Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
@olleolleolle @aspiers @vipulnsward @bdewater @hainesr @d235j @taichi-ishitani @mihyaeru21 @tuzovakaoff @JackMc Thanks for your recent contributions to rubyzip 👏.
I'm helping @simonoff with maintenance on this library now.
I'm working toward this release mainly to fix any problems I caused with #376 in trying to fix CVE-2018-1000544 (#369). I've also reviewed and pulled in some other recent small fix PRs and done some housekeeping for CI, but I haven't attempted to merge anything larger or further down in the backlog for this release.
Do you have any views on Allow tilde in zip entry names #391 ? That's the last piece needed for this release, and it has some security implications. It would be good to have someone other than me review it.
I've updated the changelog this time and added my very short summaries of some of your PRs. Comments also welcome on this.
I can merge PRs but still can't release a new version, so that may still require help from Alex (or one of the other gem owners).
Going forward: I will try to stay on top of new security-related problems and obvious bugs. There is quite a bit in the backlog, of which I have only scratched the surface, so I'd be interested to get your thoughts on other priorities.