Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade electron from 10.1.5 to 10.4.7 #71

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link
Contributor

Snyk has created this PR to upgrade electron from 10.1.5 to 10.4.7.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 14 versions ahead of your current version.
  • The recommended version was released a year ago, on 2021-05-24.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Heap-based Buffer Overflow
SNYK-JS-ELECTRON-1296565
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Race Condition
SNYK-JS-ELECTRON-1296563
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Use After Free
SNYK-JS-ELECTRON-1296561
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Type Confusion
SNYK-JS-ELECTRON-1296559
579/1000
Why? Has a fix available, CVSS 7.3
Proof of Concept
Use After Free
SNYK-JS-ELECTRON-1296557
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Heap-based Buffer Overflow
SNYK-JS-ELECTRON-1296555
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Heap-based Buffer Overflow
SNYK-JS-ELECTRON-1296553
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Integer Overflow
SNYK-JS-ELECTRON-1277205
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Heap-based Buffer Overflow
SNYK-JS-ELECTRON-1277203
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Out-of-bounds Read
SNYK-JS-ELECTRON-1261111
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Integer Overflow or Wraparound
SNYK-JS-ELECTRON-1260586
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Use After Free
SNYK-JS-ELECTRON-1259349
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Use After Free
SNYK-JS-ELECTRON-1258207
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Use After Free
SNYK-JS-ELECTRON-1253281
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Use After Free
SNYK-JS-ELECTRON-1253279
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Use After Free
SNYK-JS-ELECTRON-1252280
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Use After Free
SNYK-JS-ELECTRON-1252279
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Insecure Defaults
SNYK-JS-ELECTRON-1088602
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Out-of-bounds Write
SNYK-JS-ELECTRON-1088600
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Use After Free
SNYK-JS-ELECTRON-1087442
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Improper Input Validation
SNYK-JS-ELECTRON-1086695
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Out-of-Bounds
SNYK-JS-ELECTRON-1086693
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Out-of-Bounds
SNYK-JS-ELECTRON-1085996
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Use After Free
SNYK-JS-ELECTRON-1085994
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Use After Free
SNYK-JS-ELECTRON-1085705
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Heap Buffer Overflow
SNYK-JS-ELECTRON-1085647
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Insufficient Validation
SNYK-JS-ELECTRON-1070014
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Out-of-bounds Read
SNYK-JS-ELECTRON-1051000
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Insufficient Validation
SNYK-JS-ELECTRON-1050882
579/1000
Why? Has a fix available, CVSS 7.3
Mature
Use After Free
SNYK-JS-ELECTRON-1050424
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Use After Free
SNYK-JS-ELECTRON-1049547
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Improper Input Validation
SNYK-JS-ELECTRON-1049323
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Improper Access Control
SNYK-JS-ELECTRON-1049321
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Heap-based Buffer Overflow
SNYK-JS-ELECTRON-1048693
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Improper Validation
SNYK-JS-ELECTRON-1047306
579/1000
Why? Has a fix available, CVSS 7.3
Mature
Use After Free
SNYK-JS-ELECTRON-1041745
579/1000
Why? Has a fix available, CVSS 7.3
Mature
Improper Input Validation
SNYK-JS-ELECTRON-1277526
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Access Restriction Bypass
SNYK-JS-ELECTRON-1086694
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Information Exposure
SNYK-JS-ELECTRON-1085998
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Use After Free
SNYK-JS-ELECTRON-1070015
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Information Exposure
SNYK-JS-ELECTRON-1065981
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Information Exposure
SNYK-JS-ELECTRON-1050427
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Prototype Pollution
SNYK-JS-MINIMIST-2429795
579/1000
Why? Has a fix available, CVSS 7.3
Proof of Concept
Out Of Bounds Read
SNYK-JS-ELECTRON-1278596
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit
Out-of-bounds
SNYK-JS-ELECTRON-1257943
579/1000
Why? Has a fix available, CVSS 7.3
Mature
Use After Free
SNYK-JS-ELECTRON-1050999
579/1000
Why? Has a fix available, CVSS 7.3
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: electron
  • 10.4.7 - 2021-05-24

    Release Notes for v10.4.7

    Other Changes

    End of Support for 10.x.y

    Electron 10.x.y has reached end-of-support as per the project's support policy. Developers and applications are encouraged to upgrade to a newer version of Electron.

  • 10.4.6 - 2021-05-19

    Release Notes for v10.4.6

    Fixes

    • Fixed <webview> focus / blur events not working with contextIsolation enabled. #29026 (Also in 11, 12, 13)
    • Fixed an issue where events on webview elements were missing properties if contextIsolation was enabled. #29143 (Also in 11)
  • 10.4.5 - 2021-05-05
  • 10.4.4 - 2021-04-27
  • 10.4.3 - 2021-04-14
  • 10.4.2 - 2021-03-23
  • 10.4.1 - 2021-03-15
  • 10.4.0 - 2021-02-20
  • 10.3.2 - 2021-02-05
  • 10.3.1 - 2021-01-27
  • 10.3.0 - 2021-01-15
  • 10.2.0 - 2020-12-12
  • 10.1.7 - 2020-12-08
  • 10.1.6 - 2020-11-18
  • 10.1.5 - 2020-10-23
from electron GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant