Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Electron dependency is vulnerable #43

Open
CrookedGrandma opened this issue Jan 11, 2024 · 0 comments
Open

Electron dependency is vulnerable #43

CrookedGrandma opened this issue Jan 11, 2024 · 0 comments

Comments

@CrookedGrandma
Copy link

Hi,

Both npm audit and the OWASP Dependency Checker list the version of the electron package this package is dependent on (23.1.4) as vulnerable. An update should fix this problem, however it would require a major version upgrade; version 24.8.3 is listed as safe. Would this upgrade disrupt anything?

Source: GHSA-7m48-wc93-9g85

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant