Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: upgrade extract-zip for installer #34166

Merged
merged 1 commit into from May 12, 2022

Conversation

samuelmaddock
Copy link
Member

@samuelmaddock samuelmaddock commented May 10, 2022

Description of Change

extract-zip@^1.0.3 indirectly depends on minimist@0.0.8 which is affected by CVE-2021-44906.

By upgrading this package, it requires updating our minimum version of Node required by the Electron npm installer.

Followup: does CI run tests against the npm package scripts?

Checklist

  • PR description included and stakeholders cc'd
  • npm test passes

Release Notes

Notes: Minimum required node version to install the electron npm package is now >10

@samuelmaddock samuelmaddock requested a review from a team as a code owner May 10, 2022 22:58
@electron-cation electron-cation bot added the new-pr 🌱 PR opened in the last 24 hours label May 10, 2022
npm/install.js Outdated Show resolved Hide resolved
@MarshallOfSound MarshallOfSound added semver/major incompatible API changes and removed semver/none labels May 10, 2022
@codebytere codebytere merged commit ff5f663 into electron:main May 12, 2022
@release-clerk
Copy link

release-clerk bot commented May 12, 2022

Release Notes Persisted

Minimum required node version to install the electron npm package is now >10

@MarshallOfSound MarshallOfSound deleted the upgrade-extract-zip branch May 12, 2022 09:40
khalwa pushed a commit to solarwindscloud/electron that referenced this pull request Feb 22, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
api-review/requested 🗳 new-pr 🌱 PR opened in the last 24 hours no-backport semver/major incompatible API changes
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants