gzip-1.13 released [stable]

Jim Meyering <[email protected]> Sat, 19 Aug 2023 17:39:23 -0700
Newsgroups gmane.org.fsf.announce
Message-ID <m25y5aeedg.fsf__41332.2120717325$1692493965$gmane$org@meyering.net>
This is to announce gzip-1.13, a stable release.
Thanks to Paul and Bruno for contributing.

There have been 50 commits by 3 people in the 71 weeks since 1.12.

See the NEWS below for a brief summary.

Thanks to everyone who has contributed!
The following people contributed changes to this release:

  Bruno Haible (4)
  Jim Meyering (15)
  Paul Eggert (31)

Jim
 [on behalf of the gzip maintainers]
==================================================================

Here is the GNU gzip home page:
    http://gnu.org/s/gzip/

For a summary of changes and contributors, see:
  http://git.sv.gnu.org/gitweb/?p=gzip.git;a=shortlog;h=v1.13
or run this command from a git-cloned gzip directory:
  git shortlog v1.12..v1.13

Here are the compressed sources:
  https://ftp.gnu.org/gnu/gzip/gzip-1.13.tar.gz   (1.3MB)
  https://ftp.gnu.org/gnu/gzip/gzip-1.13.tar.xz   (820KB)

Here are the GPG detached signatures:
  https://ftp.gnu.org/gnu/gzip/gzip-1.13.tar.gz.sig
  https://ftp.gnu.org/gnu/gzip/gzip-1.13.tar.xz.sig

Use a mirror for higher download bandwidth:
  https://www.gnu.org/order/ftp.html

Here are the SHA1 and SHA256 checksums:

  9cc4f2220c8028823433e9d869dc07610aefefb5  gzip-1.13.tar.gz
  IPyBiu666Hzb8gnTUUGtnTzzErNaXmvmG/z7+e3dISo=  gzip-1.13.tar.gz
  a793e107a54769576adc16703f97c39ee7afdd4e  gzip-1.13.tar.xz
  dFTraTXbF8ZlVXbC4bD6vv04tNCTbg+H9IzQYs6RoFc=  gzip-1.13.tar.xz

Verify the base64 SHA256 checksum with cksum -a sha256 --check
from GNU coreutils-9.2 or OpenBSD's cksum since 2007.

Use a .sig file to verify that the corresponding file (without the
.sig suffix) is intact.  First, be sure to download both the .sig file
and the corresponding tarball.  Then, run a command like this:

  gpg --verify gzip-1.13.tar.gz.sig

The signature should match the fingerprint of the following key:

  pub   rsa4096/0x7FD9FCCB000BEEEE 2010-06-14 [SCEA]
        Key fingerprint = 155D 3FC5 00C8 3448 6D1E  EA67 7FD9 FCCB 000B EEEE
  uid                   [ unknown] Jim Meyering <[email protected]>
  uid                   [ unknown] Jim Meyering <[email protected]>
  uid                   [ unknown] Jim Meyering <[email protected]>

If that command fails because you don't have the required public key,
or that public key has expired, try the following commands to retrieve
or refresh it, and then rerun the 'gpg --verify' command.

  gpg --locate-external-key [email protected]

  gpg --recv-keys 7FD9FCCB000BEEEE

  wget -q -O- 'https://savannah.gnu.org/project/release-gpgkeys.php?group=gzip&download=1' | gpg --import -

As a last resort to find the key, you can try the official GNU
keyring:

  wget -q https://ftp.gnu.org/gnu/gnu-keyring.gpg
  gpg --keyring gnu-keyring.gpg --verify gzip-1.13.tar.gz.sig

This release was bootstrapped with the following tools:
  Autoconf 2.72c.32-cb6fb
  Automake 1.16i
  Gnulib v0.1-6631-g5651802c60

NEWS

* Noteworthy changes in release 1.13 (2023-08-19) [stable]

** Changes in behavior

  zless now diagnoses gzip failures, if using less 623 or later.

  When SIGPIPE is ignored, gzip now exits with status 2 (warning)
  instead of status 1 (error) when writing to a broken pipe.  This is
  more useful with programs like 'less' that treat gzip exit status 2
  as a non-failure.

** Bug fixes

  'gzip -d' no longer fails to report invalid compressed data
  that uses a dictionary distance outside the input window.
  [bug present since the beginning]

  Port to C23, which does not allow K&R-style function definitions
  with parameters, and which does not define __alignas_is_defined.

also announced here:
  https://savannah.gnu.org/news/?id=10501
signature.asc (application/pgp-signature, 857 B)
-----BEGIN PGP SIGNATURE-----

iQJFBAEBCgAvFiEEFV0/xQDINEhtHupnf9n8ywAL7u4FAmThYLsRHGppbUBtZXll
cmluZy5uZXQACgkQf9n8ywAL7u7N1xAAkvw5DiwmN7WsdoIRjfJEdlWl8ClDgLRl
YVRds8JPte8d3YEBnU3VPSoRwCv/qDWlTAXlMuyvtLv3nf9I586J11jH6W2Uot9E
Jn9Ky5CVdRmhlNBhKrazlc96Z8EUllOrp2PL5dRwkRUS1ngcrTCEMydX0tTPOZ0D
5FfBUuWfXwVKYAEPgX+X5JZGDXbG2jfBwubivOK8LwduC0yb7GH0uvs8lKb8Zew1
8xS2ZHUUE5HMkbB54D+vCQO1D9cwEFwmDv3lnNCtd3jHJgta62JbtnMZXmSNTx2R
3ZrMrjUOBGMNcwp0QHzFcTACO2gKvI/tKTb42mFxNf90ifWR4VrXzLn1Yho5E8Cp
Pg8tzv3Auz5JfWH1bfWILjTrfZi1BnarLfE377bQ2zARGV1vGgPt92KYSazHzIZb
P8ZyWcqyOpzOUIXK7jeYBBTpEiMQBQQFr2DnM+t9ZnZWRazoLOVV/9Ju7EPidgTY
t7kG6kUkCAWWiz+jswbYvWUSatWd55Iy9l0MwrkNXMTlCou8wVNy+A3INVJbKC0H
7HYAf+AOyfzEKy/5jtzbh/5u2O9b2ORT5E9waQD4q8l3pEa5GZ6ILZApl11JL+jo
IlWrrvc5odkjIPRSQ0I1mDUgA8FOFEJS8nsy1mwLPq9Eki4TGSmIAY+80B/XaAso
jI4QPc+2WRQ=
=/1jW
-----END PGP SIGNATURE-----