Skip to content

chore(deps-dev): bump electron from 41.7.1 to 41.10.3 - #464

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/electron-41.10.3
Open

chore(deps-dev): bump electron from 41.7.1 to 41.10.3#464
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/electron-41.10.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 7, 2026

Copy link
Copy Markdown
Contributor

Bumps electron from 41.7.1 to 41.10.3.

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 7, 2026
@dependabot
dependabot Bot requested a review from tomymaritano as a code owner August 7, 2026 08:22
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 7, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) August 7, 2026 08:23
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/electron-41.10.3 branch 14 times, most recently from 60c48a5 to 91e49b1 Compare August 20, 2026 18:24
tomymaritano added a commit that referenced this pull request Aug 22, 2026
<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
## Summary

Dependabot PRs fail the required `e2e` check in ~20s during `pnpm
install`, not during Playwright. Automerge is already enabled; it cannot
land while e2e is red.

**Exact failure** (PR #482 job
[96541625973](https://github.com/dripnex/app/actions/runs/32404870524/job/96541625973),
also #464 / #456 / #462 and `commitlint` on #464):

```
ERROR  Command failed with exit code 128: git clone git@github.com:electron/node-gyp.git ...
git@github.com: Permission denied (publickey).
```

This is not missing repo secrets. Dependabot-regenerated lockfiles
resolve `@electron/node-gyp` as a git dep whose `resolution.repo` is
SSH:

```
# PR #456 (shell-quote) lockfile
'@electron/node-gyp@git+https://git@github.com:electron/node-gyp.git#06b29aa...'
resolution: {commit: 06b29aa..., repo: git@github.com:electron/node-gyp.git, type: git}

# develop lockfile (e2e green after #541)
'@electron/node-gyp@https://codeload.github.com/electron/node-gyp/tar.gz/06b29aa...'
resolution: {tarball: https://codeload.github.com/electron/node-gyp/tar.gz/06b29aa...}
```

pnpm clones `resolution.repo` over SSH. GitHub-hosted runners have no
deploy key.

The `setup` job already rewrites SSH to HTTPS and therefore succeeds on
the same PRs. `e2e` and `commitlint` did a fresh `pnpm install` without
that rewrite.

`develop` itself is green after #541 — its lockfile uses the HTTPS
tarball, so e2e never hits the SSH clone.

## Type of Change

- [x] Bug fix
- [ ] New feature
- [ ] Breaking change
- [ ] Documentation update

## Fix

Add the same `git config --global 'url.https://github.com/.insteadOf'
'git@github.com:'` step that `setup` / `release` / `build` / `docs`
already use:

- `.github/workflows/ci.yml` `e2e` job — unblocks the required e2e check
- `.github/workflows/pr-title.yml` — same SSH death on Dependabot
lockfiles

Existing Dependabot PRs (#482, #464, #462, #460, #459, #456, #451, #431,
#430, #248) should go green after rebase onto this `develop` change (the
merge commit picks up the workflow).

## Related Issues

Closes #544

## Checklist

- [x] I've read [CONTRIBUTING.md](../CONTRIBUTING.md)
- [ ] Tests pass locally (`pnpm test`) — workflow-only change; no
product code
- [ ] Build succeeds (`pnpm build`) — not applicable
- [x] PR targets `develop` branch (not `main`)

<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a
href="https://cursor.com/agents/bc-65d9f024-2af5-4bbe-8318-35ae4db127d2?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-65d9f024-2af5-4bbe-8318-35ae4db127d2&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/electron-41.10.3 branch 4 times, most recently from ce52b8d to 296fef1 Compare August 26, 2026 14:23
Bumps [electron](https://github.com/electron/electron) from 41.7.1 to 41.10.3.
- [Commits](electron/electron@v41.7.1...v41.10.3)

---
updated-dependencies:
- dependency-name: electron
  dependency-version: 41.10.3
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/electron-41.10.3 branch from 296fef1 to 9e03069 Compare August 29, 2026 00:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

app:desktop dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code size/L

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants