fix(build): allow get-windows install script, refresh stale allowScripts pins
get-windows was added to apps/desktop without a root allowScripts entry, so
npm blocked its node-pre-gyp install script and the win32 prebuilt binding
was never downloaded. Every Windows desktop build then died in
stage-native-deps, including the updater's headless rebuild, leaving Windows
users unable to update the app.
The same manifest had drifted twice more: the CVE sweep in 7537de9e74 moved
Electron to 40.10.6 and left the electron@40.10.2 pin behind, and website's
allowlist still names core-js-pure, which its lockfile no longer resolves,
while fsevents runs an install script with no entry at all.
Co-authored-by: gsy324 <gsy324@users.noreply.github.com>
Co-authored-by: elbukott1 <elbukott1@users.noreply.github.com>
Co-authored-by: Brian Franco <BrianFranco@users.noreply.github.com>
This commit is contained in:
@@ -71,8 +71,9 @@
|
||||
"node-pty@1.1.0": true,
|
||||
"electron-winstaller@5.4.0": true,
|
||||
"agent-browser@0.26.0": true,
|
||||
"electron@40.10.2": true,
|
||||
"electron@40.10.6": true,
|
||||
"fsevents@2.3.2": true,
|
||||
"fsevents@2.3.3": true
|
||||
"fsevents@2.3.3": true,
|
||||
"get-windows@9.3.0": true
|
||||
}
|
||||
}
|
||||
|
||||
@@ -59,6 +59,6 @@
|
||||
},
|
||||
"allowScripts": {
|
||||
"core-js@3.49.0": true,
|
||||
"core-js-pure@3.49.0": true
|
||||
"fsevents@2.3.3": true
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user