Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade electron from 23.1.2 to 31.7.2 #106

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

karencapiiro
Copy link

snyk-top-banner

Snyk has created this PR to fix 13 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

  • packages/react-devtools/package.json

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning
Failed to update the yarn.lock, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
medium severity Heap-based Buffer Overflow
SNYK-JS-ELECTRON-8302899
  864  
high severity Out-of-bounds Read
SNYK-JS-ELECTRON-8230426
  212  
high severity Use After Free
SNYK-JS-ELECTRON-8302881
  211  
high severity External Control of Assumed-Immutable Web Parameter
SNYK-JS-ELECTRON-8302883
  211  
high severity Heap-based Buffer Overflow
SNYK-JS-ELECTRON-8302885
  211  
high severity Use After Free
SNYK-JS-ELECTRON-8302887
  211  
critical severity Out-of-Bounds Write
SNYK-JS-ELECTRON-8302889
  211  
high severity Type Confusion
SNYK-JS-ELECTRON-8302891
  211  
high severity Heap-based Buffer Overflow
SNYK-JS-ELECTRON-8302893
  211  
high severity Heap-based Buffer Overflow
SNYK-JS-ELECTRON-8302895
  211  
medium severity Heap-based Buffer Overflow
SNYK-JS-ELECTRON-8302897
  211  
high severity Out-of-bounds Read
SNYK-JS-ELECTRON-8302877
  193  
medium severity Type Confusion
SNYK-JS-ELECTRON-8302879
  155  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Type Confusion
🦉 Use After Free

@rafikmojr
Copy link
Collaborator

Logo
Checkmarx One – Scan Summary & Detailsfde9f7c4-b237-4f0d-9273-42e696753dc8

New Issues

Severity Issue Source File / Package Checkmarx Insight
CRITICAL CVE-2024-40643 Npm-htmlparser2-3.10.1 Vulnerable Package
CRITICAL CVE-2024-40643 Npm-htmlparser2-3.3.0 Vulnerable Package
CRITICAL CVE-2024-48949 Npm-elliptic-6.5.4 Vulnerable Package
CRITICAL CVE-2024-48949 Npm-elliptic-6.5.3 Vulnerable Package
CRITICAL CVE-2024-48949 Npm-elliptic-6.4.0 Vulnerable Package
HIGH CVE-2022-21213 Npm-mout-1.1.0 Vulnerable Package
HIGH CVE-2022-37620 Npm-html-minifier-3.5.3 Vulnerable Package
HIGH CVE-2022-37620 Npm-html-minifier-3.5.21 Vulnerable Package
HIGH CVE-2022-37620 Npm-html-minifier-3.2.3 Vulnerable Package
HIGH CVE-2022-37620 Npm-html-minifier-3.5.6 Vulnerable Package
HIGH CVE-2024-21536 Npm-http-proxy-middleware-0.17.4 Vulnerable Package
HIGH CVE-2024-21536 Npm-http-proxy-middleware-0.17.3 Vulnerable Package
HIGH CVE-2024-21536 Npm-http-proxy-middleware-2.0.6 Vulnerable Package
HIGH CVE-2024-29415 Npm-ip-1.1.5 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-7.2.3 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-3.3.2 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-7.5.9 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-7.2.1 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-8.13.0 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-8.12.0 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-7.5.5 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-6.2.2 Vulnerable Package
HIGH CVE-2024-4068 Npm-braces-2.3.2 Vulnerable Package
HIGH CVE-2024-4068 Npm-braces-3.0.2 Vulnerable Package
HIGH CVE-2024-4068 Npm-braces-1.8.5 Vulnerable Package
HIGH CVE-2024-45296 Npm-path-to-regexp-0.1.7 Vulnerable Package
HIGH CVE-2024-45296 Npm-path-to-regexp-1.8.0 Vulnerable Package
HIGH CVE-2024-45296 Npm-path-to-regexp-1.7.0 Vulnerable Package
HIGH CVE-2024-45590 Npm-body-parser-1.20.2 Vulnerable Package
HIGH CVE-2024-45590 Npm-body-parser-1.18.2 Vulnerable Package
HIGH CVE-2024-45590 Npm-body-parser-1.20.1 Vulnerable Package
HIGH CVE-2024-45590 Npm-body-parser-1.19.0 Vulnerable Package
MEDIUM CVE-2020-8244 Npm-bl-3.0.0 Vulnerable Package
MEDIUM CVE-2020-8244 Npm-bl-1.2.1 Vulnerable Package
MEDIUM CVE-2024-38999 Npm-requirejs-2.3.5 Vulnerable Package
MEDIUM CVE-2024-4067 Npm-micromatch-4.0.2 Vulnerable Package
MEDIUM CVE-2024-4067 Npm-micromatch-2.3.11 Vulnerable Package
MEDIUM CVE-2024-4067 Npm-micromatch-3.1.10 Vulnerable Package
MEDIUM CVE-2024-4067 Npm-micromatch-4.0.4 Vulnerable Package
MEDIUM CVE-2024-4067 Npm-micromatch-4.0.5 Vulnerable Package
MEDIUM CVE-2024-42459 Npm-elliptic-6.4.0 Vulnerable Package
MEDIUM CVE-2024-42459 Npm-elliptic-6.5.3 Vulnerable Package
MEDIUM CVE-2024-42459 Npm-elliptic-6.5.4 Vulnerable Package
MEDIUM CVE-2024-42460 Npm-elliptic-6.5.3 Vulnerable Package
MEDIUM CVE-2024-42460 Npm-elliptic-6.4.0 Vulnerable Package
MEDIUM CVE-2024-42460 Npm-elliptic-6.5.4 Vulnerable Package
MEDIUM CVE-2024-42461 Npm-elliptic-6.4.0 Vulnerable Package
MEDIUM CVE-2024-42461 Npm-elliptic-6.5.3 Vulnerable Package
MEDIUM CVE-2024-42461 Npm-elliptic-6.5.4 Vulnerable Package
MEDIUM CVE-2024-43788 Npm-webpack-5.82.1 Vulnerable Package
MEDIUM CVE-2024-43788 Npm-webpack-5.74.0 Vulnerable Package
MEDIUM CVE-2024-43796 Npm-express-4.15.4 Vulnerable Package
MEDIUM CVE-2024-43796 Npm-express-4.16.2 Vulnerable Package
MEDIUM CVE-2024-43796 Npm-express-4.17.1 Vulnerable Package
MEDIUM CVE-2024-43796 Npm-express-4.18.2 Vulnerable Package
MEDIUM CVE-2024-43796 Npm-express-4.14.0 Vulnerable Package
MEDIUM CVE-2024-43799 Npm-send-0.18.0 Vulnerable Package
MEDIUM CVE-2024-43799 Npm-send-0.15.4 Vulnerable Package
MEDIUM CVE-2024-43799 Npm-send-0.14.1 Vulnerable Package
MEDIUM CVE-2024-43799 Npm-send-0.15.3 Vulnerable Package
MEDIUM CVE-2024-43799 Npm-send-0.15.6 Vulnerable Package
MEDIUM CVE-2024-43799 Npm-send-0.16.1 Vulnerable Package
MEDIUM CVE-2024-43799 Npm-send-0.17.1 Vulnerable Package
MEDIUM CVE-2024-43800 Npm-serve-static-1.12.3 Vulnerable Package
MEDIUM CVE-2024-43800 Npm-serve-static-1.11.1 Vulnerable Package
MEDIUM CVE-2024-43800 Npm-serve-static-1.15.0 Vulnerable Package
MEDIUM CVE-2024-43800 Npm-serve-static-1.13.1 Vulnerable Package
MEDIUM CVE-2024-43800 Npm-serve-static-1.14.1 Vulnerable Package
MEDIUM CVE-2024-43800 Npm-serve-static-1.12.4 Vulnerable Package
MEDIUM CVE-2024-47068 Npm-rollup-0.36.4 Vulnerable Package
MEDIUM CVE-2024-47068 Npm-rollup-3.20.0 Vulnerable Package
MEDIUM CVE-2024-47764 Npm-cookie-0.3.1 Vulnerable Package
MEDIUM CVE-2024-47764 Npm-cookie-0.4.0 Vulnerable Package
MEDIUM CVE-2024-47764 Npm-cookie-0.5.0 Vulnerable Package
MEDIUM Cx54379275-7f08 Npm-es5-ext-0.10.64 Vulnerable Package
MEDIUM Cxe2559faa-3f01 Npm-es5-ext-0.10.63 Vulnerable Package
LOW CVE-2024-48948 Npm-elliptic-6.5.3 Vulnerable Package
LOW CVE-2024-48948 Npm-elliptic-6.5.4 Vulnerable Package
LOW CVE-2024-48948 Npm-elliptic-6.4.0 Vulnerable Package
LOW CVE-2024-48948 Npm-elliptic-6.5.7 Vulnerable Package
LOW Use_Of_Hardcoded_Password /packages/react-dom-bindings/src/shared/possibleStandardNames.js: 16 Attack Vector

Fixed Issues

Severity Issue Source File / Package
HIGH CVE-2022-38900 Npm-decode-uri-component-0.2.2
HIGH CVE-2023-1534 Npm-electron-23.1.2
HIGH CVE-2023-2033 Npm-electron-23.1.2
HIGH CVE-2023-2136 Npm-electron-23.1.2
HIGH CVE-2023-2312 Npm-electron-23.1.2
HIGH CVE-2023-2313 Npm-electron-23.1.2
HIGH CVE-2023-2457 Npm-electron-23.1.2
HIGH CVE-2023-2458 Npm-electron-23.1.2
HIGH CVE-2023-2460 Npm-electron-23.1.2
HIGH CVE-2023-2461 Npm-electron-23.1.2
HIGH CVE-2023-2721 Npm-electron-23.1.2
HIGH CVE-2023-2722 Npm-electron-23.1.2
HIGH CVE-2023-2723 Npm-electron-23.1.2
HIGH CVE-2023-2724 Npm-electron-23.1.2
HIGH CVE-2023-2725 Npm-electron-23.1.2
HIGH CVE-2023-2726 Npm-electron-23.1.2
HIGH CVE-2023-29198 Npm-electron-23.1.2
HIGH CVE-2023-2929 Npm-electron-23.1.2
HIGH CVE-2023-2930 Npm-electron-23.1.2
HIGH CVE-2023-2931 Npm-electron-23.1.2
HIGH CVE-2023-2932 Npm-electron-23.1.2
HIGH CVE-2023-2933 Npm-electron-23.1.2
HIGH CVE-2023-2934 Npm-electron-23.1.2
HIGH CVE-2023-2935 Npm-electron-23.1.2
HIGH CVE-2023-29350 Npm-electron-23.1.2
HIGH CVE-2023-2936 Npm-electron-23.1.2
HIGH CVE-2023-2939 Npm-electron-23.1.2
HIGH CVE-2023-3079 Npm-electron-23.1.2
HIGH CVE-2023-3214 Npm-electron-23.1.2
HIGH CVE-2023-3215 Npm-electron-23.1.2
HIGH CVE-2023-3216 Npm-electron-23.1.2
HIGH CVE-2023-3217 Npm-electron-23.1.2
HIGH CVE-2023-33143 Npm-electron-23.1.2
HIGH CVE-2023-3420 Npm-electron-23.1.2
HIGH CVE-2023-3421 Npm-electron-23.1.2
HIGH CVE-2023-3422 Npm-electron-23.1.2
HIGH CVE-2023-3598 Npm-electron-23.1.2
HIGH CVE-2023-36014 Npm-electron-23.1.2
HIGH CVE-2023-36024 Npm-electron-23.1.2
HIGH CVE-2023-36034 Npm-electron-23.1.2
HIGH CVE-2023-36562 Npm-electron-23.1.2
HIGH CVE-2023-36735 Npm-electron-23.1.2
HIGH CVE-2023-36741 Npm-electron-23.1.2
HIGH CVE-2023-36787 Npm-electron-23.1.2
HIGH CVE-2023-3727 Npm-electron-23.1.2
HIGH CVE-2023-3728 Npm-electron-23.1.2
HIGH CVE-2023-3729 Npm-electron-23.1.2
HIGH CVE-2023-3730 Npm-electron-23.1.2
HIGH CVE-2023-3731 Npm-electron-23.1.2
HIGH CVE-2023-3732 Npm-electron-23.1.2
HIGH CVE-2023-4068 Npm-electron-23.1.2
HIGH CVE-2023-4069 Npm-electron-23.1.2
HIGH CVE-2023-4070 Npm-electron-23.1.2
HIGH CVE-2023-4071 Npm-electron-23.1.2
HIGH CVE-2023-4072 Npm-electron-23.1.2
HIGH CVE-2023-4073 Npm-electron-23.1.2
HIGH CVE-2023-4074 Npm-electron-23.1.2
HIGH CVE-2023-4075 Npm-electron-23.1.2
HIGH CVE-2023-4076 Npm-electron-23.1.2
HIGH CVE-2023-4077 Npm-electron-23.1.2
HIGH CVE-2023-4078 Npm-electron-23.1.2
HIGH CVE-2023-4349 Npm-electron-23.1.2
HIGH CVE-2023-4351 Npm-electron-23.1.2
HIGH CVE-2023-4352 Npm-electron-23.1.2
HIGH CVE-2023-4353 Npm-electron-23.1.2
HIGH CVE-2023-4354 Npm-electron-23.1.2
HIGH CVE-2023-4355 Npm-electron-23.1.2
HIGH CVE-2023-4356 Npm-electron-23.1.2
HIGH CVE-2023-4357 Npm-electron-23.1.2
HIGH CVE-2023-4358 Npm-electron-23.1.2
HIGH CVE-2023-4362 Npm-electron-23.1.2
HIGH CVE-2023-4366 Npm-electron-23.1.2
HIGH CVE-2023-4368 Npm-electron-23.1.2
HIGH CVE-2023-4369 Npm-electron-23.1.2
HIGH CVE-2023-4427 Npm-electron-23.1.2
HIGH CVE-2023-4428 Npm-electron-23.1.2
HIGH CVE-2023-4429 Npm-electron-23.1.2
HIGH CVE-2023-4430 Npm-electron-23.1.2
HIGH CVE-2023-4431 Npm-electron-23.1.2
HIGH CVE-2023-44402 Npm-electron-23.1.2
HIGH CVE-2023-4572 Npm-electron-23.1.2
HIGH CVE-2023-4761 Npm-electron-23.1.2
HIGH CVE-2023-4762 Npm-electron-23.1.2
HIGH CVE-2023-4763 Npm-electron-23.1.2
HIGH CVE-2023-4863 Npm-electron-23.1.2
HIGH CVE-2023-5186 Npm-electron-23.1.2
HIGH CVE-2023-5187 Npm-electron-23.1.2
HIGH CVE-2023-5217 Npm-electron-23.1.2
HIGH CVE-2023-5218 Npm-electron-23.1.2
HIGH CVE-2023-5346 Npm-electron-23.1.2
HIGH CVE-2023-5472 Npm-electron-23.1.2
HIGH CVE-2023-5474 Npm-electron-23.1.2
HIGH CVE-2023-5476 Npm-electron-23.1.2
HIGH CVE-2023-5482 Npm-electron-23.1.2
HIGH CVE-2023-5849 Npm-electron-23.1.2
HIGH CVE-2023-5852 Npm-electron-23.1.2
HIGH CVE-2023-5854 Npm-electron-23.1.2
HIGH CVE-2023-5855 Npm-electron-23.1.2
HIGH CVE-2023-5856 Npm-electron-23.1.2
HIGH CVE-2023-5857 Npm-electron-23.1.2
HIGH CVE-2023-5996 Npm-electron-23.1.2
HIGH CVE-2023-5997 Npm-electron-23.1.2
HIGH CVE-2023-6112 Npm-electron-23.1.2
HIGH CVE-2023-6345 Npm-electron-23.1.2
HIGH CVE-2023-6346 Npm-electron-23.1.2
HIGH CVE-2023-6347 Npm-electron-23.1.2
HIGH CVE-2023-6348 Npm-electron-23.1.2
HIGH CVE-2023-6350 Npm-electron-23.1.2
HIGH CVE-2023-6351 Npm-electron-23.1.2
HIGH CVE-2023-6508 Npm-electron-23.1.2
HIGH CVE-2023-6509 Npm-electron-23.1.2
HIGH CVE-2023-6510 Npm-electron-23.1.2
HIGH CVE-2023-6702 Npm-electron-23.1.2
HIGH CVE-2023-6703 Npm-electron-23.1.2
HIGH CVE-2023-6704 Npm-electron-23.1.2
HIGH CVE-2023-6705 Npm-electron-23.1.2
HIGH CVE-2023-6706 Npm-electron-23.1.2
HIGH CVE-2023-6707 Npm-electron-23.1.2
HIGH CVE-2023-7024 Npm-electron-23.1.2
HIGH CVE-2024-0222 Npm-electron-23.1.2
HIGH CVE-2024-0223 Npm-electron-23.1.2
HIGH CVE-2024-0224 Npm-electron-23.1.2
HIGH CVE-2024-0225 Npm-electron-23.1.2
HIGH CVE-2024-0517 Npm-electron-23.1.2
HIGH CVE-2024-0518 Npm-electron-23.1.2
HIGH CVE-2024-0519 Npm-electron-23.1.2
HIGH CVE-2024-0804 Npm-electron-23.1.2
HIGH CVE-2024-0806 Npm-electron-23.1.2
HIGH CVE-2024-0807 Npm-electron-23.1.2
HIGH CVE-2024-0808 Npm-electron-23.1.2
HIGH CVE-2024-0812 Npm-electron-23.1.2
HIGH CVE-2024-0813 Npm-electron-23.1.2
HIGH CVE-2024-1059 Npm-electron-23.1.2
HIGH CVE-2024-1060 Npm-electron-23.1.2
HIGH CVE-2024-1077 Npm-electron-23.1.2
HIGH CVE-2024-1283 Npm-electron-23.1.2
HIGH CVE-2024-1284 Npm-electron-23.1.2
HIGH CVE-2024-1669 Npm-electron-23.1.2
HIGH CVE-2024-1670 Npm-electron-23.1.2
HIGH CVE-2024-1673 Npm-electron-23.1.2
HIGH CVE-2024-1938 Npm-electron-23.1.2
HIGH CVE-2024-1939 Npm-electron-23.1.2
HIGH CVE-2024-21326 Npm-electron-23.1.2
HIGH CVE-2024-21385 Npm-electron-23.1.2
HIGH CVE-2024-21399 Npm-electron-23.1.2
HIGH CVE-2024-2173 Npm-electron-23.1.2
HIGH CVE-2024-2174 Npm-electron-23.1.2
HIGH CVE-2024-2400 Npm-electron-23.1.2
HIGH CVE-2024-26192 Npm-electron-23.1.2
HIGH CVE-2024-2625 Npm-electron-23.1.2
HIGH CVE-2024-2627 Npm-electron-23.1.2
HIGH CVE-2024-2883 Npm-electron-23.1.2
HIGH CVE-2024-2885 Npm-electron-23.1.2
HIGH CVE-2024-2886 Npm-electron-23.1.2
HIGH CVE-2024-2887 Npm-electron-23.1.2
HIGH CVE-2024-3157 Npm-electron-23.1.2
HIGH CVE-2024-3515 Npm-electron-23.1.2
HIGH CVE-2024-3516 Npm-electron-23.1.2
HIGH Cxab55612e-3a56 Npm-braces-3.0.2
HIGH Cxab55612e-3a56 Npm-braces-1.8.5
HIGH Cxab55612e-3a56 Npm-braces-2.3.2
HIGH Cxca84a1c2-1f12 Npm-micromatch-4.0.2
HIGH Cxca84a1c2-1f12 Npm-micromatch-3.1.10
HIGH Cxca84a1c2-1f12 Npm-micromatch-4.0.5
HIGH Cxca84a1c2-1f12 Npm-micromatch-4.0.4
HIGH Cxca84a1c2-1f12 Npm-micromatch-2.3.11
MEDIUM CVE-2023-2311 Npm-electron-23.1.2
MEDIUM CVE-2023-2314 Npm-electron-23.1.2
MEDIUM CVE-2023-2459 Npm-electron-23.1.2
MEDIUM CVE-2023-2463 Npm-electron-23.1.2
MEDIUM CVE-2023-2464 Npm-electron-23.1.2
MEDIUM CVE-2023-2465 Npm-electron-23.1.2
MEDIUM CVE-2023-2466 Npm-electron-23.1.2
MEDIUM CVE-2023-2467 Npm-electron-23.1.2
MEDIUM CVE-2023-2468 Npm-electron-23.1.2
MEDIUM CVE-2023-28261 Npm-electron-23.1.2
MEDIUM CVE-2023-28286 Npm-electron-23.1.2
MEDIUM CVE-2023-29334 Npm-electron-23.1.2
MEDIUM CVE-2023-29354 Npm-electron-23.1.2
MEDIUM CVE-2023-2937 Npm-electron-23.1.2
MEDIUM CVE-2023-2938 Npm-electron-23.1.2
MEDIUM CVE-2023-2940 Npm-electron-23.1.2
MEDIUM CVE-2023-2941 Npm-electron-23.1.2
MEDIUM CVE-2023-3497 Npm-electron-23.1.2
MEDIUM CVE-2023-35392 Npm-electron-23.1.2
MEDIUM CVE-2023-36008 Npm-electron-23.1.2
MEDIUM CVE-2023-36022 Npm-electron-23.1.2
MEDIUM CVE-2023-36026 Npm-electron-23.1.2
MEDIUM CVE-2023-36027 Npm-electron-23.1.2
MEDIUM CVE-2023-36029 Npm-electron-23.1.2
MEDIUM CVE-2023-36409 Npm-electron-23.1.2
MEDIUM CVE-2023-36727 Npm-electron-23.1.2
MEDIUM CVE-2023-36878 Npm-electron-23.1.2
MEDIUM CVE-2023-3733 Npm-electron-23.1.2
MEDIUM CVE-2023-3734 Npm-electron-23.1.2
MEDIUM CVE-2023-3735 Npm-electron-23.1.2
MEDIUM CVE-2023-3736 Npm-electron-23.1.2
MEDIUM CVE-2023-3737 Npm-electron-23.1.2
MEDIUM CVE-2023-3738 Npm-electron-23.1.2
MEDIUM CVE-2023-3739 Npm-electron-23.1.2
MEDIUM CVE-2023-3740 Npm-electron-23.1.2
MEDIUM CVE-2023-3742 Npm-electron-23.1.2
MEDIUM CVE-2023-38157 Npm-electron-23.1.2
MEDIUM CVE-2023-38173

More results are available on AST platform

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants