Skip to content

chore(deps): weekly npm and Rust dependency refresh - #67

Closed
cursor[bot] wants to merge 1 commit into
nextfrom
cursor/dependency-security-updates-85be
Closed

cursor[bot] wants to merge 1 commit into
nextfrom
cursor/dependency-security-updates-85be

Conversation

@cursor

@cursor cursor Bot commented Sep 26, 2026

Copy link
Copy Markdown

Summary

Weekly dependency refresh for both the bun/npm renderer and the Rust workspace. Includes published Tauri security fixes and matching lockfile updates. Publishers of the new versions match the expected upstream bots (tauri-bot, GitHub Actions, popmotion, adrai, types, napi-rs Trusted Publishing).

Security

  • tauri 2.11.6 — IPC channel queues are now bound per webview (GHSA-w28w-mhc8-qvjv).
  • tauri-plugin-http 2.7.0 — opt-in scopeRedirects so redirect hops are checked against the HTTP scope (GHSA-2rxp-f4w5-6hjr / CVE-2026-95623). Enabled in src-tauri/tauri.conf.json. The JS package is still 2.6.1 (no npm 2.7 yet).
  • tauri-plugin-updater 2.12.0 — allowDowngrades was removed from the check IPC command and is now plugin config only (CVE-2026-95624). This app checks updates from Rust with a custom version comparator, so frontend IPC is not in play. bundle.windows.allowDowngrades is unrelated.
  • bun audit: no vulnerabilities (555 packages).
  • Known malware versions (ChainDrop / Shai-Hulud npm hashes, crates.io arrayref/internment/proc-macro1, logs-update, greentic-setup-dev) are not in either lockfile. Workflows do not use actions-cool/issues-helper or maintain-one-comment.

Dependency bumps

Frontend: @tauri-apps/plugin-updater 2.12.0, @tauri-apps/cli 2.11.5, motion 13.4.4, react-i18next 17.0.15, vite 8.3.1, vitest/@vitest/coverage-v8 5.0.2, jsdom 30.1.1, prettier 3.9.9, typescript-eslint 8.70.1, @types/node 26.6.3.

Rust: tauri 2.11.6, tauri-plugin-http 2.7.0, tauri-plugin-updater 2.12.0, tauri-plugin-single-instance 2.4.5, napi 3.13.0, napi-build 2.5.0, napi-derive 3.6.9, plus cargo update transitives (rustls-platform-verifier 0.7.1 Android Gradle change does not apply to this desktop app).

Intentionally not updated

  • React / @tauri-apps/api majors; Tauri 3.0.0-alpha.2
  • TypeScript 7.0.2 (typescript-eslint 8.x still peers >=4.8.4 <6.1.0)
  • @babel/core 8, undici 8, nanoid 6, zip 9.0.0-pre3, http-cache-reqwest stable 0.16.0 (stay on 1.0.0-alpha.9)

Test plan

  • bun run test — 377 passed
  • cargo test -p quadrant-core -p quadrant-host -p quadrant-napi with dummy creds — passed
  • Full quadrant_next compile needs GTK (gdk-3.0) and was not run in this environment
Open in Web View Automation 

Take Tauri 2.11.6, updater 2.12, and plugin-http 2.7 for published
advisories, plus napi 3.13 and current frontend patches. Enable HTTP
redirect scope checks. Leave React 19, Tauri 3, and TypeScript 7 alone.

Co-authored-by: Demir Yerli <mrquantumoff@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants