-
Notifications
You must be signed in to change notification settings - Fork 236
Dev to staging [WPB-22420] #9735
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
20c9be2
87bc2e2
39c1891
530687e
2e6721f
e1ba98c
d603894
36b9f2c
32203de
105d89b
68b50ca
736e10b
a3be121
b595c11
5e98762
3588bc9
d045c5d
69d1412
19268e6
d051014
8e4120c
0e2ce16
255bdd5
e548ede
277ee43
dce4c28
1781c33
8872a5b
302d927
9244eff
9f0ecab
bd61f11
8e4aa52
6eed77d
f5a2ce3
e83d6f1
035aae9
465f9da
3c78dd5
2906d28
f2fb21b
c8ac863
8d4d461
753e833
ea52c8b
7019b94
30c1c2e
6f9b6a9
4bbd557
4ee56f0
7ea0ebf
d72ec14
0f59bdc
083fe35
4cfa295
e271815
72d7770
4f12b9c
363e26b
c474d07
816e9ef
62b5603
6ca46fd
305882a
d212410
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,34 @@ | ||
| # Renovate is the only dependency-update automation used by this repository. | ||
| # | ||
| # `open-pull-requests-limit: 0` disables Dependabot version-update pull | ||
| # requests. The wildcard ignore rule is also required because security-update | ||
| # pull requests are not subject to that limit. | ||
|
|
||
| version: 2 | ||
|
|
||
| updates: | ||
| - package-ecosystem: 'npm' | ||
| directories: | ||
| - '**/*' | ||
| schedule: | ||
| interval: 'monthly' | ||
| open-pull-requests-limit: 0 | ||
| ignore: | ||
| - dependency-name: '*' | ||
|
|
||
| - package-ecosystem: 'github-actions' | ||
| directory: '/' | ||
| schedule: | ||
| interval: 'monthly' | ||
| open-pull-requests-limit: 0 | ||
| ignore: | ||
| - dependency-name: '*' | ||
|
Comment on lines
+19
to
+25
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Semgrep identified an issue, but thinks it may be safe to ignore. Why this might be safe to ignore:
To resolve this comment: 🔧 No guidance has been designated for this issue. Fix according to your organization's approved methods. 💬 Ignore this findingReply with Semgrep commands to ignore this finding.
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by dependabot-missing-cooldown. You can view more details about this finding in the Semgrep AppSec Platform. |
||
|
|
||
| - package-ecosystem: 'docker' | ||
| directories: | ||
| - '**/*' | ||
| schedule: | ||
| interval: 'monthly' | ||
| open-pull-requests-limit: 0 | ||
| ignore: | ||
| - dependency-name: '*' | ||
|
Comment on lines
+27
to
+34
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Semgrep identified an issue, but thinks it may be safe to ignore. Why this might be safe to ignore:
To resolve this comment: 🔧 No guidance has been designated for this issue. Fix according to your organization's approved methods. 💬 Ignore this findingReply with Semgrep commands to ignore this finding.
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by dependabot-missing-cooldown. You can view more details about this finding in the Semgrep AppSec Platform. |
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,196 @@ | ||
| /* | ||
| * Wire | ||
| * Copyright (C) 2026 Wire Swiss GmbH | ||
| * | ||
| * This program is free software: you can redistribute it and/or modify | ||
| * it under the terms of the GNU General Public License as published by | ||
| * the Free Software Foundation, either version 3 of the License, or | ||
| * (at your option) any later version. | ||
| * | ||
| * This program is distributed in the hope that it will be useful, | ||
| * but WITHOUT ANY WARRANTY; without even the implied warranty of | ||
| * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||
| * GNU General Public License for more details. | ||
| * | ||
| * You should have received a copy of the GNU General Public License | ||
| * along with this program. If not, see http://www.gnu.org/licenses/. | ||
| * | ||
| */ | ||
|
|
||
| import fs from 'fs-extra'; | ||
|
|
||
| import assert from 'node:assert'; | ||
| import os from 'node:os'; | ||
| import path from 'node:path'; | ||
|
|
||
| import {buildWindowsMsiConfig, customizeMsiProject, validateWindowsMsiAppDirectory} from './build-windows-msi'; | ||
|
|
||
| const wireJsonPath = path.join(__dirname, '../../../electron/wire.json'); | ||
| const envFilePath = path.join(__dirname, '../../../.env.defaults'); | ||
| const originalEnvironment = { | ||
| appEnvironment: process.env.APP_ENV, | ||
| appName: process.env.APP_NAME, | ||
| manufacturer: process.env.WIN_MSI_MANUFACTURER, | ||
| upgradeCode: process.env.WIN_MSI_UPGRADE_CODE, | ||
| }; | ||
|
|
||
| function restoreEnvironmentVariable(name: string, value?: string): void { | ||
| if (value === undefined) { | ||
| delete process.env[name]; | ||
| } else { | ||
| process.env[name] = value; | ||
| } | ||
| } | ||
|
|
||
| describe('build-windows-msi', () => { | ||
| afterEach(() => { | ||
| restoreEnvironmentVariable('APP_ENV', originalEnvironment.appEnvironment); | ||
| restoreEnvironmentVariable('APP_NAME', originalEnvironment.appName); | ||
| restoreEnvironmentVariable('WIN_MSI_MANUFACTURER', originalEnvironment.manufacturer); | ||
| restoreEnvironmentVariable('WIN_MSI_UPGRADE_CODE', originalEnvironment.upgradeCode); | ||
| }); | ||
|
|
||
| describe('buildWindowsMsiConfig', () => { | ||
| it('builds a per-machine MSI with a stable production upgrade identity', async () => { | ||
| const {builderConfig, windowsMsiConfig} = await buildWindowsMsiConfig(wireJsonPath, envFilePath, true); | ||
|
|
||
| assert.strictEqual(windowsMsiConfig.appId, 'com.squirrel.wire.wire'); | ||
| assert.strictEqual(windowsMsiConfig.manufacturer, 'Wire Swiss GmbH'); | ||
| assert.strictEqual(windowsMsiConfig.upgradeCode, '620FCDDD-30CB-4241-A347-D34CF682A358'); | ||
| assert.deepStrictEqual(builderConfig.extraMetadata?.author, {name: windowsMsiConfig.manufacturer}); | ||
| assert.strictEqual(builderConfig.msi?.oneClick, false); | ||
| assert.strictEqual(builderConfig.msi?.perMachine, true); | ||
| assert.strictEqual(builderConfig.msi?.runAfterFinish, false); | ||
| assert.strictEqual(builderConfig.msi?.upgradeCode, windowsMsiConfig.upgradeCode); | ||
| assert.strictEqual(typeof builderConfig.win?.signtoolOptions?.sign, 'function'); | ||
| }); | ||
|
|
||
| it('keeps the standard product upgrade identities distinct', async () => { | ||
| process.env.APP_ENV = 'internal'; | ||
| process.env.APP_NAME = 'WireInternal'; | ||
| const internal = await buildWindowsMsiConfig(wireJsonPath, envFilePath); | ||
|
|
||
| process.env.APP_ENV = 'wire-gov'; | ||
| process.env.APP_NAME = 'WireGov'; | ||
| const wireGov = await buildWindowsMsiConfig(wireJsonPath, envFilePath); | ||
|
|
||
| assert.strictEqual(internal.windowsMsiConfig.upgradeCode, '673C5C7F-2923-483B-8EDB-34EDBDFCFF8A'); | ||
| assert.strictEqual(wireGov.windowsMsiConfig.upgradeCode, '0FC26EF0-E415-4263-9C73-89D05BCD4E1A'); | ||
| assert.notStrictEqual(internal.windowsMsiConfig.upgradeCode, wireGov.windowsMsiConfig.upgradeCode); | ||
| }); | ||
|
|
||
| it('honors and normalizes a configured upgrade code', async () => { | ||
| process.env.WIN_MSI_UPGRADE_CODE = '{C88AA646-1E4B-FC0A-005A-8BB72BBADBBB}'; | ||
|
|
||
| const {windowsMsiConfig} = await buildWindowsMsiConfig(wireJsonPath, envFilePath); | ||
|
|
||
| assert.strictEqual(windowsMsiConfig.upgradeCode, 'C88AA646-1E4B-FC0A-005A-8BB72BBADBBB'); | ||
| }); | ||
|
|
||
| it('honors a configured manufacturer', async () => { | ||
| process.env.WIN_MSI_MANUFACTURER = 'Customer Corporation'; | ||
|
|
||
| const {builderConfig, windowsMsiConfig} = await buildWindowsMsiConfig(wireJsonPath, envFilePath); | ||
|
|
||
| assert.strictEqual(windowsMsiConfig.manufacturer, 'Customer Corporation'); | ||
| assert.strictEqual(builderConfig.extraMetadata?.author?.name, windowsMsiConfig.manufacturer); | ||
| }); | ||
|
|
||
| it('rejects an invalid configured upgrade code', async () => { | ||
| process.env.WIN_MSI_UPGRADE_CODE = 'not-a-guid'; | ||
|
|
||
| await assert.rejects(buildWindowsMsiConfig(wireJsonPath, envFilePath), /Invalid Windows MSI upgrade code/); | ||
| }); | ||
|
|
||
| it('requires a dedicated upgrade code for a custom-branded product', async () => { | ||
| process.env.APP_NAME = 'CustomerWire'; | ||
|
|
||
| await assert.rejects(buildWindowsMsiConfig(wireJsonPath, envFilePath), /must define a permanent/); | ||
| }); | ||
| }); | ||
|
|
||
| describe('customizeMsiProject', () => { | ||
| it('regression: detects Windows 10 and later from the actual registry build number', () => { | ||
| const project = `<Product> | ||
| <Condition Message="Windows 7 and above is required"><![CDATA[Installed OR VersionNT >= 601]]></Condition> | ||
| <Component> | ||
| <File Name="Wire.exe" Id="mainExecutable"> | ||
| <Shortcut Id="desktopShortcut" Directory="DesktopFolder" Name="Wire"/> | ||
| </File> | ||
| </Component> | ||
| </Product>`; | ||
|
|
||
| const result = customizeMsiProject(project, 'wire', 'com.squirrel.wire.wire', 'Wire', 'msi-banner.bmp'); | ||
|
|
||
| assert.match(result, /Property Id="WIRE_WINDOWS_BUILD" Secure="yes"/); | ||
| assert.match( | ||
| result, | ||
| /RegistrySearch Id="WireWindowsBuild" Root="HKLM" Key="SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion" Name="CurrentBuildNumber" Type="raw" Win64="yes"/, | ||
| ); | ||
| assert.match(result, /Installed OR WIRE_WINDOWS_BUILD >= 10240/); | ||
| assert.doesNotMatch(result, /VersionNT >= 603 AND WindowsBuild >= 10240/); | ||
| }); | ||
|
|
||
| it('brands the assisted UI and makes the URL protocol and desktop shortcut identity MSI-owned', () => { | ||
| const project = ` | ||
| <Product Name="Wire"> | ||
| <Condition Message="Windows 7 and above is required"><![CDATA[Installed OR VersionNT >= 601]]></Condition> | ||
| <Component> | ||
| <File Name="Wire.exe" Id="mainExecutable"> | ||
| <Shortcut Id="desktopShortcut" Directory="DesktopFolder" Name="Wire"/> | ||
| </File> | ||
| </Component> | ||
| </Product>`; | ||
|
|
||
| const result = customizeMsiProject(project, 'wire', 'com.squirrel.wire.wire', 'Wire', 'msi-banner.bmp'); | ||
|
|
||
| assert.match(result, /WixVariable Id="WixUIBannerBmp" Value="msi-banner\.bmp"/); | ||
| assert.match(result, /Windows 10 or above is required/); | ||
| assert.match(result, /ShortcutProperty Key="System\.AppUserModel\.ID" Value="com\.squirrel\.wire\.wire"/); | ||
| assert.match(result, /RegistryKey Root="HKLM" Key="Software\\Classes\\wire"/); | ||
| assert.match(result, /Value=""\[#mainExecutable\]" "%1""/); | ||
| assert.match(result, /Property Id="WIRE_WEBAPP_URL" Secure="yes"/); | ||
| assert.match(result, /Property Id="WIRE_CLEAR_WEBAPP_URL" Secure="yes"/); | ||
| assert.match( | ||
| result, | ||
| /RegistrySearch Id="WireExistingWebAppUrl" Root="HKLM" Key="Software\\Wire\\Wire" Name="WebAppUrl" Type="raw" Win64="yes"/, | ||
| ); | ||
| assert.match(result, /SetProperty Id="WIRE_WEBAPP_URL" Value="\[WIRE_EXISTING_WEBAPP_URL\]"/); | ||
| assert.match(result, /NOT WIRE_WEBAPP_URL AND NOT WIRE_CLEAR_WEBAPP_URL AND WIRE_EXISTING_WEBAPP_URL/); | ||
| assert.match(result, /RegistryValue Name="WebAppUrl" Type="string" Value="\[WIRE_WEBAPP_URL\]"/); | ||
| }); | ||
|
|
||
| it('fails if electron-builder no longer generates the expected main executable component', () => { | ||
| assert.throws( | ||
| () => customizeMsiProject('<Product/>', 'wire', 'com.squirrel.wire.wire', 'Wire', 'msi-banner.bmp'), | ||
| /Could not find the main executable/, | ||
| ); | ||
| }); | ||
|
|
||
| it('fails if electron-builder no longer generates the expected desktop shortcut', () => { | ||
| const project = `<Product> | ||
| <Condition Message="Windows 7 and above is required"><![CDATA[Installed OR VersionNT >= 601]]></Condition> | ||
| <Component><File Name="Wire.exe" Id="mainExecutable"/></Component> | ||
| </Product>`; | ||
|
|
||
| assert.throws( | ||
| () => customizeMsiProject(project, 'wire', 'com.squirrel.wire.wire', 'Wire', 'msi-banner.bmp'), | ||
| /Could not find the desktop shortcut/, | ||
| ); | ||
| }); | ||
| }); | ||
|
|
||
| describe('validateWindowsMsiAppDirectory', () => { | ||
| it('rejects a directory already mutated by Squirrel packaging', async () => { | ||
| const appDirectory = await fs.mkdtemp(path.join(os.tmpdir(), 'wire-msi-app-directory-')); | ||
| try { | ||
| await fs.ensureFile(path.join(appDirectory, 'Wire.exe')); | ||
| await fs.ensureFile(path.join(appDirectory, 'Squirrel.exe')); | ||
|
|
||
| await assert.rejects(validateWindowsMsiAppDirectory(appDirectory, 'Wire'), /contains the Squirrel updater/); | ||
| } finally { | ||
| await fs.remove(appDirectory); | ||
| } | ||
| }); | ||
| }); | ||
| }); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Semgrep identified an issue, but thinks it may be safe to ignore.
This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. Add a
cooldownblock withdefault-days: 7to eachpackage-ecosystementry underupdatesto wait 7 days before proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldownWhy this might be safe to ignore:
To resolve this comment:
🔧 No guidance has been designated for this issue. Fix according to your organization's approved methods.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasonsAlternatively, triage in Semgrep AppSec Platform to ignore the finding created by dependabot-missing-cooldown.
You can view more details about this finding in the Semgrep AppSec Platform.