Skip to content
pakkoapp-ossPublic

About

Lightweight native Windows archiver. No dependencies, no bloatware. WinUI 3.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

5 stars

Watchers

0 watching

Forks

Latest commit

Β 

History

877 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Pakko logo

Pakko β€” Windows ZIP Archiver

Minimal WinUI 3 GUI wrapper for Windows built-in ZIP support.

No 7-Zip. No WinRAR. No third-party compression code.

Quality Gate Status Build Status Latest Release GitHub Release Downloads License: Apache 2.0

🌐 Project website Β· πŸ›’ Get it from Microsoft Store Β· β˜• Support the project on Ko-fi Β· πŸ‡ΊπŸ‡¦ Π£ΠΊΡ€Π°Ρ—Π½ΡΡŒΠΊΠΎΡŽ

Pakko in Explorer's context menu Pakko β€” main window, light theme Pakko β€” main window, dark theme Pakko β€” browsing inside an archive


Why Not 7-Zip or WinRAR?

Pakko uses a different trust model β€” not a claim of absolute security superiority, but a different set of supply chain dependencies with different auditability properties. Both tools have supply chain characteristics (developer jurisdiction, no reproducible builds, CVE history) that some security-conscious environments find unacceptable.

For the full CVE tables and rationale, see SECURITY.md (the canonical source).


What Pakko Uses Instead

Component Source Auditability
ZIP compression System.IO.Compression β€” .NET BCL Open source, part of .NET runtime
UI framework WinUI 3 / Windows App SDK Open source on GitHub

The entire compression stack is part of the .NET Base Class Library β€” maintained by Microsoft with a public CVE process, reproducible builds, and community audit via dotnet/runtime.

Trust dependency: The .NET runtime and Windows App SDK are themselves trust dependencies. Pakko's security properties depend on the integrity of Microsoft's supply chain and build infrastructure. Organizations that trust the Microsoft/.NET ecosystem will find this architecture auditable; those that do not should evaluate accordingly.


Security Properties

  • No third-party compression dependencies β€” attack surface limited to .NET runtime
  • Open source β€” full codebase auditable
  • Minimal permissions β€” no network access, no background services
  • No telemetry β€” no data leaves the machine
  • Mark of the Web (MOTW) propagation β€” extracted files inherit Zone.Identifier from the archive by default; prevents macro execution in extracted Office docs (7-Zip does not do this by default)
  • No libarchive in-process β€” tar/RAR/7z extraction via isolated tar.exe subprocess, sandboxed in an AppContainer with no network capability, not an in-process parser
  • Group Policy / ADMX support β€” administrators can lock down risky features (e.g. tar-family extraction) fleet-wide; see docs/POLICIES.md

Tech Stack

Layer Technology
UI WinUI 3 + Windows App SDK
Language C# 12 / .NET 10 LTS
Compression System.IO.Compression (ZIP)
Distribution MSIX (self-contained)
Min OS Windows 10 1809 (build 17763) / Windows Server 2019
License Apache 2.0

Supported Formats

Format Status Method
ZIP βœ… read/write, v1.0 System.IO.Compression
TAR/GZ/BZ2/XZ/ZST/LZMA βœ… read (v1.3) + create (v1.4) tar.exe (Windows built-in), AppContainer-sandboxed for extraction
RAR βœ… read only, v1.3 tar.exe (Windows built-in) β€” libarchive has no RAR writer
7z βœ… read only, v1.3 tar.exe (Windows built-in) β€” libarchive has no 7z writer
Password-protected ZIP βœ… read (ZipCrypto, WinZip AES) and create (AES-256 only) System.IO.Compression + .NET cryptography
Encrypted 7z/RAR ❌ detected and refused with a clear error β€”

Windows 11 Integration

Pakko closes gaps in Windows Explorer:

  • Native context menu β€” Open, Extract here, Extract to folder, Add to X.zip, Add to X.tar, Compress…, Test archive, Scan for threats, Hash: CRC-32 / SHA-256 (both the modern IExplorerCommand menu and the classic "Show more options" menu); each command runs in a Pakko window with progress, a password prompt and a conflict dialog
  • File type associations β€” double-click any supported archive format opens directly into Pakko's Archive Browser, not just .zip
  • Archive Browser β€” navigate an archive's folder structure without extracting everything first, extract a selection or the whole archive, then climb past the archive root into the real filesystem (drives, "This PC") the same way NanaZip's classic file manager does
  • Scan for threats β€” hands an archive's contents to the antivirus installed on the machine (through Windows' AMSI interface), password-protected ZIP entries included
  • Recovery data (PAR2) β€” standard PAR 2.0 files written next to a new archive (5, 10 or 20 %), then "Verify with PAR2" and "Repair with PAR2" in the menu and the app; the repaired copy is a new file and the original is only read. par2cmdline and MultiPar read Pakko's sets, and Pakko reads theirs
  • Group Policy / ADMX β€” administrators can disable tar-family extraction and other risk-relevant features fleet-wide via a real ADMX template; see docs/POLICIES.md

Windows 11 23H2+ includes tar.exe (Microsoft-signed bsdtar), which Pakko uses β€” no third-party compression tools β€” to read RAR/7z/tar/gz/bz2/xz/zst/lzma, and to create tar-family archives (plain tar plus the five compression-filter variants).


