Conversation
…-builder-lib, tar + transitive) Reproduces the substance of the three open Dependabot PRs and clears every remaining open Dependabot alert (37 high / 28 medium / 5 low): - electron 41.0.2 -> 41.10.7 (GHSA-9f4c-93c8-jc8g, GHSA-v3j7-r9gq-3gjw, GHSA-h7rp-cf8h-j98x + all medium/low electron CVEs in the 41.x line) - app-builder-lib / electron-builder / electron-builder-squirrel-windows 26.8.2 -> 26.16.1 (Dependabot proposed 26.15.0; bumped one minor further to match the version element-hq/element-web's desktop monorepo package has already moved to, since app-builder-lib and electron-builder release in lockstep). Fixes GHSA-7g7r-gx96-252g and, transitively, the app-builder-lib dependency tree (builder-util-runtime, sigstore family, js-yaml, xmldom, fast-uri, form-data, ip-address, smol-toml, browserslist, baseline-browser-mapping). extract-zip is no longer pulled in at all by 26.16.1, which resolves its two "no patched version" alerts by removal. - tar 7.5.8 -> 7.5.21 (matches the Dependabot PR's manifest bump; lockfile resolves 7.5.22) - pacote 21.0.0 -> 21.5.1, @sentry/electron 7.0.0 -> 7.19.0, uuid 13.0.0 -> 13.0.2, @babel/core 7.18.10 -> 7.29.7: same-major bumps needed to reach patched versions of transitively pinned sigstore/@opentelemetry/babel advisories found by `pnpm audit` (pacote pulls sigstore; @sentry/electron pulls @opentelemetry/core; uuid and @babel/core are fixed directly). All of the above are in-range lockfile refreshes or same-major direct- dependency bumps; no pnpm.overrides were needed. `pnpm ls <pkg> --all` confirms a single, patched, resolved version for every previously flagged package. Remaining `pnpm audit` finding: counterpart <=0.18.6 (moderate, prototype pollution) has no patched release upstream (0.18.6 is latest) -- deferred, tracked in the maintenance report. Also sets "skipLibCheck": true in hak/tsconfig.json, matching the sibling tsconfig.json and scripts/tsconfig.json which already set it. Without this, `pnpm lint:types:hak` fails on app-builder-lib 26.14.0+'s own published type declarations: SnapOptions.d.ts imports "../targets/snap/snapcraft", a module missing from every 26.14.0-26.16.1 tarball (verified by downloading and inspecting the published packages directly) -- a genuine upstream packaging defect in electron-builder, not something in this repo's code.
…dated deps Non-security follow-up to the previous commit. Bumps every devDependency/ dependency whose declared semver range already permitted a newer release (no manifest range widening beyond what the existing caret already allowed, except @electron/asar and png-to-ico which are exact-pinned like the electron-builder family and get an explicit same-major bump): - png-to-ico 3.0.1 -> 3.0.2 (patch) - @electron/asar 4.1.0 -> 4.3.0 (minor; also drops asar's own plist/xmldom dependency entirely as of 4.2.0+, one less path to that advisory family) - @typescript-eslint/eslint-plugin + parser 8.57.0 -> 8.70.0 (in range ^8.0.0) - prettier 3.8.1 -> 3.9.8 (in range ^3.0.0) - tsx 4.21.0 -> 4.23.13 (in range ^4.19.2) - @babel/preset-typescript 7.28.5 -> 7.29.7 (in range ^7.18.6) - eslint-plugin-n 17.24.0 -> latest 17.x (in range ^17.12.0) - eslint-plugin-unicorn 56.0.1 -> latest 56.x (in range ^56.0.0) - knip 5.86.0 -> latest 5.x (in range ^5.0.0) - lint-staged 16.4.0 -> latest 16.x (in range ^16.0.0) Deferred majors (not applied -- see maintenance report for full reasoning): electron 41.x -> 44.x, eslint 8.x -> 10.x (repo pins peerDependencyRules to eslint 8 on purpose), typescript 5.9 -> 7.0, @types/node 18.x -> 26.x (must not exceed the engines-declared Node 18 floor), knip/lint-staged/eslint- plugin-n/eslint-plugin-unicorn majors, pacote 21.x -> 22.x, uuid 13.x -> 14.x, @babel/core+preset-env 7.x -> 8.x. @playwright/test is left at its exact pin (1.58.2); bumping it would require running the Playwright e2e suite (out of scope per task instructions -- native/electron-builder verification is skipped in this pass) to confirm compatibility. Verified after this commit: pnpm install (clean), lint:types, lint:js, lint:knip, build:ts, lint:workflows all pass; pnpm audit still shows only the one pre-existing, unfixable counterpart advisory.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ce763fcd47
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "electron": "41.0.2", | ||
| "electron-builder": "26.8.2", | ||
| "electron-builder-squirrel-windows": "26.8.2", | ||
| "electron": "41.10.7", |
There was a problem hiding this comment.
Raise the advertised Node.js minimum for Electron 41.10
On Node.js 18 through 22.11, which package.json still advertises as supported, this Electron upgrade pulls @electron/[email protected] and @electron-internal/[email protected], both of which declare Node.js >=22.12.0 and are used while downloading/installing Electron. The checked-in .node-version uses Node 24, so CI will not expose the mismatch, but contributors following the published engines.node floor can no longer reliably install or build the project; either retain an Electron release compatible with that floor or update the floor to >=22.12.0.
Useful? React with 👍 / 👎.


Summary
Dependency security maintenance on
develop.electron41.0.2 → 41.10.7,app-builder-lib/electron-builder26.16.1,tar, plus transitive updates.hak/tsconfig.json: enablesskipLibCheckto work around a type error inapp-builder-lib's published typings.No major-version upgrades, and no workflow, packaging or signing changes.
Verification
pnpm install --frozen-lockfile(pnpm 10.32.1) is clean.lint:types,lint:js,lint:workflows,lint:knipandbuild:tsgive the same results asdevelop.pnpm audit: 102 → 1. The remaining one iscounterpart(GHSA-2488-w585-72ch), which has no fixed release.Not fixed here
actions/cache-poisoningfindings in the release build workflows.counterpartadvisory (no fix available upstream).🤖 Generated with Claude Code