/dot) are rejected on every platform.\n- Symlink targets are capped at 4 KiB; per-file output is capped at `max(2 x declared size, 1 MB)` to catch entries that lie about their size.\n\n`test/security.test.js` exercises these escapes end-to-end with hand-crafted archives.\n\n## Benchmarks\n\n`yarn bench` (Apple M-series, Node 24, median of 5):\n\n| Corpus | Zip size | `extract-zip` (JS) | this | Speedup |\n|---|--:|--:|--:|--:|\n| electron-v42.2.0-darwin-arm64 | 112 MB | 817 ms | 441 ms | 1.9x |\n| 8 x 4 MB compressible | 0.1 MB | 24 ms | 3 ms | 9.4x |\n| 2000 small text files | 0.4 MB | 372 ms | 199 ms | 1.9x |\n| 200 incompressible files | 6.2 MB | 40 ms | 22 ms | 1.8x |\n| `node_modules` | 2.9 MB | 68 ms | 37 ms | 1.9x |\n\nExtraction runs in phases: validate paths and create directories, inflate and\nwrite files in parallel with zlib-ng, then apply symlinks and directory\nmetadata. The Electron number is gated by its single 182 MB framework binary,\nwhich can't be split further.\n\n## Distribution\n\nOne package ships all prebuilt binaries (~2 MB gzipped): macOS\n`darwin-universal`, Windows `x64`/`arm64`, and Linux `x64`/`arm64` for both glibc\nand musl. `binding.js` picks the right one at load time. No\n`optionalDependencies`, no postinstall, no network at install.\n\n## Building from source\n\nRequires a Rust toolchain (and `cmake` for zlib-ng).\n\n```sh\nyarn install\nyarn build # builds index..node\nyarn test\n```\n\n## Releasing\n\nReleases are driven by [semantic-release](https://semantic-release.gitbook.io/)\non every push to `main`: conventional commit messages decide the version bump,\nCI builds all targets, and the fat package is published to npm via trusted\npublishing. No manual version bumps or tags.\n\n## License\n\nBSD-2-Clause\n","readmeFilename":"README.md"}