chore(deploy): Release (next) (alpha) - #10243
electron-builder-release-bot[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
LGTM, straightforward automated release/version-bump PR. Reviewed: .changeset/pre.json entry addition, CHANGELOG.md regeneration across all workspace packages, package.json version bumps (alpha.9 -> alpha.10), and the matching PACKAGE_VERSION constant update in packages/app-builder-lib/src/version.ts — all consistent with a Changesets bot release commit and free of logic changes.
Extended reasoning...
The diff is exactly what the changesets release-bot produces: version bumps in package.json files, regenerated CHANGELOG.md entries, one new changeset id in pre.json, and the corresponding hardcoded version string bump in version.ts. No functional or security-sensitive code paths are touched, no CODEOWNER-restricted logic changed, and the bug hunt reported zero findings, so this mechanical release PR is safe to approve without further human review.
3a856bc to
31c023f
Compare
31c023f to
fb2f12f
Compare
fb2f12f to
de6d6e6
Compare
de6d6e6 to
2042f44
Compare
c4bfab0 to
701055b
Compare
701055b to
46a3ef2
Compare
81caec6 to
b170e0f
Compare
b170e0f to
c6f7c97
Compare
c6f7c97 to
554146a
Compare
554146a to
71ebfb6
Compare
71ebfb6 to
f3fbaec
Compare
ff711ea
f3fbaec to
ff711ea
Compare
ff711ea to
c3f4743
Compare
1f592d4 to
31c4a85
Compare
68110bb to
175f2a6
Compare
175f2a6 to
258c61c
Compare
258c61c to
3394ff3
Compare
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to master, this PR will be updated.
masteris currently in pre mode so this branch has prereleases rather than normal releases. If you want to exit prereleases, runchangeset pre exitonmaster.Releases
app-builder-lib@27.0.0-alpha.10
Major Changes
app-update.yml(annsis,nsis-weborelectronUpdaterAwareappxtarget with a publish configuration, including one inferred from a GitHubrepository) now fails with anInvalidConfigurationErrorwhen its publisher name cannot be determined: any customwin.sign.signhook withoutwin.sign.publisherName(its publisher name is never derived from a certificate, not even one in the config —certificateFile,certificateSubjectName,certificateSha1,cscLink— or fromWIN_CSC_LINK/CSC_LINK, because the hook may sign with another one), or a certificate without a Common Name (including a certificate-store subject, which no longer yields an undefined publisher name). Setwin.sign.publisherNameto the subject of the signing certificate (copy it from a binary your hook already signed), or setwin.verifyUpdateCodeSignature: falseonly if your updates are not Authenticode-signed or you don't use electron-updater. Error and warning messages now namewin.sign.publisherNameinstead of the removedwin.publisherName.#10264c8ca1ac@mmaiettaisAdminRightsRequiredin the update info of every per-machinensisandnsis-webbuild (perMachine: true), including assisted installers (oneClick: false) that don't setpackElevateHelperand builds withdifferentialPackage: false, and writes it into the file entry of the installer fornsis-webbuilds too, so their updates are started withelevate.exedirectly and, like other per-machine updates, are not installed automatically at launch withautoInstallEvent: "onNextLaunch"(callinstallPendingUpdateIfAvailable())#10264c8ca1ac@mmaiettadisableWebInstallerisfalse(the v27 grace period is removed; cached and install-on-next-launch web updates re-verify the web package), and the nsis-web installer verifies--package-fileand versioned package downloads against its built-in SHA-512 hashes (opt out withnsisWeb.allowUnverifiedAppPackage). SetdisableWebInstallerbefore the app is ready: a pending install-on-next-launch web update is checked against it at appready#10264c8ca1ac@mmaietta--package-file(electron-updater does this for updates) or found next to the installer is first copied into the installer's own temporary directory; the checksum is computed on that copy and that copy is what is extracted. WithnsisWeb.allowUnverifiedAppPackagea package passed via--package-fileis still copied, but not verified. The local package file is now left in place (the installer's copy is moved into the app's update cache instead), and the installation is aborted (exit code2) if a--package-filepackage cannot be copied; a package found next to the installer that cannot be copied is ignored and the package is downloaded, as when its checksum doesn't match. electron-updater removes the package it passed via--package-filefrom itspendingcache directory at startup once the app runs the version of that update (update-info.jsonrecords the version of a web installer update for this); the package of an update that is not installed yet, or whose install failed, is kept.#10264c8ca1ac@mmaiettaMinor Changes
nativeModules.buildDependenciesFromSourceno longer skips the native-dependency rebuild when the target platform differs from the host (which shipped the host's binary). Native modules cannot be cross-compiled from source, so such targets are now rebuilt with prebuilt binaries for the target and a warning is logged. feat: after packing (per slice for macOS universal, before the merge), every.nodeaddon inapp.asar,app.asar.unpackedorappis identified from its ELF / Mach-O / PE header and compared with the target platform/arch; a mismatch fails the build with the file, detected and expected target. Other mismatched native files (.so,.dylib,.dll,.exe) only warn, and files declared for another platform (package.jsonos/cpu,prebuilds/<platform>-<arch>/paths) are skipped. New opt-out optionnativeModules.verifyNativeBinaries?: boolean | "warn" | null("warn"logs only,falseskips).#102650966275@claudewriteEffectiveConfigto control writingbuilder-effective-config.yaml. Before, the file was only written for local interactive builds, so CI steps could not read the resolved configuration (e.g. the detectedelectronVersion). Settrueto always write it orfalseto never write it; the default is unchanged.#102605f2f906@Flobo2689xPatch Changes
Chore(deps): update dependency undici to v7.29.1 [security]
#102592b3417b@renovateFix: point the
PUBLISH_FOR_PULL_REQUESTandCSC_FOR_PULL_REQUESTwarnings at the current CircleCI page on secrets in forked pull request builds. The previous link returned 404.#1026879f0062@Flobo2689xPerf: make module downward search linear
#10149bd7786f@OskarEichlerFix(mac): sign with the unique certificate hash, and keep MAS
ElectronTeamIDautomation working#1023856d2d74@Bug-Reapercodesign --signwas given the certificate's common name, which fails withambiguous (matches "X" and "X" ...)when the keychain holds more than one valid certificate with that name. It is now given the certificate's SHA-1 hash, which is unique.@electron/osx-signparses the Team ID out of the identity name to fill inElectronTeamIDfor sandboxed (MAS) apps, so electron-builder now writes that key into the app'sInfo.plistitself before signing — the same value from the same source — instead of relying on the identity string carrying it. A custom signer replaces osx-sign entirely, so it keeps receiving the bare hash and itsInfo.plistis left untouched.Also fixes
savePlistFiledestroying<data>and<date>values, which it rewrote as a<dict>of byte integers and an empty<dict>respectively.Fix(migrate-schema): print an advisory, for JS/TS configs as well as JSON, YAML, TOML and package.json ones, for a
genericpublishurlwith a query string: electron-updater sends the feed query and the credential headers only to downloads on the feed's origin. The build prints the same warning once per feed (naming the query parameters, not their values) when it writes such a feed toapp-update.yml, so it does not depend onmigrate-schemahaving been run#10270ec9135d@mmaiettaFix(nsis): warn when
differentialPackage: "store-asar"finds noresources/app.asar(e.g.asar: false) instead of silently compressing the package normally#102461b0225e@claudeFix(nsis): keep installer extraction in sync with the payload format when
useZipis set (ignored with a warning for differential-aware builds and fornsis-web, which always use 7z), and only share an app package between targets (e.g. nsis + portable) whose packaging settings match#102486312a4d@claudeFix(nsis): a silent nsis-web installer run exits with code 2 when the app package cannot be downloaded, instead of waiting on the retry prompt. A cancelled package download, an app package that cannot be extracted, and a running app that cannot be closed (or that the user chose not to close) now also end an NSIS installer with exit code 2 explicitly, like its other aborts
#10264c8ca1ac@mmaiettaChore: replace ESLint and Prettier with oxlint and oxfmt
#10240a578e53@claudeRefactor: replace deprecated recursive rmdir
#10146ecde932@OskarEichlerFix: merge the update info of a target into
latest*.ymlwithdeepAssign#10264c8ca1ac@mmaiettaFix(nsis): the nsis-web installer copies, verifies and, if needed, downloads its app package before it removes the installed version, so a refused package, a
--package-filepackage that cannot be copied, or a failed or cancelled download leaves the installed version in place. Because the download can take a while, a run that isn't an update (--updated) then checks again for the running app, with the same prompt as at the start (Cancel aborts with exit code 2), before the old uninstaller would close it without asking#10264c8ca1ac@mmaiettaUpdated 5 dependencies
ec9135d4bc95cc2f6d7d17619d08ec9135dec9135da578e5363de366builder-util-runtime@10.0.0-alpha.9builder-util@27.0.0-alpha.10electron-publish@27.0.0-alpha.10dmg-builder@27.0.0-alpha.10electron-builder-squirrel-windows@27.0.0-alpha.10electron-updater@7.0.0-alpha.9
Major Changes
Feat(updater): add
verifyUpdateFiletoAppUpdater, and rename the NSIS Authenticode verification interface#10239317fc9e@LemonexeAppUpdater.verifyUpdateFilelets an app run its own verification of an update file before that file is allowed to become installable. The default implementation is a stub that immediately succeeds. It runs on every path that can lead to an install — right after a fresh download (while the file still sits under a temporary name, so an unverified file is never executable under its real name), when an update downloaded by an earlier session is reused from the cache, and before an install-on-next-launch spawns the cached installer. On failure the file is deleted and anERR_UPDATER_INVALID_UPDATE_FILEerror is emitted. Assigningnullrestores the default.The NSIS Authenticode verification interface now returns an unambiguous result object instead of the
null-means-success /string-means-error convention:BREAKING CHANGE:
NsisUpdater.verifyUpdateCodeSignatureis deprecated in favour ofverifyUpdateFileAuthenticodeSignature, which differs in return type. The old name is kept as a compatibility shim that translates in both directions and shall be removed in electron-builder v28.BREAKING CHANGE: the protected
NsisUpdater._verifyUpdateCodeSignaturemember is renamed to_verifyUpdateFileAuthenticodeSignatureand takes the new return type. A deprecated accessor under the old name forwards to it, so a subclass that assignsthis._verifyUpdateCodeSignaturekeeps working; a subclass that redeclares it as a class field shadows the accessor and must be migrated.BREAKING CHANGE: the protected
BaseUpdater.verifyInstallerSignatureOnLaunchreturnsPromise<VerifyUpdateFileResult>instead ofPromise<string | null>. An override that resolvesnullto mean "verified" now reports every install-on-next-launch as unsigned; return{ response: "success" }instead. (This member was introduced earlier in the same v27 pre-release cycle, so only apps on a 7.0.0-alpha are affected.)Feat!: electron-updater sends update-feed credentials only to downloads on the feed's origin. With the generic, s3, spaces, r2, keygen, bitbucket, github and gitlab providers, a download on another origin than the feed (scheme, host or port) — an absolute
files[].urlorpackages.<arch>.pathinlatest*.yml, a GitLab release asset link, and the blockmaps and differential range requests derived from them — is requested without the credential headers fromrequestHeaders/addAuthHeader(headers such asAuthorization, the same set that is removed on a cross-origin redirect) and without the feed URL's query string. Such a URL keeps its own query string, so pre-signed URLs work. With every provider, including custom ones, a URL that electron-updater resolves against the feed URL (such as afiles[].urlor a blockmap) gets the feed query only on the feed's origin; as on redirects, anhttp→httpsupgrade of the feed host on the default ports keeps the headers and the query. Downloads on the feed origin are unchanged, and the old blockmap from an app-setpreviousBlockmapBaseUrlOverridekeeps the credentials on that origin. If yourlatest*.ymlpoints downloads at another origin that needs these credentials, serve the files from the feed origin or use pre-signed URLs. The NSIS web-package differential download now uses the same per-download headers as other downloads. A custom provider that does not extend a built-in one must declareProvider.feedBaseUrl— its feed URL (the credential headers then only go to that origin) ornull(the request headers go to every download URL) — when the download headers include a credential header: if it does not,downloadUpdate()fails withERR_UPDATER_FEED_BASE_URL_NOT_DECLAREDbefore any download request. The first download that loses the credential headers, and the first that does not get the feed query, each log a warning once per updater, naming the headers, the query parameters and the origins (never their values), with a link to the migration guide;ERR_UPDATER_FEED_BASE_URL_NOT_DECLAREDlinks it too. New APIs:Provider.feedBaseUrl(undefined, not declared, by default),HttpExecutor.sensitiveHeaderNames,HttpExecutor.removeCrossOriginSensitiveHeadersandHttpExecutor.isCrossOrigin.#10270ec9135d@mmaiettaFeat!: NSIS web-installer updates are rejected unless
disableWebInstallerisfalse(the v27 grace period is removed; cached and install-on-next-launch web updates re-verify the web package), and the nsis-web installer verifies--package-fileand versioned package downloads against its built-in SHA-512 hashes (opt out withnsisWeb.allowUnverifiedAppPackage). SetdisableWebInstallerbefore the app is ready: a pending install-on-next-launch web update is checked against it at appready#10264c8ca1ac@mmaiettaMinor Changes
files[].blockMapUrlinlatest*.ymlnames a file's blockmap URL (e.g. a separately pre-signed one) instead of${url}.blockmapwith the file URL's query string. A relative value resolves likeurl(against the feed URL); an absolute URL is used as-is, with its own host and query string. It gets the feed query and credential headers only on the feed's origin. With ablockMapUrl, the old blockmap is not derived from the new file's URL: it comes from the local cache, else frompreviousBlockmapBaseUrlOverride, else that update is downloaded in full (which caches the new blockmap). The manifest signature coversblockMapUrlwhen present, as an extra field on the file record, so manifests without it canonicalize and verify exactly as before; an electron-updater without this change refuses a signed manifest that has one. electron-builder does not write it. The private GitHub and GitLab providers, which resolve files from the release assets, ignore it.#10270ec9135d@mmaiettaPatch Changes
#1011858e5d2e@OskarEichlerapp-update.yml(annsis,nsis-weborelectronUpdaterAwareappxtarget with a publish configuration, including one inferred from a GitHubrepository) now fails with anInvalidConfigurationErrorwhen its publisher name cannot be determined: any customwin.sign.signhook withoutwin.sign.publisherName(its publisher name is never derived from a certificate, not even one in the config —certificateFile,certificateSubjectName,certificateSha1,cscLink— or fromWIN_CSC_LINK/CSC_LINK, because the hook may sign with another one), or a certificate without a Common Name (including a certificate-store subject, which no longer yields an undefined publisher name). Setwin.sign.publisherNameto the subject of the signing certificate (copy it from a binary your hook already signed), or setwin.verifyUpdateCodeSignature: falseonly if your updates are not Authenticode-signed or you don't use electron-updater. Error and warning messages now namewin.sign.publisherNameinstead of the removedwin.publisherName.#10264c8ca1ac@mmaiettaverifyUpdateFileaspackageFilePathwhen a pending web update is installed on next launch#10264c8ca1ac@mmaiettacheckForUpdatesAndNotify#10113c10345f@OskarEichlerinstallDirectory,/D=) as the last installer argument, after--package-file#10264c8ca1ac@mmaietta#10240a578e53@claude#10127e832c81@OskarEichlerdisableWebInstallerset tofalsefor a full-installer update is logged only when the app set it; for the default of an install made by an nsis-web installer an info line says that web-installer updates needdisableWebInstaller = falseafter that update#10264c8ca1ac@mmaietta--package-file(electron-updater does this for updates) or found next to the installer is first copied into the installer's own temporary directory; the checksum is computed on that copy and that copy is what is extracted. WithnsisWeb.allowUnverifiedAppPackagea package passed via--package-fileis still copied, but not verified. The local package file is now left in place (the installer's copy is moved into the app's update cache instead), and the installation is aborted (exit code2) if a--package-filepackage cannot be copied; a package found next to the installer that cannot be copied is ignored and the package is downloaded, as when its checksum doesn't match. electron-updater removes the package it passed via--package-filefrom itspendingcache directory at startup once the app runs the version of that update (update-info.jsonrecords the version of a web installer update for this); the package of an update that is not installed yet, or whose install failed, is kept.#10264c8ca1ac@mmaiettaUpdated 1 dependency
ec9135dec9135dec9135dbuilder-util-runtime@10.0.0-alpha.9builder-util-runtime@10.0.0-alpha.9
Minor Changes
files[].blockMapUrlinlatest*.ymlnames a file's blockmap URL (e.g. a separately pre-signed one) instead of${url}.blockmapwith the file URL's query string. A relative value resolves likeurl(against the feed URL); an absolute URL is used as-is, with its own host and query string. It gets the feed query and credential headers only on the feed's origin. With ablockMapUrl, the old blockmap is not derived from the new file's URL: it comes from the local cache, else frompreviousBlockmapBaseUrlOverride, else that update is downloaded in full (which caches the new blockmap). The manifest signature coversblockMapUrlwhen present, as an extra field on the file record, so manifests without it canonicalize and verify exactly as before; an electron-updater without this change refuses a signed manifest that has one. electron-builder does not write it. The private GitHub and GitLab providers, which resolve files from the release assets, ignore it.#10270ec9135d@mmaiettafiles[].urlorpackages.<arch>.pathinlatest*.yml, a GitLab release asset link, and the blockmaps and differential range requests derived from them — is requested without the credential headers fromrequestHeaders/addAuthHeader(headers such asAuthorization, the same set that is removed on a cross-origin redirect) and without the feed URL's query string. Such a URL keeps its own query string, so pre-signed URLs work. With every provider, including custom ones, a URL that electron-updater resolves against the feed URL (such as afiles[].urlor a blockmap) gets the feed query only on the feed's origin; as on redirects, anhttp→httpsupgrade of the feed host on the default ports keeps the headers and the query. Downloads on the feed origin are unchanged, and the old blockmap from an app-setpreviousBlockmapBaseUrlOverridekeeps the credentials on that origin. If yourlatest*.ymlpoints downloads at another origin that needs these credentials, serve the files from the feed origin or use pre-signed URLs. The NSIS web-package differential download now uses the same per-download headers as other downloads. A custom provider that does not extend a built-in one must declareProvider.feedBaseUrl— its feed URL (the credential headers then only go to that origin) ornull(the request headers go to every download URL) — when the download headers include a credential header: if it does not,downloadUpdate()fails withERR_UPDATER_FEED_BASE_URL_NOT_DECLAREDbefore any download request. The first download that loses the credential headers, and the first that does not get the feed query, each log a warning once per updater, naming the headers, the query parameters and the origins (never their values), with a link to the migration guide;ERR_UPDATER_FEED_BASE_URL_NOT_DECLAREDlinks it too. New APIs:Provider.feedBaseUrl(undefined, not declared, by default),HttpExecutor.sensitiveHeaderNames,HttpExecutor.removeCrossOriginSensitiveHeadersandHttpExecutor.isCrossOrigin.#10270ec9135d@mmaiettaPatch Changes
HttpExecutor.removeCrossOriginSensitiveHeaderscopies the headers withdeepAssign, which ignores__proto__,constructorandprototypekeys#10270ec9135d@mmaiettabuilder-util@27.0.0-alpha.10
Patch Changes
#101304bc95cc@OskarEichler#101527619d08@OskarEichler#10240a578e53@claudeUpdated 1 dependency
ec9135dec9135dec9135dbuilder-util-runtime@10.0.0-alpha.9dmg-builder@27.0.0-alpha.10
Patch Changes
#1014363de366@OskarEichlerUpdated 3 dependencies
2b3417b79f0062ec9135dc8ca1ac4bc95ccbd7786f7619d0856d2d74ec9135dec9135dec9135dc8ca1ac1b0225e6312a4dc8ca1aca578e53ecde932c8ca1ac0966275c8ca1acc8ca1acc8ca1ac5f2f906app-builder-lib@27.0.0-alpha.10builder-util-runtime@10.0.0-alpha.9builder-util@27.0.0-alpha.10electron-builder@27.0.0-alpha.10
Patch Changes
genericpublishurlwith a query string: electron-updater sends the feed query and the credential headers only to downloads on the feed's origin. The build prints the same warning once per feed (naming the query parameters, not their values) when it writes such a feed toapp-update.yml, so it does not depend onmigrate-schemahaving been run#10270ec9135d@mmaiettansis.perMachine/nsisWeb.perMachine(per-machine NSIS updates) and a customwin.sign.signhook withoutwin.sign.publisherName(whatever certificate the config names); thensis-webadvisory now says that web-installer updates are rejected unlessautoUpdater.disableWebInstallerisfalseand when to setnsisWeb.allowUnverifiedAppPackage, and target names with an:archsuffix (e.g.nsis-web:ia32) are detected#10264c8ca1ac@mmaietta#10240a578e53@claudeUpdated 5 dependencies
2b3417b79f0062ec9135dc8ca1ac4bc95ccbd7786f2f6d7d17619d0856d2d74ec9135dec9135dec9135dc8ca1ac1b0225e6312a4dc8ca1aca578e5363de366ecde932c8ca1ac0966275c8ca1acc8ca1acc8ca1ac5f2f906app-builder-lib@27.0.0-alpha.10builder-util-runtime@10.0.0-alpha.9builder-util@27.0.0-alpha.10electron-publish@27.0.0-alpha.10dmg-builder@27.0.0-alpha.10electron-builder-squirrel-windows@27.0.0-alpha.10
Patch Changes
Updated 2 dependencies
2b3417b79f0062c8ca1ac4bc95ccbd7786f7619d0856d2d74ec9135dc8ca1ac1b0225e6312a4dc8ca1aca578e53ecde932c8ca1ac0966275c8ca1acc8ca1acc8ca1ac5f2f906app-builder-lib@27.0.0-alpha.10builder-util@27.0.0-alpha.10electron-forge-maker-appimage@27.0.0-alpha.10
Patch Changes
Updated 1 dependency
2b3417b79f0062c8ca1acbd7786f56d2d74ec9135dc8ca1ac1b0225e6312a4dc8ca1aca578e53ecde932c8ca1ac0966275c8ca1acc8ca1acc8ca1ac5f2f906app-builder-lib@27.0.0-alpha.10electron-forge-maker-nsis@27.0.0-alpha.10
Patch Changes
Updated 1 dependency
2b3417b79f0062c8ca1acbd7786f56d2d74ec9135dc8ca1ac1b0225e6312a4dc8ca1aca578e53ecde932c8ca1ac0966275c8ca1acc8ca1acc8ca1ac5f2f906app-builder-lib@27.0.0-alpha.10electron-forge-maker-nsis-web@27.0.0-alpha.10
Patch Changes
Updated 1 dependency
2b3417b79f0062c8ca1acbd7786f56d2d74ec9135dc8ca1ac1b0225e6312a4dc8ca1aca578e53ecde932c8ca1ac0966275c8ca1acc8ca1acc8ca1ac5f2f906app-builder-lib@27.0.0-alpha.10electron-forge-maker-snap@27.0.0-alpha.10
Patch Changes
Updated 1 dependency
2b3417b79f0062c8ca1acbd7786f56d2d74ec9135dc8ca1ac1b0225e6312a4dc8ca1aca578e53ecde932c8ca1ac0966275c8ca1acc8ca1acc8ca1ac5f2f906app-builder-lib@27.0.0-alpha.10electron-publish@27.0.0-alpha.10
Patch Changes
#101502f6d7d1@OskarEichler#10240a578e53@claudeUpdated 2 dependencies
ec9135d4bc95cc7619d08ec9135dec9135da578e53builder-util-runtime@10.0.0-alpha.9builder-util@27.0.0-alpha.10