build: upgrade cesium to drop test fixtures from image - #50
Merged
Merged
Conversation
cesium 1.104 pulls @zip.js/zip.js 2.4.x (via @cesium/engine), which publishes its test suite including an encrypted zip fixture that image scanners flag as password-protected. @cesium/engine moved zip.js to ^2.7.34 (test-free) starting at cesium 1.114; upgrading resolves 1.144.0 -> zip.js 2.8.36 with no test data, removing the need for an npm override. TerrainProvider.availability is now optionally typed; the terrainProvider is already guarded non-undefined above, so assert availability to keep behavior. Verified: build, unit (11) and integration (7) tests pass; built image carries zip.js 2.8.36 with no tests dir. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
cesium 1.144 requires Node >=22, but the shared reusable pull_request workflow (@v2) hardcodes a Node 18/20 matrix, so npm ci fails under engine-strict. No shared-workflows tag tests 22/24-only. Follow the current org convention (ts-server-boilerplate): inline the PR jobs on Node 24 via the init-npm composite action instead of delegating to the reusable workflow. Also add skipLibCheck to the base tsconfig: cesium now ships browser-oriented type defs that reference DOM types absent from the node lib set, which full tsc (run by lint-action) would otherwise reject. The build config already set it. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
syncush
approved these changes
Aug 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Image scans on
dem-heightsfail reporting an encrypted/password-protected archive.Root cause:
@zip.js/zip.js2.4.26 — pulled transitively viacesium→@cesium/engine— publishes its test suite, including a genuinely password-protected fixture atnode_modules/@zip.js/zip.js/tests/data/lorem-encrypted.zip. Scanners recurse into image layers, hit it, and fail.Fix
@cesium/enginemoved its zip.js range to^2.7.34(test-free) starting at cesium 1.114. Upgradingcesium ^1.104.0→^1.114.0resolves 1.144.0 → zip.js 2.8.36, which ships no test data — so no npm override or Dockerfile surgery is needed. Fixes the scan at the source and brings the core dependency current.One code change:
TerrainProvider.availabilityis now optionally typed. TheterrainProvideris already guarded non-undefined immediately above the call, soavailabilityis asserted to preserve prior behavior.Verification
npm ci→ cesium 1.144.0, zip.js 2.8.36, notests/npm run build(tsc) → RC=0Note: integration tests mock terrain providers, so the live DEM-tile download path is not exercised by CI — validated separately against the deployed environment.
Supersedes #49 (npm override of zip.js). Root-cause fix vs. carrying a transitive override.
🤖 Generated with Claude Code