ci: bump electron from 39.8.10 to 41.10.6 - #47
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [electron](https://github.com/electron/electron) from 39.8.10 to 41.10.6. - [Release notes](https://github.com/electron/electron/releases) - [Commits](electron/electron@v39.8.10...v41.10.6) --- updated-dependencies: - dependency-name: electron dependency-version: 41.10.6 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Clippy reviewed this pull request
This PR bumps Electron from 39.8.10 to 41.10.6 in package.json and yarn.lock, but omits two files that must be kept in sync with the Electron version pin. Both omissions are confirmed and will cause concrete failures: one blocks every production/beta release in CI, the other causes native-module ABI mismatches at build time.
3 findings — 2 blocking · 1 nit · 0 pre-existing
2 findings could not be anchored to the diff, so they are here instead:
script/validate-electron-version.ts:21— ValidElectronVersions still hardcoded to 39.8.10 after bump to 41.10.6 The ValidElectronVersions map on lines 21–22 still contains '39.8.10' for both 'production' and 'beta'. The script reads the actual version from package.json (now '41.10.6') and compares it against these constants. When RELEASE_CHANNEL is set (i.e. any production or beta deployment), the mismatch triggers process.exit(1) at the validate-electron-version CI step, blocking every release. Without RELEASE_CHANNEL it only warns and exits 0, so dev builds pass silently while all release pipelines fail.app/.npmrc:3— app/.npmrc target still set to 39.8.10, not updated to 41.10.6 The .npmrc file sets 'target = 39.8.10', which tells electron-rebuild and node-gyp to download Electron 39 native-module headers when building or rebuilding native addons. With the app now running Electron 41, any native module compiled against Electron 39 headers will have an ABI mismatch. Symptoms range from MODULE_NOT_FOUND errors at startup to segfaults, depending on the module. This affects any developer running 'yarn' or 'electron-rebuild' from a clean state, and any CI job that rebuilds native modules. The validate-electron-version.ts script also explicitly reads this file (line 76) and would catch the divergence for production channel builds — but that same check is broken by finding #1 above.
Requesting changes — there are findings to address. Address each one and mark its thread Resolved (reply first if you think a finding is wrong — a resolved thread is a decision, not a dismissal). Push, or comment /review, and I will review the new commits.
clippy-review: verdict=changes event=REQUEST_CHANGES normal=2 nit=1 pre_existing=0 inline=1 body=2 unresolved=0 head=0453166
| resolved "https://registry.yarnpkg.com/underscore/-/underscore-1.6.0.tgz#8b38b10cacdef63337b8b24e4ff86d45aea529a8" | ||
| integrity sha1-izixDKze9jM3uLJOT/htRa6lKag= | ||
|
|
||
| "undici-types@>=7.24.0 <7.24.7": |
There was a problem hiding this comment.
nit: undici-types resolves to 7.24.6 but undici runtime is 7.30.0, leaving 6 minor versions of types missing
@types/node@24.19.1 depends on undici-types '>=7.24.0 <7.24.7', which Yarn resolves to 7.24.6. The actual undici runtime installed is 7.30.0. Any API surface added or changed in undici between 7.24.6 and 7.30.0 is absent from the TypeScript type definitions. The project does not import undici directly today, so this is latent; but if fetch/undici internals are used indirectly through @types/node globals, the types will be stale by 6 patch versions.
There was a problem hiding this comment.
Clippy reviewed this pull request
This PR bumps Electron from 39.8.10 to 41.10.6 and updates yarn.lock accordingly. Two files that must track the Electron version were not updated: app/.npmrc (used for native module compilation) and script/validate-electron-version.ts (the CI release gate). Both will cause hard failures — one a runtime ABI crash, the other a blocked deploy pipeline. A third plausible issue is a runtime crash on macOS/Windows certificate dialogs because showCertificateTrustDialog was removed in Electron 40.
4 findings — 3 blocking · 0 nit · 1 pre-existing
4 findings could not be anchored to the diff, so they are here instead:
app/.npmrc:3— Native module target version not updated from 39.8.10 to 41.10.6app/.npmrcline 3 still readstarget = 39.8.10. This file is read by node-gyp (viaelectron-rebuildand electron-builder's native module rebuild step) to download the correct Electron ABI headers when compiling native addons (e.g.keytar-forked,fs-admin-forked,desktop-notifications). Withtarget = 39.8.10, node-gyp fetches Electron 39 headers and produces binaries with the Electron 39 ABI. When those binaries are loaded into the Electron 41 runtime, Node.js rejects them with aNODE_MODULE_VERSION mismatcherror and the process crashes on startup.script/validate-electron-version.ts:21-22— ValidElectronVersions still hardcodes '39.8.10' for production and beta channelsValidElectronVersionsmapsproductionandbetachannels to'39.8.10'(lines 21–22). The CI job runsyarn validate-electron-versionwithRELEASE_CHANNELset toproductionorbetabefore publishing. The script reads the actual version frompackage.json(41.10.6) and compares it to the expected39.8.10; on mismatch it callsprocess.exit(1). Every production and beta release attempt will be blocked by this guard until the values are updated to'41.10.6'.app/src/main-process/app-window.ts:387— showCertificateTrustDialog called via 'as any' cast; API was removed in Electron 40dialog.showCertificateTrustDialogis deliberately cast toanyat line 386 because it was never included in Electron's type definitions. The comment says "not included yet" — this method was a macOS/Windows native dialog API that was removed from Electron in the v40 cycle. With Electron 41, callingd.showCertificateTrustDialog(...)at runtime will throwTypeError: d.showCertificateTrustDialog is not a function. This crash fires whenever a TLS certificate error is encountered and the cert-trust dialog is triggered, silently swallowing the error and leaving users with no certificate trust UI.script/validate-electron-version.ts:76— pre-existing: resolveVersionInNpmRcFile uses an unanchored regex with unescaped dots The regex/\d+.\d+.\d+/has two problems: (1) the dots match any character, not literal dots, and (2) there is no anchor on thetarget =key. If any line in.npmrcbefore thetargetline contains a digit-letter-digit-letter-digit pattern (e.g. a URL fragment), the function silently returns the wrong version string and the deploy gate passes with an incorrect value. This is a pre-existing issue not introduced by this diff, but the bumped version makes the validation logic more important to get right.
Requesting changes — there are findings to address. Address each one and mark its thread Resolved (reply first if you think a finding is wrong — a resolved thread is a decision, not a dismissal). Push, or comment /review, and I will review the new commits.
clippy-review: verdict=changes event=REQUEST_CHANGES normal=3 nit=0 pre_existing=1 inline=0 body=4 unresolved=0 head=0453166
|
Warning Automated review failed — exit 1 Push a new commit or comment |
|
Warning Automated review failed — exit 1 Attempt 1 of 4 failed. Clippy retries automatically at 19:24 UTC (in 15 min); a push or |
|
Warning Automated review failed — exit 1 Attempt 4 of 4 failed, and Clippy has stopped retrying. Push a new commit or comment |
Bumps electron from 39.8.10 to 41.10.6.
Release notes
Sourced from electron's releases.
... (truncated)
Commits
832e70afix: don't let pending shell operations block app exit on Windows (#52899)b8d49a4chore: cherry-pick 39 changes from angle, chromium and skia (#52707)29fc130fix: inherit sandbox flags in windows opened by a sandboxed top-level frame (...c595b05fix: return opaque responses from file and http protocol handlers for cross-o...6462a2efix: inherit nodeIntegrationInWorker from the embedder for <webview> and wind...d9c6215chore: cherry-pick 4 changes from chromium and v8 (#52775)a46a5afbuild: run the Windows builds on the VM runners (41-x-y) (#52770)5bff19cbuild: add release-assets.json expected-asset manifest (41-x-y) (#52734)15e2928fix: resolve target bundle path once at start of install (#50764)2ba8050chore: cherry-pick 33 changes from angle, chromium, skia and v8 (#52702)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.