Skip to content

chore: dependency security maintenance (2026-09-18) - #5

Open
Kvrnn wants to merge 2 commits into
developfrom
chore/maintenance-2026-09-18
Open

Kvrnn wants to merge 2 commits into
developfrom
chore/maintenance-2026-09-18

Conversation

@Kvrnn

@Kvrnn Kvrnn commented Sep 18, 2026

Copy link
Copy Markdown
Member

Summary

Dependency security maintenance on develop.

  • Resolves all critical/high Dependabot alerts: electron 41.0.2 → 41.10.7, app-builder-lib / electron-builder 26.16.1, tar, plus transitive updates.
  • In-range minor/patch updates for the remaining outdated dependencies.
  • hak/tsconfig.json: enables skipLibCheck to work around a type error in app-builder-lib's published typings.

No major-version upgrades, and no workflow, packaging or signing changes.

Verification

  • pnpm install --frozen-lockfile (pnpm 10.32.1) is clean.
  • lint:types, lint:js, lint:workflows, lint:knip and build:ts give the same results as develop.
  • pnpm audit: 102 → 1. The remaining one is counterpart (GHSA-2488-w585-72ch), which has no fixed release.
  • Native modules (seshat / keytar) and packaging were not rebuilt locally.

Not fixed here

  • Inherited CodeQL / zizmor actions/cache-poisoning findings in the release build workflows.
  • The counterpart advisory (no fix available upstream).

🤖 Generated with Claude Code

…-builder-lib, tar + transitive)

Reproduces the substance of the three open Dependabot PRs and clears every
remaining open Dependabot alert (37 high / 28 medium / 5 low):

- electron 41.0.2 -> 41.10.7 (GHSA-9f4c-93c8-jc8g, GHSA-v3j7-r9gq-3gjw,
  GHSA-h7rp-cf8h-j98x + all medium/low electron CVEs in the 41.x line)
- app-builder-lib / electron-builder / electron-builder-squirrel-windows
  26.8.2 -> 26.16.1 (Dependabot proposed 26.15.0; bumped one minor further to
  match the version element-hq/element-web's desktop monorepo package has
  already moved to, since app-builder-lib and electron-builder release in
  lockstep). Fixes GHSA-7g7r-gx96-252g and, transitively, the app-builder-lib
  dependency tree (builder-util-runtime, sigstore family, js-yaml, xmldom,
  fast-uri, form-data, ip-address, smol-toml, browserslist,
  baseline-browser-mapping). extract-zip is no longer pulled in at all by
  26.16.1, which resolves its two "no patched version" alerts by removal.
- tar 7.5.8 -> 7.5.21 (matches the Dependabot PR's manifest bump; lockfile
  resolves 7.5.22)
- pacote 21.0.0 -> 21.5.1, @sentry/electron 7.0.0 -> 7.19.0, uuid 13.0.0 ->
  13.0.2, @babel/core 7.18.10 -> 7.29.7: same-major bumps needed to reach
  patched versions of transitively pinned sigstore/@opentelemetry/babel
  advisories found by `pnpm audit` (pacote pulls sigstore; @sentry/electron
  pulls @opentelemetry/core; uuid and @babel/core are fixed directly).

All of the above are in-range lockfile refreshes or same-major direct-
dependency bumps; no pnpm.overrides were needed. `pnpm ls <pkg> --all`
confirms a single, patched, resolved version for every previously flagged
package. Remaining `pnpm audit` finding: counterpart <=0.18.6 (moderate,
prototype pollution) has no patched release upstream (0.18.6 is latest) --
deferred, tracked in the maintenance report.

Also sets "skipLibCheck": true in hak/tsconfig.json, matching the sibling
tsconfig.json and scripts/tsconfig.json which already set it. Without this,
`pnpm lint:types:hak` fails on app-builder-lib 26.14.0+'s own published
type declarations: SnapOptions.d.ts imports "../targets/snap/snapcraft",
a module missing from every 26.14.0-26.16.1 tarball (verified by downloading
and inspecting the published packages directly) -- a genuine upstream
packaging defect in electron-builder, not something in this repo's code.
…dated deps

Non-security follow-up to the previous commit. Bumps every devDependency/
dependency whose declared semver range already permitted a newer release
(no manifest range widening beyond what the existing caret already allowed,
except @electron/asar and png-to-ico which are exact-pinned like the
electron-builder family and get an explicit same-major bump):

- png-to-ico 3.0.1 -> 3.0.2 (patch)
- @electron/asar 4.1.0 -> 4.3.0 (minor; also drops asar's own plist/xmldom
  dependency entirely as of 4.2.0+, one less path to that advisory family)
- @typescript-eslint/eslint-plugin + parser 8.57.0 -> 8.70.0 (in range ^8.0.0)
- prettier 3.8.1 -> 3.9.8 (in range ^3.0.0)
- tsx 4.21.0 -> 4.23.13 (in range ^4.19.2)
- @babel/preset-typescript 7.28.5 -> 7.29.7 (in range ^7.18.6)
- eslint-plugin-n 17.24.0 -> latest 17.x (in range ^17.12.0)
- eslint-plugin-unicorn 56.0.1 -> latest 56.x (in range ^56.0.0)
- knip 5.86.0 -> latest 5.x (in range ^5.0.0)
- lint-staged 16.4.0 -> latest 16.x (in range ^16.0.0)

Deferred majors (not applied -- see maintenance report for full reasoning):
electron 41.x -> 44.x, eslint 8.x -> 10.x (repo pins peerDependencyRules to
eslint 8 on purpose), typescript 5.9 -> 7.0, @types/node 18.x -> 26.x (must
not exceed the engines-declared Node 18 floor), knip/lint-staged/eslint-
plugin-n/eslint-plugin-unicorn majors, pacote 21.x -> 22.x, uuid 13.x ->
14.x, @babel/core+preset-env 7.x -> 8.x. @playwright/test is left at its
exact pin (1.58.2); bumping it would require running the Playwright e2e
suite (out of scope per task instructions -- native/electron-builder
verification is skipped in this pass) to confirm compatibility.

Verified after this commit: pnpm install (clean), lint:types, lint:js,
lint:knip, build:ts, lint:workflows all pass; pnpm audit still shows only
the one pre-existing, unfixable counterpart advisory.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-18T20:31:13.520445Z ce763fc PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @noble/hashes is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yaml → npm/[email protected] → npm/@noble/[email protected]

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@noble/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @noble/hashes is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yaml → npm/[email protected] → npm/@noble/[email protected]

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@noble/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: medium. Approved; Cursor Bugbot was not present after the first check poll, so that signal was skipped, and remaining approval criteria are met. No reviewers assigned.

Open in Web View Automation 

Sent by Cursor Approval Agent: NST: PR Approver

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ce763fcd47

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread package.json
"electron": "41.0.2",
"electron-builder": "26.8.2",
"electron-builder-squirrel-windows": "26.8.2",
"electron": "41.10.7",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Raise the advertised Node.js minimum for Electron 41.10

On Node.js 18 through 22.11, which package.json still advertises as supported, this Electron upgrade pulls @electron/[email protected] and @electron-internal/[email protected], both of which declare Node.js >=22.12.0 and are used while downloading/installing Electron. The checked-in .node-version uses Node 24, so CI will not expose the mismatch, but contributors following the published engines.node floor can no longer reliably install or build the project; either retain an Electron release compatible with that floor or update the floor to >=22.12.0.

Useful? React with 👍 / 👎.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant