Skip to content

build: strip @zip.js/zip.js test fixture from image - #48

Closed
shimoncohen wants to merge 1 commit into
masterfrom
build/strip-zipjs-test-fixture
Closed

shimoncohen wants to merge 1 commit into
masterfrom
build/strip-zipjs-test-fixture

Conversation

@shimoncohen

Copy link
Copy Markdown
Contributor

Problem

Image scan fails on dem-heights reporting an encrypted/password-protected archive.

Root cause: @zip.js/zip.js (a prod dependency via @cesium/engine) ships an encrypted zip test fixture at node_modules/@zip.js/zip.js/tests/data/lorem-encrypted.zip. The scanner recurses into image layers, hits this genuinely password-protected zip, and fails. Other images (e.g. maps-playground) don't pull the full package, so they pass. The zip wrapper and layer compression are not involved.

Fix

Remove @zip.js/zip.js/tests after npm prune --omit=dev, before node_modules is copied to the production stage. The fixture is test data, not loaded at runtime.

Verification

Rebuilt the image and inspected node_modules/@zip.js/zip.js in the final layer:

  • tests/ dir absent, lorem-encrypted.zip gone
  • library intact (index.js, lib/, dist/, package.json) — Cesium's zip.js still functional

🤖 Generated with Claude Code

The @zip.js/zip.js package (prod dep via @cesium/engine) ships an encrypted
zip test fixture (tests/data/lorem-encrypted.zip). Image scanners recurse into
layers, hit it, and fail the scan reporting a password-protected archive. The
fixture is not used at runtime.

Remove the tests dir after npm prune so it never ships in the image.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@shimoncohen

Copy link
Copy Markdown
Contributor Author

Superseded by #49 — fixes the scan at the source by overriding @zip.js/zip.js to a test-free version (2.8.36) instead of stripping the tests dir from the image.

@shimoncohen
shimoncohen deleted the build/strip-zipjs-test-fixture branch August 10, 2026 10:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant