Skip to content

chore: update curl to current 8.18.0#186

Open
curtdept wants to merge 1 commit intoaws:nodejs24.xfrom
curtdept:nodejs24.x
Open

chore: update curl to current 8.18.0#186
curtdept wants to merge 1 commit intoaws:nodejs24.xfrom
curtdept:nodejs24.x

Conversation

@curtdept
Copy link

@curtdept curtdept commented Feb 12, 2026

This PR updates the curl dependency to the latest released 8.18.0 and modifies the preinstall script to point to the appropriate subdirectory.

8.18.0 is needed to mitigate a large number of identified CVEs in this package since the previous bump.

Release information and package for curl: https://github.com/curl/curl/releases/tag/curl-8_18_0

Relates to: #159

Checklist

  • I have run npm install to generate the package-lock.json correctly and included it in the PR.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

Copilot AI review requested due to automatic review settings February 12, 2026 19:17
@curtdept
Copy link
Author

curtdept commented Feb 12, 2026

@godcrampy can you help push this along please? Scanning tools have been quite unhappy for some time about this. Fork test on a clean up to date repo was successful.

https://github.com/curtdept/aws-lambda-nodejs-runtime-interface-client/actions/runs/21960662538

Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR aims to update the curl dependency from an older version to 8.18.0 to mitigate multiple CVEs. The change modifies the preinstall script to reference a version-specific subdirectory when extracting and building curl.

Changes:

  • Updated CURL_DIR path in preinstall script to include version-specific subdirectory (curl-8.18.0)

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant