Replace decompress with yauzl in Ark and Kallichore install scripts - #16256
Open
juliasilge wants to merge 1 commit into
Open
juliasilge wants to merge 1 commit into
juliasilge wants to merge 1 commit into
Conversation
|
E2E Tests 🚀 Why these tags?
More on automatic tags from changed files. |
Member
Author
juliasilge
marked this pull request as ready for review
September 26, 2026 02:14
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR replaces the
decompressdev dependency withyauzlin the install scripts for Ark and Kallichore. It is a follow-up to #16236, and part of setting us up for posit-dev/positron-builds#1269.Summary
decompresshas a critical advisory with no fix. After some other easy-ish fixes, it would be the only critical advisory inpositron-rand inpositron-supervisor. Only two scripts use it:extensions/positron-r/scripts/install-kernel.ts, which installs Arkextensions/positron-supervisor/scripts/install-kallichore-server.ts, which installs KallichoreThese scripts extract flat zip files that contain one binary and its license files. For this reason, a full archive library is not necessary. The scripts now use
yauzl3.4.0, whichpositron-duckdbalready uses inside of our project.yauzlhas no advisories and has one dependency (pend). AT LEAST FOR NOW. 😩The changes are:
extractZip()helper replaces the call todecompress(). The helper keeps the Unix file mode from the archive, so the binaries stay executable. Zip files made on Windows have no Unix mode, so these files get0644.yauzlrejects entries with absolute paths or..segments, which stops a "zip slip" attack.decompressand@types/decompresschange toyauzland@types/yauzlindevDependencies.positron-rand 49 packages frompositron-supervisor. The only version change isyauzlfrom 2.10.0 to 3.4.0.@vscode/vsceinpositron-rkeeps its own copy ofyauzl2.The two extensions do not share script code, so each script has its own copy of the helper. If someone feels strongly about not keeping two copies, I am certainly flexible on this.
npm audit results:
positron-rpositron-supervisorThere are no changes to runtime dependencies or to code that we ship.
Not in this PR
positron-rstill has high advisories forjs-yamlandserialize-javascript, frommocha@11.positron-supervisorstill has high advisories foraxiosandform-data. These are runtime dependencies, so a separate PR will need to update them.Release Notes
New Features
Bug Fixes
Validation Steps
@:critical @:win
This change is only to dev dependencies and build scripts. I did these checks locally on macOS:
resources/arkandresources/kallichore. Then I rannpm run install-kernelandnpm run install-kallichore. The extracted files are the same as the output ofunzip.arkandkcserverare executable and start correctly.kcserverwith a file that is not executable, and I ran the install again. The script replaced the file, and the new binary is executable.0644.../entry. The helper rejected the zip, and it wrote no files outside the target folder.CI builds and the Windows tests run these scripts on Linux and Windows.