Skip to content

deps: update libarchive to v3.8.4 - #25380

Closed
github-actions[bot] wants to merge 1 commit into
mainfrom
deps/update-libarchive-49
Closed

github-actions[bot] wants to merge 1 commit into
mainfrom
deps/update-libarchive-49

Conversation

@github-actions

@github-actions github-actions Bot commented Dec 7, 2025

Copy link
Copy Markdown
Contributor

What does this PR do?

Updates libarchive to version v3.8.4

Compare: libarchive/libarchive@9525f90...d114cee

Auto-updated by this workflow

@robobun

robobun commented Dec 7, 2025 •

Copy link
Copy Markdown
Collaborator
Updated 7:48 PM PT - Dec 6th, 2025

❌ @RiskyMH, your commit 19f19aa has 1 failures in Build #32968 (All Failures):


🧪   To try this PR locally:

bunx bun-pr 25380

That installs a local version of the PR into your bun-25380 executable, so you can run:

bun-25380 --bun

@coderabbitai

coderabbitai Bot commented Dec 7, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Updated the libarchive repository commit hash in the CMake build configuration from 9525f90ca4bd14c7b335e2f8c84a4607b0af6bdf to d114ceee6de08a7a60ff1209492ba38bf9436f79. No changes to logic, error handling, or control flow.

Changes

Cohort / File(s) Summary
Build configuration dependency updates
cmake/targets/BuildLibArchive.cmake
Updated libarchive repository commit hash reference

Pre-merge checks

❌ Failed checks (1 warning)
Check name Status Explanation Resolution
Description check ⚠️ Warning The description covers the 'What does this PR do?' section with version info and comparison link, but completely omits the 'How did you verify your code works?' section required by the template. Add the 'How did you verify your code works?' section to the description to fully comply with the repository's template requirements.
✅ Passed checks (1 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: updating libarchive to v3.8.4, which matches the single file modification in the changeset.

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 5eb2145 and 19f19aa.

📒 Files selected for processing (1)
  • cmake/targets/BuildLibArchive.cmake (1 hunks)
🧰 Additional context used
🧠 Learnings (1)
📓 Common learnings
Learnt from: ShlomoCode
Repo: oven-sh/bun PR: 23515
File: .github/workflows/claude.yml:60-60
Timestamp: 2025-10-12T02:25:02.232Z
Learning: When reviewing GitHub Actions workflows, using semantic version tags (like v1, v2) for official actions from reputable organizations (e.g., actions from github/, anthropics/, etc.) is common and acceptable practice. Don't flag these as security issues requiring commit SHA pinning.
🔇 Additional comments (1)
cmake/targets/BuildLibArchive.cmake (1)

7-7: Commit hash verified — this update includes security fixes.

The commit hash d114ceee6de08a7a60ff1209492ba38bf9436f79 is confirmed as the v3.8.4 release (published December 1, 2025). This version includes fixes for CVE-2025-5914, CVE-2025-5915, CVE-2025-5916, CVE-2025-5917, and CVE-2025-5918, making this a security-focused release. The update is safe to proceed.


Comment @coderabbitai help to get the list of available commands and usage tips.

Jarred-Sumner added a commit that referenced this pull request Apr 14, 2026
## What does this PR do?

The scheduled `update-*.yml` workflows have been failing since #28640
removed `cmake/targets/*.cmake` — they were still reading pinned commits
from those files. The dependency definitions now live in
`scripts/build/deps/*.ts` as `const <NAME>_COMMIT = "..."`.

**Workflows fixed** —
`update-{libarchive,cares,hdrhistogram,highway,libdeflate,lolhtml,lshpack,zstd}.yml`
now read/write the `_COMMIT` constant in the corresponding
`scripts/build/deps/*.ts` file. The replacement step also moved to the
safe `env:` pattern instead of inlining `${{ }}` into the shell.

**libarchive bumped** — 3.8.1 → 3.8.7
([compare](libarchive/libarchive@9525f90...ded8229)).
`archive_write_add_filter_gzip.c.patch` rebased onto the new upstream,
which reformatted the surrounding code; no semantic change — still adds
the `gzip:os` option used by `bun pm pack` for reproducible tarballs.

The other 7 deps were not version-bumped here; their now-working
workflows will open bump PRs on the next scheduled run.

