Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability roundup 89: electron-5.0.13: 1 advisory [6.8] #93257

Closed
1 task
ckauhaus opened this issue Jul 16, 2020 · 5 comments
Closed
1 task

Vulnerability roundup 89: electron-5.0.13: 1 advisory [6.8] #93257

ckauhaus opened this issue Jul 16, 2020 · 5 comments

Comments

@ckauhaus
Copy link
Contributor

search, files

Scanned versions: nixos-20.03: dabbc5a; nixos-unstable: c71518e. May contain false positives.

Cc @manveru
Cc @prusnak
Cc @travisbhartwell

@prusnak
Copy link
Member

prusnak commented Jul 17, 2020

both master and nixos-20.03 contain electron 5.0.13 which is the latest from the 5.x series

@prusnak prusnak closed this as completed Jul 17, 2020
@ckauhaus
Copy link
Contributor Author

We have currently Electron 3, 4, 5, 6, 7, 8, and 9 in master. The default is still Electron 4. AFAICS Electron 3, 4, and 5 are not supported anymore upstream. In my opinion the default should be set to a supported version and Electron <= 5 should be marked as insecure in master.

@prusnak
Copy link
Member

prusnak commented Jul 17, 2020

I sent a PR to upgrade the electron to latest in June - it is still waiting to be merged: #89758

Once this is merged I agree we should mark Electron <=5 as insecure.

I can even include this change into #89758 if that is desired.

@prusnak
Copy link
Member

prusnak commented Jul 20, 2020

Marked electron < 6 insecure in 1499874 (part of #89758)

@ckauhaus
Copy link
Contributor Author

thanks - what a pity that unmerged PRs are sometimes lingering to long

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants