build: update electron to 43 and keep node_modules out of the asar
Electron 40 is affected by GHSA-9f4c-93c8-jc8g (CVSS 7.2): a sandboxed iframe can bypass the allow-popups restriction through the OpenURL navigation path. Motionity renders no iframes, so the practical exposure was near zero, but Electron only patches its latest three majors — on 40 there would be no fix for the next advisory either. npm audit now reports zero vulnerabilities. electron/main.js needed no changes: it uses only APIs stable across 40 to 43. While verifying the packaged output, the asar turned out to carry @ffmpeg's transitive dependencies (node-fetch, whatwg-url, regenerator-runtime and friends). The app loads the vendored UMD bundle from src/vendor/ffmpeg/ and requires nothing outside electron and node builtins, so build.files now excludes node_modules wholesale instead of naming @ffmpeg — the same result without having to track a dependency tree that is not ours. Verified: electron-builder 26.15.3 packages electron 43.4.0, and the asar contains the five vendored ffmpeg files and zero node_modules entries. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
+2
-2
@@ -27,7 +27,7 @@
|
||||
"@ffmpeg/ffmpeg": "^0.11.6"
|
||||
},
|
||||
"devDependencies": {
|
||||
"electron": "^40.0.0",
|
||||
"electron": "^43.4.0",
|
||||
"electron-builder": "^26.0.0"
|
||||
},
|
||||
"build": {
|
||||
@@ -43,7 +43,7 @@
|
||||
"scripts/server.cjs",
|
||||
"src/**/*",
|
||||
"!src/**/*.map",
|
||||
"!node_modules/@ffmpeg/**"
|
||||
"!node_modules/**"
|
||||
],
|
||||
"win": {
|
||||
"target": [
|
||||
|
||||
Reference in New Issue
Block a user