Skip to content

ci: bump electron from 39.8.10 to 41.10.6 - #47

Open
dependabot[bot] wants to merge 1 commit into
linuxfrom
dependabot/npm_and_yarn/electron-41.10.6
Open

dependabot[bot] wants to merge 1 commit into
linuxfrom
dependabot/npm_and_yarn/electron-41.10.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor

Bumps electron from 39.8.10 to 41.10.6.

Release notes

Sourced from electron's releases.

electron v41.10.6

Release Notes for v41.10.6

Fixes

  • Fixed registerFileProtocol and registerHttpProtocol returning readable responses to cross-origin no-cors fetches; they now return opaque responses like protocol.handle. #52854 (Also in 42, 43, 44)
  • Fixed an issue on Windows where the app process could fail to exit after app.quit() while a shell.openExternal() or shell.openPath() call was still waiting on a system "Open with" dialog. #52899 (Also in 43, 44)
  • Fixed windows opened by a sandboxed top-level frame not inheriting the opener's sandbox restrictions. #52849 (Also in 42, 43, 44)
  • <webview> and window.open now inherit nodeIntegrationInWorker from the embedder, consistent with the other Node and sandbox preferences. #52829 (Also in 42, 43, 44)

Other Changes

  • Backported fixes from upstream ANGLE, Chromium and Skia. #52707
  • Backported fixes from upstream Chromium and V8. #52775

electron v41.10.5

Release Notes for v41.10.5

Fixes

  • Fixed an issue where the Squirrel.Mac installer could resolve the target bundle path to different locations at different stages of an install. #50764 (Also in 39, 42)

Other Changes

  • Backported fixes from upstream ANGLE, Chromium, Skia and V8. #52702
  • No user-facing change; semver/none. #52734

electron v41.10.4

Release Notes for v41.10.4

Fixes

  • Fixed a UAF with protocol.registerStreamProtocol when an error is emitted during a read. #52513 (Also in 42, 43, 44)
  • Fixed a crash that could occur when closing DevTools while the host WebContents was being destroyed. #52512 (Also in 42, 43, 44)
  • Windows opened from links inside a sandboxed iframe now inherit the iframe's sandbox restrictions unless allow-popups-to-escape-sandbox is set. #52486 (Also in 42, 43)

electron v41.10.3

Release Notes for v41.10.3

Fixes

  • Fixed app.disableHardwareAcceleration() not fully disabling GPU hardware usage on Windows starting from Electron 38. #52368 (Also in 42, 43, 44)
  • Fixed unnecessary autofill popup creation for fields without datalist suggestions, which could cause input latency on macOS. #52320 (Also in 42, 43, 44)

Other Changes

  • Backported fixes from upstream Chromium and V8. #52396

electron v41.10.2

Release Notes for v41.10.2

Fixes

... (truncated)

Commits
  • 832e70a fix: don't let pending shell operations block app exit on Windows (#52899)
  • b8d49a4 chore: cherry-pick 39 changes from angle, chromium and skia (#52707)
  • 29fc130 fix: inherit sandbox flags in windows opened by a sandboxed top-level frame (...
  • c595b05 fix: return opaque responses from file and http protocol handlers for cross-o...
  • 6462a2e fix: inherit nodeIntegrationInWorker from the embedder for <webview> and wind...
  • d9c6215 chore: cherry-pick 4 changes from chromium and v8 (#52775)
  • a46a5af build: run the Windows builds on the VM runners (41-x-y) (#52770)
  • 5bff19c build: add release-assets.json expected-asset manifest (41-x-y) (#52734)
  • 15e2928 fix: resolve target bundle path once at start of install (#50764)
  • 2ba8050 chore: cherry-pick 33 changes from angle, chromium, skia and v8 (#52702)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [electron](https://github.com/electron/electron) from 39.8.10 to 41.10.6.
- [Release notes](https://github.com/electron/electron/releases)
- [Commits](electron/electron@v39.8.10...v41.10.6)

---
updated-dependencies:
- dependency-name: electron
  dependency-version: 41.10.6
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 3, 2026
@dependabot
dependabot Bot requested a review from Cam8863 as a code owner October 3, 2026 13:01

@clippy-qa clippy-qa Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clippy reviewed this pull request

This PR bumps Electron from 39.8.10 to 41.10.6 in package.json and yarn.lock, but omits two files that must be kept in sync with the Electron version pin. Both omissions are confirmed and will cause concrete failures: one blocks every production/beta release in CI, the other causes native-module ABI mismatches at build time.

3 findings — 2 blocking · 1 nit · 0 pre-existing

2 findings could not be anchored to the diff, so they are here instead:

  • script/validate-electron-version.ts:21 — ValidElectronVersions still hardcoded to 39.8.10 after bump to 41.10.6 The ValidElectronVersions map on lines 21–22 still contains '39.8.10' for both 'production' and 'beta'. The script reads the actual version from package.json (now '41.10.6') and compares it against these constants. When RELEASE_CHANNEL is set (i.e. any production or beta deployment), the mismatch triggers process.exit(1) at the validate-electron-version CI step, blocking every release. Without RELEASE_CHANNEL it only warns and exits 0, so dev builds pass silently while all release pipelines fail.
  • app/.npmrc:3 — app/.npmrc target still set to 39.8.10, not updated to 41.10.6 The .npmrc file sets 'target = 39.8.10', which tells electron-rebuild and node-gyp to download Electron 39 native-module headers when building or rebuilding native addons. With the app now running Electron 41, any native module compiled against Electron 39 headers will have an ABI mismatch. Symptoms range from MODULE_NOT_FOUND errors at startup to segfaults, depending on the module. This affects any developer running 'yarn' or 'electron-rebuild' from a clean state, and any CI job that rebuilds native modules. The validate-electron-version.ts script also explicitly reads this file (line 76) and would catch the divergence for production channel builds — but that same check is broken by finding #1 above.

Requesting changes — there are findings to address. Address each one and mark its thread Resolved (reply first if you think a finding is wrong — a resolved thread is a decision, not a dismissal). Push, or comment /review, and I will review the new commits.

clippy-review: verdict=changes event=REQUEST_CHANGES normal=2 nit=1 pre_existing=0 inline=1 body=2 unresolved=0 head=0453166

Comment thread yarn.lock
resolved "https://registry.yarnpkg.com/underscore/-/underscore-1.6.0.tgz#8b38b10cacdef63337b8b24e4ff86d45aea529a8"
integrity sha1-izixDKze9jM3uLJOT/htRa6lKag=

"undici-types@>=7.24.0 <7.24.7":

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: undici-types resolves to 7.24.6 but undici runtime is 7.30.0, leaving 6 minor versions of types missing

@types/node@24.19.1 depends on undici-types '>=7.24.0 <7.24.7', which Yarn resolves to 7.24.6. The actual undici runtime installed is 7.30.0. Any API surface added or changed in undici between 7.24.6 and 7.30.0 is absent from the TypeScript type definitions. The project does not import undici directly today, so this is latent; but if fetch/undici internals are used indirectly through @types/node globals, the types will be stale by 6 patch versions.

@clippy-qa clippy-qa Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clippy reviewed this pull request

This PR bumps Electron from 39.8.10 to 41.10.6 and updates yarn.lock accordingly. Two files that must track the Electron version were not updated: app/.npmrc (used for native module compilation) and script/validate-electron-version.ts (the CI release gate). Both will cause hard failures — one a runtime ABI crash, the other a blocked deploy pipeline. A third plausible issue is a runtime crash on macOS/Windows certificate dialogs because showCertificateTrustDialog was removed in Electron 40.

4 findings — 3 blocking · 0 nit · 1 pre-existing

4 findings could not be anchored to the diff, so they are here instead:

  • app/.npmrc:3 — Native module target version not updated from 39.8.10 to 41.10.6 app/.npmrc line 3 still reads target = 39.8.10. This file is read by node-gyp (via electron-rebuild and electron-builder's native module rebuild step) to download the correct Electron ABI headers when compiling native addons (e.g. keytar-forked, fs-admin-forked, desktop-notifications). With target = 39.8.10, node-gyp fetches Electron 39 headers and produces binaries with the Electron 39 ABI. When those binaries are loaded into the Electron 41 runtime, Node.js rejects them with a NODE_MODULE_VERSION mismatch error and the process crashes on startup.
  • script/validate-electron-version.ts:21-22 — ValidElectronVersions still hardcodes '39.8.10' for production and beta channels ValidElectronVersions maps production and beta channels to '39.8.10' (lines 21–22). The CI job runs yarn validate-electron-version with RELEASE_CHANNEL set to production or beta before publishing. The script reads the actual version from package.json (41.10.6) and compares it to the expected 39.8.10; on mismatch it calls process.exit(1). Every production and beta release attempt will be blocked by this guard until the values are updated to '41.10.6'.
  • app/src/main-process/app-window.ts:387 — showCertificateTrustDialog called via 'as any' cast; API was removed in Electron 40 dialog.showCertificateTrustDialog is deliberately cast to any at line 386 because it was never included in Electron's type definitions. The comment says "not included yet" — this method was a macOS/Windows native dialog API that was removed from Electron in the v40 cycle. With Electron 41, calling d.showCertificateTrustDialog(...) at runtime will throw TypeError: d.showCertificateTrustDialog is not a function. This crash fires whenever a TLS certificate error is encountered and the cert-trust dialog is triggered, silently swallowing the error and leaving users with no certificate trust UI.
  • script/validate-electron-version.ts:76 — pre-existing: resolveVersionInNpmRcFile uses an unanchored regex with unescaped dots The regex /\d+.\d+.\d+/ has two problems: (1) the dots match any character, not literal dots, and (2) there is no anchor on the target = key. If any line in .npmrc before the target line contains a digit-letter-digit-letter-digit pattern (e.g. a URL fragment), the function silently returns the wrong version string and the deploy gate passes with an incorrect value. This is a pre-existing issue not introduced by this diff, but the bumped version makes the validation logic more important to get right.

Requesting changes — there are findings to address. Address each one and mark its thread Resolved (reply first if you think a finding is wrong — a resolved thread is a decision, not a dismissal). Push, or comment /review, and I will review the new commits.

clippy-review: verdict=changes event=REQUEST_CHANGES normal=3 nit=0 pre_existing=1 inline=0 body=4 unresolved=0 head=0453166

@clippy-qa

clippy-qa Bot commented Oct 3, 2026

Copy link
Copy Markdown

Warning

Automated review failed — exit 1

Push a new commit or comment /review to trigger another attempt.

@clippy-qa

clippy-qa Bot commented Oct 3, 2026

Copy link
Copy Markdown

Warning

Automated review failed — exit 1

Attempt 1 of 4 failed. Clippy retries automatically at 19:24 UTC (in 15 min); a push or /review before then retries at once.

@clippy-qa

clippy-qa Bot commented Oct 4, 2026

Copy link
Copy Markdown

Warning

Automated review failed — exit 1

Attempt 4 of 4 failed, and Clippy has stopped retrying. Push a new commit or comment /review to try again.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants