Skip to content

chore: update deps and actions - #613

Merged
achou11 merged 48 commits into
mainfrom
deps/2026-06-19
Jun 26, 2026
Merged

chore: update deps and actions#613
achou11 merged 48 commits into
mainfrom
deps/2026-06-19

Conversation

@achou11

@achou11 achou11 commented Jun 26, 2026

Copy link
Copy Markdown
Member
  • Upgrades Electron to 42
  • Upgrades development Node version to 24.17.0
  • Using Node >=24.16.0 causes a transitive dep for @electron/packager to break, requiring an override (see e0565af). Apparently, Node 24.18.0 fixes the issue but the relevant electron upstream projects are replacing the dep anyways.
  • Update in transitive dep causes a runtime error from @comapeo/map-server to occur. For now, we specify an override for the offending transitive dep (see fix: address breaking change from typebox patch release comapeo-map-server#58)
  • Sentry configuration is updated to move away from deprecated APIs in Sentry core (see c3a08da)

@awana-lockfile-bot

Copy link
Copy Markdown

package-lock.json changes

Summary

Status Count
ADDED 13
UPDATED 151
DOWNGRADED 2
REMOVED 47
Click to toggle table visibility
Name Status Previous Current
@apm-js-collab/code-transformer-bundler-plugins ADDED - 0.5.0
@apm-js-collab/code-transformer ADDED - 0.15.0
@apm-js-collab/tracing-hooks ADDED - 0.10.0
@comapeo/core-react UPDATED 11.0.6 11.0.7
@comapeo/core UPDATED 7.2.0 7.3.0
@comapeo/map-server UPDATED 1.1.3 1.1.4
@digidem/types UPDATED 2.3.0 2.4.1
@electron-internal/extract-zip UPDATED 1.0.3 1.0.4
@eslint-react/ast UPDATED 5.9.0 5.9.5
@eslint-react/core UPDATED 5.9.0 5.9.5
@eslint-react/eslint-plugin UPDATED 5.9.0 5.9.5
@eslint-react/eslint UPDATED 5.9.0 5.9.5
@eslint-react/jsx UPDATED 5.9.0 5.9.5
@eslint-react/shared UPDATED 5.9.0 5.9.5
@eslint-react/var UPDATED 5.9.0 5.9.5
@fastify/otel REMOVED 0.18.0 -
@formatjs/cli-lib UPDATED 8.7.10 8.7.11
@formatjs/icu-messageformat-parser UPDATED 3.5.11 3.5.12
@formatjs/intl UPDATED 4.1.13 4.1.14
@formatjs/ts-transformer UPDATED 4.4.13 4.4.14
@formatjs/unplugin UPDATED 1.1.19 1.1.20
@mapbox/jsonlint-lines-primitives UPDATED 2.0.2 2.0.3
@mapbox/mapbox-gl-style-spec UPDATED 14.24.1 14.25.0
@mapbox/unitbezier UPDATED 0.0.1 1.0.0
@maplibre/mlt UPDATED 1.1.11 1.1.12
@mui/core-downloads-tracker UPDATED 9.1.1 9.1.2
@mui/material UPDATED 9.1.1 9.1.2
@mui/system UPDATED 9.1.1 9.1.2
@napi-rs/wasm-runtime UPDATED 1.1.5 1.1.6
@opentelemetry/instrumentation-amqplib REMOVED 0.61.0 -
@opentelemetry/instrumentation-connect REMOVED 0.57.0 -
@opentelemetry/instrumentation-dataloader REMOVED 0.31.0 -
@opentelemetry/instrumentation-fs REMOVED 0.33.0 -
@opentelemetry/instrumentation-generic-pool REMOVED 0.57.0 -
@opentelemetry/instrumentation-graphql REMOVED 0.62.0 -
@opentelemetry/instrumentation-hapi REMOVED 0.60.0 -
@opentelemetry/instrumentation-http REMOVED 0.214.0 -
@opentelemetry/instrumentation-ioredis REMOVED 0.62.0 -
@opentelemetry/instrumentation-kafkajs REMOVED 0.23.0 -
@opentelemetry/instrumentation-knex REMOVED 0.58.0 -
@opentelemetry/instrumentation-koa REMOVED 0.62.0 -
@opentelemetry/instrumentation-lru-memoizer REMOVED 0.58.0 -
@opentelemetry/instrumentation-mongodb REMOVED 0.67.0 -
@opentelemetry/instrumentation-mongoose REMOVED 0.60.0 -
@opentelemetry/instrumentation-mysql REMOVED 0.60.0 -
@opentelemetry/instrumentation-mysql2 REMOVED 0.60.0 -
@opentelemetry/instrumentation-pg REMOVED 0.66.0 -
@opentelemetry/instrumentation-redis REMOVED 0.62.0 -
@opentelemetry/instrumentation-tedious REMOVED 0.33.0 -
@opentelemetry/redis-common REMOVED 0.38.3 -
@opentelemetry/sql-common REMOVED 0.41.2 -
@oxc-parser/binding-android-arm-eabi UPDATED 0.133.0 0.134.0
@oxc-parser/binding-android-arm64 UPDATED 0.133.0 0.134.0
@oxc-parser/binding-darwin-arm64 UPDATED 0.133.0 0.134.0
@oxc-parser/binding-darwin-x64 UPDATED 0.133.0 0.134.0
@oxc-parser/binding-freebsd-x64 UPDATED 0.133.0 0.134.0
@oxc-parser/binding-linux-arm-gnueabihf UPDATED 0.133.0 0.134.0
@oxc-parser/binding-linux-arm-musleabihf UPDATED 0.133.0 0.134.0
@oxc-parser/binding-linux-arm64-gnu UPDATED 0.133.0 0.134.0
@oxc-parser/binding-linux-arm64-musl UPDATED 0.133.0 0.134.0
@oxc-parser/binding-linux-ppc64-gnu UPDATED 0.133.0 0.134.0
@oxc-parser/binding-linux-riscv64-gnu UPDATED 0.133.0 0.134.0
@oxc-parser/binding-linux-riscv64-musl UPDATED 0.133.0 0.134.0
@oxc-parser/binding-linux-s390x-gnu UPDATED 0.133.0 0.134.0
@oxc-parser/binding-linux-x64-gnu UPDATED 0.133.0 0.134.0
@oxc-parser/binding-linux-x64-musl UPDATED 0.133.0 0.134.0
@oxc-parser/binding-openharmony-arm64 UPDATED 0.133.0 0.134.0
@oxc-parser/binding-wasm32-wasi UPDATED 0.133.0 0.134.0
@oxc-parser/binding-win32-arm64-msvc UPDATED 0.133.0 0.134.0
@oxc-parser/binding-win32-ia32-msvc UPDATED 0.133.0 0.134.0
@oxc-parser/binding-win32-x64-msvc UPDATED 0.133.0 0.134.0
@oxc-project/types UPDATED 0.133.0 0.134.0
@oxc-resolver/binding-android-arm-eabi UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-android-arm64 UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-darwin-arm64 UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-darwin-x64 UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-freebsd-x64 UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-linux-arm-gnueabihf UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-linux-arm-musleabihf UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-linux-arm64-gnu UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-linux-arm64-musl UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-linux-ppc64-gnu UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-linux-riscv64-gnu UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-linux-riscv64-musl UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-linux-s390x-gnu UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-linux-x64-gnu UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-linux-x64-musl UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-openharmony-arm64 UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-wasm32-wasi UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-win32-arm64-msvc UPDATED 11.20.0 11.21.3
@oxc-resolver/binding-win32-x64-msvc UPDATED 11.20.0 11.21.3
@playwright/test UPDATED 1.61.0 1.61.1
@prisma/instrumentation REMOVED 7.6.0 -
@rolldown/binding-android-arm64 UPDATED 1.1.1 1.1.3
@rolldown/binding-darwin-arm64 UPDATED 1.1.1 1.1.3
@rolldown/binding-darwin-x64 UPDATED 1.1.1 1.1.3
@rolldown/binding-freebsd-x64 UPDATED 1.1.1 1.1.3
@rolldown/binding-linux-arm-gnueabihf UPDATED 1.1.1 1.1.3
@rolldown/binding-linux-arm64-gnu UPDATED 1.1.1 1.1.3
@rolldown/binding-linux-arm64-musl UPDATED 1.1.1 1.1.3
@rolldown/binding-linux-ppc64-gnu UPDATED 1.1.1 1.1.3
@rolldown/binding-linux-s390x-gnu UPDATED 1.1.1 1.1.3
@rolldown/binding-linux-x64-gnu UPDATED 1.1.1 1.1.3
@rolldown/binding-linux-x64-musl UPDATED 1.1.1 1.1.3
@rolldown/binding-openharmony-arm64 UPDATED 1.1.1 1.1.3
@rolldown/binding-wasm32-wasi UPDATED 1.1.1 1.1.3
@rolldown/binding-win32-arm64-msvc UPDATED 1.1.1 1.1.3
@rolldown/binding-win32-x64-msvc UPDATED 1.1.1 1.1.3
@sentry-internal/browser-utils REMOVED 10.50.0 -
@sentry-internal/feedback REMOVED 10.50.0 -
@sentry-internal/replay-canvas REMOVED 10.50.0 -
@sentry-internal/replay REMOVED 10.50.0 -
@sentry/browser-utils ADDED - 10.60.0
@sentry/browser UPDATED 10.50.0 10.60.0
@sentry/conventions ADDED - 0.12.0
@sentry/core UPDATED 10.50.0 10.60.0
@sentry/electron UPDATED 7.13.0 7.14.0
@sentry/feedback ADDED - 10.60.0
@sentry/node-core UPDATED 10.50.0 10.60.0
@sentry/node UPDATED 10.50.0 10.60.0
@sentry/opentelemetry UPDATED 10.50.0 10.60.0
@sentry/react UPDATED 10.50.0 10.60.0
@sentry/replay-canvas ADDED - 10.60.0
@sentry/replay ADDED - 10.60.0
@sentry/server-utils ADDED - 10.60.0
@tanstack/devtools-event-client UPDATED 0.4.3 0.4.4
@tanstack/eslint-plugin-query UPDATED 5.101.0 5.101.1
@tanstack/query-core UPDATED 5.101.0 5.101.1
@tanstack/react-query UPDATED 5.101.0 5.101.1
@tanstack/react-router UPDATED 1.170.15 1.170.16
@tanstack/react-virtual UPDATED 3.14.2 3.14.4
@tanstack/virtual-core UPDATED 3.17.0 3.17.2
@tybys/wasm-util UPDATED 0.10.2 0.10.3
@types/connect REMOVED 3.4.38 -
@types/mysql REMOVED 2.15.27 -
@types/pg-pool REMOVED 2.0.7 -
@types/pg REMOVED 8.15.6 -
@types/tedious REMOVED 4.0.14 -
@types/yauzl REMOVED 2.10.3 -
@typescript-eslint/eslint-plugin UPDATED 8.61.0 8.62.0
@typescript-eslint/parser UPDATED 8.61.0 8.62.0
@typescript-eslint/project-service UPDATED 8.61.0 8.62.0
@typescript-eslint/scope-manager UPDATED 8.61.0 8.62.0
@typescript-eslint/tsconfig-utils UPDATED 8.61.0 8.62.0
@typescript-eslint/type-utils UPDATED 8.61.0 8.62.0
@typescript-eslint/types UPDATED 8.61.0 8.62.0
@typescript-eslint/typescript-estree UPDATED 8.61.0 8.62.0
@typescript-eslint/utils UPDATED 8.61.0 8.62.0
@typescript-eslint/visitor-keys UPDATED 8.61.0 8.62.0
@vitejs/plugin-react UPDATED 6.0.2 6.0.3
astring ADDED - 1.9.0
bare-semver UPDATED 1.0.3 1.1.0
baseline-browser-mapping UPDATED 2.10.37 2.10.40
better-sqlite3 UPDATED 12.10.1 12.11.1
browserslist UPDATED 4.28.2 4.28.4
comapeocat UPDATED 1.1.0 1.2.0
electron-to-chromium UPDATED 1.5.372 1.5.379
electron UPDATED 41.7.2 42.5.0
enhanced-resolve UPDATED 5.24.0 5.24.1
eslint-plugin-formatjs UPDATED 6.4.15 6.4.16
eslint-plugin-react-dom UPDATED 5.9.0 5.9.5
eslint-plugin-react-jsx UPDATED 5.9.0 5.9.5
eslint-plugin-react-naming-convention UPDATED 5.9.0 5.9.5
eslint-plugin-react-rsc UPDATED 5.9.0 5.9.5
eslint-plugin-react-web-api UPDATED 5.9.0 5.9.5
eslint-plugin-react-x UPDATED 5.9.0 5.9.5
extract-zip DOWNGRADED 2.0.1 1.0.4
fd-slicer REMOVED 1.1.0 -
forwarded-parse REMOVED 2.1.2 -
glob-to-regexp REMOVED 0.4.1 -
globals UPDATED 17.6.0 17.7.0
import-in-the-middle UPDATED 3.0.2 3.2.0
intl-messageformat UPDATED 11.2.8 11.2.9
isbot UPDATED 5.1.43 5.1.44
knip UPDATED 6.16.1 6.21.0
meriyah ADDED - 6.1.4
minimizer-webpack-plugin ADDED - 5.6.1
nan UPDATED 2.27.0 2.28.0
nanoid UPDATED 3.3.12 3.3.15
node-releases UPDATED 2.0.47 2.0.50
oxc-parser UPDATED 0.133.0 0.134.0
oxc-resolver UPDATED 11.20.0 11.21.3
pend REMOVED 1.2.0 -
pg-int8 REMOVED 1.0.1 -
pg-protocol REMOVED 1.14.0 -
pg-types REMOVED 2.2.0 -
playwright-core UPDATED 1.61.0 1.61.1
playwright UPDATED 1.61.0 1.61.1
postgres-array REMOVED 2.0.0 -
postgres-bytea REMOVED 1.0.1 -
postgres-date REMOVED 1.0.7 -
postgres-interval REMOVED 1.2.0 -
prettier UPDATED 3.8.4 3.8.5
react-intl UPDATED 10.1.13 10.1.14
rolldown UPDATED 1.1.1 1.1.3
semifies ADDED - 1.0.0
semver UPDATED 7.8.4 7.8.5
shell-quote UPDATED 1.8.4 1.9.0
smol-toml UPDATED 1.6.1 1.7.0
systeminformation UPDATED 5.31.7 5.31.11
tar UPDATED 7.5.16 7.5.17
terser-webpack-plugin REMOVED 5.6.1 -
typebox DOWNGRADED 1.2.11 1.1.27
typescript-eslint UPDATED 8.61.0 8.62.0
unbash UPDATED 3.0.0 4.0.1
undici UPDATED 6.26.0 6.27.0
unplugin UPDATED 3.0.0 3.2.0
vite UPDATED 8.0.16 8.1.0
webpack UPDATED 5.107.2 5.108.1
xstate UPDATED 5.32.1 5.32.2
yallist UPDATED 3.1.1 4.0.0
yargs UPDATED 17.7.2 17.7.3
yauzl REMOVED 2.10.0 -

@socket-security

socket-security Bot commented Jun 26, 2026

Copy link
Copy Markdown

@socket-security

socket-security Bot commented Jun 26, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @emnapi/runtime is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/@rolldown/plugin-babel@0.2.3npm/@tanstack/router-plugin@1.168.18npm/vite@8.1.0npm/@formatjs/unplugin@1.1.20npm/knip@6.21.0npm/@emnapi/runtime@1.11.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@emnapi/runtime@1.11.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @mui/material is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/@mui/material@9.1.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@mui/material@9.1.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @sentry/node-core is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/@sentry/electron@7.14.0npm/@sentry/node-core@10.60.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@sentry/node-core@10.60.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @typescript-eslint/eslint-plugin is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/typescript-eslint@8.62.0npm/@typescript-eslint/eslint-plugin@8.62.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@typescript-eslint/eslint-plugin@8.62.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm better-sqlite3 is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/@comapeo/map-server@1.1.4npm/@comapeo/core@7.3.0npm/better-sqlite3@12.11.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/better-sqlite3@12.11.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm typebox is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/@comapeo/map-server@1.1.4npm/typebox@1.1.27

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/typebox@1.1.27. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm yargs is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/@electron-forge/cli@7.11.2npm/@electron-forge/shared-types@7.11.2npm/yargs@17.7.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/yargs@17.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

achou11 added 2 commits June 26, 2026 12:47
Initial usage of the `electron` CLI will print a log line about downloading
the binary (https://github.com/electron/electron/blob/v42.5.0/npm/index.js#L8).

Update the check in CI to only take the last line of output
Running into issue described in electron/forge#3845.

Alternative solution is to keep install scripts disabled and running the rebuilds
as a step in the relevant workflow.
@achou11
achou11 merged commit f1d7f69 into main Jun 26, 2026
29 of 30 checks passed
@achou11
achou11 deleted the deps/2026-06-19 branch June 26, 2026 17:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant