You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
GitHub dependabot is flagging electron versions prior to 22.3.25 as having the following "High" level vulnerability:
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
I'm happy to submit a pull request with the updated version unless there are already plans in place to do so. Would this be helpful? If so, would a reference to the latest electron version (27.0.1) be helpful or just to the version that fixes the vulnerability?
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
GitHub dependabot is flagging electron versions prior to 22.3.25 as having the following "High" level vulnerability:
I'm happy to submit a pull request with the updated version unless there are already plans in place to do so. Would this be helpful? If so, would a reference to the latest electron version (
27.0.1) be helpful or just to the version that fixes the vulnerability?Thank you!
All reactions