Coming soon
Developer library · .NET · C# and VB.NET
Bastion Archive Sdk
Forty archive formats. One managed assembly. Safe by default.
A fully managed .NET archive library. It reads more than forty archive, package, disk-image and file-system formats, writes the ones worth writing — ZIP, 7z, tar and the stream formats — takes no third-party runtime dependency, and extracts hostile archives safely by default.
40+
archive, package, disk-image and file-system formats read, each verified against the tool that owns it
18
target frameworks from .NET Framework 4.6 to .NET 10 — one assembly each, no native code
0
third-party runtime dependencies. Every codec is written in the library, from published specifications
2.2bn
fuzzing executions in the latest campaign — 8 defects found, none open
Extract safely. Create 7z. A dozen lines.
Every archive-level operation returns a result object rather than throwing. The same code reads naturally in C# and VB.NET, and every sample ships in both.
VB.NET
Imports Bastion.Archive
' Extract anything it reads - safely, by default.
Dim x = clsArchive.ExtractAll("upload.7z", "C:\Inbox", clsExtractionPolicy.Default)
If x.ErrorCode <> enmErrorCode.None Then
Console.WriteLine(x.ToString()) ' refused, never thrown
Return
End If
' A solid, encrypted 7z with 7-Zip's own level 9 settings.
Dim s = clsCompressionSettings.SevenZip(level:=9)
s.Solid = True
s.HeaderEncryption = True
s.Password = strPassword
Dim r = clsArchive.Create("backup.7z", "C:\Data\*", enmArchiveFormat.SevenZip, s)
C#
using Bastion.Archive;
// Extract anything it reads - safely, by default.
var x = clsArchive.ExtractAll("upload.7z", @"C:\Inbox", clsExtractionPolicy.Default);
if (x.ErrorCode != enmErrorCode.None)
{
Console.WriteLine(x.ToString()); // refused, never thrown
return;
}
// A solid, encrypted 7z with 7-Zip's own level 9 settings.
var s = clsCompressionSettings.SevenZip(level: 9);
s.Solid = true;
s.HeaderEncryption = true;
s.Password = password;
var r = clsArchive.Create("backup.7z", @"C:\Data\*", enmArchiveFormat.SevenZip, s);
Why teams choose it
Every codec written here
Deflate, Deflate64, LZMA, LZMA2, BZip2, XZ, PPMd, Zstandard, the branch and delta filters, the checksums and the encryption are all implemented in the library. It never calls DeflateStream or System.Formats.Tar, so a runtime upgrade can never change its output.
Nothing throws into your code
Reading a broken archive somebody else made is an answer, not an accident. Every operation returns ErrorCode, ErrorDescription, Detail and Warnings — no Try block needed.
Safe with hostile input
Paths canonicalised, zip bombs and overlapping entries refused, limits enforced while the operation runs, checksums verified before data is exposed, links opt-in. On by default, not available on request.
Deterministic, and tested for it
The same input and settings give byte-identical output on every framework and operating system, serial or parallel — SHA-256-verifiable. Timestamps and ordering are settings, never ambient state.
Safe output
Fail-if-exists by default. Everything is written to a temporary neighbour, moved into place only when complete, then reopened and validated. Updating an archive is a rebuild, never an in-place mutation.
Bounded memory
Every read and write path streams. Memory is decoupled from archive size and entry count; there is no “load the whole archive” path anywhere.
Also in the box: a FileSystem abstraction where disk folders, memory folders and ZIP and 7z archives are all folders; an async twin for every long-running call with per-call cancellation; progress, password, overwrite and retry events; self-extracting archives for x64 and ARM64; split and spanned volume sets; and Mark-of-the-Web propagation, including out of nested archives.
