Skip to content

build: package patched libheif for Cosmos runtimes - #1

Open
scottt732 wants to merge 3 commits into
mainfrom
feat/patched-libheif-nexus
Open

scottt732 wants to merge 3 commits into
mainfrom
feat/patched-libheif-nexus

Conversation

@scottt732

Copy link
Copy Markdown
Member

Build libheif 1.23.4 into Cosmos-scoped libvips packages for Sharp 0.35.4. This provides patched native image parsing for Lambda Linux x64 and cosmos-www Alpine ARM64, plus Alpine x64 CI and Apple Silicon development.

The fork builds and tests artifacts only. The private cosmos-actions publisher will verify the successful run and exact commit before publishing to Nexus; public forks receive no Nexus credentials. Existing HEVC codec support is unchanged.

How It Was Found

ENG-14549 tracks the libheif security remediation: https://linear.app/cosmos/issue/ENG-14549. Released npm native packages lag the patched libheif source.

How It Was Tested

Local Node and Bash syntax checks, actionlint, and git diff checks passed. CI builds each native target and tests upstream Sharp loading, native dependency versions, JPEG/PNG/WebP/AVIF decoding, resize and malformed-input rejection in representative runtime containers. Native builds intentionally run in CI.

No deployment or feature-flag change in this PR. Consumers will pin verified Nexus artifacts in ENG-14550 and ENG-14551, followed by dev/prod rollout verification.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant