Commit ae5a0f40b57 for nodejs
commit ae5a0f40b5787a369b6cde39c36fb2760a4cd309
Author: Antoine du Hamel <duhamelantoine1995@gmail.com>
Date: Sat Oct 10 01:50:12 2026 +0200
tools: switch to PGP and SHA256 in ICU updater
Signed-off-by: Antoine du Hamel <duhamelantoine1995@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66469
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Steven R Loomis <srl295@gmail.com>
diff --git a/doc/contributing/maintaining/maintaining-icu.md b/doc/contributing/maintaining/maintaining-icu.md
index e83aa8a5b0c..93dbda2c7d9 100644
--- a/doc/contributing/maintaining/maintaining-icu.md
+++ b/doc/contributing/maintaining/maintaining-icu.md
@@ -177,9 +177,19 @@ make clean
tools/license-builder.sh
```
-* Update the URL and hash for the full ICU file in `tools/icu/current_ver.dep`.
- It should match the ICU URL used in the first step. When this is done, the
- following should build with small ICU.
+* Verify the PGP signature of the full ICU file:
+
+```bash
+gpgv --keyring tools/dep_updaters/icu.kbx \
+ icu4c-*-sources.tgz.asc icu4c-*-sources.tgz
+```
+
+* If the release was signed with a key not present in that keyring, update it
+ from the [ICU `KEYS` file](https://github.com/unicode-org/icu/blob/HEAD/KEYS)
+ after confirming the new key out-of-band.
+* Update the URL and SHA-256 hash for the full ICU file in
+ `tools/icu/current_ver.dep`. It should match the ICU URL used in the first
+ step. When this is done, the following should build with small ICU.
```bash
# clean up
diff --git a/tools/dep_updaters/icu.kbx b/tools/dep_updaters/icu.kbx
new file mode 100644
index 00000000000..6abb79eaaf3
Binary files /dev/null and b/tools/dep_updaters/icu.kbx differ
diff --git a/tools/dep_updaters/update-icu.sh b/tools/dep_updaters/update-icu.sh
index 8cd402d9326..8f39befd9f2 100755
--- a/tools/dep_updaters/update-icu.sh
+++ b/tools/dep_updaters/update-icu.sh
@@ -1,6 +1,8 @@
#!/bin/sh
set -e
-# Shell script to update icu in the source tree to a specific version
+# Shell script to update icu in the source tree to a specific version.
+# Pass `--update-keys` to update the local copy of the key files after verifying
+# the upstream file history.
BASE_DIR=$(cd "$(dirname "$0")/../.." && pwd)
DEPS_DIR="$BASE_DIR/deps"
@@ -36,28 +38,48 @@ NEW_VERSION_TGZ="icu4c-${NEW_VERSION}-sources.tgz"
NEW_VERSION_TGZ_URL="https://github.com/unicode-org/icu/releases/download/release-${NEW_VERSION}/${NEW_VERSION_TGZ}"
-NEW_VERSION_MD5="https://github.com/unicode-org/icu/releases/download/release-${NEW_VERSION}/icu4c-${NEW_VERSION}-sources.md5"
-
-CHECKSUM=$(curl -sL "$NEW_VERSION_MD5" | grep "$NEW_VERSION_TGZ" | grep -v "\.asc$" | awk '{print $1}')
+WORKSPACE=$(mktemp -d 2> /dev/null || mktemp -d -t 'tmp')
+NEW_VERSION_TGZ_PATH="$WORKSPACE/$NEW_VERSION_TGZ"
+
+cleanup () {
+ EXIT_CODE=$?
+ [ -d "$WORKSPACE" ] && rm -rf "$WORKSPACE"
+ exit $EXIT_CODE
+}
+
+trap cleanup INT TERM EXIT
+
+echo "Fetching ICU source archive"
+curl -sSLfo "$NEW_VERSION_TGZ_PATH" "$NEW_VERSION_TGZ_URL"
+
+KEYRING="$BASE_DIR/tools/dep_updaters/icu.kbx"
+if [ "$1" = "--update-keys" ]; then
+ KEYS_FILE="$WORKSPACE/KEYS"
+ GNUPGHOME="$WORKSPACE/gnupg"
+ mkdir -m 700 "$GNUPGHOME"
+ echo "Fetching the upstream KEYS file"
+ curl -sSLfo "$KEYS_FILE" "https://github.com/unicode-org/icu/raw/refs/tags/release-${NEW_VERSION}/KEYS"
+ GNUPGHOME="$GNUPGHOME" gpg --no-default-keyring --keyring "$WORKSPACE/icu.kbx" --batch --import --import-options import-minimal < "$KEYS_FILE"
+ mv "$WORKSPACE/icu.kbx" "$KEYRING"
+fi
-GENERATED_CHECKSUM=$( curl -sL "$NEW_VERSION_TGZ_URL" | md5sum | cut -d ' ' -f1)
+echo "Verifying PGP signature"
+curl -sSLfo "$NEW_VERSION_TGZ_PATH.asc" "$NEW_VERSION_TGZ_URL.asc"
+gpgv --keyring "$KEYRING" "$NEW_VERSION_TGZ_PATH.asc" "$NEW_VERSION_TGZ_PATH"
-echo "Comparing checksums: deposited '$CHECKSUM' with '$GENERATED_CHECKSUM'"
+CHECKSUM=$(shasum -a 256 "$NEW_VERSION_TGZ_PATH" | cut -d ' ' -f1)
+echo "sha256: $CHECKSUM"
-if [ "$CHECKSUM" != "$GENERATED_CHECKSUM" ]; then
- echo "Skipped because checksums do not match."
- exit 0
-fi
-
-./configure --with-intl=full-icu --with-icu-source="$NEW_VERSION_TGZ_URL"
+./configure --with-intl=full-icu --with-icu-source="$NEW_VERSION_TGZ_PATH"
"$TOOLS_DIR/icu/shrink-icu-src.py"
rm -rf "$DEPS_DIR/icu"
-perl -i -pe "s|\"url\": .*|\"url\": \"$NEW_VERSION_TGZ_URL\",|" "$TOOLS_DIR/icu/current_ver.dep"
-
-perl -i -pe "s|\"md5\": .*|\"md5\": \"$CHECKSUM\"|" "$TOOLS_DIR/icu/current_ver.dep"
+URL="$NEW_VERSION_TGZ_URL" SHA256="$CHECKSUM" "$NODE" -e '
+ const { URL: url, SHA256: sha256 } = process.env;
+ console.log(JSON.stringify([{ url, sha256 }], null, 2));
+' > "$TOOLS_DIR/icu/current_ver.dep"
rm -rf out "$DEPS_DIR/icu" "$DEPS_DIR/icu4c*"
diff --git a/tools/icu/current_ver.dep b/tools/icu/current_ver.dep
index 3d923fec865..577b585578e 100644
--- a/tools/icu/current_ver.dep
+++ b/tools/icu/current_ver.dep
@@ -1,6 +1,6 @@
[
{
"url": "https://github.com/unicode-org/icu/releases/download/release-78.3/icu4c-78.3-sources.tgz",
- "md5": "a7b736b570ef0e180c96a31715a00c78"
+ "sha256": "3a2e7a47604ba702f345878308e6fefeca612ee895cf4a5f222e7955fabfe0c0"
}
]