<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" xml:lang="en-US">
  <id>tag:github.com,2008:https://github.com/google/log4jscanner/releases</id>
  <link type="text/html" rel="alternate" href="https://github.com/google/log4jscanner/releases"/>
  <link type="application/atom+xml" rel="self" href="https://github.com/google/log4jscanner/releases.atom"/>
  <title>Release notes from log4jscanner</title>
  <updated>2022-05-25T22:02:38Z</updated>
  <entry>
    <id>tag:github.com,2008:Repository/442545507/v0.5.0</id>
    <updated>2022-05-25T22:09:10Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/google/log4jscanner/releases/tag/v0.5.0"/>
    <title>v0.5.0</title>
    <content type="html">&lt;h2&gt;What&#39;s Changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;jar: fix pool.Dynamic test flakiness by &lt;a class=&quot;user-mention notranslate&quot; data-hovercard-type=&quot;user&quot; data-hovercard-url=&quot;/users/aktau/hovercard&quot; data-octo-click=&quot;hovercard-link-click&quot; data-octo-dimensions=&quot;link_type:self&quot; href=&quot;https://github.com/aktau&quot;&gt;@aktau&lt;/a&gt; in &lt;a class=&quot;issue-link js-issue-link&quot; data-error-text=&quot;Failed to load title&quot; data-id=&quot;1174043323&quot; data-permission-text=&quot;Title is private&quot; data-url=&quot;https://github.com/google/log4jscanner/issues/58&quot; data-hovercard-type=&quot;pull_request&quot; data-hovercard-url=&quot;/google/log4jscanner/pull/58/hovercard&quot; href=&quot;https://github.com/google/log4jscanner/pull/58&quot;&gt;#58&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Report CVEs identified by &lt;a class=&quot;user-mention notranslate&quot; data-hovercard-type=&quot;user&quot; data-hovercard-url=&quot;/users/singlethink/hovercard&quot; data-octo-click=&quot;hovercard-link-click&quot; data-octo-dimensions=&quot;link_type:self&quot; href=&quot;https://github.com/singlethink&quot;&gt;@singlethink&lt;/a&gt; in &lt;a class=&quot;issue-link js-issue-link&quot; data-error-text=&quot;Failed to load title&quot; data-id=&quot;1230292013&quot; data-permission-text=&quot;Title is private&quot; data-url=&quot;https://github.com/google/log4jscanner/issues/60&quot; data-hovercard-type=&quot;pull_request&quot; data-hovercard-url=&quot;/google/log4jscanner/pull/60/hovercard&quot; href=&quot;https://github.com/google/log4jscanner/pull/60&quot;&gt;#60&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Make Parser used by Walker configurable by &lt;a class=&quot;user-mention notranslate&quot; data-hovercard-type=&quot;user&quot; data-hovercard-url=&quot;/users/singlethink/hovercard&quot; data-octo-click=&quot;hovercard-link-click&quot; data-octo-dimensions=&quot;link_type:self&quot; href=&quot;https://github.com/singlethink&quot;&gt;@singlethink&lt;/a&gt; in &lt;a class=&quot;issue-link js-issue-link&quot; data-error-text=&quot;Failed to load title&quot; data-id=&quot;1230325590&quot; data-permission-text=&quot;Title is private&quot; data-url=&quot;https://github.com/google/log4jscanner/issues/61&quot; data-hovercard-type=&quot;pull_request&quot; data-hovercard-url=&quot;/google/log4jscanner/pull/61/hovercard&quot; href=&quot;https://github.com/google/log4jscanner/pull/61&quot;&gt;#61&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Add license to pool files. by &lt;a class=&quot;user-mention notranslate&quot; data-hovercard-type=&quot;user&quot; data-hovercard-url=&quot;/users/singlethink/hovercard&quot; data-octo-click=&quot;hovercard-link-click&quot; data-octo-dimensions=&quot;link_type:self&quot; href=&quot;https://github.com/singlethink&quot;&gt;@singlethink&lt;/a&gt; in &lt;a class=&quot;issue-link js-issue-link&quot; data-error-text=&quot;Failed to load title&quot; data-id=&quot;1230282489&quot; data-permission-text=&quot;Title is private&quot; data-url=&quot;https://github.com/google/log4jscanner/issues/59&quot; data-hovercard-type=&quot;pull_request&quot; data-hovercard-url=&quot;/google/log4jscanner/pull/59/hovercard&quot; href=&quot;https://github.com/google/log4jscanner/pull/59&quot;&gt;#59&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;jar: support Go 1.19 archive/zip by &lt;a class=&quot;user-mention notranslate&quot; data-hovercard-type=&quot;user&quot; data-hovercard-url=&quot;/users/ianlancetaylor/hovercard&quot; data-octo-click=&quot;hovercard-link-click&quot; data-octo-dimensions=&quot;link_type:self&quot; href=&quot;https://github.com/ianlancetaylor&quot;&gt;@ianlancetaylor&lt;/a&gt; in &lt;a class=&quot;issue-link js-issue-link&quot; data-error-text=&quot;Failed to load title&quot; data-id=&quot;1248783037&quot; data-permission-text=&quot;Title is private&quot; data-url=&quot;https://github.com/google/log4jscanner/issues/63&quot; data-hovercard-type=&quot;pull_request&quot; data-hovercard-url=&quot;/google/log4jscanner/pull/63/hovercard&quot; href=&quot;https://github.com/google/log4jscanner/pull/63&quot;&gt;#63&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Full Changelog&lt;/strong&gt;: &lt;a class=&quot;commit-link&quot; href=&quot;https://github.com/google/log4jscanner/compare/v0.4.0...v0.5.0&quot;&gt;&lt;tt&gt;v0.4.0...v0.5.0&lt;/tt&gt;&lt;/a&gt;&lt;/p&gt;</content>
    <author>
      <name>ericchiang</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/2342749?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/442545507/v0.4.0</id>
    <updated>2022-03-18T20:34:46Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/google/log4jscanner/releases/tag/v0.4.0"/>
    <title>v0.4.0</title>
    <content type="html">&lt;p&gt;jar: do not keep large buffers unnecessarily&lt;/p&gt;

