chore: Update electron-builder v26.0.3 #3047
Merged
+185
−105
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🔐 Security Enhancement: Electron-Builder v26.0.3 + ASAR Integrity Protection
Upgrades electron-builder to v26.0.3 and implements ASAR integrity validation to prevent malicious app.asar replacement attacks (e.g., Loki C2, MITRE ATT&CK T1218.015).
✅ Security Improvements
true
(blocks malicious ASAR files)true
(prevents external code injection)🎯 Smart Implementation
Rocket.Chat.exe
), Linux (rocketchat-desktop
), macOS (Rocket.Chat.app
)🛠️ Technical Changes
electron-builder
:25.1.8
→26.0.3
afterPack
hook for platform-specific fuse applicationpublisherName
,signDlls
,StartupWMClass
,MimeType
Closes: CORE-1069 - Protects against documented Electron security vulnerabilities while maintaining all distribution channels.
https://rocketchat.atlassian.net/browse/CORE-1069