Skip to content

fix(node): Refresh inherited Yarn APT keyrings before dependencies - #1746

Open
Jerome Brown (oWretch) wants to merge 1 commit into
devcontainers:mainfrom
oWretch:fix/node-refresh-inherited-yarn-keyring
Open

Jerome Brown (oWretch) wants to merge 1 commit into
devcontainers:mainfrom
oWretch:fix/node-refresh-inherited-yarn-keyring

Conversation

@oWretch

Copy link
Copy Markdown

Summary

Refresh an inherited Yarn APT repository before Node feature prerequisite installation can run apt-get update. Reuse the same repository setup for fresh APT-based Yarn installations.

Problem

Older devcontainer images already contain Yarn and an unmanaged signing keyring. The installer skips repository setup when Yarn is already installed, so adding the feature does not refresh inherited trust data. Prerequisite installation can also invoke APT before install_yarn runs. This breaks unrelated package installation after upstream key rotation, even when the feature uses the default Corepack mode.

Reproduced with mcr.microsoft.com/devcontainers/python:1.2.8-3.13-bookworm and NO_PUBKEY 62D54FD4003F6525. Related: devcontainers/images#1752, devcontainers/images#1797, and #1547. This does not request disabling signature verification or changing historical image tags.

Changes

  • Refresh the standard inherited yarn.list repository before installing prerequisites, regardless of the Yarn installation mode.
  • Download and dearmor key data in a temporary directory before replacing the scoped keyring, with readable permissions and cleanup on failure.
  • Add a regression scenario using the affected published Python image, checking Yarn and all APT repository signatures.
  • Bump the Node feature patch version to 2.1.1.

Validation

  • Bash syntax checks passed for the installer and regression script.
  • JSON metadata and regression scenario checks passed.
  • Isolated command-mock checks passed for successful refresh, failed download, invalid key data, and refresh ordering before prerequisite installation.
  • git diff --check passed.
  • Container regression test not run locally: Docker is unavailable in the development container. The added scenario is intended for upstream feature CI.

@oWretch
Jerome Brown (oWretch) requested a review from a team as a code owner October 3, 2026 00:40

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant