hardsqlite
ZLib
hardsqlite | ZLib | |
---|---|---|
3 | 49 | |
1 | 5,306 | |
- | - | |
0.0 | 8.8 | |
about 1 year ago | 6 days ago | |
C | C | |
GNU General Public License v3.0 or later | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
hardsqlite
- Zlib Critical Vulnerability
-
SQLite the only database you will ever need in most cases
But filesystems are secure (mostly, ignoring unicode issues) whilst sqlite is an insecure hack.
You'll have hard time to harden sqlite, removing all the insecure defaults, fix the broken and exploitable full text search apis, but esp. its built-in hacks. Like explained here https://github.com/rurban/hardsqlite or here https://research.checkpoint.com/2019/select-code_execution-f...
-
You can eliminate much of your complexity by just using SQLite in production
All the testing does not help from it's design flaws and insecurities. I've tried here, but not recommended https://github.com/rurban/hardsqlite
ZLib
- Zlib 1.3.1 Out
-
Vulnerability found after scanning debian 12 bookworm VM
A fix has been checked into the upstream git repo: https://github.com/madler/zlib/pull/843 but a release has not yet been made including it.
-
ZLib VS jdeflate - a user suggested alternative
2 projects | 25 Nov 2023
-
CVE-2023-4863: Heap buffer overflow in WebP (Chrome)
So the real issue here is that the lack of tree validation before the tree construction, I believe. I'm surprised that this check was not yet implemented (I actually checked libwebp to make sure that I was missing one). Given this blind spot, an automated test based on the domain knowledge is likely useless to catch this bug.
[1] https://github.com/madler/zlib/blob/master/examples/enough.c
-
Notes: Advanced Node.js Concepts by Stephen Grider
In the source code of the Node.js opensource project, lib folder contains JavaScript code, mostly wrappers over C++ and function definitions. On the contrary, src folder contains C++ implementations of the functions, which pulls dependencies from the V8 project, the libuv project, the zlib project, the llhttp project, and many more - which are all placed at the deps folder.
- Zlib 1.3 · madler/zlib 09155ea
- Zlib 1.3 – A Spiffy yet Delicately Unobtrusive Compression Library
- Exploring the Internals of Linux v0.01
-
Dear Pirates Donate as much as you can
Seeing the text in red got me thinking for a moment, "wow, didn't realize pirates had such love for an open-source compression library"
-
Updated packages: do Arch devs update/build the original source as is or...
cd "${srcdir}/zlib-$pkgver/contrib/minizip" make install DESTDIR="${pkgdir}" install -D -m644 "${srcdir}/zlib-$pkgver/LICENSE" "${pkgdir}/usr/share/licenses/minizip/LICENSE" # https://github.com/madler/zlib/pull/229 rm "${pkgdir}/usr/include/minizip/crypt.h"
What are some alternatives?
litestore - A lightweight, self-contained, RESTful, searchable, multi-format NoSQL document store.
zstd - Zstandard - Fast real-time compression algorithm
sqlcipher - SQLCipher is a standalone fork of SQLite that adds 256 bit AES encryption of database files and other security features.
LZ4 - Extremely Fast Compression algorithm
gmailfs - FUSE-based filesystem for using an IMAP server (like gmail) as normal storage like a hard disk.
Snappy - A fast compressor/decompressor
temporal_tables - Temporal Tables PostgreSQL Extension
LZMA - (Unofficial) Git mirror of LZMA SDK releases
rqlite - The lightweight, distributed relational database built on SQLite.
Onion - C library to create simple HTTP servers and Web Applications.
datasette - An open source multi-tool for exploring and publishing data
Minizip-ng - Fork of the popular zip manipulation library found in the zlib distribution.