&lt;p&gt;This uses a sync.Pool wrapper (called pool.Dynamic) that prevents the
&lt;br /&gt;pool from holding on to very large buffers indefinitely, while still
&lt;br /&gt;amortizing the cost of allocation. The policy appears to give good
&lt;br /&gt;results both with the pre-existing tests and the specific tests added
&lt;br /&gt;for the pool.&lt;/p&gt;

&lt;p&gt;This is useful because the library is also used from long-running server
&lt;br /&gt;contexts, where it would be unfortunate to pin very large buffers for
&lt;br /&gt;too long. See &lt;a class=&quot;issue-link js-issue-link&quot; href=&quot;https://github.com/golang/go/issues/23199&quot;&gt;golang/go#23199&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Example algorithm run (from the test):&lt;/p&gt;

&lt;p&gt;```
&lt;br /&gt;num  allocs   value      target            capacity
&lt;br /&gt;1    1        100000     100000.000000     100000
&lt;br /&gt;2    1        1          52048.000000      100000
&lt;br /&gt;3    1        1          28072.000000      100000
&lt;br /&gt;4    1        1          16084.000000      100000
&lt;br /&gt;5    1        1          10090.000000      100000
&lt;br /&gt;6    1        1          7093.000000       100000
&lt;br /&gt;7    2        10         5594.500000       4096
&lt;br /&gt;8    2        1          4845.250000       4096
&lt;br /&gt;9    2        1          4470.625000       4096
&lt;br /&gt;10   2        1          4283.312500       4096
&lt;br /&gt;11   2        1          4189.656250       4096
&lt;br /&gt;12   2        1          4142.828125       4096
&lt;br /&gt;13   2        1          4119.414062       4096
&lt;br /&gt;14   2        1          4107.707031       4096
&lt;br /&gt;15   2        12         4101.853516       4096
&lt;br /&gt;16   2        1          4098.926758       4096
&lt;br /&gt;17   2        1          4097.463379       4096
&lt;br /&gt;18   2        1          4096.731689       4096
&lt;br /&gt;19   2        1          4096.365845       4096
&lt;br /&gt;20   2        1          4096.182922       4096
&lt;br /&gt;21   2        1          4096.091461       4096
&lt;br /&gt;22   2        1          4096.045731       4096
&lt;br /&gt;23   2        1000       4096.022865       4096
&lt;br /&gt;24   2        100        4096.011433       4096
&lt;br /&gt;25   3        10000      10000.000000      10000
&lt;br /&gt;26   4        100000     100000.000000     100000
&lt;br /&gt;27   4        1          52048.000000      100000
&lt;br /&gt;28   4        100000     100000.000000     100000
&lt;br /&gt;29   4        1          52048.000000      100000
&lt;br /&gt;30   4        50000      51024.000000      100000
&lt;br /&gt;31   4        1          27560.000000      100000
&lt;br /&gt;32   4        1          15828.000000      100000
&lt;br /&gt;33   4        25000      25000.000000      100000
&lt;br /&gt;34   4        1          14548.000000      100000
&lt;br /&gt;35   4        1          9322.000000       100000
&lt;br /&gt;36   5        1          6709.000000       4096
&lt;br /&gt;37   6        100000     100000.000000     100000
&lt;br /&gt;38   6        1          52048.000000      100000
&lt;br /&gt;39   6        1          28072.000000      100000
&lt;br /&gt;40   6        1          16084.000000      100000
&lt;br /&gt;41   6        1          10090.000000      100000
&lt;br /&gt;42   6        1          7093.000000       100000
&lt;br /&gt;43   7        1          5594.500000       4096
&lt;br /&gt;44   7        1          4845.250000       4096
&lt;br /&gt;45   7        1          4470.625000       4096
&lt;br /&gt;46   7        1          4283.312500       4096
&lt;br /&gt;47   7        100        4189.656250       4096
&lt;br /&gt;48   7        100        4142.828125       4096
&lt;br /&gt;49   7        100        4119.414062       4096
&lt;br /&gt;50   7        1          4107.707031       4096
&lt;br /&gt;51   7        1          4101.853516       4096
&lt;br /&gt;52   7        1          4098.926758       4096
&lt;br /&gt;53   7        1          4097.463379       4096
&lt;br /&gt;54   7        1          4096.731689       4096
&lt;br /&gt;55   7        100        4096.365845       4096
&lt;br /&gt;56   7        200        4096.182922       4096
&lt;br /&gt;57   7        300        4096.091461       4096
&lt;br /&gt;58   7        100        4096.045731       4096
&lt;br /&gt;59   7        50         4096.022865       4096
&lt;br /&gt;60   7        50         4096.011433       4096
&lt;br /&gt;61   7        50         4096.005716       4096
&lt;br /&gt;62   7        50         4096.002858       4096
&lt;br /&gt;63   7        50         4096.001429       4096
&lt;br /&gt;64   7        1          4096.000715       4096
&lt;br /&gt;65   7        1          4096.000357       4096
&lt;br /&gt;66   7        1          4096.000179       4096
&lt;br /&gt;67   7        1          4096.000089       4096
&lt;br /&gt;68   8        100000000  100000000.000000  100000000
&lt;br /&gt;69   8        1000000    50500000.000000   100000000
&lt;br /&gt;70   8        100000     25300000.000000   100000000
&lt;br /&gt;71   8        10000      12655000.000000   100000000
&lt;br /&gt;72   8        1000       6329548.000000    100000000
&lt;br /&gt;73   9        100        3166822.000000    4096
&lt;br /&gt;74   9        10         1585459.000000    4096
&lt;br /&gt;75   9        1          794777.500000     4096
&lt;br /&gt;76   9        1          399436.750000     4096
&lt;br /&gt;77   9        500        201766.375000     4096
&lt;br /&gt;78   9        2020       102931.187500     4096
&lt;br /&gt;79   9        400        53513.593750      4096
&lt;br /&gt;80   9        3984       28804.796875      4096
&lt;br /&gt;81   9        5          16450.398438      4096
&lt;br /&gt;82   9        200        10273.199219      4096
&lt;br /&gt;83   9        500        7184.599609       4096
&lt;br /&gt;84   10       40000      40000.000000      40000
&lt;br /&gt;85   10       35000      37500.000000      40000
&lt;br /&gt;86   11       45000      45000.000000      45000
&lt;br /&gt;87   11       42000      43500.000000      45000
&lt;br /&gt;88   11       38000      40750.000000      45000
&lt;br /&gt;89   11       38000      39375.000000      45000
&lt;br /&gt;90   11       39000      39187.500000      45000
&lt;br /&gt;91   11       41000      41000.000000      45000
&lt;br /&gt;92   11       42000      42000.000000      45000
&lt;br /&gt;93   11       42000      42000.000000      45000
&lt;br /&gt;94   11       2000       23048.000000      45000
&lt;br /&gt;95   11       4000       13572.000000      45000
&lt;br /&gt;96   11       3949       8834.000000       45000
&lt;br /&gt;97   11       2011       6465.000000       45000
&lt;br /&gt;98   11       4096       5280.500000       45000
&lt;br /&gt;99   11       33         4688.250000       45000
&lt;br /&gt;100  11       0          4392.125000       45000
&lt;br /&gt;101  12       4938       4938.000000       4938
&lt;br /&gt;102  12       1          4517.000000       4938
&lt;br /&gt;103  12       1          4306.500000       4938
&lt;br /&gt;104  12       1200       4201.250000       4938
&lt;br /&gt;105  12       2400       4148.625000       4938
&lt;br /&gt;106  12       1200       4122.312500       4938
&lt;br /&gt;107  12       200        4109.156250       4938
&lt;br /&gt;108  12       400        4102.578125       4938
&lt;br /&gt;109  12       600        4099.289062       4938
&lt;br /&gt;110  12       700        4097.644531       4938
&lt;br /&gt;111  12       100        4096.822266       4938
&lt;br /&gt;112  12       400        4096.411133       4938
&lt;br /&gt;113  12       500        4096.205566       4938
&lt;br /&gt;114  12       700        4096.102783       4938
&lt;br /&gt;115  12       600        4096.051392       4938
&lt;br /&gt;116  12       900        4096.025696       4938
&lt;br /&gt;117  12       1000       4096.012848       4938
&lt;br /&gt;118  12       1100       4096.006424       4938
&lt;br /&gt;119  12       1200       4096.003212       4938
&lt;br /&gt;120  12       1000       4096.001606       4938
&lt;br /&gt;```&lt;/p&gt;

