chore(repo): Update dependency electron to v41 [SECURITY] - #10064
renovate[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
@clerk/astro
@clerk/backend
@clerk/chrome-extension
@clerk/clerk-js
@clerk/electron
@clerk/electron-passkeys
@clerk/eslint-plugin
@clerk/expo
@clerk/expo-biometrics
@clerk/expo-google-signin
@clerk/expo-passkeys
@clerk/express
@clerk/fastify
@clerk/hono
@clerk/localizations
@clerk/mosaic
@clerk/nextjs
@clerk/nuxt
@clerk/react
@clerk/react-router
@clerk/shared
@clerk/tanstack-react-start
@clerk/testing
@clerk/ui
@clerk/upgrade
@clerk/vue
commit: |
This PR contains the following updates:
^39.2.6→^41.0.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Electron: can enable Node.js integration in Web Workers despite embedder restrictions
CVE-2026-102676 / GHSA-9qh4-3jw8-366w
More information
Details
Impact
A
<webview>could enable Node.js integration in its Web Workers even when its embedder had Node.js integration disabled, giving guest content more privilege than the embedder allowed.Apps are only affected if they enable the
<webview>tag and the embedder is unsandboxed. Apps that do not use<webview>, or that keep the embedder sandboxed, are not affected.Workarounds
Remove
nodeIntegrationInWorkerfrom the guest preferences in awill-attach-webviewhandler, or do not enable the<webview>tag when loading untrusted content.Fixed Versions
44.0.0-beta.543.4.142.9.241.10.6For more information
If you have any questions or comments about this advisory, email us at security@electronjs.org
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled
CVE-2026-102675 / GHSA-j84w-jfhq-vhvj
More information
Details
Impact
Responses served through
protocol.registerFileProtocolorprotocol.registerHttpProtocolfor a custom scheme registered withsupportFetchAPI: truebut withoutcorsEnabled: truecould be read cross-origin by web content. This completes the fix for CVE-2026-70604.Apps are only affected if they register such a scheme, serve it through one of those handlers, and load untrusted content. Apps that set
corsEnabled: true, or that do not load untrusted content, are not affected.Workarounds
Set
corsEnabled: trueon the scheme, or do not load untrusted content in windows that can reach it.Fixed Versions
44.0.0-beta.543.4.142.9.241.10.6For more information
If you have any questions or comments about this advisory, email us at security@electronjs.org
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions
CVE-2026-102674 / GHSA-gr2m-v5gq-v685
More information
Details
Impact
Windows opened from a sandboxed top-level document did not inherit that document's HTML
sandboxrestrictions, so content that was meant to run sandboxed could open a window with the app's full origin. GHSA-hq2x-r82h-9wj4 covers the same issue for sandboxed iframes.Apps are only affected if they render untrusted content in a sandboxed top-level document that allows popups. Apps that deny popups from untrusted content with
setWindowOpenHandlerare not affected.Workarounds
Return
{ action: 'deny' }fromsetWindowOpenHandlerfor windows opened by untrusted content.Fixed Versions
44.0.0-beta.543.4.142.9.241.10.6For more information
If you have any questions or comments about this advisory, email us at security@electronjs.org
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
CVE-2026-102673 / GHSA-hq2x-r82h-9wj4
More information
Details
Impact
Popups opened from a sandboxed iframe through a link (for example
target="_blank"or a middle-click) did not inherit the iframe's HTMLsandboxrestrictions. Content that was meant to run sandboxed could open a popup with the embedding app's full origin, gaining access to that origin's cookies, storage, and same-origin scripting.Apps are only affected if they embed untrusted content in iframes sandboxed with
allow-scripts allow-popups. Apps that do not embed untrusted content in sandboxed iframes are not affected.Workarounds
Use
setWindowOpenHandleron the parentWebContentsto deny or constrain popups opened from sandboxed frames, or do not applyallow-popupsto sandboxed iframes that render untrusted content.Fixed Versions
43.0.042.5.241.10.4For more information
If you have any questions or comments about this advisory, email us at security@electronjs.org
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
electron/electron (electron)
v41.10.6: electron v41.10.6Compare Source
Release Notes for v41.10.6
Fixes
registerFileProtocolandregisterHttpProtocolreturning readable responses to cross-originno-corsfetches; they now return opaque responses likeprotocol.handle. #52854 (Also in 42, 43, 44)app.quit()while ashell.openExternal()orshell.openPath()call was still waiting on a system "Open with" dialog. #52899 (Also in 43, 44)<webview>andwindow.opennow inheritnodeIntegrationInWorkerfrom the embedder, consistent with the other Node and sandbox preferences. #52829 (Also in 42, 43, 44)Other Changes
v41.10.5: electron v41.10.5Compare Source
Release Notes for v41.10.5
Fixes
Other Changes
v41.10.4: electron v41.10.4Compare Source
Release Notes for v41.10.4
Fixes
protocol.registerStreamProtocolwhen an error is emitted during a read. #52513 (Also in 42, 43, 44)allow-popups-to-escape-sandboxis set. #52486 (Also in 42, 43)v41.10.3: electron v41.10.3Compare Source
Release Notes for v41.10.3
Fixes
app.disableHardwareAcceleration()not fully disabling GPU hardware usage on Windows starting from Electron 38. #52368 (Also in 42, 43, 44)Other Changes
v41.10.2: electron v41.10.2Compare Source
Release Notes for v41.10.2
Fixes
WebAssembly.compileStreaming()orWebAssembly.instantiateStreaming()withnodeIntegrationenabled. #52240 (Also in 42, 43)Other Changes
v41.10.1: electron v41.10.1Compare Source
Release Notes for v41.10.1
Fixes
v41.10.0: electron v41.10.0Compare Source
Release Notes for v41.10.0
Other Changes
v41.9.2: electron v41.9.2Compare Source
Release Notes for v41.9.2
Fixes
v41.9.1: electron v41.9.1Compare Source
Release Notes for v41.9.1
Fixes
ProtocolResponse.urlrequests being made through the default session instead of the session the protocol handler was registered on whenProtocolResponse.sessionwas not set. #52134 (Also in 40, 42, 43)BaseWindow. #52118 (Also in 42, 43)Other Changes
v41.9.0: electron v41.9.0Compare Source
Release Notes for v41.9.0
Fixes
NativeWindowViews::MoveBehindTaskBarIfNeeded(). #52023 (Also in 42, 43)Other Changes
v41.8.0: electron v41.8.0Compare Source
Release Notes for v41.8.0
Fixes
webContents.reload()or navigating synchronously from therender-process-goneevent; the event is now emitted after the renderer's teardown notification has completed. #51917 (Also in 42, 43)Other Changes
Documentation
v41.7.2: electron v41.7.2Compare Source
Release Notes for v41.7.2
Fixes
win.center(). Additionally, fixed an issue where frameless windows would appear slightly off-center on Windows. #51919 (Also in 42, 43)Other Changes
Buffer/TextEncoderAPIs and a crash infs.writeFileSyncwith non-ASCII strings on Apple Silicon. #51851 (Also in 42, 43)v41.7.1: electron v41.7.1Compare Source
Release Notes for v41.7.1
Fixes
webContents.print(). #51728 (Also in 42)webContents.print()did not prefill the print dialog on macOS. #51682 (Also in 40, 42)v41.7.0: electron v41.7.0Compare Source
Release Notes for v41.7.0
Features
--experimental-inspector-network-resourceNode.js flag to be passed through Electron. #51377 (Also in 42)Fixes
Other Changes
v41.6.1: electron v41.6.1Compare Source
Release Notes for v41.6.1
Other Changes
v41.6.0: electron v41.6.0Compare Source
Release Notes for v41.6.0
Fixes
touchID.promptReasontoapp.configureWebAuthn()to customize the prompt text. #51604 (Also in 42, 43)v41.5.2: electron v41.5.2Compare Source
Release Notes for v41.5.2
Fixes
v41.5.1: electron v41.5.1Compare Source
Release Notes for v41.5.1
Fixes
app.getLoginItemSettings()returningundefinedforexecutableWillLaunchAtLoginon macOS; the property is now always a boolean. #51508 (Also in 40, 42)desktopNameis not provided inpackage.json. #51480 (Also in 42)v41.5.0: electron v41.5.0Compare Source
Release Notes for v41.5.0
Features
app.configureWebAuthn()to enable the Touch ID platform authenticator for WebAuthn on macOS, and aselect-webauthn-accountsession event for choosing between multiple discoverable credentials. #51412 (Also in 42)Fixes
setResizable. #51427 (Also in 42)UnhookWindowsHookExfailure insetIgnoreMouseEvents(true, { forward: true })teardown could cause duplicate low-level mouse hooks to be installed on the next activation. #51419 (Also in 42)--remote-debugging-portnot working when inspecting from Chrome'schrome://inspectpage. The DevTools page would appear empty due to the frontend URL pointing to a CDN that returned 404 for Electron's Chromium builds. #51413v41.4.0: electron v41.4.0Compare Source
Release Notes for v41.4.0
Features
contentTracing.enableHeapProfiling(). #51178 (Also in 42)Fixes
fetch()and XHR are blocked for custom protocols registered withsupportFetchAPI: trueunlesscorsEnabled: trueis also set; cross-originmode: 'no-cors'requests now receive an opaque response. #51270 (Also in 39, 40, 42)webRequest.onBeforeSendHeaders()callback. #51365 (Also in 40, 42)webPreference.offscreen.deviceScaleFactorto allow user specify a value, instead of using user's primary display's value. #50375 (Also in 40)<geolocation>HTML element. #51373 (Also in 42)contentTracingAPIs beforeapp.whenReady()would crash the application. #51352 (Also in 42)contenteditableelements. #51343 (Also in 40, 42)Other Changes
4955347. #512644927361,4926688,4934134,4933194,4941583,4962818. #51259v41.3.0: electron v41.3.0Compare Source
Release Notes for v41.3.0
Fixes
webContents.printToPDFrejecting on all subsequent calls after a prior call was rejected with an invalidpageRangesvalue. #51221 (Also in 40, 42)app-region: draginside a hiddenWebContentsViewwould still drag the parent window on Windows. #51246 (Also in 40, 42)enable_pdfdisabled. #51248 (Also in 42)setResizable(false)followed bysetResizable(true). #51217 (Also in 42)Other Changes
v41.2.2: electron v41.2.2Compare Source
Release Notes for v41.2.2
Fixes
nodeIntegrationInWorkerdidn't always work in AudioWorklet. #51006 (Also in 42)always-on-top-changedeven to fire with incorrect values. #51135 (Also in 40, 42)Other Changes
gn genfailing to resolveelectron_versionwhen building from agit worktreecheckout. #51165 (Also in 39, 40, 42)v41.2.1: electron v41.2.1Compare Source
Release Notes for v41.2.1
Fixes
metadatafields tocontentTracingtraces. #51021 (Also in 42)kResizeThresholdto trigger the resize on corners. #51002 (Also in 42)fs.staton files inside asar archives returningundefinedforblksizeandblocksinstead of numeric values. #50876 (Also in 40, 42)setSimpleFullScreenon macOS would exit when web content calledrequestFullscreen(). #50985 (Also in 40, 42)app.setPath('sessionData')was called with a non-existent directory. #50958 (Also in 42)frame: false, matching the behavior for windows with frames. #50863 (Also in 42)Other Changes
v41.2.0: electron v41.2.0Compare Source
Release Notes for v41.2.0
Features
allowExtensionsprivilege toprotocol.registerSchemesAsPrivileged()to enable Chrome extensions on custom protocols. #50529 (Also in 40, 42)Fixes
Invoke in DisallowJavascriptExecutionScopecrash on application quit when aWebContents(or other JS-emitting native object) is garbage-collected during shutdown. #50694 (Also in 40, 42)show/hideevents andWebContentsvisibility state could be reported incorrectly when multipleWebContentsViews were attached to a window. #50715 (Also in 40, 42)getFileHandlerequests on the same path could stall indefinitely. #50670 (Also in 40, 42)webContents.print()callback may not fire correctly in some cases. #50604 (Also in 42)Other Changes
v41.1.1: electron v41.1.1Compare Source
Release Notes for v41.1.1
Fixes
contentTracing.getTraceBufferUsage()while a trace session is active. #50594 (Also in 39, 40, 42)Other Changes
v41.1.0: electron v41.1.0Compare Source
Release Notes for v41.1.0
Features
urgencyoption in Notifications on Windows. #50382 (Also in 42)Fixes
clipboard.readImage()when the clipboard contains malformed image data. #50492 (Also in 39, 40, 42)release()after the texture object was garbage collected. #50501 (Also in 39, 40, 42)Other Changes
v41.0.4: electron v41.0.4Compare Source
Release Notes for v41.0.4
Fixes
Other Changes
v41.0.3: electron v41.0.3[Compare Source](https://redirect.githu