Skip to content

fix(desktop): upgrade Next.js and Electron, gate releases on critical advisories - #147

Merged
graikos merged 10 commits into
mainfrom
fix/nextjs-upgrade
Oct 6, 2026
Merged

graikos merged 10 commits into
mainfrom
fix/nextjs-upgrade

Conversation

@graikos

@graikos graikos commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator

Fixes F-2026-19193 (Medium): Packaged Windows Desktop Uses a Next.js Version Affected by Unauthenticated Remote Code Execution. It covers the finding's upgrade and release-gate recommendations; the loopback capability token is left as follow-up (below).

The desktop app forks the Next.js standalone server on 127.0.0.1:5051. We shipped Next 14.2.35, and GHSA-p293-qw3h-jr36 (unauthenticated RCE on Windows-hosted servers) covers every release from 13.4.0 up to 15.5.24. No 14.x release fixes it, so this PR moves to the 15.5 line. Electron 43.1.0, the other framework in the packaged app, had four high-severity advisories fixed in 43.4.1, so it moves too.

Changes

  • next ^15.5.26 in ui and desktop (one copy in the lockfile, so the standalone tree cannot trace an older one).
  • react, react-dom, @types/react, @types/react-dom ^19.2 (resolved 19.3.0), which the Next 15 App Router requires.
  • outputFileTracingRoot moves out of experimental, as Next 15 expects. next-env.d.ts regenerated by Next 15.
  • electron ^43.7.6 (was 43.1.0): fixes GHSA-gr2m-v5gq-v685, GHSA-j84w-jfhq-vhvj, GHSA-9qh4-3jw8-366w, GHSA-qmv3-fv6v-rmhq.
  • desktop-release.yml runs bun audit --audit-level=critical on every leg after install and stops before packaging on any critical advisory. It passes today; it would have caught the Next advisory.
  • Desktop audit guide and README record the version floor and the gate.

15.5 keeps webpack as the default builder, so our webpack block (no minification because of the BigInt bug, WASM, top-level await, the mina-signer alias) is unchanged. Next 16 builds with Turbopack by default and would need that block ported. Every page is already a client component, so Next 15's async params change does not apply. Next 15 adds sharp as an optional dependency; we do not use next/image.

Testing

  • UI typecheck against React 19 types: clean.
  • bun run --filter ui build and bun run --filter ui test (14 pass).
  • bun run --filter desktop build, electron-builder --dir --linux, bun run --filter desktop test (7 pass).
  • The packaged app contains next 15.5.26, React 19.3.0 and Electron 43.7.6, with no older copy.
  • Served the packaged UI and loaded it in headless Chromium: hydration works, cross-origin isolation holds, the o1js worker loads, and MinaGuard.compile() finishes in the browser with the VK in contracts/.vk-hash.
  • next dev serves every route, with no React warnings in the browser.
  • Desktop app on a Fedora host: opens and runs vault flows.
  • bun audit --audit-level=critical exits 0; --audit-level=high exits 1 (build-time tooling only), so the gate discriminates.
  • Not run locally: test:ui, test:e2e (CI runs both), and the Windows installer.
  • Still to verify: the Windows artifact from the desktop-release dry run should contain resources/ui-standalone/ui/node_modules/next/package.json at 15.5.26.

Not in this PR

  • A per-launch capability token on the loopback Next server (defense in depth).
  • qs moderate advisories via express (backend; needs an override past express's ~6.15 range).
  • High advisories in build-time tooling (postcss, js-yaml, fast-uri, tar, @xmldom/xmldom, installer undici): none ship or see untrusted input.

@graikos
graikos force-pushed the fix/nextjs-upgrade branch from 937f7df to 46a7f9f Compare October 2, 2026 14:13
@graikos

graikos commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator Author

/preview

@graikos
graikos marked this pull request as ready for review October 2, 2026 14:14
@graikos
graikos requested a review from mellowcroc October 5, 2026 07:56
Comment thread .github/workflows/desktop-release.yml
Comment thread docs/desktop-audit-guide.md Outdated
@graikos

graikos commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator Author

/preview

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Preview Environment

Service URL
Frontend https://mina-nodes.duckdns.org/preview/147/
API https://mina-nodes.duckdns.org/preview/147/health
GraphQL https://mina-nodes.duckdns.org/preview/147/graphql
Accounts https://mina-nodes.duckdns.org/preview/147/accounts/acquire-account
Explorer https://mina-nodes.duckdns.org/preview/147/explorer

Comment /preview down to tear this down; it is also removed automatically when the PR closes.

@graikos
graikos requested a review from mellowcroc October 5, 2026 12:54
@graikos
graikos merged commit a907be4 into main Oct 6, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants