Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade electron from 10.3.2 to 10.4.7 #21

Merged

Conversation

abdulrahman305
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade electron from 10.3.2 to 10.4.7.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 8 versions ahead of your current version.

  • The recommended version was released on 3 years ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Use After Free
SNYK-JS-ELECTRON-1253279
53 No Known Exploit
high severity Heap-based Buffer Overflow
SNYK-JS-ELECTRON-1296553
53 No Known Exploit
high severity Heap-based Buffer Overflow
SNYK-JS-ELECTRON-1296555
53 No Known Exploit
high severity Use After Free
SNYK-JS-ELECTRON-1253281
53 No Known Exploit
high severity Out-of-Bounds
SNYK-JS-ELECTRON-1086693
53 No Known Exploit
high severity Use After Free
SNYK-JS-ELECTRON-1296557
53 No Known Exploit
high severity Integer Overflow or Wraparound
SNYK-JS-ELECTRON-1260586
53 No Known Exploit
high severity Out-of-bounds Read
SNYK-JS-ELECTRON-1261111
53 No Known Exploit
high severity Use After Free
SNYK-JS-ELECTRON-1296561
53 No Known Exploit
high severity Use After Free
SNYK-JS-ELECTRON-1087442
53 No Known Exploit
high severity Insecure Defaults
SNYK-JS-ELECTRON-1088602
53 No Known Exploit
high severity Use After Free
SNYK-JS-ELECTRON-1252279
53 Mature
high severity Heap-based Buffer Overflow
SNYK-JS-ELECTRON-1296565
53 No Known Exploit
high severity Heap Buffer Overflow
SNYK-JS-ELECTRON-1085647
53 No Known Exploit
high severity Prototype Pollution
SNYK-JS-PROTOBUFJS-2441248
53 Proof of Concept
high severity Prototype Pollution
SNYK-JS-PROTOBUFJS-5756498
53 Proof of Concept
high severity Denial of Service (DoS)
SNYK-JS-WS-7266574
53 Proof of Concept
high severity Use After Free
SNYK-JS-ELECTRON-1085994
53 No Known Exploit
high severity Use After Free
SNYK-JS-ELECTRON-1252280
53 No Known Exploit
high severity Out-of-Bounds
SNYK-JS-ELECTRON-1085996
53 No Known Exploit
medium severity Information Exposure
SNYK-JS-ELECTRON-1085998
53 No Known Exploit
medium severity Uncontrolled Resource Consumption
SNYK-JS-GRPCGRPCJS-7242922
53 No Known Exploit
medium severity Prototype Pollution
SNYK-JS-JSON5-3182856
53 Proof of Concept
low severity Out Of Bounds Read
SNYK-JS-ELECTRON-1278596
53 No Known Exploit
critical severity Out-of-bounds
SNYK-JS-ELECTRON-1257943
53 Mature
high severity Use After Free
SNYK-JS-ELECTRON-1258207
53 No Known Exploit
high severity Use After Free
SNYK-JS-ELECTRON-1259349
53 No Known Exploit
high severity Type Confusion
SNYK-JS-ELECTRON-1296559
53 Proof of Concept
high severity Improper Input Validation
SNYK-JS-ELECTRON-1086695
53 No Known Exploit
high severity Out-of-bounds Write
SNYK-JS-ELECTRON-1088600
53 Mature
high severity Race Condition
SNYK-JS-ELECTRON-1296563
53 No Known Exploit
high severity Heap-based Buffer Overflow
SNYK-JS-ELECTRON-1277203
53 No Known Exploit
high severity Integer Overflow
SNYK-JS-ELECTRON-1277205
53 No Known Exploit
high severity Use After Free
SNYK-JS-ELECTRON-1085705
53 Mature
medium severity Improper Control of Dynamically-Managed Code Resources
SNYK-JS-EJS-6689533
53 No Known Exploit
medium severity Access Restriction Bypass
SNYK-JS-ELECTRON-1086694
53 No Known Exploit
medium severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JS-TAR-6476909
53 Proof of Concept
medium severity Open Redirect
SNYK-JS-EXPRESS-6474509
53 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HTTPCACHESEMANTICS-3248783
53 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-JSON5-3182856
53 Proof of Concept
medium severity Improper Input Validation
SNYK-JS-ELECTRON-1277526
53 No Known Exploit
medium severity Template Injection
SNYK-JS-DOMPURIFY-6474511
53 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-WORDWRAP-3149973
53 Proof of Concept
Release notes
Package name: electron
  • 10.4.7 - 2021-05-24

    Release Notes for v10.4.7

    Other Changes

    End of Support for 10.x.y

    Electron 10.x.y has reached end-of-support as per the project's support policy. Developers and applications are encouraged to upgrade to a newer version of Electron.

  • 10.4.6 - 2021-05-19

    Release Notes for v10.4.6

    Fixes

    • Fixed <webview> focus / blur events not working with contextIsolation enabled. #29026 (Also in 11, 12, 13)
    • Fixed an issue where events on webview elements were missing properties if contextIsolation was enabled. #29143 (Also in 11)
  • 10.4.5 - 2021-05-05
  • 10.4.4 - 2021-04-27
  • 10.4.3 - 2021-04-14
  • 10.4.2 - 2021-03-23
  • 10.4.1 - 2021-03-15
  • 10.4.0 - 2021-02-20
  • 10.3.2 - 2021-02-05
from electron GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

[//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"electron","from":"10.3.2","to":"10.4.7"}],"env":"prod","hasFixes":true,"isBreakingChange":false,"isMajorUpgrade":false,"issuesToFix":[{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1253279","issue_id":"SNYK-JS-ELECTRON-1253279","priority_score":193,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.01195},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Thu Apr 22 2021 14:48:55 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":1.97},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1296553","issue_id":"SNYK-JS-ELECTRON-1296553","priority_score":143,"priority_score_factors":[{"name":"confidentiality","value":"low"},{"name":"integrity","value":"low"},{"name":"availability","value":"low"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00551},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Fri Jun 04 2021 15:39:06 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":5.62},{"name":"likelihood","value":2.54},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Heap-based Buffer Overflow"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1296555","issue_id":"SNYK-JS-ELECTRON-1296555","priority_score":143,"priority_score_factors":[{"name":"confidentiality","value":"low"},{"name":"integrity","value":"low"},{"name":"availability","value":"low"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00551},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Fri Jun 04 2021 15:39:07 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":5.62},{"name":"likelihood","value":2.54},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Heap-based Buffer Overflow"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1253281","issue_id":"SNYK-JS-ELECTRON-1253281","priority_score":193,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.01195},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Thu Apr 22 2021 14:48:54 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":1.97},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1086693","issue_id":"SNYK-JS-ELECTRON-1086693","priority_score":201,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"low"},{"name":"availability","value":"low"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"unproven"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.01287},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Thu Mar 25 2021 17:09:21 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":7.84},{"name":"likelihood","value":2.56},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Out-of-Bounds"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1296557","issue_id":"SNYK-JS-ELECTRON-1296557","priority_score":191,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00632},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Fri Jun 04 2021 15:39:07 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":1.95},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1260586","issue_id":"SNYK-JS-ELECTRON-1260586","priority_score":230,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"low"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.0132},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Sun May 02 2021 14:50:38 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":2.34},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Integer Overflow or Wraparound"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1261111","issue_id":"SNYK-JS-ELECTRON-1261111","priority_score":130,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"none"},{"name":"availability","value":"none"},{"name":"scope","value":"changed"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00452},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Wed Apr 28 2021 15:14:35 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":6.65},{"name":"likelihood","value":1.94},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Out-of-bounds Read"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1296561","issue_id":"SNYK-JS-ELECTRON-1296561","priority_score":191,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00632},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Fri Jun 04 2021 15:39:08 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":1.95},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1087442","issue_id":"SNYK-JS-ELECTRON-1087442","priority_score":192,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.0091},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Thu Mar 25 2021 17:11:59 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":1.96},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1088602","issue_id":"SNYK-JS-ELECTRON-1088602","priority_score":169,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"none"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00578},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Thu Mar 25 2021 17:09:19 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":8.63},{"name":"likelihood","value":1.95},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Insecure Defaults"},{"exploit_maturity":"mature","id":"SNYK-JS-ELECTRON-1252279","issue_id":"SNYK-JS-ELECTRON-1252279","priority_score":864,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"high"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.04553},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Wed Apr 28 2021 15:14:34 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":8.82},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1296565","issue_id":"SNYK-JS-ELECTRON-1296565","priority_score":143,"priority_score_factors":[{"name":"confidentiality","value":"low"},{"name":"integrity","value":"low"},{"name":"availability","value":"low"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00312},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Fri Jun 04 2021 15:39:09 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":5.62},{"name":"likelihood","value":2.53},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Heap-based Buffer Overflow"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1085647","issue_id":"SNYK-JS-ELECTRON-1085647","priority_score":192,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00767},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Tue Mar 16 2021 15:53:43 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":1.95},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Heap Buffer Overflow"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-PROTOBUFJS-2441248","issue_id":"SNYK-JS-PROTOBUFJS-2441248","priority_score":186,"priority_score_factors":[{"name":"confidentiality","value":"none"},{"name":"integrity","value":"high"},{"name":"availability","value":"low"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"proofOfConcept"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00146},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Mon May 23 2022 13:17:16 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":true},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":99},{"name":"impact","value":7.03},{"name":"likelihood","value":2.64},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Prototype Pollution"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-PROTOBUFJS-5756498","issue_id":"SNYK-JS-PROTOBUFJS-5756498","priority_score":208,"priority_score_factors":[{"name":"confidentiality","value":"low"},{"name":"integrity","value":"low"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"proofOfConcept"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00415},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Thu Jul 06 2023 07:32:10 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":true},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":99},{"name":"impact","value":7.84},{"name":"likelihood","value":2.65},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Prototype Pollution"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-WS-7266574","issue_id":"SNYK-JS-WS-7266574","priority_score":169,"priority_score_factors":[{"name":"confidentiality","value":"none"},{"name":"integrity","value":"none"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"proofOfConcept"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00044},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Mon Jun 17 2024 14:34:03 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":true},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":99},{"name":"impact","value":5.99},{"name":"likelihood","value":2.81},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Denial of Service (DoS)"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1085994","issue_id":"SNYK-JS-ELECTRON-1085994","priority_score":192,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.0091},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Tue Mar 16 2021 15:53:42 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":1.96},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1252280","issue_id":"SNYK-JS-ELECTRON-1252280","priority_score":193,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.01195},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Thu Apr 22 2021 14:48:53 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":1.97},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1085996","issue_id":"SNYK-JS-ELECTRON-1085996","priority_score":194,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.01287},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Tue Mar 16 2021 15:53:42 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":1.97},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Out-of-Bounds"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1085998","issue_id":"SNYK-JS-ELECTRON-1085998","priority_score":61,"priority_score_factors":[{"name":"confidentiality","value":"low"},{"name":"integrity","value":"none"},{"name":"availability","value":"none"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.01274},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Tue Mar 16 2021 15:53:43 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"medium"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":2.35},{"name":"likelihood","value":2.56},{"name":"scoreVersion","value":"V5"}],"severity":"medium","title":"Information Exposure"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-GRPCGRPCJS-7242922","issue_id":"SNYK-JS-GRPCGRPCJS-7242922","priority_score":49,"priority_score_factors":[{"name":"confidentiality","value":"none"},{"name":"integrity","value":"none"},{"name":"availability","value":"low"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00046},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Tue Jun 11 2024 07:12:19 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":true},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"medium"},{"name":"relativePopularityRank","value":99},{"name":"impact","value":2.35},{"name":"likelihood","value":2.06},{"name":"scoreVersion","value":"V5"}],"severity":"medium","title":"Uncontrolled Resource Consumption"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-JSON5-3182856","issue_id":"SNYK-JS-JSON5-3182856","priority_score":178,"priority_score_factors":[{"name":"confidentiality","value":"low"},{"name":"integrity","value":"low"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"proofOfConcept"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"low"},{"name":"attackComplexity","value":"high"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00667},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Sun Dec 25 2022 08:45:14 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":true},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"medium"},{"name":"relativePopularityRank","value":99},{"name":"impact","value":7.84},{"name":"likelihood","value":2.27},{"name":"scoreVersion","value":"V5"}],"severity":"medium","title":"Prototype Pollution"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1278596","issue_id":"SNYK-JS-ELECTRON-1278596","priority_score":53,"priority_score_factors":[{"name":"confidentiality","value":"low"},{"name":"integrity","value":"none"},{"name":"availability","value":"none"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"high"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00533},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Sun May 02 2021 14:50:40 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"low"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":2.35},{"name":"likelihood","value":2.24},{"name":"scoreVersion","value":"V5"}],"severity":"low","title":"Out Of Bounds Read"},{"exploit_maturity":"mature","id":"SNYK-JS-ELECTRON-1257943","issue_id":"SNYK-JS-ELECTRON-1257943","priority_score":479,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"functional"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00973},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Wed Apr 28 2021 15:14:34 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"critical"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":4.89},{"name":"scoreVersion","value":"V5"}],"severity":"critical","title":"Out-of-bounds"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1258207","issue_id":"SNYK-JS-ELECTRON-1258207","priority_score":195,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.01639},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Sun May 02 2021 14:50:37 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":1.98},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1259349","issue_id":"SNYK-JS-ELECTRON-1259349","priority_score":190,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00107},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Wed Apr 28 2021 15:14:35 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":1.93},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-ELECTRON-1296559","issue_id":"SNYK-JS-ELECTRON-1296559","priority_score":289,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"proofOfConcept"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00632},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Fri Jun 04 2021 15:39:08 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":2.95},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Type Confusion"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1086695","issue_id":"SNYK-JS-ELECTRON-1086695","priority_score":199,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"low"},{"name":"availability","value":"low"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"unproven"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00523},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Thu Mar 25 2021 17:11:00 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":7.84},{"name":"likelihood","value":2.54},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Improper Input Validation"},{"exploit_maturity":"mature","id":"SNYK-JS-ELECTRON-1088600","issue_id":"SNYK-JS-ELECTRON-1088600","priority_score":864,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"high"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.03804},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Thu Mar 25 2021 17:09:20 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":8.82},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Out-of-bounds Write"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1296563","issue_id":"SNYK-JS-ELECTRON-1296563","priority_score":143,"priority_score_factors":[{"name":"confidentiality","value":"low"},{"name":"integrity","value":"low"},{"name":"availability","value":"low"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00632},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Fri Jun 04 2021 15:39:09 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":5.62},{"name":"likelihood","value":2.54},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Race Condition"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1277203","issue_id":"SNYK-JS-ELECTRON-1277203","priority_score":152,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"none"},{"name":"availability","value":"none"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00333},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Wed Apr 28 2021 15:14:36 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":5.99},{"name":"likelihood","value":2.53},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Heap-based Buffer Overflow"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1277205","issue_id":"SNYK-JS-ELECTRON-1277205","priority_score":194,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.0132},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Wed Apr 28 2021 15:14:37 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":1.97},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Integer Overflow"},{"exploit_maturity":"mature","id":"SNYK-JS-ELECTRON-1085705","issue_id":"SNYK-JS-ELECTRON-1085705","priority_score":864,"priority_score_factors":[{"name":"confidentiality","value":"high"},{"name":"integrity","value":"high"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"high"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.01139},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Tue Mar 16 2021 15:53:46 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"high"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":9.79},{"name":"likelihood","value":8.82},{"name":"scoreVersion","value":"V5"}],"severity":"high","title":"Use After Free"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-EJS-6689533","issue_id":"SNYK-JS-EJS-6689533","priority_score":49,"priority_score_factors":[{"name":"confidentiality","value":"none"},{"name":"integrity","value":"low"},{"name":"availability","value":"none"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00129},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Mon Apr 29 2024 10:24:25 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":true},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"medium"},{"name":"relativePopularityRank","value":99},{"name":"impact","value":2.35},{"name":"likelihood","value":2.06},{"name":"scoreVersion","value":"V5"}],"severity":"medium","title":"Improper Control of Dynamically-Managed Code Resources"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1086694","issue_id":"SNYK-JS-ELECTRON-1086694","priority_score":108,"priority_score_factors":[{"name":"confidentiality","value":"low"},{"name":"integrity","value":"low"},{"name":"availability","value":"none"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"unproven"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.01226},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Thu Mar 25 2021 17:09:21 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"medium"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":4.19},{"name":"likelihood","value":2.56},{"name":"scoreVersion","value":"V5"}],"severity":"medium","title":"Access Restriction Bypass"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-TAR-6476909","issue_id":"SNYK-JS-TAR-6476909","priority_score":142,"priority_score_factors":[{"name":"confidentiality","value":"none"},{"name":"integrity","value":"none"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"proofOfConcept"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00045},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Fri Mar 22 2024 12:56:33 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":true},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"medium"},{"name":"relativePopularityRank","value":99},{"name":"impact","value":5.99},{"name":"likelihood","value":2.36},{"name":"scoreVersion","value":"V5"}],"severity":"medium","title":"Uncontrolled Resource Consumption ('Resource Exhaustion')"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-EXPRESS-6474509","issue_id":"SNYK-JS-EXPRESS-6474509","priority_score":98,"priority_score_factors":[{"name":"confidentiality","value":"low"},{"name":"integrity","value":"low"},{"name":"availability","value":"none"},{"name":"scope","value":"changed"},{"name":"exploitCodeMaturity"},{"name":"userInteraction","value":"required"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00044},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Tue Mar 26 2024 07:34:23 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"medium"},{"name":"relativePopularityRank","value":99},{"name":"impact","value":4.54},{"name":"likelihood","value":2.15},{"name":"scoreVersion","value":"V5"}],"severity":"medium","title":"Open Redirect"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-HTTPCACHESEMANTICS-3248783","issue_id":"SNYK-JS-HTTPCACHESEMANTICS-3248783","priority_score":63,"priority_score_factors":[{"name":"confidentiality","value":"none"},{"name":"integrity","value":"none"},{"name":"availability","value":"low"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"proofOfConcept"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00116},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Mon Jan 30 2023 14:39:52 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":true},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"medium"},{"name":"relativePopularityRank","value":99},{"name":"impact","value":2.35},{"name":"likelihood","value":2.64},{"name":"scoreVersion","value":"V5"}],"severity":"medium","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-JSON5-3182856","issue_id":"SNYK-JS-JSON5-3182856","priority_score":178,"priority_score_factors":[{"name":"confidentiality","value":"low"},{"name":"integrity","value":"low"},{"name":"availability","value":"high"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"proofOfConcept"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"low"},{"name":"attackComplexity","value":"high"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00667},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Sun Dec 25 2022 08:45:14 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":true},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"medium"},{"name":"relativePopularityRank","value":99},{"name":"impact","value":7.84},{"name":"likelihood","value":2.27},{"name":"scoreVersion","value":"V5"}],"severity":"medium","title":"Prototype Pollution"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-ELECTRON-1277526","issue_id":"SNYK-JS-ELECTRON-1277526","priority_score":96,"priority_score_factors":[{"name":"confidentiality","value":"low"},{"name":"integrity","value":"low"},{"name":"availability","value":"none"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"unproven"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"high"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.01558},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Sun May 02 2021 14:50:38 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":false},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"medium"},{"name":"relativePopularityRank","value":97},{"name":"impact","value":4.19},{"name":"likelihood","value":2.28},{"name":"scoreVersion","value":"V5"}],"severity":"medium","title":"Improper Input Validation"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-DOMPURIFY-6474511","issue_id":"SNYK-JS-DOMPURIFY-6474511","priority_score":67,"priority_score_factors":[{"name":"confidentiality","value":"none"},{"name":"integrity","value":"none"},{"name":"availability","value":"low"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"proofOfConcept"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"low"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.01055},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Thu Apr 11 2024 09:49:38 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":true},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"medium"},{"name":"relativePopularityRank","value":99},{"name":"impact","value":2.35},{"name":"likelihood","value":2.83},{"name":"scoreVersion","value":"V5"}],"severity":"medium","title":"Template Injection"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-WORDWRAP-3149973","issue_id":"SNYK-JS-WORDWRAP-3149973","priority_score":57,"priority_score_factors":[{"name":"confidentiality","value":"none"},{"name":"integrity","value":"none"},{"name":"availability","value":"low"},{"name":"scope","value":"unchanged"},{"name":"exploitCodeMaturity","value":"proofOfConcept"},{"name":"userInteraction","value":"none"},{"name":"privilegesRequired","value":"none"},{"name":"attackComplexity","value":"high"},{"name":"attackVector","value":"network"},{"name":"epss","value":0.00095},{"name":"isTrending","value":false},{"name":"publicationDate","value":"Wed Mar 22 2023 15:02:56 GMT+0000 (Coordinated Universal Time)"},{"name":"isReachable","value":false},{"name":"isTransitive","value":true},{"name":"isMalicious","value":false},{"name":"businessCriticality","value":"high"},{"name":"relativeImportance","value":"low"},{"name":"relativePopularityRank","value":99},{"name":"impact","value":2.35},{"name":"likelihood","value":2.42},{"name":"scoreVersion","value":"V5"}],"severity":"low","title":"Regular Expression Denial of Service (ReDoS)"}],"prId":"22ef6fb8-4fbf-4b5e-a5d3-b9a4a6d57fcd","prPublicId":"22ef6fb8-4fbf-4b5e-a5d3-b9a4a6d57fcd","packageManager":"npm","priorityScoreList":[193,143,143,193,201,191,230,130,191,192,169,864,143,192,186,208,169,192,193,194,61,49,178,53,479,195,190,289,199,864,143,152,194,864,49,108,142,98,63,96,67,57],"projectPublicId":"cc063525-7ce4-44ac-b381-1a9d2e4dce87","projectUrl":"https://app.snyk.io/org/abdulrahman305/project/cc063525-7ce4-44ac-b381-1a9d2e4dce87?utm_source=github&utm_medium=referral&page=upgrade-pr","prType":"upgrade","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["priorityScore"],"type":"auto","upgrade":["SNYK-JS-ELECTRON-1253279","SNYK-JS-ELECTRON-1296553","SNYK-JS-ELECTRON-1296555","SNYK-JS-ELECTRON-1253281","SNYK-JS-ELECTRON-1086693","SNYK-JS-ELECTRON-1296557","SNYK-JS-ELECTRON-1260586","SNYK-JS-ELECTRON-1261111","SNYK-JS-ELECTRON-1296561","SNYK-JS-ELECTRON-1087442","SNYK-JS-ELECTRON-1088602","SNYK-JS-ELECTRON-1252279","SNYK-JS-ELECTRON-1296565","SNYK-JS-ELECTRON-1085647","SNYK-JS-PROTOBUFJS-2441248","SNYK-JS-PROTOBUFJS-5756498","SNYK-JS-WS-7266574","SNYK-JS-ELECTRON-1085994","SNYK-JS-ELECTRON-125228...

Snyk has created this PR to upgrade electron from 10.3.2 to 10.4.7.

See this package in npm:
electron

See this project in Snyk:
https://app.snyk.io/org/abdulrahman305/project/cc063525-7ce4-44ac-b381-1a9d2e4dce87?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

korbit-ai bot commented Aug 10, 2024

👋 I'm here to help you review your pull request. When you're ready for me to perform a review, you can comment anywhere on this pull request with this command: /korbit-review.

As a reminder, here are some helpful tips on how we can collaborate together:

  • To have me re-scan your pull request, simply re-invoke the /korbit-review command in a new comment.
  • You can interact with me by tagging @korbit-ai in any conversation in your pull requests.
  • On any comment I make on your code, please leave a 👍 if it is helpful and a 👎 if it is unhelpful. This will help me learn and improve as we work together
  • Lastly, to learn more, check out our Docs.

Copy link

codeautopilot bot commented Aug 10, 2024

Your organization has reached the subscribed usage limit. You can upgrade your account by purchasing a subscription at Stripe payment link

Disclaimer: This comment was entirely generated using AI. Be aware that the information provided may be incorrect.

Current plan usage: 100.17%

Have feedback or need help?
Discord
Documentation
support@codeautopilot.com

Copy link

coderabbitai bot commented Aug 10, 2024

Important

Review skipped

Ignore keyword(s) in the title.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media?

❤️ Share
🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Generate unit testing code for this file.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai generate unit testing code for this file.
    • @coderabbitai modularize this function.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read src/utils.ts and generate unit testing code.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.
    • @coderabbitai help me debug CodeRabbit configuration file.

Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

@gitauto-ai gitauto-ai bot added the gitauto label Oct 2, 2024
@abdulrahman305 abdulrahman305 merged commit bf31f35 into master Oct 23, 2024
4 checks passed
@abdulrahman305 abdulrahman305 deleted the snyk-upgrade-933ddd0e4e3e385bce195514fad0f9bb branch October 23, 2024 06:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants