fix(desktop): upgrade Next.js and Electron, gate releases on critical advisories - #147
Merged
Merged
Conversation
graikos
force-pushed
the
fix/nextjs-upgrade
branch
from
October 2, 2026 14:13
937f7df to
46a7f9f
Compare
Collaborator
Author
|
/preview |
graikos
marked this pull request as ready for review
October 2, 2026 14:14
mellowcroc
reviewed
Oct 5, 2026
Collaborator
Author
|
/preview |
Preview EnvironmentComment |
mellowcroc
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes F-2026-19193 (Medium): Packaged Windows Desktop Uses a Next.js Version Affected by Unauthenticated Remote Code Execution. It covers the finding's upgrade and release-gate recommendations; the loopback capability token is left as follow-up (below).
The desktop app forks the Next.js standalone server on
127.0.0.1:5051. We shipped Next 14.2.35, and GHSA-p293-qw3h-jr36 (unauthenticated RCE on Windows-hosted servers) covers every release from 13.4.0 up to 15.5.24. No 14.x release fixes it, so this PR moves to the 15.5 line. Electron 43.1.0, the other framework in the packaged app, had four high-severity advisories fixed in 43.4.1, so it moves too.Changes
next^15.5.26 inuianddesktop(one copy in the lockfile, so the standalone tree cannot trace an older one).react,react-dom,@types/react,@types/react-dom^19.2 (resolved 19.3.0), which the Next 15 App Router requires.outputFileTracingRootmoves out ofexperimental, as Next 15 expects.next-env.d.tsregenerated by Next 15.electron^43.7.6 (was 43.1.0): fixes GHSA-gr2m-v5gq-v685, GHSA-j84w-jfhq-vhvj, GHSA-9qh4-3jw8-366w, GHSA-qmv3-fv6v-rmhq.desktop-release.ymlrunsbun audit --audit-level=criticalon every leg after install and stops before packaging on any critical advisory. It passes today; it would have caught the Next advisory.15.5 keeps webpack as the default builder, so our webpack block (no minification because of the BigInt bug, WASM, top-level await, the mina-signer alias) is unchanged. Next 16 builds with Turbopack by default and would need that block ported. Every page is already a client component, so Next 15's async
paramschange does not apply. Next 15 addssharpas an optional dependency; we do not usenext/image.Testing
bun run --filter ui buildandbun run --filter ui test(14 pass).bun run --filter desktop build,electron-builder --dir --linux,bun run --filter desktop test(7 pass).next15.5.26, React 19.3.0 and Electron 43.7.6, with no older copy.MinaGuard.compile()finishes in the browser with the VK incontracts/.vk-hash.next devserves every route, with no React warnings in the browser.bun audit --audit-level=criticalexits 0;--audit-level=highexits 1 (build-time tooling only), so the gate discriminates.test:ui,test:e2e(CI runs both), and the Windows installer.resources/ui-standalone/ui/node_modules/next/package.jsonat 15.5.26.Not in this PR
qsmoderate advisories viaexpress(backend; needs an override past express's~6.15range).postcss,js-yaml,fast-uri,tar,@xmldom/xmldom, installerundici): none ship or see untrusted input.