Skip to content

chore(repo): Update dependency electron to v41 [SECURITY] - #10064

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-electron-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-electron-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
electron ^39.2.6 → ^41.0.0 age adoption passing confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Electron: can enable Node.js integration in Web Workers despite embedder restrictions

CVE-2026-102676 / GHSA-9qh4-3jw8-366w

More information

Details

Impact

A <webview> could enable Node.js integration in its Web Workers even when its embedder had Node.js integration disabled, giving guest content more privilege than the embedder allowed.

Apps are only affected if they enable the <webview> tag and the embedder is unsandboxed. Apps that do not use <webview>, or that keep the embedder sandboxed, are not affected.

Workarounds

Remove nodeIntegrationInWorker from the guest preferences in a will-attach-webview handler, or do not enable the <webview> tag when loading untrusted content.

Fixed Versions
  • 44.0.0-beta.5
  • 43.4.1
  • 42.9.2
  • 41.10.6
For more information

If you have any questions or comments about this advisory, email us at security@electronjs.org

Severity

  • CVSS Score: 8.3 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled

CVE-2026-102675 / GHSA-j84w-jfhq-vhvj

More information

Details

Impact

Responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a custom scheme registered with supportFetchAPI: true but without corsEnabled: true could be read cross-origin by web content. This completes the fix for CVE-2026-70604.

Apps are only affected if they register such a scheme, serve it through one of those handlers, and load untrusted content. Apps that set corsEnabled: true, or that do not load untrusted content, are not affected.

Workarounds

Set corsEnabled: true on the scheme, or do not load untrusted content in windows that can reach it.

Fixed Versions
  • 44.0.0-beta.5
  • 43.4.1
  • 42.9.2
  • 41.10.6
For more information

If you have any questions or comments about this advisory, email us at security@electronjs.org

Severity

  • CVSS Score: 7.4 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions

CVE-2026-102674 / GHSA-gr2m-v5gq-v685

More information

Details

Impact

Windows opened from a sandboxed top-level document did not inherit that document's HTML sandbox restrictions, so content that was meant to run sandboxed could open a window with the app's full origin. GHSA-hq2x-r82h-9wj4 covers the same issue for sandboxed iframes.

Apps are only affected if they render untrusted content in a sandboxed top-level document that allows popups. Apps that deny popups from untrusted content with setWindowOpenHandler are not affected.

Workarounds

Return { action: 'deny' } from setWindowOpenHandler for windows opened by untrusted content.

Fixed Versions
  • 44.0.0-beta.5
  • 43.4.1
  • 42.9.2
  • 41.10.6
For more information

If you have any questions or comments about this advisory, email us at security@electronjs.org

Severity

  • CVSS Score: 8.2 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab

CVE-2026-102673 / GHSA-hq2x-r82h-9wj4

More information

Details

Impact

Popups opened from a sandboxed iframe through a link (for example target="_blank" or a middle-click) did not inherit the iframe's HTML sandbox restrictions. Content that was meant to run sandboxed could open a popup with the embedding app's full origin, gaining access to that origin's cookies, storage, and same-origin scripting.

Apps are only affected if they embed untrusted content in iframes sandboxed with allow-scripts allow-popups. Apps that do not embed untrusted content in sandboxed iframes are not affected.

Workarounds

Use setWindowOpenHandler on the parent WebContents to deny or constrain popups opened from sandboxed frames, or do not apply allow-popups to sandboxed iframes that render untrusted content.

Fixed Versions
  • 43.0.0
  • 42.5.2
  • 41.10.4
For more information

If you have any questions or comments about this advisory, email us at security@electronjs.org

Severity

  • CVSS Score: 8.2 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

electron/electron (electron)

v41.10.6: electron v41.10.6

Compare Source

Release Notes for v41.10.6

Fixes

  • Fixed registerFileProtocol and registerHttpProtocol returning readable responses to cross-origin no-cors fetches; they now return opaque responses like protocol.handle. #​52854 (Also in 42, 43, 44)
  • Fixed an issue on Windows where the app process could fail to exit after app.quit() while a shell.openExternal() or shell.openPath() call was still waiting on a system "Open with" dialog. #​52899 (Also in 43, 44)
  • Fixed windows opened by a sandboxed top-level frame not inheriting the opener's sandbox restrictions. #​52849 (Also in 42, 43, 44)
  • <webview> and window.open now inherit nodeIntegrationInWorker from the embedder, consistent with the other Node and sandbox preferences. #​52829 (Also in 42, 43, 44)

Other Changes

  • Backported fixes from upstream ANGLE, Chromium and Skia. #​52707
  • Backported fixes from upstream Chromium and V8. #​52775

v41.10.5: electron v41.10.5

Compare Source

Release Notes for v41.10.5

Fixes

  • Fixed an issue where the Squirrel.Mac installer could resolve the target bundle path to different locations at different stages of an install. #​50764 (Also in 39, 42)

Other Changes

  • Backported fixes from upstream ANGLE, Chromium, Skia and V8. #​52702
  • No user-facing change; semver/none. #​52734

v41.10.4: electron v41.10.4

Compare Source

Release Notes for v41.10.4

Fixes

  • Fixed a UAF with protocol.registerStreamProtocol when an error is emitted during a read. #​52513 (Also in 42, 43, 44)
  • Fixed a crash that could occur when closing DevTools while the host WebContents was being destroyed. #​52512 (Also in 42, 43, 44)
  • Windows opened from links inside a sandboxed iframe now inherit the iframe's sandbox restrictions unless allow-popups-to-escape-sandbox is set. #​52486 (Also in 42, 43)

v41.10.3: electron v41.10.3

Compare Source

Release Notes for v41.10.3

Fixes

  • Fixed app.disableHardwareAcceleration() not fully disabling GPU hardware usage on Windows starting from Electron 38. #​52368 (Also in 42, 43, 44)
  • Fixed unnecessary autofill popup creation for fields without datalist suggestions, which could cause input latency on macOS. #​52320 (Also in 42, 43, 44)

Other Changes

  • Backported fixes from upstream Chromium and V8. #​52396

v41.10.2: electron v41.10.2

Compare Source

Release Notes for v41.10.2

Fixes

  • Fixed a renderer crash when calling WebAssembly.compileStreaming() or WebAssembly.instantiateStreaming() with nodeIntegration enabled. #​52240 (Also in 42, 43)

Other Changes

  • Backported fixes from upstream Chromium. #​52304

v41.10.1: electron v41.10.1

Compare Source

Release Notes for v41.10.1

Fixes

  • Fixed crash triggered by replacing an open application menu. #​52278 (Also in 42, 43, 44)

v41.10.0: electron v41.10.0

Compare Source

Release Notes for v41.10.0

Other Changes

  • Backported fixes from upstream Chromium, ANGLE, Dawn, Skia, and V8. #​52231
  • Updated Node.js to v24.18.0. #​52104

v41.9.2: electron v41.9.2

Compare Source

Release Notes for v41.9.2

Fixes

  • Fixed an issue where clicking the maximize button could progressively shrink the window in some Wayland environments. #​52074 (Also in 42, 43)

v41.9.1: electron v41.9.1

Compare Source

Release Notes for v41.9.1

Fixes

  • Fixed ProtocolResponse.url requests being made through the default session instead of the session the protocol handler was registered on when ProtocolResponse.session was not set. #​52134 (Also in 40, 42, 43)
  • Made "reload" menu items work with BaseWindow. #​52118 (Also in 42, 43)

Other Changes

  • Backported fixes from upstream Chromium. #​52120
  • Backported fixes from upstream Chromium. #​52170

v41.9.0: electron v41.9.0

Compare Source

Release Notes for v41.9.0

Fixes

  • Fixed Windows edge case in NativeWindowViews::MoveBehindTaskBarIfNeeded(). #​52023 (Also in 42, 43)

Other Changes

  • Backported fixes from upstream Chromium. #​51976
  • Updated Node.js to v24.17.0. #​52065

v41.8.0: electron v41.8.0

Compare Source

Release Notes for v41.8.0

Fixes

  • Fixed a browser process crash when calling webContents.reload() or navigating synchronously from the render-process-gone event; the event is now emitted after the renderer's teardown notification has completed. #​51917 (Also in 42, 43)
  • Fixed a bug on Linux where a 1px line appeared at the top of frameless windows if the window and web contents had different background colors. #​52004 (Also in 42, 43)

Other Changes

  • Backported fixes from upstream Chromium and V8. #​51936
  • Backported fixes from upstream Chromium, Skia and Dawn. #​51943
  • Updated Node.js to v24.16.0. #​51746

Documentation

v41.7.2: electron v41.7.2

Compare Source

Release Notes for v41.7.2

Fixes

  • Fixed an issue on Linux and Windows where frameless windows would shrink when calling win.center(). Additionally, fixed an issue where frameless windows would appear slightly off-center on Windows. #​51919 (Also in 42, 43)
  • Fixed an issue where the "Toggle Developer Tools" menu item failed to function correctly with BaseWindow. #​51902 (Also in 42, 43)

Other Changes

v41.7.1: electron v41.7.1

Compare Source

Release Notes for v41.7.1

Fixes

  • Fixed a potential crash when using webContents.print(). #​51728 (Also in 42)
  • Fixed an issue where custom options in webContents.print() did not prefill the print dialog on macOS. #​51682 (Also in 40, 42)

v41.7.0: electron v41.7.0

Compare Source

Release Notes for v41.7.0

Features

  • Allowed the --experimental-inspector-network-resource Node.js flag to be passed through Electron. #​51377 (Also in 42)

Fixes

Other Changes

  • Backported a batch of upstream fixes for memory-safety and validation issues across media, GPU, networking, accessibility, compositing and the ANGLE GL backend. #​51667
  • Backported fixes for several use-after-free and object-lifetime issues in input, UI, Aura, HID and file-system teardown paths, a runtime-effect validation gap in Skia, and an integer overflow in the GLSL translator. #​51647

v41.6.1: electron v41.6.1

Compare Source

Release Notes for v41.6.1

Other Changes

  • Improved performance of native event emission, IPC dispatch, and option-dictionary parsing. #​51613 (Also in 42)
  • Security: backported 20 High-severity fixes from Chrome 148 stable release. #​51612

v41.6.0: electron v41.6.0

Compare Source

Release Notes for v41.6.0

Fixes

  • Fixed a crash in the macOS Touch ID WebAuthn prompt caused by a missing string resource, and added touchID.promptReason to app.configureWebAuthn() to customize the prompt text. #​51604 (Also in 42, 43)

v41.5.2: electron v41.5.2

Compare Source

Release Notes for v41.5.2

Fixes

  • Improved external resize band positioning and scaling for frameless windows on Windows. #​51560 (Also in 43)

v41.5.1: electron v41.5.1

Compare Source

Release Notes for v41.5.1

Fixes

  • Fixed app.getLoginItemSettings() returning undefined for executableWillLaunchAtLogin on macOS; the property is now always a boolean. #​51508 (Also in 40, 42)
  • Fixed a potential race condition crash when closing DevTools. #​51474 (Also in 42)
  • Fixed cross-origin isolation failing for non-file origins. #​51403 (Also in 42)
  • Improved the way Electron determines the default XDG App ID and WM_CLASS on Linux for better platform compatibility if desktopName is not provided in package.json. #​51480 (Also in 42)

v41.5.0: electron v41.5.0

Compare Source

Release Notes for v41.5.0

Features

  • Added app.configureWebAuthn() to enable the Touch ID platform authenticator for WebAuthn on macOS, and a select-webauthn-account session event for choosing between multiple discoverable credentials. #​51412 (Also in 42)

Fixes

  • Fixed a regression on Windows where frameless windows changed their size after calling setResizable. #​51427 (Also in 42)
  • Fixed an issue on Windows where a transient UnhookWindowsHookEx failure in setIgnoreMouseEvents(true, { forward: true }) teardown could cause duplicate low-level mouse hooks to be installed on the next activation. #​51419 (Also in 42)
  • Fixed remote debugging via --remote-debugging-port not working when inspecting from Chrome's chrome://inspect page. The DevTools page would appear empty due to the frontend URL pointing to a CDN that returned 404 for Electron's Chromium builds. #​51413

v41.4.0: electron v41.4.0

Compare Source

Release Notes for v41.4.0

Features

  • Added support for heap profiling via contentTracing.enableHeapProfiling(). #​51178 (Also in 42)

Fixes

  • Ensured cross-origin fetch() and XHR are blocked for custom protocols registered with supportFetchAPI: true unless corsEnabled: true is also set; cross-origin mode: 'no-cors' requests now receive an opaque response. #​51270 (Also in 39, 40, 42)
  • Fixed a crash when providing invalid HTTP header names or values in the webRequest.onBeforeSendHeaders() callback. #​51365 (Also in 40, 42)
  • Fixed a bug that cause offscreen rendering doesn't have valid screen info and unable to get valid result of related media queries.
    • Added webPreference.offscreen.deviceScaleFactor to allow user specify a value, instead of using user's primary display's value. #​50375 (Also in 40)
  • Fixed a bug where errors would occur when using the Chrome DevTools Fetch API. #​51371 (Also in 42)
  • Fixed a crash that could occur when an autofill suggestion popup was shown while a window was closing. #​51321 (Also in 42)
  • Fixed a regression where frameless fullscreen windows had white borders on Windows. #​51332 (Also in 42)
  • Fixed a renderer crash when a page uses the <geolocation> HTML element. #​51373 (Also in 42)
  • Fixed an issue where calling contentTracing APIs before app.whenReady() would crash the application. #​51352 (Also in 42)
  • Fixed an issue where some toast notification properties didn't work as expected in WinRT. #​51397 (Also in 42)
  • Fixed buggy behavior where Backspace would accept macOS text replacements inside contenteditable elements. #​51343 (Also in 40, 42)
  • This PR fixes a regression in silent printing where custom DPI values from webContents.print were not honored, causing incorrect output scaling in real-world print flows. #​51355 (Also in 42)

Other Changes

v41.3.0: electron v41.3.0

Compare Source

Release Notes for v41.3.0

Fixes

  • Fixed webContents.printToPDF rejecting on all subsequent calls after a prior call was rejected with an invalid pageRanges value. #​51221 (Also in 40, 42)
  • Fixed an issue where app-region: drag inside a hidden WebContentsView would still drag the parent window on Windows. #​51246 (Also in 40, 42)
  • Fixed an issue where an Electron macOS update would not be applied if another app was previously blocking the macOS system update loop. #​51210 (Also in 40, 42)
  • Fixed build failure when building with enable_pdf disabled. #​51248 (Also in 42)
  • Fixed frameless transparent windows on Windows losing their transparency after setResizable(false) followed by setResizable(true). #​51217 (Also in 42)

Other Changes

v41.2.2: electron v41.2.2

Compare Source

Release Notes for v41.2.2

Fixes

  • Fixed absent 'Electron Isolated Context' in the execution context dropdown in Dev Tools. #​51078 (Also in 42)
  • Fixed an issue where nodeIntegrationInWorker didn't always work in AudioWorklet. #​51006 (Also in 42)
  • Fixed an issue where saving edited PDF files would fail with a cross-origin SecurityError. #​51073 (Also in 42)
  • Fixed bug that could occasionally cause browserWindow's always-on-top-changed even to fire with incorrect values. #​51135 (Also in 40, 42)
  • Fixed test scaffolding bug when running tests locally on Linux. #​51150 (Also in 40, 42)

Other Changes

v41.2.1: electron v41.2.1

Compare Source

Release Notes for v41.2.1

Fixes

  • Added missing metadata fields to contentTracing traces. #​51021 (Also in 42)
  • Changed the kResizeThreshold to trigger the resize on corners. #​51002 (Also in 42)
  • Fixed fs.stat on files inside asar archives returning undefined for blksize and blocks instead of numeric values. #​50876 (Also in 40, 42)
  • Fixed a crash when rendering PDFs when Site Isolation is disabled. #​50845 (Also in 42)
  • Fixed a memory leak where Menu items were not cleaned up after Menu.setApplicationMenu was called repeatedly. #​50830 (Also in 40, 42)
  • Fixed an issue where DevTools would re-attach to the window when opened after previously being detached. #​50816 (Also in 39, 40, 42)
  • Fixed an issue where setSimpleFullScreen on macOS would exit when web content called requestFullscreen(). #​50985 (Also in 40, 42)
  • Fixed an issue where closing devtools immediately after focus caused a crash. #​51037 (Also in 42)
  • Fixed an issue where webContents.print() would ignore pageSize / mediaSize when silent was true. #​50856 (Also in 42)
  • Fixed aspect ratio min/max size clamping to correctly account for extraSize on macOS. #​50835 (Also in 40, 42)
  • Fixed crash when app.setPath('sessionData') was called with a non-existent directory. #​50958 (Also in 42)
  • Fixed resize hit targets for frameless windows on Windows. Resize targets now start at the side and bottom edges of the window and extend outward when frame: false, matching the behavior for windows with frames. #​50863 (Also in 42)
  • Fixed the crash keys being lost and the crash reporter hanging on macOS when many dynamic crash keys were registered. #​50837 (Also in 40, 42)
  • Moved Electron-specific help menu links to the default app only; unpackaged apps will no longer see these items in their default menu. #​50859 (Also in 40, 42)

Other Changes

  • Backported fix for none. #​50880
  • Backported upstream fixes for two edge cases in the WebNN TFLite graph builder. #​50983
  • Backported upstream v8 fixes for a maglev use-count accounting issue and an inspector InspectedContext lifetime issue. #​50991
  • Updated Chromium to 146.0.7680.188. #​50787
  • Updated Node.js to v24.14.1. #​50478

v41.2.0: electron v41.2.0

Compare Source

Release Notes for v41.2.0

Features

  • Added allowExtensions privilege to protocol.registerSchemesAsPrivileged() to enable Chrome extensions on custom protocols. #​50529 (Also in 40, 42)

Fixes

  • BrowserWindow now enforces min/max size constraints on window creation, even if they conflict with the requested width and height. #​50753 (Also in 42)
  • Fixed a regression on Linux where transparent frameless windows would have visible borders. Also fixed a longstanding issue where transparent windows on Linux could show smeared and glitched content as windows moved around. #​50605
  • Fixed an intermittent Invoke in DisallowJavascriptExecutionScope crash on application quit when a WebContents (or other JS-emitting native object) is garbage-collected during shutdown. #​50694 (Also in 40, 42)
  • Fixed an issue on macOS where show/hide events and WebContents visibility state could be reported incorrectly when multiple WebContentsViews were attached to a window. #​50715 (Also in 40, 42)
  • Fixed an issue where concurrent getFileHandle requests on the same path could stall indefinitely. #​50670 (Also in 40, 42)
  • Fixed an issue where margins did not look as expected when printing in silent mode. #​50652 (Also in 42)
  • Fixed an issue where the webContents.print() callback may not fire correctly in some cases. #​50604 (Also in 42)
  • Fixed the appearance of maximized windows on GNOME in Wayland, especially when non-default GTK themes like Breeze are set. #​50645 (Also in 42)
  • Removed "representedObject is not a WeakPtrToElectronMenuModelAsNSObject" logging when interacting with macOS menus. #​50613 (Also in 42)

Other Changes

  • Updated Chromium to 146.0.7680.179. #​50616

v41.1.1: electron v41.1.1

Compare Source

Release Notes for v41.1.1

Fixes

  • Fixed a crash when calling contentTracing.getTraceBufferUsage() while a trace session is active. #​50594 (Also in 39, 40, 42)
  • Fixed printing on Linux failing with "Invalid printer settings". #​50486 (Also in 42)

Other Changes

  • Enabled profile-guided optimization for V8 builtins in release builds, improving JavaScript builtin performance (Array, String, RegExp, etc.). #​50574 (Also in 40, 42)

v41.1.0: electron v41.1.0

Compare Source

Release Notes for v41.1.0

Features

  • Added nativeTheme.shouldDifferentiateWithoutColor on macOS. #​50408 (Also in 42)
  • Notes: Added support for the urgency option in Notifications on Windows. #​50382 (Also in 42)

Fixes

  • Fixed a bug where Windows notification icons could fail to save because their temporary filenames contained invalid characters. #​50483 (Also in 40)
  • Fixed a crash in clipboard.readImage() when the clipboard contains malformed image data. #​50492 (Also in 39, 40, 42)
  • Fixed a crash when calling an offscreen shared texture's release() after the texture object was garbage collected. #​50501 (Also in 39, 40, 42)
  • Fixed an accessibility issue where the AXMenuOpened event was not fired on menu creation. #​50506 (Also in 40, 42)
  • Fixed an issue where an app shortcut may lose its icon after auto-updating on Windows. #​50519 (Also in 40)

Other Changes

  • Updated Chromium to 146.0.7680.166. #​50458

v41.0.4: electron v41.0.4

Compare Source

Release Notes for v41.0.4

Fixes

  • Fixed crash when handling JavaScript dialogs from windows opened with invalid or empty URLs. #​50399 (Also in 39, 40, 42)
  • Fixed improper focus tracking in BaseWindow on MacOS. #​50340 (Also in 39, 40, 42)
  • Fixed logic bug that rendered certain window types un-resizable on MAS builds. #​50354 (Also in 40, 42)
  • Fixed utilityProcess exit event reporting incorrect exit codes on Windows when the exit code has the high bit. #​50386 (Also in 40, 42)
  • Fixed window freeze when failing to enter/exit fullscreen on macOS. #​50343 (Also in 39, 40, 42)
  • Improved the appearance of shadows and borders on frameless windows on Wayland. #​50213

Other Changes

  • Added support for using a proxy during yarn install. #​50350 (Also in 39, 40, 42)
  • Updated Chromium to 146.0.7680.153. #​50346

v41.0.3: electron v41.0.3

[Compare Source](https://redirect.githu

❗ Important

✂ PR body was truncated to here.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Oct 3, 2026
@vercel

vercel Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
clerk-js-sandbox Ready Ready Preview Oct 3, 2026 11:18pm UTC
swingset Ready Ready Preview Oct 3, 2026 11:18pm UTC

Request Review

@changeset-bot

changeset-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 3cea6aa

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository YAML (base), Organization UI (inherited)
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 75608b8f-96bf-401a-a024-524ba0d97016

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@10064

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@10064

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@10064

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@10064

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@10064

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@10064

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@10064

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@10064

@clerk/expo-biometrics

npm i https://pkg.pr.new/@clerk/expo-biometrics@10064

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@10064

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@10064

@clerk/express

npm i https://pkg.pr.new/@clerk/express@10064

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@10064

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@10064

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@10064

@clerk/mosaic

npm i https://pkg.pr.new/@clerk/mosaic@10064

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@10064

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@10064

@clerk/react

npm i https://pkg.pr.new/@clerk/react@10064

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@10064

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@10064

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@10064

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@10064

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@10064

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@10064

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@10064

commit: 3cea6aa

This branch was successfully deployed

2 active deployments
Preview – swingset — 3cea6aa4 Deployed Oct 3, 2026 by vercel[bot]
Preview – clerk-js-sandbox — 3cea6aa4 Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants