Skip to content

chore(deploy): Release (next) (alpha) - #10243

Open
electron-builder-release-bot[bot] wants to merge 1 commit into
masterfrom
changeset-release/master
Open

electron-builder-release-bot[bot] wants to merge 1 commit into
masterfrom
changeset-release/master

Conversation

@electron-builder-release-bot

@electron-builder-release-bot electron-builder-release-bot Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to master, this PR will be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

master is currently in pre mode so this branch has prereleases rather than normal releases. If you want to exit prereleases, run changeset pre exit on master.

⚠️⚠️⚠️⚠️⚠️⚠️

Releases

app-builder-lib@27.0.0-alpha.10

Major Changes

  • Feat!: a code-signed Windows build that writes app-update.yml (an nsis, nsis-web or electronUpdaterAware appx target with a publish configuration, including one inferred from a GitHub repository) now fails with an InvalidConfigurationError when its publisher name cannot be determined: any custom win.sign.sign hook without win.sign.publisherName (its publisher name is never derived from a certificate, not even one in the config — certificateFile, certificateSubjectName, certificateSha1, cscLink — or from WIN_CSC_LINK / CSC_LINK, because the hook may sign with another one), or a certificate without a Common Name (including a certificate-store subject, which no longer yields an undefined publisher name). Set win.sign.publisherName to the subject of the signing certificate (copy it from a binary your hook already signed), or set win.verifyUpdateCodeSignature: false only if your updates are not Authenticode-signed or you don't use electron-updater. Error and warning messages now name win.sign.publisherName instead of the removed win.publisherName. #10264 c8ca1ac @mmaietta
  • Feat!: electron-builder sets isAdminRightsRequired in the update info of every per-machine nsis and nsis-web build (perMachine: true), including assisted installers (oneClick: false) that don't set packElevateHelper and builds with differentialPackage: false, and writes it into the file entry of the installer for nsis-web builds too, so their updates are started with elevate.exe directly and, like other per-machine updates, are not installed automatically at launch with autoInstallEvent: "onNextLaunch" (call installPendingUpdateIfAvailable()) #10264 c8ca1ac @mmaietta
  • Feat!: NSIS web-installer updates are rejected unless disableWebInstaller is false (the v27 grace period is removed; cached and install-on-next-launch web updates re-verify the web package), and the nsis-web installer verifies --package-file and versioned package downloads against its built-in SHA-512 hashes (opt out with nsisWeb.allowUnverifiedAppPackage). Set disableWebInstaller before the app is ready: a pending install-on-next-launch web update is checked against it at app ready #10264 c8ca1ac @mmaietta
  • Feat!: the nsis-web installer verifies and installs its own copy of a local app package. A package passed via --package-file (electron-updater does this for updates) or found next to the installer is first copied into the installer's own temporary directory; the checksum is computed on that copy and that copy is what is extracted. With nsisWeb.allowUnverifiedAppPackage a package passed via --package-file is still copied, but not verified. The local package file is now left in place (the installer's copy is moved into the app's update cache instead), and the installation is aborted (exit code 2) if a --package-file package cannot be copied; a package found next to the installer that cannot be copied is ignored and the package is downloaded, as when its checksum doesn't match. electron-updater removes the package it passed via --package-file from its pending cache directory at startup once the app runs the version of that update (update-info.json records the version of a web installer update for this); the package of an update that is not installed yet, or whose install failed, is kept. #10264 c8ca1ac @mmaietta

Minor Changes

  • Fix: nativeModules.buildDependenciesFromSource no longer skips the native-dependency rebuild when the target platform differs from the host (which shipped the host's binary). Native modules cannot be cross-compiled from source, so such targets are now rebuilt with prebuilt binaries for the target and a warning is logged. feat: after packing (per slice for macOS universal, before the merge), every .node addon in app.asar, app.asar.unpacked or app is identified from its ELF / Mach-O / PE header and compared with the target platform/arch; a mismatch fails the build with the file, detected and expected target. Other mismatched native files (.so, .dylib, .dll, .exe) only warn, and files declared for another platform (package.json os/cpu, prebuilds/<platform>-<arch>/ paths) are skipped. New opt-out option nativeModules.verifyNativeBinaries?: boolean | "warn" | null ("warn" logs only, false skips). #10265 0966275 @claude
  • Feat: add writeEffectiveConfig to control writing builder-effective-config.yaml. Before, the file was only written for local interactive builds, so CI steps could not read the resolved configuration (e.g. the detected electronVersion). Set true to always write it or false to never write it; the default is unchanged. #10260 5f2f906 @Flobo2689x

Patch Changes

  • Chore(deps): update dependency undici to v7.29.1 [security] #10259 2b3417b @renovate

  • Fix: point the PUBLISH_FOR_PULL_REQUEST and CSC_FOR_PULL_REQUEST warnings at the current CircleCI page on secrets in forked pull request builds. The previous link returned 404. #10268 79f0062 @Flobo2689x

  • Perf: make module downward search linear #10149 bd7786f @OskarEichler

  • Fix(mac): sign with the unique certificate hash, and keep MAS ElectronTeamID automation working #10238 56d2d74 @Bug-Reaper

    codesign --sign was given the certificate's common name, which fails with ambiguous (matches "X" and "X" ...) when the keychain holds more than one valid certificate with that name. It is now given the certificate's SHA-1 hash, which is unique.

    @electron/osx-sign parses the Team ID out of the identity name to fill in ElectronTeamID for sandboxed (MAS) apps, so electron-builder now writes that key into the app's Info.plist itself before signing — the same value from the same source — instead of relying on the identity string carrying it. A custom signer replaces osx-sign entirely, so it keeps receiving the bare hash and its Info.plist is left untouched.

    Also fixes savePlistFile destroying <data> and <date> values, which it rewrote as a <dict> of byte integers and an empty <dict> respectively.

  • Fix(migrate-schema): print an advisory, for JS/TS configs as well as JSON, YAML, TOML and package.json ones, for a generic publish url with a query string: electron-updater sends the feed query and the credential headers only to downloads on the feed's origin. The build prints the same warning once per feed (naming the query parameters, not their values) when it writes such a feed to app-update.yml, so it does not depend on migrate-schema having been run #10270 ec9135d @mmaietta

  • Fix(nsis): warn when differentialPackage: "store-asar" finds no resources/app.asar (e.g. asar: false) instead of silently compressing the package normally #10246 1b0225e @claude

  • Fix(nsis): keep installer extraction in sync with the payload format when useZip is set (ignored with a warning for differential-aware builds and for nsis-web, which always use 7z), and only share an app package between targets (e.g. nsis + portable) whose packaging settings match #10248 6312a4d @claude

  • Fix(nsis): a silent nsis-web installer run exits with code 2 when the app package cannot be downloaded, instead of waiting on the retry prompt. A cancelled package download, an app package that cannot be extracted, and a running app that cannot be closed (or that the user chose not to close) now also end an NSIS installer with exit code 2 explicitly, like its other aborts #10264 c8ca1ac @mmaietta

  • Chore: replace ESLint and Prettier with oxlint and oxfmt #10240 a578e53 @claude

  • Refactor: replace deprecated recursive rmdir #10146 ecde932 @OskarEichler

  • Fix: merge the update info of a target into latest*.yml with deepAssign #10264 c8ca1ac @mmaietta

  • Fix(nsis): the nsis-web installer copies, verifies and, if needed, downloads its app package before it removes the installed version, so a refused package, a --package-file package that cannot be copied, or a failed or cancelled download leaves the installed version in place. Because the download can take a while, a run that isn't an update (--updated) then checks again for the running app, with the same prompt as at the start (Cancel aborts with exit code 2), before the old uninstaller would close it without asking #10264 c8ca1ac @mmaietta

Updated 5 dependencies

ec9135d 4bc95cc 2f6d7d1 7619d08 ec9135d ec9135d a578e53 63de366

  • builder-util-runtime@10.0.0-alpha.9
  • builder-util@27.0.0-alpha.10
  • electron-publish@27.0.0-alpha.10
  • dmg-builder@27.0.0-alpha.10
  • electron-builder-squirrel-windows@27.0.0-alpha.10

electron-updater@7.0.0-alpha.9

Major Changes

  • Feat(updater): add verifyUpdateFile to AppUpdater, and rename the NSIS Authenticode verification interface #10239 317fc9e @Lemonexe

    AppUpdater.verifyUpdateFile lets an app run its own verification of an update file before that file is allowed to become installable. The default implementation is a stub that immediately succeeds. It runs on every path that can lead to an install — right after a fresh download (while the file still sits under a temporary name, so an unverified file is never executable under its real name), when an update downloaded by an earlier session is reused from the cache, and before an install-on-next-launch spawns the cached installer. On failure the file is deleted and an ERR_UPDATER_INVALID_UPDATE_FILE error is emitted. Assigning null restores the default.

    The NSIS Authenticode verification interface now returns an unambiguous result object instead of the null-means-success / string-means-error convention:

    type VerifyUpdateFileResult =
      | { response: "success" }
      | { response: "failure"; message: string };

    BREAKING CHANGE: NsisUpdater.verifyUpdateCodeSignature is deprecated in favour of verifyUpdateFileAuthenticodeSignature, which differs in return type. The old name is kept as a compatibility shim that translates in both directions and shall be removed in electron-builder v28.

    // Before
    autoUpdater.verifyUpdateCodeSignature = async (publisherNames, path) =>
      isValid ? null : "why it failed";
    
    // After
    autoUpdater.verifyUpdateFileAuthenticodeSignature = async (
      publisherNames,
      path
    ) =>
      isValid
        ? { response: "success" }
        : { response: "failure", message: "why it failed" };

    BREAKING CHANGE: the protected NsisUpdater._verifyUpdateCodeSignature member is renamed to _verifyUpdateFileAuthenticodeSignature and takes the new return type. A deprecated accessor under the old name forwards to it, so a subclass that assigns this._verifyUpdateCodeSignature keeps working; a subclass that redeclares it as a class field shadows the accessor and must be migrated.

    BREAKING CHANGE: the protected BaseUpdater.verifyInstallerSignatureOnLaunch returns Promise<VerifyUpdateFileResult> instead of Promise<string | null>. An override that resolves null to mean "verified" now reports every install-on-next-launch as unsigned; return { response: "success" } instead. (This member was introduced earlier in the same v27 pre-release cycle, so only apps on a 7.0.0-alpha are affected.)

  • Feat!: electron-updater sends update-feed credentials only to downloads on the feed's origin. With the generic, s3, spaces, r2, keygen, bitbucket, github and gitlab providers, a download on another origin than the feed (scheme, host or port) — an absolute files[].url or packages.<arch>.path in latest*.yml, a GitLab release asset link, and the blockmaps and differential range requests derived from them — is requested without the credential headers from requestHeaders / addAuthHeader (headers such as Authorization, the same set that is removed on a cross-origin redirect) and without the feed URL's query string. Such a URL keeps its own query string, so pre-signed URLs work. With every provider, including custom ones, a URL that electron-updater resolves against the feed URL (such as a files[].url or a blockmap) gets the feed query only on the feed's origin; as on redirects, an http → https upgrade of the feed host on the default ports keeps the headers and the query. Downloads on the feed origin are unchanged, and the old blockmap from an app-set previousBlockmapBaseUrlOverride keeps the credentials on that origin. If your latest*.yml points downloads at another origin that needs these credentials, serve the files from the feed origin or use pre-signed URLs. The NSIS web-package differential download now uses the same per-download headers as other downloads. A custom provider that does not extend a built-in one must declare Provider.feedBaseUrl — its feed URL (the credential headers then only go to that origin) or null (the request headers go to every download URL) — when the download headers include a credential header: if it does not, downloadUpdate() fails with ERR_UPDATER_FEED_BASE_URL_NOT_DECLARED before any download request. The first download that loses the credential headers, and the first that does not get the feed query, each log a warning once per updater, naming the headers, the query parameters and the origins (never their values), with a link to the migration guide; ERR_UPDATER_FEED_BASE_URL_NOT_DECLARED links it too. New APIs: Provider.feedBaseUrl (undefined, not declared, by default), HttpExecutor.sensitiveHeaderNames, HttpExecutor.removeCrossOriginSensitiveHeaders and HttpExecutor.isCrossOrigin. #10270 ec9135d @mmaietta

  • Feat!: NSIS web-installer updates are rejected unless disableWebInstaller is false (the v27 grace period is removed; cached and install-on-next-launch web updates re-verify the web package), and the nsis-web installer verifies --package-file and versioned package downloads against its built-in SHA-512 hashes (opt out with nsisWeb.allowUnverifiedAppPackage). Set disableWebInstaller before the app is ready: a pending install-on-next-launch web update is checked against it at app ready #10264 c8ca1ac @mmaietta

Minor Changes

  • Feat(updater): optional files[].blockMapUrl in latest*.yml names a file's blockmap URL (e.g. a separately pre-signed one) instead of ${url}.blockmap with the file URL's query string. A relative value resolves like url (against the feed URL); an absolute URL is used as-is, with its own host and query string. It gets the feed query and credential headers only on the feed's origin. With a blockMapUrl, the old blockmap is not derived from the new file's URL: it comes from the local cache, else from previousBlockmapBaseUrlOverride, else that update is downloaded in full (which caches the new blockmap). The manifest signature covers blockMapUrl when present, as an extra field on the file record, so manifests without it canonicalize and verify exactly as before; an electron-updater without this change refuses a signed manifest that has one. electron-builder does not write it. The private GitHub and GitLab providers, which resolve files from the release assets, ignore it. #10270 ec9135d @mmaietta

Patch Changes

  • Fix: report accurate differential download progress deltas #10118 58e5d2e @OskarEichler
  • Feat!: a code-signed Windows build that writes app-update.yml (an nsis, nsis-web or electronUpdaterAware appx target with a publish configuration, including one inferred from a GitHub repository) now fails with an InvalidConfigurationError when its publisher name cannot be determined: any custom win.sign.sign hook without win.sign.publisherName (its publisher name is never derived from a certificate, not even one in the config — certificateFile, certificateSubjectName, certificateSha1, cscLink — or from WIN_CSC_LINK / CSC_LINK, because the hook may sign with another one), or a certificate without a Common Name (including a certificate-store subject, which no longer yields an undefined publisher name). Set win.sign.publisherName to the subject of the signing certificate (copy it from a binary your hook already signed), or set win.verifyUpdateCodeSignature: false only if your updates are not Authenticode-signed or you don't use electron-updater. Error and warning messages now name win.sign.publisherName instead of the removed win.publisherName. #10264 c8ca1ac @mmaietta
  • Fix(updater): pass the web installer package to verifyUpdateFile as packageFilePath when a pending web update is installed on next launch #10264 c8ca1ac @mmaietta
  • Fix: handle background download rejections from checkForUpdatesAndNotify #10113 c10345f @OskarEichler
  • Fix(updater): pass the NSIS install directory (installDirectory, /D=) as the last installer argument, after --package-file #10264 c8ca1ac @mmaietta
  • Chore: replace ESLint and Prettier with oxlint and oxfmt #10240 a578e53 @claude
  • Fix: reject traversal segments as update cache filenames #10127 e832c81 @OskarEichler
  • Fix(updater): the warning about disableWebInstaller set to false for a full-installer update is logged only when the app set it; for the default of an install made by an nsis-web installer an info line says that web-installer updates need disableWebInstaller = false after that update #10264 c8ca1ac @mmaietta
  • Feat!: the nsis-web installer verifies and installs its own copy of a local app package. A package passed via --package-file (electron-updater does this for updates) or found next to the installer is first copied into the installer's own temporary directory; the checksum is computed on that copy and that copy is what is extracted. With nsisWeb.allowUnverifiedAppPackage a package passed via --package-file is still copied, but not verified. The local package file is now left in place (the installer's copy is moved into the app's update cache instead), and the installation is aborted (exit code 2) if a --package-file package cannot be copied; a package found next to the installer that cannot be copied is ignored and the package is downloaded, as when its checksum doesn't match. electron-updater removes the package it passed via --package-file from its pending cache directory at startup once the app runs the version of that update (update-info.json records the version of a web installer update for this); the package of an update that is not installed yet, or whose install failed, is kept. #10264 c8ca1ac @mmaietta
Updated 1 dependency

ec9135d ec9135d ec9135d

  • builder-util-runtime@10.0.0-alpha.9

builder-util-runtime@10.0.0-alpha.9

Minor Changes

  • Feat(updater): optional files[].blockMapUrl in latest*.yml names a file's blockmap URL (e.g. a separately pre-signed one) instead of ${url}.blockmap with the file URL's query string. A relative value resolves like url (against the feed URL); an absolute URL is used as-is, with its own host and query string. It gets the feed query and credential headers only on the feed's origin. With a blockMapUrl, the old blockmap is not derived from the new file's URL: it comes from the local cache, else from previousBlockmapBaseUrlOverride, else that update is downloaded in full (which caches the new blockmap). The manifest signature covers blockMapUrl when present, as an extra field on the file record, so manifests without it canonicalize and verify exactly as before; an electron-updater without this change refuses a signed manifest that has one. electron-builder does not write it. The private GitHub and GitLab providers, which resolve files from the release assets, ignore it. #10270 ec9135d @mmaietta
  • Feat!: electron-updater sends update-feed credentials only to downloads on the feed's origin. With the generic, s3, spaces, r2, keygen, bitbucket, github and gitlab providers, a download on another origin than the feed (scheme, host or port) — an absolute files[].url or packages.<arch>.path in latest*.yml, a GitLab release asset link, and the blockmaps and differential range requests derived from them — is requested without the credential headers from requestHeaders / addAuthHeader (headers such as Authorization, the same set that is removed on a cross-origin redirect) and without the feed URL's query string. Such a URL keeps its own query string, so pre-signed URLs work. With every provider, including custom ones, a URL that electron-updater resolves against the feed URL (such as a files[].url or a blockmap) gets the feed query only on the feed's origin; as on redirects, an http → https upgrade of the feed host on the default ports keeps the headers and the query. Downloads on the feed origin are unchanged, and the old blockmap from an app-set previousBlockmapBaseUrlOverride keeps the credentials on that origin. If your latest*.yml points downloads at another origin that needs these credentials, serve the files from the feed origin or use pre-signed URLs. The NSIS web-package differential download now uses the same per-download headers as other downloads. A custom provider that does not extend a built-in one must declare Provider.feedBaseUrl — its feed URL (the credential headers then only go to that origin) or null (the request headers go to every download URL) — when the download headers include a credential header: if it does not, downloadUpdate() fails with ERR_UPDATER_FEED_BASE_URL_NOT_DECLARED before any download request. The first download that loses the credential headers, and the first that does not get the feed query, each log a warning once per updater, naming the headers, the query parameters and the origins (never their values), with a link to the migration guide; ERR_UPDATER_FEED_BASE_URL_NOT_DECLARED links it too. New APIs: Provider.feedBaseUrl (undefined, not declared, by default), HttpExecutor.sensitiveHeaderNames, HttpExecutor.removeCrossOriginSensitiveHeaders and HttpExecutor.isCrossOrigin. #10270 ec9135d @mmaietta

Patch Changes

  • Fix: HttpExecutor.removeCrossOriginSensitiveHeaders copies the headers with deepAssign, which ignores __proto__, constructor and prototype keys #10270 ec9135d @mmaietta

builder-util@27.0.0-alpha.10

Patch Changes

Updated 1 dependency

ec9135d ec9135d ec9135d

  • builder-util-runtime@10.0.0-alpha.9

dmg-builder@27.0.0-alpha.10

Patch Changes

Updated 3 dependencies

2b3417b 79f0062 ec9135d c8ca1ac 4bc95cc bd7786f 7619d08 56d2d74 ec9135d ec9135d ec9135d c8ca1ac 1b0225e 6312a4d c8ca1ac a578e53 ecde932 c8ca1ac 0966275 c8ca1ac c8ca1ac c8ca1ac 5f2f906

  • app-builder-lib@27.0.0-alpha.10
  • builder-util-runtime@10.0.0-alpha.9
  • builder-util@27.0.0-alpha.10

electron-builder@27.0.0-alpha.10

Patch Changes

  • Fix(migrate-schema): print an advisory, for JS/TS configs as well as JSON, YAML, TOML and package.json ones, for a generic publish url with a query string: electron-updater sends the feed query and the credential headers only to downloads on the feed's origin. The build prints the same warning once per feed (naming the query parameters, not their values) when it writes such a feed to app-update.yml, so it does not depend on migrate-schema having been run #10270 ec9135d @mmaietta
  • Fix(migrate-schema): print advisories, for JS/TS configs as well as JSON, YAML, TOML and package.json ones, for nsis.perMachine / nsisWeb.perMachine (per-machine NSIS updates) and a custom win.sign.sign hook without win.sign.publisherName (whatever certificate the config names); the nsis-web advisory now says that web-installer updates are rejected unless autoUpdater.disableWebInstaller is false and when to set nsisWeb.allowUnverifiedAppPackage, and target names with an :arch suffix (e.g. nsis-web:ia32) are detected #10264 c8ca1ac @mmaietta
  • Chore: replace ESLint and Prettier with oxlint and oxfmt #10240 a578e53 @claude
Updated 5 dependencies

2b3417b 79f0062 ec9135d c8ca1ac 4bc95cc bd7786f 2f6d7d1 7619d08 56d2d74 ec9135d ec9135d ec9135d c8ca1ac 1b0225e 6312a4d c8ca1ac a578e53 63de366 ecde932 c8ca1ac 0966275 c8ca1ac c8ca1ac c8ca1ac 5f2f906

