Repository navigation
process.versions does not list all bundled dependencies #45260
Description
Activity
- addedprocessIssues and PRs related to the process subsystem.Issues and PRs related to the process subsystem.
on Oct 31, 2022 - addedgood first issueIssues that are suitable for first-time contributors.Issues that are suitable for first-time contributors.
on Nov 1, 2022 For contributors looking for where to start; the versions are included in
src/node_metadata.ccReacted by Xavier Stouder, MURAKAMI Masahiko, Debadree Chatterjee and MertIs this possible to give indications about how to get version of full-js libs (like
acorn) or libs that doesn't expose their version number (likebase64)?For
acornandundici, thepackage.jsonis in the source tree and contains the version number. I'll let someone else suggest a good way to expose it to our C++ code.The other concern is the policy regarding update of deps.
For example right nowbase64is pointing to this commit:
aklomp/base64@dc6a41c
and it implies that the CMakeList shows0.4.0while the the next commit (aklomp/base64@9ae5ad3) is only bumping the version to0.5.0. That means that node.js is shipping a0.5.0version that hides under0.4.0.nitesh-chowdhary commented
on Nov 2, 2022 on Nov 2, 2022 · Hidden as off-topicshow commentMore actionsWould parsing the package.json for all js libraries and then including them be a good idea? put quite some thought into it this is the only one that came to my mind from my limited knowledge, would love to know about any other possible way of including this in cpp code
Let me push back on this a little. I don't think it's necessary to list version numbers for "static" dependencies (things that are always built into the binary and never linked dynamically) because those are:
a) fixed, and
b) implementation details that aren't relevant most of the time
When the configure script grows e.g. a
--shared-uvwasioption, then it's reasonable to add aprocess.version.uvwasikey for debugging purposes.Likewise, a hypothetical
--disable-histogramshould be reflected.But things that are hidden and immutable? No point in listing them.
From a functional perspective, perhaps. However, when producing something like an SBOM, it's important detail that should be included.
Not sure I follow. Can you give an example when that's relevant? SBOM = Source Bill Of Materials?
SBOM == Software Bill of Materials. See background info here: https://www.ntia.gov/SBOM
To be certain, the
process.versionsby itself does not provide all of the information necessary for this purpose but it helps.Also to be clear, I'm not suggesting that this is the only reason we should provide this additional detail.
10 remaining items
- added a commit that references this issue
on Jan 1, 2023 - added 3 commits that reference this issue
on Jan 3, 2023 - added a commit that references this issue
on Jan 5, 2023 - added a commit that references this issue
on Jan 26, 2023 - added a commit that references this issue
on May 14, 2023 - added 2 commits that reference this issue
on May 14, 2023 - added a commit that references this issue
on Nov 10, 2023 - added 2 commits that reference this issue
on Apr 25, 2024 - added a commit that references this issue
on May 22, 2026
The
process. VersionsAPI lists the versions of vendored dependencies that are bundled into Node.js. Unfortunately, it only shows a subset. Notably missing from the list are:deps/acorndeps/base64deps/cjs-module-lexerdeps/histogramdeps/undicideps/uvwasi