Skip to content

build: upgrade cesium to drop test fixtures from image - #50

Merged
shimoncohen merged 2 commits into
masterfrom
build/bump-cesium
Aug 13, 2026
Merged

shimoncohen merged 2 commits into
masterfrom
build/bump-cesium

Conversation

@shimoncohen

Copy link
Copy Markdown
Contributor

Problem

Image scans on dem-heights fail reporting an encrypted/password-protected archive.

Root cause: @zip.js/zip.js 2.4.26 — pulled transitively via cesium → @cesium/engine — publishes its test suite, including a genuinely password-protected fixture at node_modules/@zip.js/zip.js/tests/data/lorem-encrypted.zip. Scanners recurse into image layers, hit it, and fail.

Fix

@cesium/engine moved its zip.js range to ^2.7.34 (test-free) starting at cesium 1.114. Upgrading cesium ^1.104.0 → ^1.114.0 resolves 1.144.0 → zip.js 2.8.36, which ships no test data — so no npm override or Dockerfile surgery is needed. Fixes the scan at the source and brings the core dependency current.

One code change: TerrainProvider.availability is now optionally typed. The terrainProvider is already guarded non-undefined immediately above the call, so availability is asserted to preserve prior behavior.

Verification

  • npm ci → cesium 1.144.0, zip.js 2.8.36, no tests/
  • npm run build (tsc) → RC=0
  • Unit tests → 11 passed
  • Integration tests → 7 passed (height-sampling flows exercised)
  • Docker build → RC=0; final image carries zip.js 2.8.36 with no tests dir

Note: integration tests mock terrain providers, so the live DEM-tile download path is not exercised by CI — validated separately against the deployed environment.

Supersedes #49 (npm override of zip.js). Root-cause fix vs. carrying a transitive override.

🤖 Generated with Claude Code

cesium 1.104 pulls @zip.js/zip.js 2.4.x (via @cesium/engine), which publishes
its test suite including an encrypted zip fixture that image scanners flag as
password-protected. @cesium/engine moved zip.js to ^2.7.34 (test-free) starting
at cesium 1.114; upgrading resolves 1.144.0 -> zip.js 2.8.36 with no test data,
removing the need for an npm override.

TerrainProvider.availability is now optionally typed; the terrainProvider is
already guarded non-undefined above, so assert availability to keep behavior.

Verified: build, unit (11) and integration (7) tests pass; built image carries
zip.js 2.8.36 with no tests dir.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
cesium 1.144 requires Node >=22, but the shared reusable pull_request workflow
(@v2) hardcodes a Node 18/20 matrix, so npm ci fails under engine-strict. No
shared-workflows tag tests 22/24-only. Follow the current org convention
(ts-server-boilerplate): inline the PR jobs on Node 24 via the init-npm
composite action instead of delegating to the reusable workflow.

Also add skipLibCheck to the base tsconfig: cesium now ships browser-oriented
type defs that reference DOM types absent from the node lib set, which full tsc
(run by lint-action) would otherwise reject. The build config already set it.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@shimoncohen shimoncohen self-assigned this Aug 10, 2026
@shimoncohen
shimoncohen requested a review from syncush August 10, 2026 13:19
@shimoncohen
shimoncohen merged commit ce6e75d into master Aug 13, 2026
6 checks passed
@syncush
syncush deleted the build/bump-cesium branch August 16, 2026 10:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants