Merge pull request #1444 from robinwatts:master

PiperOrigin-RevId: 899489367
diff --git a/.github/workflows/fuzz.yml b/.github/workflows/fuzz.yml
index 6744197..a1734e4 100644
--- a/.github/workflows/fuzz.yml
+++ b/.github/workflows/fuzz.yml
@@ -40,7 +40,7 @@
         dry-run: false
 
     - name: Upload Crash
-      uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
+      uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
       if: failure()
       with:
         name: artifacts
diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml
index dfd2244..ead2bea 100644
--- a/.github/workflows/release.yaml
+++ b/.github/workflows/release.yaml
@@ -130,7 +130,7 @@
           -DestinationPath brotli-${{matrix.triplet}}.zip
 
     - name: Upload package
-      uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
+      uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
       with:
         name: brotli-${{matrix.triplet}}
         path: brotli-${{matrix.triplet}}.zip
@@ -160,7 +160,7 @@
         tar cvfJ testdata.txz tests/testdata
 
     - name: Upload archive
-      uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
+      uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
       with:
         name: testdata
         path: testdata.txz
diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
index 8faecb5..2e547b6 100644
--- a/.github/workflows/scorecard.yml
+++ b/.github/workflows/scorecard.yml
@@ -69,7 +69,7 @@
       # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
       # format to the repository Actions tab.
       - name: "Upload artifact"
-        uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
+        uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
         with:
           name: SARIF file
           path: results.sarif
diff --git a/c/dec/decode.c b/c/dec/decode.c
index c4972a5..5510d10 100644
--- a/c/dec/decode.c
+++ b/c/dec/decode.c
@@ -481,6 +481,9 @@
                                                         uint8_t* ringbuffer,
                                                         int pos,
                                                         const int limit) {
+  const int kMaximalOverread = 4;
+  int pos_limit = limit;
+  int copies = 0;
   /* Calculate range where CheckInputAmount is always true.
      Start with the number of bytes we can read. */
   int64_t new_lim = br->guard_in - br->next_in;
@@ -488,9 +491,6 @@
   new_lim *= 8;
   /* At most 15 bits per symbol, so this is safe. */
   new_lim /= 15;
-  const int kMaximalOverread = 4;
-  int pos_limit = limit;
-  int copies = 0;
   if ((new_lim - kMaximalOverread) <= limit) {
     // Safe cast, since new_lim is already < num_steps
     pos_limit = (int)(new_lim - kMaximalOverread);
@@ -2091,10 +2091,10 @@
       } while (--i != 0);
     } else { /* safe */
       do {
+        brotli_reg_t literal;
         if (BROTLI_PREDICT_FALSE(s->block_length[0] == 0)) {
           goto NextLiteralBlock;
         }
-        brotli_reg_t literal;
         if (!SafeReadSymbol(s->literal_htree, br, &literal)) {
           result = BROTLI_DECODER_NEEDS_MORE_INPUT;
           goto saveStateAndReturn;
diff --git a/c/enc/encode.c b/c/enc/encode.c
index 9e72744..b2583e4 100644
--- a/c/enc/encode.c
+++ b/c/enc/encode.c
@@ -761,11 +761,12 @@
 
 BrotliEncoderState* BrotliEncoderCreateInstance(
     brotli_alloc_func alloc_func, brotli_free_func free_func, void* opaque) {
+  BrotliEncoderState* state;
   BROTLI_BOOL healthy = BrotliEncoderEnsureStaticInit();
   if (!healthy) {
     return 0;
   }
-  BrotliEncoderState* state = (BrotliEncoderState*)BrotliBootstrapAlloc(
+  state = (BrotliEncoderState*)BrotliBootstrapAlloc(
       sizeof(BrotliEncoderState), alloc_func, free_func, opaque);
   if (state == NULL) {
     /* BROTLI_DUMP(); */