&lt;p&gt;Benchmarks also show that the pool does retain the buffer, as
&lt;br /&gt;performance is not worsened over the previous commit:&lt;/p&gt;

&lt;p&gt;```
&lt;br /&gt;$ git checkout main
&lt;br /&gt;TMPDIR=&quot;$HOME/tmp/tmpdir&quot;
&lt;br /&gt;mkdir &quot;$TMPDIR&quot; || true
&lt;br /&gt;for file in jar/testdata/* ; do
&lt;br /&gt;  RTMPDIR=&quot;$TMPDIR/$(basename $file)&quot;
&lt;br /&gt;  mkdir &quot;$RTMPDIR&quot; || true
&lt;br /&gt;  ln -fv &quot;$PWD/$file&quot; &quot;$RTMPDIR&quot;
&lt;br /&gt;done
&lt;br /&gt;for commit in $(git log --pretty=oneline | head -5 | awk &#39;{print $1}&#39; | tac) ; do
&lt;br /&gt;  git checkout $commit
&lt;br /&gt;  go build
&lt;br /&gt;  hyperfine --ignore-failure --warmup 1 &quot;./log4jscanner $TMPDIR/400mb_jar_in_jar.jar&quot;
&lt;br /&gt;  rm log4jscanner
&lt;br /&gt;done
&lt;br /&gt;HEAD is now at &lt;a class=&quot;commit-link&quot; href=&quot;https://github.com/google/log4jscanner/commit/48d70bfb7e99a469832f21854710f7cddb3e17fd&quot;&gt;&lt;tt&gt;48d70bf&lt;/tt&gt;&lt;/a&gt; jar: add benchmarks with 400mb_jar_in_jar.jar
&lt;br /&gt;  Time (mean ± σ):      2.026 s ±  0.324 s    [User: 2.363 s, System: 1.269 s]
&lt;br /&gt;  Range (min … max):    1.651 s …  2.749 s    10 runs&lt;/p&gt;

&lt;p&gt;HEAD is now at &lt;a class=&quot;commit-link&quot; href=&quot;https://github.com/google/log4jscanner/commit/bf524fa630d15ee2ce737b8350596d669beaabaf&quot;&gt;&lt;tt&gt;bf524fa&lt;/tt&gt;&lt;/a&gt; jar: close the zip.File reader before recursing
&lt;br /&gt;  Time (mean ± σ):      1.908 s ±  0.297 s    [User: 2.084 s, System: 1.218 s]
&lt;br /&gt;  Range (min … max):    1.502 s …  2.567 s    10 runs&lt;/p&gt;

&lt;p&gt;HEAD is now at &lt;a class=&quot;commit-link&quot; href=&quot;https://github.com/google/log4jscanner/commit/4b23cd3db5400b191c5310c07415848bc0a2bb6d&quot;&gt;&lt;tt&gt;4b23cd3&lt;/tt&gt;&lt;/a&gt; jar: prefer io.ReadFull over io.ReadAll
&lt;br /&gt;  Time (mean ± σ):     445.9 ms ±  51.2 ms    [User: 401.7 ms, System: 79.9 ms]
&lt;br /&gt;  Range (min … max):   386.3 ms … 566.1 ms    10 runs&lt;/p&gt;

&lt;p&gt;HEAD is now at &lt;a class=&quot;commit-link&quot; href=&quot;https://github.com/google/log4jscanner/commit/37376ef3d7fcb898fd5e192d12a2afe4718ffc33&quot;&gt;&lt;tt&gt;37376ef&lt;/tt&gt;&lt;/a&gt; jar: reuse buffers for nested .jar&#39;s
&lt;br /&gt;  Time (mean ± σ):     464.5 ms ±  41.8 ms    [User: 420.5 ms, System: 93.7 ms]
&lt;br /&gt;  Range (min … max):   409.2 ms … 545.5 ms    10 runs&lt;/p&gt;

&lt;p&gt;HEAD is now at c17a81b jar: do not keep large buffers unnecessarily
&lt;br /&gt;  Time (mean ± σ):     436.1 ms ±  26.2 ms    [User: 409.5 ms, System: 77.6 ms]
&lt;br /&gt;  Range (min … max):   390.2 ms … 472.7 ms    10 runs
&lt;br /&gt;```&lt;/p&gt;</content>
    <author>
      <name>ericchiang</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/2342749?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/442545507/v0.3.0</id>
    <updated>2022-01-19T18:19:33Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/google/log4jscanner/releases/tag/v0.3.0"/>
    <title>v0.3.0</title>
    <content type="html">&lt;p&gt;scripts: don&#39;t include &#39;.&#39; in the release TAR file&lt;/p&gt;

&lt;p&gt;Also print the contents of the file after building to help debugging.&lt;/p&gt;</content>
    <author>
      <name>ericchiang</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/2342749?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/442545507/v0.2.0</id>
    <updated>2022-01-05T23:15:20Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/google/log4jscanner/releases/tag/v0.2.0"/>
    <title>v0.2.0</title>
    <content type="html">&lt;p&gt;Fix additional corruption with zips created on linux containing empty…&lt;/p&gt;

&lt;p&gt;… directories&lt;/p&gt;

&lt;p&gt;This is similar to &lt;a class=&quot;issue-link js-issue-link&quot; href=&quot;https://github.com/google/log4jscanner/pull/36&quot;&gt;#36&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Go&#39;s zip library has some &quot;interesting&quot; behavior where if you call
&lt;br /&gt;zipWriter.CreateHeader with a file header that already contains
&lt;br /&gt;extra metadata encoding the last modified time for an empty directory,
&lt;br /&gt;it will append the current last modified time to the existing one
&lt;br /&gt;stored in the `Extra` field. This leads to corruption similar to &lt;a class=&quot;issue-link js-issue-link&quot; href=&quot;https://github.com/google/log4jscanner/pull/36&quot;&gt;#36&lt;/a&gt;
&lt;br /&gt;where MacOS will refuse to open the zip and `zipinfo -v` will show a
&lt;br /&gt;&quot;There are an extra -xxx bytes preceding this file&quot; warning.&lt;/p&gt;

&lt;p&gt;I think the Go&#39;s library solution to this would be to use CreateRaw,
&lt;br /&gt;but we actually do want most of the logic that CreateHeader implements
&lt;br /&gt;(see &lt;a class=&quot;issue-link js-issue-link&quot; href=&quot;https://github.com/google/log4jscanner/pull/36&quot;&gt;#36&lt;/a&gt; where we switched to CreateHeader). So instead, I just clear
&lt;br /&gt;the Extra field in the file header when copying over directories. This
&lt;br /&gt;means that directories will have their last modified time reset to the
&lt;br /&gt;current date. This is somewhat incorrect, but seems to me like a
&lt;br /&gt;reasonable compromise to me.&lt;/p&gt;</content>
    <author>
      <name>ericchiang</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/2342749?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/442545507/v0.1.0</id>
    <updated>2021-12-29T22:54:16Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/google/log4jscanner/releases/tag/v0.1.0"/>
    <title>v0.1.0</title>
    <content>No content.</content>
    <author>
      <name>ericchiang</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/2342749?s=60&amp;v=4"/>
  </entry>
</feed>
