chore(deps): bump builder-util-runtime and electron-builder - #1938
chore(deps): bump builder-util-runtime and electron-builder#1938dependabot[bot] wants to merge 1 commit into
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
920d3f2 to
52842c3
Compare
enyst
left a comment
There was a problem hiding this comment.
🟡 Acceptable
[CRITICAL ISSUES]
- [package-lock.json] Supply Chain Risk: This resolution includes artifacts inside the seven-day guardrail:
brace-expansion@5.0.8(2026-07-23 11:39 UTC),fs-extra@11.4.0(2026-07-23 19:52 UTC),undici@6.28.0(2026-07-24 12:55 UTC),tar@7.5.22(2026-07-24 15:48 UTC), andsax@1.6.1(2026-07-24 18:50 UTC). Do not approve or merge before the newest artifact reaches seven days, after 2026-07-31 18:50 UTC.
The Electron Builder release itself has signed npm artifacts and provenance, but the fresh transitive artifacts still trigger the repository policy. This PR also resolves to the same lockfile state as the companion Electron Builder Dependabot PR, so only one should eventually be merged.
[RISK ASSESSMENT]
- [Overall PR]
⚠️ Risk Assessment: 🟡 MEDIUM
The build tool has broad packaging access and introduces several newly resolved dependencies; freshness is the blocking signal.
VERDICT: ❌ Needs waiting
KEY INSIGHT: The direct dependency is established, but the resolved artifact set is not yet old enough for autonomous approval.
Improve this review? If any feedback above seems incorrect or irrelevant to this repository, you can teach the reviewer to do better:
- Add a
.agents/skills/custom-codereview-guide.mdfile to your branch (or edit it if one already exists) with the/codereviewtrigger and the context the reviewer is missing. See the customization docs.- Re-request a review; the reviewer reads guidelines from the PR branch.
- When merged, the guideline goes through normal code review.
Resolve with AI? Install the iterate skill and run
/iterate.Was this review helpful? React with 👍 or 👎.
This review was generated by an AI agent (OpenHands) on behalf of the reviewer.
52842c3 to
0b76e3a
Compare
0b76e3a to
1b5b275
Compare
1b5b275 to
cc4a98e
Compare
cc4a98e to
6cacb2c
Compare
6cacb2c to
d78a1cd
Compare
d78a1cd to
612471c
Compare
612471c to
48103de
Compare
Bumps [builder-util-runtime](https://github.com/electron-userland/electron-builder/tree/HEAD/packages/builder-util-runtime) to 9.7.0 and updates ancestor dependency [electron-builder](https://github.com/electron-userland/electron-builder/tree/HEAD/packages/electron-builder). These dependencies need to be updated together. Updates `builder-util-runtime` from 9.5.1 to 9.7.0 - [Release notes](https://github.com/electron-userland/electron-builder/releases) - [Changelog](https://github.com/electron-userland/electron-builder/blob/master/packages/builder-util-runtime/CHANGELOG.md) - [Commits](https://github.com/electron-userland/electron-builder/commits/HEAD/packages/builder-util-runtime) Updates `electron-builder` from 26.8.1 to 26.15.3 - [Release notes](https://github.com/electron-userland/electron-builder/releases) - [Changelog](https://github.com/electron-userland/electron-builder/blob/master/packages/electron-builder/CHANGELOG.md) - [Commits](https://github.com/electron-userland/electron-builder/commits/electron-builder@26.15.3/packages/electron-builder) --- updated-dependencies: - dependency-name: builder-util-runtime dependency-version: 9.7.0 dependency-type: indirect - dependency-name: electron-builder dependency-version: 26.15.3 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
48103de to
16184f4
Compare
✅ Mock-LLM E2E Tests60/60 passed Commit: Details
Posted by the Mock-LLM E2E workflow · results are deterministic (scripted LLM responses) |
✅ Mock-LLM Docker E2E Test Results60/60 passed Commit: Details
Posted by the Mock-LLM E2E workflow · results are deterministic (scripted LLM responses) |
|
This repository has moved to https://github.com/OpenHands/OpenHands. We’d appreciate it if you re-opened this pull request there. Thank you! |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps builder-util-runtime to 9.7.0 and updates ancestor dependency electron-builder. These dependencies need to be updated together.
Updates
builder-util-runtimefrom 9.5.1 to 9.7.0Changelog
Sourced from builder-util-runtime's changelog.
Commits
Updates
electron-builderfrom 26.8.1 to 26.15.3Release notes
Sourced from electron-builder's releases.
... (truncated)
Changelog
Sourced from electron-builder's changelog.
... (truncated)
Commits
512a57echore(deploy): Release v26.15.3 (#9858)a6117b3chore(deploy): Release v26.15.2 (#9848)d57f094chore(deploy): Release v26.15.1 (#9842)bed3a9cchore(deploy): Release v26.15.0 (electron-updater@6.8.9) (#9825)198c10cchore: replace app-builder-binnode-dep-treeandrebuild-node-modules(#9...e236392chore(deploy): Release v26.14.0 (#9812)72d298cchore(deploy): Release v26.13.1 (#9805)ffd11c7chore(deploy): Release v26.13.0 (electron-updater@6.8.8) (#9793)2c8c71achore(deploy): Release v26.12.1 (electron-updater@6.8.7) (#9782)d6a5aeefix: harden generated-file output, argument construction, and download valida...🐳 Docker images for this PR
• GHCR package: https://github.com/OpenHands/agent-canvas/pkgs/container/agent-canvas
ghcr.io/openhands/agent-canvasghcr.io/openhands/agent-server:1.37.0-pythonopenhands-automation==1.3.116184f4c75579a0746617aebaae4cba5d87273cePull (multi-arch manifest)
# Multi-arch manifest — Docker automatically pulls the correct architecture docker pull ghcr.io/openhands/agent-canvas:sha-16184f4Run
All tags pushed for this build
About Multi-Architecture Support
sha-16184f4) is a multi-arch manifest supporting both amd64 and arm64sha-16184f4-amd64) are also available if needed