Closes [#26652](#26652)
Closes [#26432](#26432)
Closes [#26209](#26209)
Closes [#25955](#25955)
Closes [#25818](#25818)
Closes [#25726](#25726)
Closes [#25625](#25625)
Closes [#25507](#25507)
Closes [#25380](#25380)

## How did you verify your code works?

- [x] `bun scripts/build.ts --target=libarchive` — patches apply
cleanly, builds `libarchive.a` with `ARCHIVE_VERSION_NUMBER 3008007`
- [x] `bun bd test test/js/bun/archive.test.ts` — 99 pass
- [x] `bun bd test test/cli/install/bun-pack.test.ts` — 70 pass
- [x] `bun pm pack` gzip header byte 9 = `0xff`, confirming the rebased
patch is functional
- [x] All 8 workflows: extraction sed returns valid 40-char hash from
the live `.ts` file (GNU sed)
- [x] All 8 workflows: replacement sed rewrites exactly one line,
round-trips back through extraction
- [x] All 8 workflows: YAML parses, no `cmake` references remain
structwafel pushed a commit to structwafel/bun that referenced this pull request Apr 25, 2026
…h#29289)

## What does this PR do?

The scheduled `update-*.yml` workflows have been failing since oven-sh#28640
removed `cmake/targets/*.cmake` — they were still reading pinned commits
from those files. The dependency definitions now live in
`scripts/build/deps/*.ts` as `const <NAME>_COMMIT = "..."`.

**Workflows fixed** —
`update-{libarchive,cares,hdrhistogram,highway,libdeflate,lolhtml,lshpack,zstd}.yml`
now read/write the `_COMMIT` constant in the corresponding
`scripts/build/deps/*.ts` file. The replacement step also moved to the
safe `env:` pattern instead of inlining `${{ }}` into the shell.

**libarchive bumped** — 3.8.1 → 3.8.7
([compare](libarchive/libarchive@9525f90...ded8229)).
`archive_write_add_filter_gzip.c.patch` rebased onto the new upstream,
which reformatted the surrounding code; no semantic change — still adds
the `gzip:os` option used by `bun pm pack` for reproducible tarballs.

The other 7 deps were not version-bumped here; their now-working
workflows will open bump PRs on the next scheduled run.

Closes [oven-sh#26652](oven-sh#26652)
Closes [oven-sh#26432](oven-sh#26432)
Closes [oven-sh#26209](oven-sh#26209)
Closes [oven-sh#25955](oven-sh#25955)
Closes [oven-sh#25818](oven-sh#25818)
Closes [oven-sh#25726](oven-sh#25726)
Closes [oven-sh#25625](oven-sh#25625)
Closes [oven-sh#25507](oven-sh#25507)
Closes [oven-sh#25380](oven-sh#25380)

## How did you verify your code works?

- [x] `bun scripts/build.ts --target=libarchive` — patches apply
cleanly, builds `libarchive.a` with `ARCHIVE_VERSION_NUMBER 3008007`
- [x] `bun bd test test/js/bun/archive.test.ts` — 99 pass
- [x] `bun bd test test/cli/install/bun-pack.test.ts` — 70 pass
- [x] `bun pm pack` gzip header byte 9 = `0xff`, confirming the rebased
patch is functional
- [x] All 8 workflows: extraction sed returns valid 40-char hash from
the live `.ts` file (GNU sed)
- [x] All 8 workflows: replacement sed rewrites exactly one line,
round-trips back through extraction
- [x] All 8 workflows: YAML parses, no `cmake` references remain
xhjkl pushed a commit to xhjkl/bun that referenced this pull request May 14, 2026
…h#29289)

## What does this PR do?

The scheduled `update-*.yml` workflows have been failing since oven-sh#28640
removed `cmake/targets/*.cmake` — they were still reading pinned commits
from those files. The dependency definitions now live in
`scripts/build/deps/*.ts` as `const <NAME>_COMMIT = "..."`.

**Workflows fixed** —
`update-{libarchive,cares,hdrhistogram,highway,libdeflate,lolhtml,lshpack,zstd}.yml`
now read/write the `_COMMIT` constant in the corresponding
`scripts/build/deps/*.ts` file. The replacement step also moved to the
safe `env:` pattern instead of inlining `${{ }}` into the shell.

**libarchive bumped** — 3.8.1 → 3.8.7
([compare](libarchive/libarchive@9525f90...ded8229)).
`archive_write_add_filter_gzip.c.patch` rebased onto the new upstream,
which reformatted the surrounding code; no semantic change — still adds
the `gzip:os` option used by `bun pm pack` for reproducible tarballs.

The other 7 deps were not version-bumped here; their now-working
workflows will open bump PRs on the next scheduled run.

Closes [oven-sh#26652](oven-sh#26652)
Closes [oven-sh#26432](oven-sh#26432)
Closes [oven-sh#26209](oven-sh#26209)
Closes [oven-sh#25955](oven-sh#25955)
Closes [oven-sh#25818](oven-sh#25818)
Closes [oven-sh#25726](oven-sh#25726)
Closes [oven-sh#25625](oven-sh#25625)
Closes [oven-sh#25507](oven-sh#25507)
Closes [oven-sh#25380](oven-sh#25380)

## How did you verify your code works?

- [x] `bun scripts/build.ts --target=libarchive` — patches apply
cleanly, builds `libarchive.a` with `ARCHIVE_VERSION_NUMBER 3008007`
- [x] `bun bd test test/js/bun/archive.test.ts` — 99 pass
- [x] `bun bd test test/cli/install/bun-pack.test.ts` — 70 pass
- [x] `bun pm pack` gzip header byte 9 = `0xff`, confirming the rebased
patch is functional
- [x] All 8 workflows: extraction sed returns valid 40-char hash from
the live `.ts` file (GNU sed)
- [x] All 8 workflows: replacement sed rewrites exactly one line,
round-trips back through extraction
- [x] All 8 workflows: YAML parses, no `cmake` references remain
liooil pushed a commit to liooil/poly that referenced this pull request Aug 7, 2026
## What does this PR do?

The scheduled `update-*.yml` workflows have been failing since #28640
removed `cmake/targets/*.cmake` — they were still reading pinned commits
from those files. The dependency definitions now live in
`scripts/build/deps/*.ts` as `const <NAME>_COMMIT = "..."`.

**Workflows fixed** —
`update-{libarchive,cares,hdrhistogram,highway,libdeflate,lolhtml,lshpack,zstd}.yml`
now read/write the `_COMMIT` constant in the corresponding
`scripts/build/deps/*.ts` file. The replacement step also moved to the
safe `env:` pattern instead of inlining `${{ }}` into the shell.

**libarchive bumped** — 3.8.1 → 3.8.7
([compare](libarchive/libarchive@9525f90...ded8229)).
`archive_write_add_filter_gzip.c.patch` rebased onto the new upstream,
which reformatted the surrounding code; no semantic change — still adds
the `gzip:os` option used by `bun pm pack` for reproducible tarballs.

The other 7 deps were not version-bumped here; their now-working
workflows will open bump PRs on the next scheduled run.

Closes [oven-sh/bun#26652](oven-sh/bun#26652)
Closes [oven-sh/bun#26432](oven-sh/bun#26432)
Closes [oven-sh/bun#26209](oven-sh/bun#26209)
Closes [oven-sh/bun#25955](oven-sh/bun#25955)
Closes [oven-sh/bun#25818](oven-sh/bun#25818)
Closes [oven-sh/bun#25726](oven-sh/bun#25726)
Closes [oven-sh/bun#25625](oven-sh/bun#25625)
Closes [oven-sh/bun#25507](oven-sh/bun#25507)
Closes [oven-sh/bun#25380](oven-sh/bun#25380)

## How did you verify your code works?

- [x] `bun scripts/build.ts --target=libarchive` — patches apply
cleanly, builds `libarchive.a` with `ARCHIVE_VERSION_NUMBER 3008007`
- [x] `bun bd test test/js/bun/archive.test.ts` — 99 pass
- [x] `bun bd test test/cli/install/bun-pack.test.ts` — 70 pass
- [x] `bun pm pack` gzip header byte 9 = `0xff`, confirming the rebased
patch is functional
- [x] All 8 workflows: extraction sed returns valid 40-char hash from
the live `.ts` file (GNU sed)
- [x] All 8 workflows: replacement sed rewrites exactly one line,
round-trips back through extraction
- [x] All 8 workflows: YAML parses, no `cmake` references remain
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants