Repository navigation
fix(desktop): align Electron pins with 41.10.6 advisory fixes - #132
Draft
RecursiveIntell wants to merge 1 commit into
Draft
RecursiveIntell wants to merge 1 commit into
RecursiveIntell wants to merge 1 commit into
Conversation
૮ >ﻌ< ა ci reviewran on 109f009 — fix(desktop): align Electron pins with 41.10.6 advisory fixe
|
| Package | Before | After |
|---|---|---|
| electron | 41.10.3 |
41.10.6 |
How to fix:
Add the ci-reviewed label after verifying the version changes are expected.
⚠️ Warnings
OSV vulnerability scan · View job
91 known vulnerabilities found in pinned dependencies.
- CVE-2026-84947 in package-lock.json
- CVE-2026-84947 in plugins/platforms/photon/sidecar/package-lock.json
- CVE-2026-101917 in uv.lock
- CVE-2026-84933 in package-lock.json
- CVE-2026-84933 in plugins/platforms/photon/sidecar/package-lock.json
- CVE-2026-103261 in uv.lock
- CVE-2026-85024 in package-lock.json
- CVE-2026-85024 in package-lock.json
- CVE-2026-85024 in plugins/platforms/photon/sidecar/package-lock.json
- CVE-2026-84890 in package-lock.json
- CVE-2026-84890 in plugins/platforms/photon/sidecar/package-lock.json
- CVE-2026-101918 in uv.lock
- CVE-2026-84394 in package-lock.json
- CVE-2026-84394 in website/package-lock.json
- CVE-2026-64847 in uv.lock
- CVE-2026-92599 in package-lock.json
- CVE-2026-92599 in website/package-lock.json
- CVE-2026-102276 in package-lock.json
- CVE-2026-102276 in package-lock.json
- CVE-2026-102276 in website/package-lock.json
How to fix:
Review the findings in the Security tab. Update the affected dependencies if a patched version is available.
debug info
CI timings
CI timings · View report · View job
Wall time 5m29s vs 7m23s (-25.7%). 14 job(s) slower, 4 faster, 1 unchanged.
- JS & TS checks / ui-tui/packages/hermes-ink / check: -52.0s
- JS & TS checks / apps/desktop / check:test:ui:shard-3of3: +44.0s
- JS & TS checks / apps/bootstrap-installer / check: +37.0s
- JS & TS checks / apps/desktop / check:lint: +36.0s
- JS & TS checks / apps/desktop / check:test:desktop:platforms: +35.0s
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The packaged desktop runtime pins Electron 41.10.3, below the reviewed upstream advisory fixes through 41.10.6. Advance development and packaging pins together, retarget the existing version-specific install-script authorization, and update the root workspace lock through canonical npm resolution. Exactly three pin/lock files change; the lock changes exactly two entries, preserving other package versions, dependency edges and engine/aging rules.
Electron 41.10.6 was released and uploaded on August 18 and meets the repository's 14-day aging rule. Relevant upstream advisories: webview worker integration, top-level popup sandbox, iframe popup sandbox, and legacy protocol handlers. Existing defenses mitigate some mechanisms; Windows sandbox recovery prevents a blanket nonexposure claim.
Electron 41 reached end of life on August 24, 2026. This same-major advisory patch does not restore supported-major status. Electron's official schedule and support policy require a separately reviewed and qualified supported-major migration.
Validation: npm 12.0.2 metadata-only lock generation passed with installation/scripts disabled; offline canonical resolution reproduced the identical lock. Artifact checks and exact forward/rollback replay passed. Final independent source review matched all three file hashes and Git blobs, official tarball integrity, 46-day release age, ABI145 and packaging alignment, with no introduced static defect. This is source/artifact acceptance, not installed or packaged runtime qualification. Desktop E2E is disabled; no dependency install, desktop build, native runtime or live Ares test ran. Hosted CI remains a separate gate.
Base
04997747879d54a242941d344c3a38293c307076, treecbabd9591dc00fdf8deed90aeb3e8b1dc5bd2ebc. Exact rollback patch SHA2560f75577deb16877a1e40fbaa4acb8fa87c358dd5d36f8cf9099cbfd46ef0cf7erestores these preimages. No installation, activation, deployment, service or live rollback action accompanies this draft. Python dependency proposals are outside this change.