Skip to content

v2.1.0: Bug fixes, security hardening, standalone binary

Latest

Choose a tag to compare

@pratham2402 pratham2402 released this 11 Jun 06:02
· 1 commit to master since this release

What's Changed

Bug Fixes

  • Fix signal handler not breaking main loop in watchdog mode (proper shutdown with threading.Event)
  • Fix double-extension archives (.tar.gz) bypassing zip-bomb security checks
  • Fix RAR5 format detection (signatures now sorted by length before matching)
  • Fix tarfile path traversal vulnerability on Python < 3.12 (explicit filter='data')
  • Fix memory leak in polling monitor (periodic cleanup of stale entries)
  • Fix memory leak in watchdog handler (entries for deleted files now cleaned up)
  • Fix _find_archives bailing on first OSError instead of per-item error isolation
  • Fix os.makedirs('') edge case in CLI setup config save
  • Remove dead import os in security.py

Optimizations

  • Use direct __version__ import instead of __import__() dynamic lookup
  • Deduplicate post-extraction delete/trash logic into shared helper
  • Remove redundant zipfile import inside CLI setup test function

New Features

  • Standalone binary distribution via PyInstaller with build script
  • Multi-platform GitHub Actions CI (Linux x86_64, macOS arm64, Windows x86_64)
  • Binaries auto-attached to releases on version tags

Full Changelog: v2.0.0...v2.1.0