[Snyk] Security upgrade electron from 11.1.1 to 29.4.3 #970
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)
Snyk has created this PR to fix 41 vulnerabilities in the yarn dependencies of this project.
Snyk changed the following file(s):
packages/react-devtools/package.json
packages/react-devtools/.snyk
Note for zero-installs users
If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the
.yarn/cache/
directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to runyarn
to update the contents of the./yarn/cache
directory.If you are not using zero-install you can ignore this as your flow should likely be unchanged.
⚠️ Warning
``` Failed to update the yarn.lock, please update manually before merging. ```Vulnerabilities that will be fixed with an upgrade:
SNYK-JS-ELECTRON-2805803
SNYK-JS-ELECTRON-1257943
SNYK-JS-ELECTRON-1085705
SNYK-JS-ELECTRON-1088600
SNYK-JS-ELECTRON-1252279
SNYK-JS-ELECTRON-1312314
SNYK-JS-ELECTRON-1313765
SNYK-JS-ELECTRON-1534883
SNYK-JS-ELECTRON-1656743
SNYK-JS-ELECTRON-1910985
SNYK-JS-ELECTRON-3014411
SNYK-JS-ELECTRON-3091122
SNYK-JS-ELECTRON-6179663
SNYK-JS-ELECTRON-5923343
SNYK-JS-ELECTRON-2946881
SNYK-JS-ELECTRON-1911949
SNYK-JS-ELECTRON-2414027
SNYK-JS-ELECTRON-2322001
SNYK-JS-ELECTRON-2434822
SNYK-JS-ELECTRON-6137744
SNYK-JS-ELECTRON-6253729
SNYK-JS-ELECTRON-1296559
SNYK-JS-ELECTRON-1536581
SNYK-JS-ELECTRON-1912085
SNYK-JS-ELECTRON-6253728
SNYK-JS-ELECTRON-7411376
SNYK-JS-ELECTRON-7411377
SNYK-JS-ELECTRON-7411378
SNYK-JS-ELECTRON-7411379
SNYK-JS-ELECTRON-7411381
SNYK-JS-ELECTRON-7411382
SNYK-JS-ELECTRON-7411383
SNYK-JS-ELECTRON-7411386
SNYK-JS-ELECTRON-7411387
SNYK-JS-ELECTRON-7411389
SNYK-JS-ELECTRON-7411388
SNYK-JS-ELECTRON-6146931
SNYK-JS-ELECTRON-1070013
SNYK-JS-ELECTRON-1315668
SNYK-JS-ELECTRON-2332173
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Type Confusion
🦉 Use After Free
🦉 Prototype Pollution
🦉 More lessons are available in Snyk Learn
[//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"electron","from":"11.1.1","to":"29.4.3"}],"env":"prod","issuesToFix":[{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-2805803","priority_score":919,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Type Confusion"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1257943","priority_score":876,"priority_score_factors":[{"type":"exploit","label":"Functional","score":171},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Out-of-bounds"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1656743","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1312314","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Access of Resource Using Incompatible Type ('Type Confusion')"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1088600","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Out-of-bounds Write"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1313765","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1252279","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1534883","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Type Confusion"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1085705","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-3014411","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-3091122","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Type Confusion"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-6179663","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Out-of-bounds Read"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1910985","priority_score":869,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-5923343","priority_score":865,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.3","score":365},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Heap-based Buffer Overflow"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-2946881","priority_score":859,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.6","score":430},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Heap-based Buffer Overflow"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-ELECTRON-1911949","priority_score":811,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Type Confusion"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-2414027","priority_score":809,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.6","score":380},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-2322001","priority_score":794,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.3","score":365},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-2434822","priority_score":794,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.3","score":365},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Type Confusion"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-6137744","priority_score":794,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.3","score":365},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Heap-based Buffer Overflow"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-6253729","priority_score":766,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9.6","score":480},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Use After Free"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-ELECTRON-1536581","priority_score":761,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-ELECTRON-1296559","priority_score":761,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Type Confusion"},{"exploit_maturity":"Mature","id":"SNYK-JS-ELECTRON-1912085","priority_score":754,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.5","score":325},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Information Exposure"},{"exploit_maturity":"Proof of Concept","id":"SNYK-JS-LODASH-567746","priority_score":731,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.2","score":410},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Prototype Pollution"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-7411376","priority_score":726,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-7411377","priority_score":726,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-7411378","priority_score":726,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-7411379","priority_score":726,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Heap-based Buffer Overflow"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-7411381","priority_score":726,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Out-of-Bounds Write"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-7411382","priority_score":726,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-7411383","priority_score":726,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Type Confusion"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-6253728","priority_score":726,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Heap-based Buffer Overflow"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-7411386","priority_score":726,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-7411387","priority_score":726,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-7411389","priority_score":726,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Out-of-bounds Read"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-7411388","priority_score":721,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.7","score":435},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-6146931","priority_score":718,"priority_score_factors":[{"type":"socialTrends","label":true,"score":111},{"type":"fixability","label":true,"score":167},{"type":"cvssScore","label":"8.8","score":440},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Heap-based Buffer Overflow"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-1315668","priority_score":704,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Out-of-bounds Write"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-1070013","priority_score":704,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Use After Free"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ELECTRON-2332173","priority_score":704,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Improper Input Validation"}],"prId":"16795947-da83-4969-b721-b56eb6f8f7a7","prPublicId":"16795947-da83-4969-b721-b56eb6f8f7a7","packageManager":"yarn","priorityScoreList":[919,876,869,869,869,869,869,869,869,869,869,869,869,865,859,811,809,794,794,794,766,761,761,754,731,726,726,726,726,726,726,726,726,726,726,726,721,718,704,704,704],"projectPublicId":"614fa02e-79ee-4d0b-9573-ca57c76f8962","projectUrl":"https://app.snyk.io/org/kuhlmanjakob/project/614fa02e-79ee-4d0b-9573-ca57c76f8962?utm_source=github&utm_medium=referral&page=fix-pr","prType":"backlog","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["pkg-based-remediation","updated-fix-title","pr-warning-shown","priorityScore"],"type":"auto","upgrade":["SNYK-JS-ELECTRON-1070013","SNYK-JS-ELECTRON-1085705","SNYK-JS-ELECTRON-1088600","SNYK-JS-ELECTRON-1252279","SNYK-JS-ELECTRON-1257943","SNYK-JS-ELECTRON-1296559","SNYK-JS-ELECTRON-1312314","SNYK-JS-ELECTRON-1313765","SNYK-JS-ELECTRON-1315668","SNYK-JS-ELECTRON-1534883","SNYK-JS-ELECTRON-1536581","SNYK-JS-ELECTRON-1656743","SNYK-JS-ELECTRON-1910985","SNYK-JS-ELECTRON-1911949","SNYK-JS-ELECTRON-1912085","SNYK-JS-ELECTRON-2322001","SNYK-JS-ELECTRON-2332173","SNYK-JS-ELECTRON-2414027","SNYK-JS-ELECTRON-2434822","SNYK-JS-ELECTRON-2805803","SNYK-JS-ELECTRON-2946881","SNYK-JS-ELECTRON-3014411","SNYK-JS-ELECTRON-3091122","SNYK-JS-ELECTRON-5923343","SNYK-JS-ELECTRON-6137744","SNYK-JS-ELECTRON-6146931","SNYK-JS-ELECTRON-6179663","SNYK-JS-ELECTRON-6253728","SNYK-JS-ELECTRON-6253729","SNYK-JS-ELECTRON-7411376","SNYK-JS-ELECTRON-7411377","SNYK-JS-ELECTRON-7411378","SNYK-JS-ELECTRON-7411379","SNYK-JS-ELECTRON-7411381","SNYK-JS-ELECTRON-7411382","SNYK-JS-ELECTRON-7411383","SNYK-JS-ELECTRON-7411386","SNYK-JS-ELECTRON-7411387","SNYK-JS-ELECTRON-7411388","SNYK-JS-ELECTRON-7411389"],"vulns":["SNYK-JS-ELECTRON-2805803","SNYK-JS-ELECTRON-1257943","SNYK-JS-ELECTRON-1656743","SNYK-JS-ELECTRON-1312314","SNYK-JS-ELECTRON-1088600","SNYK-JS-ELECTRON-1313765","SNYK-JS-ELECTRON-1252279","SNYK-JS-ELECTRON-1534883","SNYK-JS-ELECTRON-1085705","SNYK-JS-ELECTRON-3014411","SNYK-JS-ELECTRON-3091122","SNYK-JS-ELECTRON-6179663","SNYK-JS-ELECTRON-1910985","SNYK-JS-ELECTRON-5923343","SNYK-JS-ELECTRON-2946881","SNYK-JS-ELECTRON-1911949","SNYK-JS-ELECTRON-2414027","SNYK-JS-ELECTRON-2322001","SNYK-JS-ELECTRON-2434822","SNYK-JS-ELECTRON-6137744","SNYK-JS-ELECTRON-6253729","SNYK-JS-ELECTRON-1536581","SNYK-JS-ELECTRON-1296559","SNYK-JS-ELECTRON-1912085","SNYK-JS-LODASH-567746","SNYK-JS-ELECTRON-7411376","SNYK-JS-ELECTRON-7411377","SNYK-JS-ELECTRON-7411378","SNYK-JS-ELECTRON-7411379","SNYK-JS-ELECTRON-7411381","SNYK-JS-ELECTRON-7411382","SNYK-JS-ELECTRON-7411383","SNYK-JS-ELECTRON-6253728","SNYK-JS-ELECTRON-7411386","SNYK-JS-ELECTRON-7411387","SNYK-JS-ELECTRON-7411389","SNYK-JS-ELECTRON-7411388","SNYK-JS-ELECTRON-6146931","SNYK-JS-ELECTRON-1315668","SNYK-JS-ELECTRON-1070013","SNYK-JS-ELECTRON-2332173"],"patch":["SNYK-JS-LODASH-567746"],"isBreakingChange":true,"remediationStrategy":"dependency"}'