Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump electron version from 27.1.3 to 27.3.10 #29421

Closed
wants to merge 4 commits into from

Conversation

0x4248
Copy link

@0x4248 0x4248 commented Apr 27, 2024

This PR bumps the electon version to fix a out-of-bounds vulnerability.

Sources

Chrome releases
Synk

PR Tasks

@CLAassistant
Copy link

CLAassistant commented Apr 27, 2024

CLA assistant check
All committers have signed the CLA.

@cypress-app-bot
Copy link
Collaborator

@0x4248 0x4248 changed the title Update package.json Update package.json to patch vulnerable package Apr 27, 2024
@jennifer-shehane
Copy link
Member

@0x4248 Thanks for surfacing. We'll need to evaluate what this change means for us since we heavily rely on Electron's logic.

@ryanthemanuel ryanthemanuel changed the title Update package.json to patch vulnerable package chore(deps): bump electron version from 27.1.3 to 27.3.10 Apr 29, 2024
@jennifer-shehane
Copy link
Member

@0x4248 Again, thanks for surfacing this! We'll have to close this PR and open a new one since outside contributors don't have the necessary permissions we'll need to rebuild the binary to make this change complete.

@0x4248
Copy link
Author

0x4248 commented Apr 29, 2024

Ok, thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

5 participants