An open index of dependabot pull requests across open source projects.

electron

Ecosystem:
npm
Package URL:
pkg:npm/electron
Total PRs:
7,506 Dependabot PRs
Latest PR:
about 2 hours ago
Unique Repositories:
2,089 repositories
Unique Repos (30 days):
1,305 repositories
Security Advisories
Unpreventable top-level navigation
GHSA-2q4g-w47c-4674 CVE-2020-15174 HIGH published almost 5 years ago • updated 3 months ago
### Impact The `will-navigate` event that apps use to prevent navigations to unexpected destinations [as per our security recommendations](https://...
Context isolation bypass via contextBridge in Electron
GHSA-h9jc-284h-533g CVE-2020-4077 HIGH published about 5 years ago • updated 3 months ago
### Impact Apps using both `contextIsolation` and `contextBridge` are affected. This is a context isolation bypass, meaning that code running in t...
Heap buffer overflow in GPU
GHSA-995f-9x5r-2rcj CVE-2022-4135 CRITICAL published almost 3 years ago • updated about 1 month ago
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentia...
Arbitrary file read via window-open IPC in Electron
GHSA-f9mq-jph6-9mhm CVE-2020-4075 MODERATE published about 5 years ago • updated 3 months ago
### Impact The vulnerability allows arbitrary local file read by defining unsafe window options on a child window opened via window.open. ### Work...
Electron context isolation bypass via nested unserializable return value
GHSA-p7v2-p9m8-qqg7 CVE-2023-29198 MODERATE published about 2 years ago • updated about 1 month ago
### Impact Apps using `contextIsolation` and `contextBridge` are affected. This is a context isolation bypass, meaning that code running in the ma...
Recent PRs
Package Details
Name: electron
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/electron
JSON API: View JSON
Security Advisories

28

Active advisories
CRITICAL 2
HIGH 13
MODERATE 9
LOW 4
View All npm Advisories
Package Information
Description:

Build cross platform desktop apps with JavaScript, HTML, and CSS

Repository: https://github.com/electron/electron
Homepage: https://github.com/electron/electron
Latest Release: 33.2.1
10 months ago
Dependent Repos: 93,246
Dependent Packages: 5,167
Downloads: 3,520,591
Ranking: Top 0.1097% by dependent repos Top 0.171% by downloads Top 0.0183% by dependent pkgs
PR Status
Open 3,079 (41.1%)
Merged 760 (10.1%)
Closed 2,853 (38.1%)
PR Types
Removal 3 (0.0%)
Minor 1,187 (15.8%)
Major 4,880 (65.1%)
Patch 618 (8.2%)