Formats it reads
Every format below has been verified against the tool that owns it — 7-Zip, Info-ZIP, bsdtar, xz, zstd, makecab, DISM, qemu-img, WinRAR, WinZip, Windows Explorer and macOS Archive Utility among them. Nothing is listed on the strength of the specification alone. Anything it cannot read correctly is refused by name, never read approximately.
| Family | Formats |
|---|---|
| Archives | ZIP (zipx methods, WinZip AES, Zip64) · 7z (verified against six 7-Zip releases) · tar (ustar, GNU, pax, sparse) · RAR 5.0 (extract only) · CAB (not Quantum) · cpio · ar and .deb · RPM · xar · LHA/LZH · ARJ · NSIS installers |
| Compressed streams | gzip · bzip2 · XZ · LZMA · Zstandard · LZ4 · Brotli · Unix compress (.Z) · tar.gz, tar.bz2, tar.xz, tar.zst |
| Disk images | ISO 9660 with Joliet, Rock Ridge and El Torito · UDF 1.02–2.50 · WIM and ESD, including LZMS solid resources · VHD, including differencing · VHDX (fixed, dynamic) · VMDK · QCOW2, including LUKS-encrypted · VDI · DMG (every hdiutil compressor) |
| File systems | FAT12/16/32 · NTFS (not NTFS-compressed files) · ext2/3/4 · HFS+ and HFSX · APFS · SquashFS · cramfs · GPT and MBR partition maps |
| Executables and containers | PE sections and resources · ELF · Mach-O, including universal binaries · UEFI firmware volumes · CHM · Compound File (OLE2, MSI) · Intel HEX · numeric split sets (.001) · self-extracting archives |
Formats it writes
Far fewer, deliberately. Reading a format and writing it are separate pieces of work, and a format not listed here says so by name when asked to write it.
| Format | Create | Update | Encrypt | Volumes | Notes |
|---|---|---|---|---|---|
| ZIP | Yes | Yes | Yes | Yes | Store, Deflate, Deflate64, bzip2, LZMA, XZ, PPMd. Zip64. WinZip AES-128/192/256. Update rebuilds in one pass, untouched entries copied still compressed. |
| 7z | Yes | Yes | Yes | Yes | Every coder and filter it reads: LZMA, LZMA2, PPMd, BZip2, Deflate and all branch filters. Solid blocks, compressed and encrypted headers, AES-256. |
| tar family | Yes | No | — | — | ustar, GNU and pax, plus .tar.gz, .tar.bz2, .tar.xz and .tar.zst in one call. |
| gzip, bzip2, XZ, LZMA | Yes | — | — | — | Single streams, verified both ways against the reference tools. |
| Zstandard | Yes | — | — | — | Within 1% of the reference zstd at level 9, smaller at levels 1 and 5. 7-Zip cannot create a .zst at all. |
| WIM | Partial | No | — | Yes | Stored and XPRESS-compressed images that DISM lists and applies. 7-Zip’s own WIM writer only stores. |
| Self-extracting | Yes | — | Yes | Yes | A managed stub for x64 and ARM64: silent runs, passwords, overwrite handling and a custom icon. |
| RAR | No | — | — | — | Never. The UnRAR licence forbids re-creating RAR compression, so no .NET library writes it. |
Hostile archives, handled
The archive is hostile and the caller is trusted. Whatever it contains, an archive must never write outside its target directory, exhaust the machine, hand back bytes it did not have, or crash the process. The defaults are strict, and loosening one is a change somebody can find in code review.
| Setting | Default | What it stops |
|---|---|---|
AllowParentTraversal / AllowAbsolutePaths | False | Zip-slip: .., C:\Windows, /etc and UNC paths in entry names |
RejectReservedNames / RejectAlternateStreams | True | CON, NUL, COM1 and file.txt:hidden on Windows |
SymbolicLinks / HardLinks | Skip, with a warning | A link written first and followed by a later entry writing through it |
RefuseOverlappingEntries / RefuseDuplicateEntries | True | One file that reads as two things, and names whose outcome depends on order |
MaxCompressionRatio | 100,000 | Zip bombs — the Fifield class exceeds 28,000,000 |
MaxTotalBytes / MaxEntryCount / MaxNestingDepth | 1 TiB / 10 million / 256 | Archives that unpack to more than a disk holds, or whose listing is the attack |
VerifyChecksums / Overwrite | True / fail if it exists | Bytes that do not match, and archives replacing files already there |
A security corpus that never regresses
Zip bombs, traversal in every shape three platforms allow, link escapes, overlapping entries and a 140,000-input mutation soak that insists on an error, never an exception.
