pith-zip 0.1.0

ZIP container reading: stored and deflated entries, plus a minimal XML reader
Documentation
# Security Policy

## Reporting a Vulnerability

Report privately through GitHub: open the repository's **Security** tab and choose
**Report a vulnerability**. The report stays visible only to the maintainers until a
fix ships.

Direct link: <https://github.com/pith-hash/pith-zip/security/advisories/new>

Please do not open a public issue for a security vulnerability.

If the link above returns a 404, private vulnerability reporting is not enabled yet on
this repository; open an issue asking for it to be turned on, without describing the
vulnerability.

## Suite hardening guarantees

This repository is part of the **pith** suite. Beyond the reporting policy above,
the following properties are enforced by CI and are relevant when assessing a
report:

- `#![forbid(unsafe_code)]` is declared in every crate root; a report of memory
  unsafety implies a compiler bug or a violation of this declaration.
- The dependency graph is limited to other `pith-*` crates and `std`
  (`scripts/check-zero-deps.py`); supply-chain reports should name the offending
  dependency edge.
- Parser crates ship a fuzz corpus (`fuzz/corpus/`) replayed in CI; a crash
  reproduction should include the failing corpus input.
- `reference.json` vectors are hex-exact and shared across the Python, Node and
  Go SDKs; a correctness report should state which vector diverges, in which
  SDK.