Skip to content

fix(patch): reject binary file changes in npm patch commit - #10008

Open
manzoorwanijk wants to merge 1 commit into
npm:latestfrom
manzoorwanijk:feat/patch-binary-files
Open

manzoorwanijk wants to merge 1 commit into
npm:latestfrom
manzoorwanijk:feat/patch-binary-files

Conversation

@manzoorwanijk

Copy link
Copy Markdown
Contributor

Patches are unified text diffs, but npm patch commit read every file as UTF-8, so an edited image, font or wasm file was written into the patch as a corrupted text diff instead of failing. This PR makes commit reject changed binary files with EPATCHBINARY and list them, so they can be reverted before committing.

  • lib/utils/patch-diff.js treats a file as binary when it contains a NUL byte or is not valid UTF-8. Unchanged binaries are ignored.
  • Adds, deletes and modifications of binary files are all rejected, and no patch file or patchedDependencies entry is written.
  • Documented the limitation in docs/lib/content/commands/npm-patch.md.

Full binary patching is left out on purpose: patch-package, Yarn, pnpm and Bun all use text diffs only.

References

Follow-up to #9439

@manzoorwanijk

Copy link
Copy Markdown
Contributor Author

CC: @reggi @martinrrm

@manzoorwanijk
manzoorwanijk marked this pull request as ready for review September 21, 2026 08:13
@manzoorwanijk
manzoorwanijk requested a review from a team as a code owner September 21, 2026 08:13
@manzoorwanijk
manzoorwanijk force-pushed the feat/patch-binary-files branch from 863d9b5 to 1a4a7cc Compare October 5, 2026 07:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant