Skip to content

fix(deps): drop node-apk to remove vulnerable node-forge - #211

Merged
finalerock44 merged 1 commit into
devfrom
fix/drop-node-apk
Oct 2, 2026
Merged

finalerock44 merged 1 commit into
devfrom
fix/drop-node-apk

Conversation

@finalerock44

Copy link
Copy Markdown
Contributor

node-apk pulled in node-forge, which has an unpatched high-severity advisory (GHSA-86w9-cpqp-85rv, RSA PKCS#1 v1.5 signature forgery) that fails pnpm audit on every PR. node-forge 1.4.0 is the latest release and the upstream fix (digitalbazaar/forge#1152) is unmerged a month on; node-apk itself hasn't been released since 2023.

The CLI only ever needed the package name, so read it straight out of AndroidManifest.xml: node-stream-zip (already a dependency) extracts the entry and a small Android binary XML reader takes the root 's package attribute.

Checked against aapt2 and node-apk on 54 real APKs (fixtures, emulator overlays, customer reproduction binaries), all identical. Those all use UTF-16 string pools, so unit tests build UTF-8 and UTF-16 manifests by hand (both verified readable by aapt and aapt2) and cover the error paths.

What & why

Type of change

  • fix — bug fix
  • feat — new feature
  • perf — performance improvement
  • refactor — code change that's neither a fix nor a feature
  • docs — documentation only
  • chore / ci / build / test — tooling, no user-facing change
  • Breaking change (title has ! or PR notes a BREAKING CHANGE:)

Checklist

  • PR title follows the Conventional Commits format (see comment above)
  • pnpm lint passes
  • pnpm typecheck passes
  • pnpm build passes
  • I have not bumped the version or edited CHANGELOG.md (release-please handles this)
  • I have signed the CLA (the bot will prompt on first contribution)
  • Docs / README.md / STYLE_GUIDE.md updated if behaviour or output changed

How to test

node-apk pulled in node-forge, which has an unpatched high-severity
advisory (GHSA-86w9-cpqp-85rv, RSA PKCS#1 v1.5 signature forgery) that
fails `pnpm audit` on every PR. node-forge 1.4.0 is the latest release
and the upstream fix (digitalbazaar/forge#1152) is unmerged a month on;
node-apk itself hasn't been released since 2023.

The CLI only ever needed the package name, so read it straight out of
AndroidManifest.xml: node-stream-zip (already a dependency) extracts the
entry and a small Android binary XML reader takes the root <manifest>'s
package attribute.

Checked against aapt2 and node-apk on 54 real APKs (fixtures, emulator
overlays, customer reproduction binaries), all identical. Those all use
UTF-16 string pools, so unit tests build UTF-8 and UTF-16 manifests by
hand (both verified readable by aapt and aapt2) and cover the error
paths.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@finalerock44 finalerock44 self-assigned this Oct 2, 2026
@claude

claude Bot commented Oct 2, 2026

Copy link
Copy Markdown

Code review

No issues found. Checked for bugs and CLAUDE.md compliance.

@finalerock44
finalerock44 merged commit 12fc601 into dev Oct 2, 2026
9 checks passed
@finalerock44
finalerock44 deleted the fix/drop-node-apk branch October 2, 2026 17:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant