An open index of dependabot pull requests across open source projects.

electron

Ecosystem:
npm
Package URL:
pkg:npm/electron
Total PRs:
10,833 Dependabot PRs
Latest PR:
about 5 hours ago
Unique Repositories:
2,830 repositories
Unique Repos (30 days):
227 repositories
Security Advisories
ASAR Integrity bypass via filetype confusion in electron
GHSA-7m48-wc93-9g85 CVE-2023-44402 MODERATE published over 2 years ago • updated 6 days ago
### Impact This only impacts apps that have the `embeddedAsarIntegrityValidation` and `onlyLoadAppFromAsar` [fuses](https://www.electronjs.org/docs...
Context isolation bypass via contextBridge in Electron
GHSA-h9jc-284h-533g CVE-2020-4077 HIGH published over 5 years ago • updated 8 days ago
### Impact Apps using both `contextIsolation` and `contextBridge` are affected. This is a context isolation bypass, meaning that code running in t...
Context isolation bypass via Promise in Electron
GHSA-6vrv-94jv-crrg CVE-2020-15096 LOW published over 5 years ago • updated 6 days ago
### Impact Apps using `contextIsolation` are affected. This is a context isolation bypass, meaning that code running in the main world context in ...
Electron's Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled
GHSA-gxh7-wv9q-fwfr CVE-2023-23623 HIGH published over 2 years ago • updated 6 days ago
### Impact A Content-Security-Policy that disables eval, specifically setting a `script-src` directive and _not_ providing `unsafe-eval` in that di...
Unpreventable top-level navigation
GHSA-2q4g-w47c-4674 CVE-2020-15174 HIGH published over 5 years ago • updated 2 days ago
### Impact The `will-navigate` event that apps use to prevent navigations to unexpected destinations [as per our security recommendations](https://...
Recent PRs (filtered by: Patch PRs )
Package Details
Name: electron
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/electron
JSON API: View JSON
Security Advisories

28

Active advisories
CRITICAL 2
HIGH 12
MODERATE 10
LOW 4
View All npm Advisories
Package Information
Description:

Build cross platform desktop apps with JavaScript, HTML, and CSS

Repository: https://github.com/electron/electron
Homepage: https://github.com/electron/electron
Latest Release: 33.2.1
over 1 year ago
Dependent Repos: 93,246
Dependent Packages: 5,167
Downloads: 3,520,591
Ranking: Top 0.1097% by dependent repos Top 0.171% by downloads Top 0.0183% by dependent pkgs
PR Status
Open 4,257 (39.3%)
Merged 974 (9.0%)
Closed 4,791 (44.3%)
PR Types
Removal 3 (0.0%)
Minor 1,736 (16.0%)
Major 7,393 (68.3%)
Patch 882 (8.1%)