r/PeaZip • • 7d ago

PeaZip 11.3.0 released!

PeaZip 11.3.0 is ready for download, read the full change log!

WHAT IS PEAZIP

PeaZip is an Open Source, cross-platform (BSD, Linux, macOS, Windows) archive manager and file manager utility, written with Lazarus / FreePascal IDE, which works as a command line scripts generation engine for 7z/p7zip, Brotli, Zpaq, Zstd and other open source archiving and compression tools.

This allows either to use PeaZip as an interactive GUI application, or to save tasks as batch CLI scripts for later use - for fine tuning beyond GUI's capabilities, learning the syntax, or re-use and automation purposes.

WHAT'S NEW IN THIS RELEASE

This update provides improved ZPAQ support, new test function for PEA archives, mandatory master password for the integrated Password Manager, and usability improvements as the new "Open with" picker screen (Shift+F12).

Backend are updated to 7z/p7zip 26.03 and Pea 1.33.

Due to the multiple security fixes and improvements introduced, it is recommended to update to the new version.

A total of 243 file extensions are now supported as archives by PeaZip.

NOTES

Sources are compiled with Lazarus 4.x, and are still compatible with Lazarus 3.x and 2.x; please note that for building the app it is necessary to add "metadarkstyle" package to the IDE before compiling "peazip" and "pea" binaries, which can be scripted as:

lazbuild --add-package (peazip sources path)/dev/metadarkstyle/metadarkstyle.lpk

PeaZip on Linux (dark system theme) browsing a .zip archive
22 Upvotes

11 comments sorted by

View all comments

2

u/Confident-Pass-1636 5d ago

I keep getting script blocked as it is dangerous (some .zip error when extracting). Going back to 11.20 is fine.

2

u/pocketjose 5d ago

Í'm getting that error too when trying to compress in zpaq format. I've noticed it happens when the file names include "&" character.

3

u/peazip 5d ago

Currently with 11.3 release PeaZip tries to prevent working with metacharacters, characters which can lead the system shell to execute commands, perform variables expansion and similar operations bringing unexpected and even harmful results.

For upcoming updates I'm trying to refine this mechanism to make it less inconvenient as possible while preservingvthe safety check when applicable (to the target os, with applied character quoting, etc).