  • app-builder-lib@27.0.0-alpha.10
  • builder-util-runtime@10.0.0-alpha.9
  • builder-util@27.0.0-alpha.10
  • electron-publish@27.0.0-alpha.10
  • dmg-builder@27.0.0-alpha.10

electron-builder-squirrel-windows@27.0.0-alpha.10

Patch Changes

Updated 2 dependencies

2b3417b 79f0062 c8ca1ac 4bc95cc bd7786f 7619d08 56d2d74 ec9135d c8ca1ac 1b0225e 6312a4d c8ca1ac a578e53 ecde932 c8ca1ac 0966275 c8ca1ac c8ca1ac c8ca1ac 5f2f906

  • app-builder-lib@27.0.0-alpha.10
  • builder-util@27.0.0-alpha.10

electron-forge-maker-appimage@27.0.0-alpha.10

Patch Changes

Updated 1 dependency

2b3417b 79f0062 c8ca1ac bd7786f 56d2d74 ec9135d c8ca1ac 1b0225e 6312a4d c8ca1ac a578e53 ecde932 c8ca1ac 0966275 c8ca1ac c8ca1ac c8ca1ac 5f2f906

  • app-builder-lib@27.0.0-alpha.10

electron-forge-maker-nsis@27.0.0-alpha.10

Patch Changes

Updated 1 dependency

2b3417b 79f0062 c8ca1ac bd7786f 56d2d74 ec9135d c8ca1ac 1b0225e 6312a4d c8ca1ac a578e53 ecde932 c8ca1ac 0966275 c8ca1ac c8ca1ac c8ca1ac 5f2f906

  • app-builder-lib@27.0.0-alpha.10

electron-forge-maker-nsis-web@27.0.0-alpha.10

Patch Changes

Updated 1 dependency

2b3417b 79f0062 c8ca1ac bd7786f 56d2d74 ec9135d c8ca1ac 1b0225e 6312a4d c8ca1ac a578e53 ecde932 c8ca1ac 0966275 c8ca1ac c8ca1ac c8ca1ac 5f2f906

  • app-builder-lib@27.0.0-alpha.10

electron-forge-maker-snap@27.0.0-alpha.10

Patch Changes

Updated 1 dependency

2b3417b 79f0062 c8ca1ac bd7786f 56d2d74 ec9135d c8ca1ac 1b0225e 6312a4d c8ca1ac a578e53 ecde932 c8ca1ac 0966275 c8ca1ac c8ca1ac c8ca1ac 5f2f906

  • app-builder-lib@27.0.0-alpha.10

electron-publish@27.0.0-alpha.10

Patch Changes

Updated 2 dependencies

ec9135d 4bc95cc 7619d08 ec9135d ec9135d a578e53

  • builder-util-runtime@10.0.0-alpha.9
  • builder-util@27.0.0-alpha.10

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, straightforward automated release/version-bump PR. Reviewed: .changeset/pre.json entry addition, CHANGELOG.md regeneration across all workspace packages, package.json version bumps (alpha.9 -> alpha.10), and the matching PACKAGE_VERSION constant update in packages/app-builder-lib/src/version.ts — all consistent with a Changesets bot release commit and free of logic changes.

Extended reasoning...

The diff is exactly what the changesets release-bot produces: version bumps in package.json files, regenerated CHANGELOG.md entries, one new changeset id in pre.json, and the corresponding hardcoded version string bump in version.ts. No functional or security-sensitive code paths are touched, no CODEOWNER-restricted logic changed, and the bug hunt reported zero findings, so this mechanical release PR is safe to approve without further human review.

@electron-builder-release-bot
electron-builder-release-bot Bot force-pushed the changeset-release/master branch 2 times, most recently from 3a856bc to 31c023f Compare September 26, 2026 14:52

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@electron-builder-release-bot
electron-builder-release-bot Bot force-pushed the changeset-release/master branch 2 times, most recently from c4bfab0 to 701055b Compare September 27, 2026 06:45

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@electron-builder-release-bot
electron-builder-release-bot Bot force-pushed the changeset-release/master branch 3 times, most recently from 81caec6 to b170e0f Compare September 27, 2026 13:59

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

mmaietta
mmaietta previously approved these changes Sep 29, 2026

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@electron-builder-release-bot
electron-builder-release-bot Bot force-pushed the changeset-release/master branch 2 times, most recently from 1f592d4 to 31c4a85 Compare September 30, 2026 19:00

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@electron-builder-release-bot
electron-builder-release-bot Bot force-pushed the changeset-release/master branch 2 times, most recently from 68110bb to 175f2a6 Compare September 30, 2026 21:33

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant