FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

fix node-pre-gyp spawn on windows with node 18+ by rcolfin · Pull Request #11 · figma/nodegit · GitHub

Repository navigation

fix node-pre-gyp spawn on windows with node 18+ - #11

Closed
rcolfin wants to merge 1 commit into
figma:figmafrom
rcolfin:fix-install
Closed

rcolfin wants to merge 1 commit into
figma:figmafrom
rcolfin:fix-install

Conversation

rcolfin commented Feb 24, 2025

Copy link
Copy Markdown

spawning cmd files without shell: true wasn't really allowed before, but not it's expressly disallowed because of a recent vulnerability reported to node

spawning cmd files without shell: true wasn't really allowed before, but not it's expressly disallowed because of a recent vulnerability reported to node

rcolfin commented Feb 25, 2025

Copy link
Copy Markdown
Author

This is to work around installation issues on Windows whereby the .cmd file cannot be installed without using shell=True.

rcolfin commented Mar 22, 2025

Copy link
Copy Markdown
Author

@weeyum @jfirebaugh Could you please review?

leumasme commented Apr 13, 2025 •
edited
Loading

Copy link
Copy Markdown

+1 on this, currently errors with ERROR - finished with error code: Error: spawn EINVAL on install
See also: https://nodejs.org/en/blog/vulnerability/april-2024-security-releases-2
While that post claims that this can be circumvented with --security-revert=CVE-2024-27980, I could not get this to work - assumedly because the install process spawns the preinstall and install scripts as separate node instances without preserving that parameter.

Copy link
Copy Markdown
Member

Hey, sorry, we don't really intend for this fork to be something we provide community support for. I suggest making your own fork if this is something you need.

jfirebaugh closed this Apr 28, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants


Back | FazBrowse Home | New Git URL