From 7210db5646151c163f130d312811eb001f7f73ec Mon Sep 17 00:00:00 2001 From: Brooklyn Nicholson Date: Sat, 8 Aug 2026 21:23:16 -0500 Subject: [PATCH] fix(build): allow get-windows install script, refresh stale allowScripts pins get-windows was added to apps/desktop without a root allowScripts entry, so npm blocked its node-pre-gyp install script and the win32 prebuilt binding was never downloaded. Every Windows desktop build then died in stage-native-deps, including the updater's headless rebuild, leaving Windows users unable to update the app. The same manifest had drifted twice more: the CVE sweep in 7537de9e74 moved Electron to 40.10.6 and left the electron@40.10.2 pin behind, and website's allowlist still names core-js-pure, which its lockfile no longer resolves, while fsevents runs an install script with no entry at all. Co-authored-by: gsy324 Co-authored-by: elbukott1 Co-authored-by: Brian Franco --- package.json | 5 +++-- website/package.json | 2 +- 2 files changed, 4 insertions(+), 3 deletions(-) diff --git a/package.json b/package.json index 7f9b40649c..b89c014e4b 100644 --- a/package.json +++ b/package.json @@ -71,8 +71,9 @@ "node-pty@1.1.0": true, "electron-winstaller@5.4.0": true, "agent-browser@0.26.0": true, - "electron@40.10.2": true, + "electron@40.10.6": true, "fsevents@2.3.2": true, - "fsevents@2.3.3": true + "fsevents@2.3.3": true, + "get-windows@9.3.0": true } } diff --git a/website/package.json b/website/package.json index 635dbb5fc6..d040d879ef 100644 --- a/website/package.json +++ b/website/package.json @@ -59,6 +59,6 @@ }, "allowScripts": { "core-js@3.49.0": true, - "core-js-pure@3.49.0": true + "fsevents@2.3.3": true } }