Command-Line Interface

pakko.exe (project name Archiver.CLI) is a standalone, self-contained command-line build with 7z-familiar commands (x/t/i/a/l, and r to repair from PAR2 files) β€” it runs independently of the GUI/MSIX. See docs/CLI.md for the full command/switch specification. Download it as its own per-architecture zip (with a SHA256SUMS file for verification) from the project's GitHub Releases page β€” every version tag is built and published there automatically. The zip is not added to PATH; from v1.7.0 the Microsoft Store/MSIX install also gives the pakko command in any terminal, and the zip can be installed with winget once the winget catalog accepts the package β€” see docs/CLI.md's "Distribution" section.


Project Status

ZIP archive/extract (with passwords), the native shell extension (context menu, file associations, MOTW propagation), sandboxed RAR/7z/tar-family read + tar-family create via tar.exe, the Archive Browser, antivirus scan, PAR2 recovery data, the pakko command line and Group Policy/ADMX support are all implemented and on-device verified. Per-release history: CHANGELOG.md.

  • βœ… Archive (single / separate) with compression level selector, ZIP or any tar-family format
  • βœ… Extract with smart folder logic, ZIP slip protection, and a per-conflict Ask/Overwrite/ Rename/Skip resolution
  • βœ… Password-protected ZIP β€” extract, test, browse, and threat-scan (ZipCrypto + WinZip AES), with a password prompt in the app, the Explorer menu, and the CLI (-p); create AES-256 encrypted ZIPs from the app or pakko a -p (file names inside the archive stay visible)
  • βœ… System tray icon
  • βœ… File log (%LocalAppData%\Pakko\logs\pakko.log)
  • βœ… i18n β€” 37 locales, OS-language auto-match with English fallback
  • βœ… MSIX packaging, signed with a dev cert via Deploy.ps1
  • βœ… Mid-file cancellation (async streaming)
  • βœ… Safe temp file/dir pattern β€” no partial files on cancel
  • βœ… Compression-ratio bomb detection (1000:1 threshold), confirm-and-extract if the destination has room, for ZIP and every tar-family format
  • βœ… UTF-8 filenames β€” Cyrillic and emoji round-trip verified
  • βœ… Native right-click context menu β€” Open, Extract here, Extract to folder, Add to X.zip/X.tar, Compress…, Test archive, Scan for threats, Hash (CRC-32, SHA-256)
  • βœ… Scan for threats β€” archive contents checked by the installed antivirus through AMSI
  • βœ… Extracted files and folders keep the dates stored in the archive
  • βœ… Recovery data (PAR2) β€” created next to an archive from the app or pakko a -rr, verified by pakko t, Explorer and the app, repaired into a new file by pakko r, Explorer and the app
  • βœ… pakko command line β€” in any terminal after a Store install, or as a standalone zip
  • βœ… File type association (every readable format). No URI protocol is registered (the former pakko:// scheme was removed), so a web page cannot launch Pakko through a link of its own
  • βœ… MOTW propagation on extracted files by default, always for Archive Browser previews; the user may leave it off for one trusted archive, unless Group Policy decides
  • βœ… Alternate Data Stream / reserved-filename / reparse-point protections during extraction
  • βœ… Archive Browser β€” navigate, extract selected/all, preview an image or text file without a manual extract, climb past the archive root into the real filesystem
  • βœ… RAR/7z/tar-family extraction runs inside an AppContainer sandbox β€” quarantine staging, ACL'd output directory, Job Object process limits, no network capability
  • βœ… Group Policy / ADMX support β€” see docs/POLICIES.md
  • βœ… Full automated test suite, run on every push in CI (see the Build Status badge above)

Now available on the Microsoft Store: https://apps.microsoft.com/detail/9p5mw010d8pr (also installable via winget install 9P5MW010D8PR --source msstore). GitHub Releases remain available as an alternative for every version tag.

See docs/SPEC.md's "Future Roadmap" section for the version-to-focus table, and docs/TASKS.md for the detailed task list.


Known Issues

  • Context menu flickers on the first right-click in a newly opened Explorer window β€” this is a known Windows Explorer verb/icon-cache artifact (Explorer caches top-level shell-extension verbs across COM DLL registrations until it requeries them), not a Pakko bug.

Building and Deploying

Prerequisites: Visual Studio 2026 (.NET desktop + Desktop C++ workloads, MSVC v143 x64/ARM64 build tools), .NET 10 SDK.

See scripts/README.md for the full build/sign/deploy steps and CONTRIBUTING.md for the contributor workflow. Production code signing with a trusted certificate is planned (T-F10) β€” see docs/SIGNING.md for Pakko's Code Signing Policy (team roles, build process, and artifacts covered).


Running Tests

dotnet test --filter "Category!=Slow&Category!=VeryLarge"

Always run without a path argument β€” all projects must stay green after every change. See docs/TESTING.md for the full test plan, fixture generation, and the Category=Slow/Category=VeryLarge tiers.


Documents

About

Lightweight native Windows archiver. No dependencies, no bloatware. WinUI 3.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages