Skip to content

[release-25.11] nodePackages.prebuild-install: mark as potentially vulnerable#470915

Merged
tomodachi94 merged 1 commit intoNixOS:release-25.11from
tomodachi94:release-25.11
Dec 15, 2025
Merged

[release-25.11] nodePackages.prebuild-install: mark as potentially vulnerable#470915
tomodachi94 merged 1 commit intoNixOS:release-25.11from
tomodachi94:release-25.11

Conversation

@tomodachi94
Copy link
Member

Dropped in #470892. This package might be vulnerable to CVE-2025-59343 due to its dependency on an old version of tar-fs. I don't know if this CVE can be exploited with prebuild-install, but better safe than sorry here.

Things done

  • Built on platform:
    • x86_64-linux
    • aarch64-linux
    • x86_64-darwin
    • aarch64-darwin
  • Tested, as applicable:
  • Ran nixpkgs-review on this PR. See nixpkgs-review usage.
  • Tested basic functionality of all binary files, usually in ./result/bin/.
  • Nixpkgs Release Notes
    • Package update: when the change is major or breaking.
  • NixOS Release Notes
    • Module addition: when adding a new NixOS module.
    • Module update: when the change is significant.
  • Fits CONTRIBUTING.md, pkgs/README.md, maintainers/README.md and other READMEs.

Add a 👍 reaction to pull requests you find important.

@tomodachi94 tomodachi94 added the 1.severity: security Issues which raise a security issue, or PRs that fix one label Dec 15, 2025
@tomodachi94 tomodachi94 requested a review from pyrox0 December 15, 2025 03:29
Copy link
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This report is automatically generated by the PR / Check / cherry-pick CI workflow.

Some of the commits in this PR require the author's and reviewer's attention.

If you need to merge this PR despite the warnings, please dismiss this review shortly before merging.

Important

79933db is not a cherry-pick, because: Package was dropped on master (#470892). Please review this commit manually.

Hint: The full diffs are also available in the runner logs with slightly better highlighting.

@tomodachi94 tomodachi94 requested a review from a team December 15, 2025 03:29
This package might be vulnerable to CVE-2025-59343 due to its dependency
on an old version of tar-fs.

I don't know if this CVE can be exploited with prebuild-install,
but better safe than sorry here.

Not-cherry-picked-because: Package was dropped on master (NixOS#470892)
@nixpkgs-ci nixpkgs-ci bot added 10.rebuild-darwin: 0 This PR does not cause any packages to rebuild on Darwin. 10.rebuild-linux: 0 This PR does not cause any packages to rebuild on Linux. 6.topic: nodejs Node.js is a free, open-source, cross-platform JavaScript runtime environment 4.workflow: backport This targets a stable branch labels Dec 15, 2025
Copy link
Member

@pyrox0 pyrox0 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@pyrox0 pyrox0 dismissed github-actions[bot]’s stale review December 15, 2025 04:21

unneeded, package is dropped on master but is kept for back-compat on 25.11

@nixpkgs-ci nixpkgs-ci bot added the 12.approvals: 1 This PR was reviewed and approved by one person. label Dec 15, 2025
@tomodachi94 tomodachi94 added this pull request to the merge queue Dec 15, 2025
Merged via the queue into NixOS:release-25.11 with commit 7be9787 Dec 15, 2025
33 of 36 checks passed
@tomodachi94 tomodachi94 deleted the release-25.11 branch December 15, 2025 15:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

1.severity: security Issues which raise a security issue, or PRs that fix one 4.workflow: backport This targets a stable branch 6.topic: nodejs Node.js is a free, open-source, cross-platform JavaScript runtime environment 10.rebuild-darwin: 0 This PR does not cause any packages to rebuild on Darwin. 10.rebuild-linux: 0 This PR does not cause any packages to rebuild on Linux. 12.approvals: 1 This PR was reviewed and approved by one person.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants