Skip to content

build: override @zip.js/zip.js to drop test fixtures from image - #49

Closed
shimoncohen wants to merge 1 commit into
masterfrom
build/bump-zipjs-override
Closed

shimoncohen wants to merge 1 commit into
masterfrom
build/bump-zipjs-override

Conversation

@shimoncohen

Copy link
Copy Markdown
Contributor

Problem

Image scans on dem-heights fail reporting an encrypted/password-protected archive.

Root cause: @zip.js/zip.js 2.4.26 — pinned transitively via cesium → @cesium/engine — publishes its full test suite, including a genuinely password-protected fixture at node_modules/@zip.js/zip.js/tests/data/lorem-encrypted.zip. Scanners recurse into image layers, hit it, and fail. Other images don't pull the full package, so they pass. The install is correct; the old published version simply bundles its tests.

Fix

Upstream stopped shipping tests in 2.7.0 (2.4.26 → 152 files/68 tests; 2.7.0 → 65 files/0 tests). Add an npm overrides entry forcing @zip.js/zip.js to ^2.7.0, which resolves to 2.8.36. This removes the fixture at the source rather than stripping files from the image.

Verification

  • npm ci from the updated lockfile → zip.js 2.8.36
  • npm run build (tsc) → clean, RC=0 — cesium@1.104 typechecks against 2.8.36
  • Docker build → RC=0; inspected final image: tests/ dir absent, lorem-encrypted.zip gone

Note: runtime KMZ/zip paths not exercised (dem-heights is a heights service and doesn't load zips); the change is a transitive dep bump validated by typecheck + build.

Supersedes #48 (which stripped the tests dir in the Dockerfile — symptom, not root cause).

🤖 Generated with Claude Code

@zip.js/zip.js 2.4.26 (pinned transitively via cesium -> @cesium/engine)
publishes its test suite, including an encrypted zip fixture
(tests/data/lorem-encrypted.zip). Image scanners recurse into layers, hit the
password-protected zip, and fail the scan. Upstream stopped shipping tests in
2.7.0; the override forces a test-free version (resolves 2.8.36), which cesium
accepts and tsc typechecks against.

Fixes the scan at the source instead of stripping files from the image.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@shimoncohen

Copy link
Copy Markdown
Contributor Author

Superseded by #50 — upgrades cesium so @cesium/engine pulls a test-free zip.js (2.8.36) natively, removing the need for the override. Root-cause fix.

@shimoncohen
shimoncohen deleted the build/bump-zipjs-override branch August 10, 2026 11:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant