build/openwhisk/core/standalone/src/main/scala/org/apache/openwhisk/standalone/Unzip.scala (in the openserverless-build submodule, shipped in the 0.9.0-incubating-RC7 source release) contains code taken from Stack Overflow:
def apply(is: InputStream, dir: File): Unit = {
//Based on https://stackoverflow.com/a/40547896/1035417
Stack Overflow contributions are licensed under CC BY-SA, and the ASF third-party licensing policy does not allow this code in an Apache project without the original author's permission:
Can Stack Overflow code be included? No, not without contacting the original author and getting permission from them to use the code in an Apache project under the Apache License 2.0.
— https://www.apache.org/legal/resolved.html#stackoverflow
The file was vendored unchanged from Apache OpenWhisk (core/standalone/.../Unzip.scala), so the problem is inherited, but it is still part of our release.
The code is small: it iterates a ZipInputStream and writes each entry to disk. It has one caller, UserEventLauncher.scala:139.
Possible fixes:
- Rewrite
Unzip from scratch (clean-room) using java.util.zip directly, or replace it with an existing Apache-licensed utility (e.g. Apache Commons Compress). Drop the Stack Overflow reference.
- Or, if the code is kept, obtain and record permission from the answer's author to use it under the Apache License 2.0.
While rewriting it, it would also be worth guarding against "zip slip" (entries whose names contain ../ resolving outside dir). The current code writes to dest.resolve(zipEntry.getName) without checking that the result stays under dest.
build/openwhisk/core/standalone/src/main/scala/org/apache/openwhisk/standalone/Unzip.scala(in theopenserverless-buildsubmodule, shipped in the 0.9.0-incubating-RC7 source release) contains code taken from Stack Overflow:Stack Overflow contributions are licensed under CC BY-SA, and the ASF third-party licensing policy does not allow this code in an Apache project without the original author's permission:
The file was vendored unchanged from Apache OpenWhisk (
core/standalone/.../Unzip.scala), so the problem is inherited, but it is still part of our release.The code is small: it iterates a
ZipInputStreamand writes each entry to disk. It has one caller,UserEventLauncher.scala:139.Possible fixes:
Unzipfrom scratch (clean-room) usingjava.util.zipdirectly, or replace it with an existing Apache-licensed utility (e.g. Apache Commons Compress). Drop the Stack Overflow reference.While rewriting it, it would also be worth guarding against "zip slip" (entries whose names contain
../resolving outsidedir). The current code writes todest.resolve(zipEntry.getName)without checking that the result stays underdest.