Cross-tool verification
Reads what other tools wrote and hands what it wrote back to them. A reader and writer that share a misunderstanding agree perfectly and produce files nothing else opens — so both sides are gated externally.
Coverage-guided fuzzing
AFL++ over the whole read path. The campaign finished on 24 September 2026: 2.205 billion executions, 49 crashes, 8 defects, none open, and every one now a permanent test.
Performance, printed as measured
Against 7-Zip 26.03 (x64), both single-threaded, on the Silesia corpus. Where this library is faster it is said; where it is slower the figure is printed rather than omitted.
| Measure | Against 7-Zip | Detail |
|---|---|---|
| Deflate decode | 101% | Faster than 7-Zip on seven of twelve files |
| Deflate encode | 75% | 29% to 174% across the corpus |
| LZMA2 decode | 58% | Up to 140% on xml |
| LZMA2 encode | 29% | The weakest figure on the page, and work in hand |
| LZMA2 compressed size | Within a few per cent | 13.8% smaller than 7-Zip on nci, 9.4% smaller on xml |
Reading is where most archive work happens, and reading is competitive: Deflate — what the overwhelming majority of ZIP files use — decodes as fast as 7-Zip’s native code.
It fits where your application already runs
| Frameworks | .NET Framework 4.6 to 4.8.1 · .NET Core 2.0 to 3.1 · .NET 5 to .NET 10 — eighteen builds, no netstandard facade |
| Platforms | Windows, on every build — the same bytes out on every run, serial or parallel |
| Languages | C# and VB.NET, with every sample in both |
| Dependencies | None third-party. Microsoft’s own polyfills only on the older targets that lack the API; none at all on .NET 6 and later |
| Deployment | One DLL. Nothing native to ship, sign, or exclude from a trimmed or AOT build |
How it compares
Capability and licensing matrix for commercial .NET archive libraries, from each vendor’s published documentation, surveyed September 2026. A ? means the capability was not stated either way — it is not a claim that the product lacks it.
Free libraries exist, and several are no longer maintained: SharpZipLib’s last release was January 2023, and DotNetZip is archived with an unpatched traversal CVE (CVE-2024-48510). Zip-slip remains the dominant vulnerability class in this category — which is why the guards above are on by default.
OEM licensing
One licence type, priced for commercial software teams. Every Bastion Archive Sdk licence is an OEM licence: build it into your product and ship that product to as many customers as you like, on as many machines as they like.
- Royalty-free redistribution inside your own applications
- Desktop, server, cloud and SaaS deployment — no per-server or per-instance fees
- Perpetual licence with 12 months of updates; renewals at 35% of list
- Every build, .NET Framework to .NET 10, and every sample in C# and VB.NET
- Everything in Developer OEM
- $349 per developer
- Everything in Developer OEM
- No developer count to track as the team grows
- Source-code escrow available, priced on request
Launch prices in US dollars. Final pricing is confirmed at release.
Try it properly first
A thirty-day evaluation of the complete component. Nothing removed and no limits — you evaluate exactly what you would buy.
Because the trial is the whole product, sales are final, and accepting the terms and conditions of sale is part of completing a purchase. The one exception: report a serious defect and, if we cannot fix it and release an update within thirty days, we refund you in full.
Need more than the component? Custom development and integration work built on it is available, remotely or on site — talk to us.
Get notified when Bastion Archive Sdk is released
Tell us what you are building. We will let you know the moment the evaluation is available — and answer plainly whether it fits.