build: override @zip.js/zip.js to drop test fixtures from image - #49
Closed
shimoncohen wants to merge 1 commit into
Closed
shimoncohen wants to merge 1 commit into
shimoncohen wants to merge 1 commit into
Conversation
@zip.js/zip.js 2.4.26 (pinned transitively via cesium -> @cesium/engine) publishes its test suite, including an encrypted zip fixture (tests/data/lorem-encrypted.zip). Image scanners recurse into layers, hit the password-protected zip, and fail the scan. Upstream stopped shipping tests in 2.7.0; the override forces a test-free version (resolves 2.8.36), which cesium accepts and tsc typechecks against. Fixes the scan at the source instead of stripping files from the image. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This was referenced Aug 10, 2026
Contributor
Author
|
Superseded by #50 — upgrades cesium so @cesium/engine pulls a test-free zip.js (2.8.36) natively, removing the need for the override. Root-cause fix. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Image scans on
dem-heightsfail reporting an encrypted/password-protected archive.Root cause:
@zip.js/zip.js2.4.26 — pinned transitively viacesium→@cesium/engine— publishes its full test suite, including a genuinely password-protected fixture atnode_modules/@zip.js/zip.js/tests/data/lorem-encrypted.zip. Scanners recurse into image layers, hit it, and fail. Other images don't pull the full package, so they pass. The install is correct; the old published version simply bundles its tests.Fix
Upstream stopped shipping tests in 2.7.0 (2.4.26 → 152 files/68 tests; 2.7.0 → 65 files/0 tests). Add an npm
overridesentry forcing@zip.js/zip.jsto^2.7.0, which resolves to 2.8.36. This removes the fixture at the source rather than stripping files from the image.Verification
npm cifrom the updated lockfile → zip.js 2.8.36npm run build(tsc) → clean, RC=0 — cesium@1.104 typechecks against 2.8.36tests/dir absent,lorem-encrypted.zipgoneNote: runtime KMZ/zip paths not exercised (dem-heights is a heights service and doesn't load zips); the change is a transitive dep bump validated by typecheck + build.
Supersedes #48 (which stripped the tests dir in the Dockerfile — symptom, not root cause).
🤖 Generated with Claude Code