Skip to content

chore: upgrade Electron to 44.5.1 and refresh dependencies - #1552

Merged
manojVivek merged 2 commits into
mainfrom
codex/dependency-upgrades-2026-10-03
Oct 3, 2026
Merged

manojVivek merged 2 commits into
mainfrom
codex/dependency-upgrades-2026-10-03

Conversation

@manojVivek

Copy link
Copy Markdown
Collaborator

✨ Pull Request

📓 Referenced Issue

Dependency maintenance; no linked issue.

ℹ️ About the PR

The desktop app is pinned to Electron 44.4.1, and its development and packaged runtime dependency trees retain older vulnerable transitive packages. Upgrade Electron to 44.5.1 and refresh compatible dependencies, while preserving the existing application APIs and compiler/linter major versions.

  • Upgrade 24 desktop dependencies, including React/React DOM 19.3.0, MCP SDK 1.31.0, Redux Toolkit 2.13.0, Electron Builder 26.17.0, Electron Updater 6.8.10, and Playwright 1.63.0. Electron remains exactly pinned.
  • Upgrade six extension dependencies, including copy-webpack-plugin 14.0.0 and web-ext 10.7.0. Track its npm lockfile and use npm ci in CI and development instructions.
  • Refresh compatible security fixes in both desktop and packaged-app Yarn/npm lockfiles, without dependency overrides.
  • Require release publication on or before 2026-10-01 11:47:58 UTC, the 48-hour cutoff used for this review. Electron 44.5.1 was published to npm on September 30 at 06:59:15 UTC. Registry timestamp checks passed for all 246 changed desktop lock entries and all 532 distinct locked extension package versions.

TypeScript 7 and ESLint 10 remain deferred because current plugins do not support their peer requirements. Vitest 5 requires a separate migration.

Security audits improve desktop npm findings from 38 to 19 affected packages and production findings from 15 to 4. The remaining desktop findings represent two upstream advisories without published fixes: braces and http-cache-semantics. The packaged app retains only the braces advisory. Extension production dependencies audit clean; its three development findings represent one unresolved node-forge advisory in web-ext's tooling.

🖼️ Testing Scenarios / Screenshots

Validated locally on macOS arm64 using Node 24.21.0:

  • Desktop postinstall, production build, lint, and TypeScript checking passed.
  • 245 unit tests passed across 35 files.
  • 238 end-to-end tests passed on the final dependency tree. An initial design-overlay popover timeout did not recur in the final full run; no test changes were made.
  • Unsigned, unnotarized macOS arm64 directory packaging passed using Electron Builder 26.17.0 and Electron 44.5.1 (--dir --mac --arm64 --publish never).
  • Extension npm ci and npm run release passed (build, lint, and local packaging). Lint reports three existing warnings: two bundled React innerHTML warnings and the missing Gecko data-collection declaration.
  • Frozen desktop and packaged-app Yarn installs, release-age verification, direct dependency consistency checks, and git diff --check passed.

The separate dependency-free MCP bootstrap suite retains one environment-dependent baseline failure: the installed /Applications/ResponsivelyApp.app takes precedence over the test's temporary home-directory fixture (9/10 tests pass).

manojVivek and others added 2 commits October 3, 2026 17:58
Upgrade Electron to 44.5.1, refresh compatible desktop and extension dependencies, and lock extension installs. Verify new releases against the 48-hour cutoff and update vulnerable transitive dependencies within supported ranges.

Co-authored-by: Codex <noreply@openai.com>
@manojVivek
manojVivek enabled auto-merge (squash) October 3, 2026 12:31
@manojVivek
manojVivek merged commit 3137186 into main Oct 3, 2026
4 checks passed
@manojVivek
manojVivek deleted the codex/dependency-upgrades-2026-10-03 branch October 3, 2026 12:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant