Skip to content

Bump Electron to 44, lodash to 4.18, refresh vulnerable transitive packages - #191

Open
fildunsky wants to merge 2 commits into
davidsmorais:masterfrom
fildunsky:chore/deps-electron-44
Open

fildunsky wants to merge 2 commits into
davidsmorais:masterfrom
fildunsky:chore/deps-electron-44

Conversation

@fildunsky

@fildunsky fildunsky commented Sep 6, 2026 •

Copy link
Copy Markdown

Dependency refresh, independent of #190 (no overlap in files).

  • Electron 37.3.1 → 44.2.0. Electron 37 is out of support; only 42–44 still get Chromium security fixes. Kuro runs unchanged on 44 (main and renderer start without errors on Ubuntu GNOME / Wayland; a deb built from this branch is in daily use). Electron 44 picks native Wayland automatically where available, which also helps the font-size / scaling reports in [Feature 🚀]: Support to Wayland (and/or increase the font even more) #140.
  • Wayland follow-up: on native Wayland the desktop matches a window to its .desktop file by app id rather than StartupWMClass, so the window got GNOME's generic icon. app.setDesktopName() now names the file electron-builder installs (with snap / flatpak variants), restoring the icon and notification attribution.
  • lodash 4.17.23 → 4.18.1 (CVE-2021-23337, CVE-2026-4800). Kuro only uses kebabCase, so neither was exploitable here, but the bump is free.
  • Lock refresh of the transitive packages flagged by yarn audit / Dependabot, within their existing ranges: ajv 8.20.0, fast-uri 3.1.7, tmp 0.2.7, @tootallnate/once 2.0.1, postcss 8.5.28, @xmldom/xmldom 0.8.15, follow-redirects 1.16.0, lodash-es 4.18.1, picomatch 2.3.2, flatted 3.4.4.

yarn audit --groups dependencies (what actually ships in the app) is now clean: 0 findings across 70 packages. The remaining yarn audit findings are all in dev tooling (electron-builder 24, xo 0.53, stylelint 14) and not shipped.

Deliberately not touched: conf and electron-store. Their current majors are ESM-only and would require converting the whole app to ES modules; the ajv/fast-uri fixes are reachable inside the ^8 range they already declare.

Supersedes the open Dependabot PRs #173, #175, #176, #177, #180 (39.8.5 is itself out of support by now), #182, #183, #184, #185, #186 (3.1.2 misses the later fast-uri advisories), #187, #188.

Note: installing electron@44 needs Node ≥ 20 (@electron/get is ESM); Node 18 fails in the postinstall.

…ages

Electron 37 is out of support (only 42–44 still receive Chromium security
fixes). Bump to 44.2.0; the app runs unchanged on it. Electron 44 defaults
to native Wayland where available.

lodash 4.17.23 → 4.18.1 (CVE-2021-23337, CVE-2026-4800) and a refresh of the
lock entries flagged by `yarn audit` / Dependabot within their existing
ranges: ajv 8.20.0, fast-uri 3.1.7, tmp 0.2.7, @tootallnate/once 2.0.1,
postcss 8.5.28, @xmldom/xmldom 0.8.15, follow-redirects 1.16.0,
lodash-es 4.18.1, picomatch 2.3.2, flatted 3.4.4.

`yarn audit --groups dependencies` is now clean (0 of 70 runtime packages).
Supersedes davidsmorais#173, davidsmorais#175, davidsmorais#176, davidsmorais#177, davidsmorais#180, davidsmorais#182, davidsmorais#183, davidsmorais#184, davidsmorais#185, davidsmorais#186,
davidsmorais#187, davidsmorais#188.
Electron 44 runs on native Wayland by default. There the desktop matches a
window (and libnotify notifications) to its .desktop file by the Wayland app
id rather than by StartupWMClass, so Kuro showed GNOME's generic gear icon.
Set app.setDesktopName() to the file electron-builder installs
(`kuro-desktop.desktop` for deb/rpm/pacman/AppImage, `<snap>_<app>.desktop`
in a snap, `<FLATPAK_ID>.desktop` in a flatpak).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant