Skip to content

build: use @electron-internal/extract-zip - #909

Merged
dsanders11 merged 1 commit into
mainfrom
chore/electron-internal-extract-zip
Sep 26, 2026
Merged

dsanders11 merged 1 commit into
mainfrom
chore/electron-internal-extract-zip

Conversation

@claude

@claude claude Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Requested by David Sanders · Slack thread

This swaps our direct extract-zip dependency for @electron-internal/extract-zip (1.0.5), the Electron-maintained native drop-in replacement. It has the same default-export extract(zipPath, { dir }) signature, so the two call sites in e auto-roll and the dist download path only change their import. It also drops extract-zip and its yauzl-based dependency tree from the lockfile, since nothing else depended on it. Build, lint, and tests pass apart from the existing e-init test that can't bootstrap depot_tools in the sandbox (it fails on main too), and in a manual check the new package extracted a zip with nested dirs, exec bits, and framework-style symlinks identically to extract-zip. No .yarnrc.yml change was needed because 1.0.5 is older than the age gate.

🤖 Generated with Claude Code

https://claude.ai/code/session_016v1gicQBW7wMJeDkqcScc6


Generated by Claude Code

Replace the extract-zip dependency with @electron-internal/extract-zip,
a native drop-in replacement with the same extract(zipPath, { dir })
API. This drops extract-zip and its yauzl-based dependency tree.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016v1gicQBW7wMJeDkqcScc6
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​electron-internal/​extract-zip@​1.0.5951009988100

View full report

@dsanders11
dsanders11 marked this pull request as ready for review September 26, 2026 00:50
@dsanders11
dsanders11 requested review from a team and ckerr as code owners September 26, 2026 00:50

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, straightforward dependency swap. Checked that import sites in src/e-auto-roll.ts and src/utils/download-dist.ts, package.json, and yarn.lock are all consistently updated with no leftover references to the old extract-zip package, and the new package resolves cleanly in the lockfile with the same call signature.

Extended reasoning...

The change swaps a direct npm dependency (extract-zip) for an internal fork (@ electron-internal/extract-zip) across package.json, two import sites, a comment, and the lockfile. It touches no auth, crypto, or permission logic — only a build-time dependency and its two call sites, both of which use the identical default-export signature. The diff is small, mechanical, and self-consistent (no leftover references to the old package name), and no reviewer raised an outstanding objection in the timeline (one approval from dsanders11, no CHANGES_REQUESTED). The one ruled-out item (missing @ electron-internal/* entry in npmPreapprovedPackages) is a future-maintenance note, not a defect in this PR, since 1.0.5 already clears the age gate per the author's description and the lockfile confirms.

@dsanders11
dsanders11 merged commit 6d4271f into main Sep 26, 2026
14 checks passed
@dsanders11
dsanders11 deleted the chore/electron-internal-extract-zip branch September 26, 2026 01:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants