Skip to content

fix(desktop): align Electron pins with 41.10.6 advisory fixes - #132

Draft
RecursiveIntell wants to merge 1 commit into
mainfrom
fix/ares-electron-41-security-patch-20261004
Draft

RecursiveIntell wants to merge 1 commit into
mainfrom
fix/ares-electron-41-security-patch-20261004

Conversation

@RecursiveIntell

Copy link
Copy Markdown
Owner

The packaged desktop runtime pins Electron 41.10.3, below the reviewed upstream advisory fixes through 41.10.6. Advance development and packaging pins together, retarget the existing version-specific install-script authorization, and update the root workspace lock through canonical npm resolution. Exactly three pin/lock files change; the lock changes exactly two entries, preserving other package versions, dependency edges and engine/aging rules.

Electron 41.10.6 was released and uploaded on August 18 and meets the repository's 14-day aging rule. Relevant upstream advisories: webview worker integration, top-level popup sandbox, iframe popup sandbox, and legacy protocol handlers. Existing defenses mitigate some mechanisms; Windows sandbox recovery prevents a blanket nonexposure claim.

Electron 41 reached end of life on August 24, 2026. This same-major advisory patch does not restore supported-major status. Electron's official schedule and support policy require a separately reviewed and qualified supported-major migration.

Validation: npm 12.0.2 metadata-only lock generation passed with installation/scripts disabled; offline canonical resolution reproduced the identical lock. Artifact checks and exact forward/rollback replay passed. Final independent source review matched all three file hashes and Git blobs, official tarball integrity, 46-day release age, ABI145 and packaging alignment, with no introduced static defect. This is source/artifact acceptance, not installed or packaged runtime qualification. Desktop E2E is disabled; no dependency install, desktop build, native runtime or live Ares test ran. Hosted CI remains a separate gate.

Base 04997747879d54a242941d344c3a38293c307076, tree cbabd9591dc00fdf8deed90aeb3e8b1dc5bd2ebc. Exact rollback patch SHA256 0f75577deb16877a1e40fbaa4acb8fa87c358dd5d36f8cf9099cbfd46ef0cf7e restores these preimages. No installation, activation, deployment, service or live rollback action accompanies this draft. Python dependency proposals are outside this change.

@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

૮ >ﻌ< ა ci review

ran on 109f009 — fix(desktop): align Electron pins with 41.10.6 advisory fixe

⚠️ Action required

package-lock.json · View job

Locked npm dependency versions changed.

package-lock.json

Package Before After
electron 41.10.3 41.10.6

How to fix:

Add the ci-reviewed label after verifying the version changes are expected.


⚠️ Warnings

OSV vulnerability scan · View job

91 known vulnerabilities found in pinned dependencies.

How to fix:

Review the findings in the Security tab. Update the affected dependencies if a patched version is available.


debug info

CI timings

CI timings · View report · View job

Wall time 5m29s vs 7m23s (-25.7%). 14 job(s) slower, 4 faster, 1 unchanged.

  • JS & TS checks / ui-tui/packages/hermes-ink / check: -52.0s
  • JS & TS checks / apps/desktop / check:test:ui:shard-3of3: +44.0s
  • JS & TS checks / apps/bootstrap-installer / check: +37.0s
  • JS & TS checks / apps/desktop / check:lint: +36.0s
  • JS & TS checks / apps/desktop / check:test:desktop:platforms: +35.0s

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant