Files
twenty/packages/twenty-companion
Charles Bochet f19d8ff7e9 security: bump electron 36 → 39 in twenty-companion (#21327)
Clears the Electron advisory batch (use-after-free, IPC scoping, origin
handling, ASAR integrity, …) — patched in **39.8.5+**, resolves to
**39.8.10**.

- `twenty-companion` is the standalone desktop companion app
(electron-forge; @electron-forge 7.8 supports Electron 39). Main-process
code only uses basic `require('electron')` APIs, stable across 36→39.
- Lockfile + manifest only; gate-safe; hardened install clean.

⚠️ **Verification caveat:** there's no CI job that builds/tests
twenty-companion, so this isn't exercised by CI, and I couldn't verify
runtime locally (electron-forge packaging downloads the ~100MB Electron
binary / needs a display, and the repo's `enableScripts: false` skips
the binary). **Recommend a manual smoke test** (`yarn make`/`start` in
twenty-companion) before relying on the bump.
2026-06-08 17:15:33 +02:00
..
2026-03-04 14:11:57 +00:00
2026-03-04 14:11:57 +00:00
2026-03-04 14:11:57 +00:00
2026-03-04 14:11:57 +00:00
2026-03-04 14:11:57 +00:00
2026-03-04 14:11:57 +00:00
2026-03-04 14:11:57 +00:00
2026-03-04 14:11:57 +00:00
2026-03-04 14:11:57 +00:00
2026-03-04 14:11:57 +00:00

Twenty Desktop

WARNING: This application is a Proof of Concept (POC) and must NOT be used in production. It is intended for demonstration and experimentation purposes only. Security, stability, and performance have not been validated for production use.

This is a demo application that shows off what you can build with the Recall.ai Desktop Recording SDK.

This repo is intended to be a mockup of the kind of experience you can build using the Desktop Recording SDK.

Need help? Reach out to our support team support@recall.ai.

Setup

  • Copy the env.example file to a .env file:

    • cp .env.example .env
  • Replace RECALLAI_API_URL with the base URL for the Recall region that you're using that matches your API key, example:

    • RECALLAI_API_URL=https://us-east-1.recall.ai
  • Modify .env to include your Recall.ai API key:

    • RECALLAI_API_KEY=<your key>

Required: This project also uses live transcription with Assembly AI. You'll need to configure your own Assembly credentials on the Recall.ai dashboard. Follow our AssemblyAI real-time transcription guide to set this up.

If you want to enable the AI summary after a recording is finished, you can specify an OpenRouter API key.

OPENROUTER_KEY=<your key>

Twenty CRM Integration (optional)

To automatically create callRecording records in Twenty when a meeting starts (and mark them as ended when the meeting closes), configure:

TWENTY_API_URL=http://localhost:3000
TWENTY_API_KEY=<your key>

The call-recording Twenty app must be installed in your workspace first (packages/twenty-apps/internal/call-recording). Generate an API key at <your-twenty-instance>/settings/api-webhooks.

To launch the Twenty Desktop application, start the server first, then the app:

npm ci
npm start

Screenshots

Screenshot 2025-06-16 at 10 10 57 PM Screenshot 2025-06-16 at 10 22 44 PM Screenshot 2025-06-16 at 10 14 38 PM