# @tryghost/zip

Latest version **3.5.14** (published 2026-09-30) · MIT license · 0 weekly downloads

## Install

```sh
npm install @tryghost/zip
pnpm add @tryghost/zip
yarn add @tryghost/zip
bun add @tryghost/zip
```

## Health

**Score 55/100 (C)** — status: active.

Positive: no vulnerabilities; recently updated; high maintenance score.

Warnings: low downloads; no types; no esm support.

## Facts

| | |
|---|---|
| Version | 3.5.14 |
| Published | 2026-09-30 |
| First published | 2020-03-20 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 0 |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 37 |
| Author | Ghost Foundation |
| Maintainers | zimoatghost, allouis, kernalghost, chrisraible, erisds, johnonolan, kevinansfield, cobbspur, aileencgn, jloh, minimaluminium, sam-lord, pauladamdavis, bobvaneck, joeegrigg, hadret, erik-ghost, sagzy, vershwal, zach1618, mike182uk, luissazevedo, lsinger, nickmoreton, renatoworks, rblstr-ghost, evanhahn-ghost, austin.burdine, weylandswart, ghost-slimer, tmciesco, jonatan-ghost, 9larsons |

## Links

- npm: https://www.npmjs.com/package/@tryghost/zip
- Repository: https://github.com/TryGhost/framework
- npm.io page: https://npm.io/package/@tryghost/zip

## Recent versions

- 3.5.14 (latest) — 2026-09-30
- 3.5.13 — 2026-09-11
- 3.5.12 — 2026-09-03
- 3.5.11 — 2026-09-01
- 3.5.10 — 2026-09-01
- 3.5.9 — 2026-08-26
- 3.5.8 — 2026-08-20
- 3.5.7 — 2026-08-17
- 3.5.6 — 2026-08-12
- 3.5.5 — 2026-07-23
- 3.5.4 — 2026-07-22
- 3.5.3 — 2026-07-20
- 3.5.2 — 2026-07-20
- 3.5.1 — 2026-07-15
- 3.5.0 — 2026-06-25
- … 75 more at https://npm.io/package/@tryghost/zip/versions

## README

# Zip

## Install

`npm install @tryghost/zip --save`

or

`pnpm add @tryghost/zip`

## Purpose

Zip compression and extraction utilities with safety checks for symlinks and unsafe filenames.

## Usage

```
const zip = require('@tryghost/zip');

// Create a zip from a folder

let res = await zip.compress('path/to/a/folder', 'path/to/archive.zip', [options])

// Extract a zip to a folder

let res = await zip.extract('path/to/archive.zip', 'path/to/files', [options])
```

### `extract` options

- `limits.perEntryUncompressedBytes` / `limits.totalUncompressedBytes` — reject archives whose entries exceed the given uncompressed sizes.
- `onEntry(entry, zipfile)` — called for every entry before it is written.
- `ensureOwnerPermissions` (default `false`) — when `true`, normalizes extracted entry permissions so the owner can always read, move and remove the result. Directories gain at least owner `rwx` and files gain at least owner `rw`, while existing execute/group/world bits are preserved. The source zip is never modified.

    This fixes archives that contain read-only directories (for example a `dr-xr-xr-x` / `0555` folder), which otherwise fail to extract because nested files cannot be written into them. It is intended for **trusted temporary extraction** of user-supplied archives (such as theme zips) where the caller must be able to read, move and remove the extracted tree.

    ```
    let res = await zip.extract('path/to/upload.zip', 'path/to/tmp', {ensureOwnerPermissions: true})
    ```

## Develop

This is a mono repository, managed with [Nx](https://nx.dev).

Follow the instructions for the top-level repo.

1. `git clone` this repo & `cd` into it as usual
2. Run `pnpm install` to install top-level dependencies.

## Run

- `pnpm dev`

## Test

- `pnpm lint` runs oxlint
- `pnpm test` runs lint and tests

# Copyright & License

Copyright (c) 2013-2026 Ghost Foundation - Released under the [MIT license](LICENSE).

---
_Source: https://npm.io/package/@tryghost/zip · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
