Repository navigation
Conversation
…ages Electron 37 is out of support (only 42–44 still receive Chromium security fixes). Bump to 44.2.0; the app runs unchanged on it. Electron 44 defaults to native Wayland where available. lodash 4.17.23 → 4.18.1 (CVE-2021-23337, CVE-2026-4800) and a refresh of the lock entries flagged by `yarn audit` / Dependabot within their existing ranges: ajv 8.20.0, fast-uri 3.1.7, tmp 0.2.7, @tootallnate/once 2.0.1, postcss 8.5.28, @xmldom/xmldom 0.8.15, follow-redirects 1.16.0, lodash-es 4.18.1, picomatch 2.3.2, flatted 3.4.4. `yarn audit --groups dependencies` is now clean (0 of 70 runtime packages). Supersedes davidsmorais#173, davidsmorais#175, davidsmorais#176, davidsmorais#177, davidsmorais#180, davidsmorais#182, davidsmorais#183, davidsmorais#184, davidsmorais#185, davidsmorais#186, davidsmorais#187, davidsmorais#188.
Electron 44 runs on native Wayland by default. There the desktop matches a window (and libnotify notifications) to its .desktop file by the Wayland app id rather than by StartupWMClass, so Kuro showed GNOME's generic gear icon. Set app.setDesktopName() to the file electron-builder installs (`kuro-desktop.desktop` for deb/rpm/pacman/AppImage, `<snap>_<app>.desktop` in a snap, `<FLATPAK_ID>.desktop` in a flatpak).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Dependency refresh, independent of #190 (no overlap in files).
.desktopfile by app id rather thanStartupWMClass, so the window got GNOME's generic icon.app.setDesktopName()now names the file electron-builder installs (with snap / flatpak variants), restoring the icon and notification attribution.kebabCase, so neither was exploitable here, but the bump is free.yarn audit/ Dependabot, within their existing ranges: ajv 8.20.0, fast-uri 3.1.7, tmp 0.2.7, @tootallnate/once 2.0.1, postcss 8.5.28, @xmldom/xmldom 0.8.15, follow-redirects 1.16.0, lodash-es 4.18.1, picomatch 2.3.2, flatted 3.4.4.yarn audit --groups dependencies(what actually ships in the app) is now clean: 0 findings across 70 packages. The remainingyarn auditfindings are all in dev tooling (electron-builder 24, xo 0.53, stylelint 14) and not shipped.Deliberately not touched:
confandelectron-store. Their current majors are ESM-only and would require converting the whole app to ES modules; the ajv/fast-uri fixes are reachable inside the^8range they already declare.Supersedes the open Dependabot PRs #173, #175, #176, #177, #180 (39.8.5 is itself out of support by now), #182, #183, #184, #185, #186 (3.1.2 misses the later fast-uri advisories), #187, #188.
Note: installing
electron@44needs Node ≥ 20 (@electron/getis ESM); Node 18 fails in the postinstall.