Skip to content

Guidance on Electron Vulnerabilities #1121

Description

@darrinmn9

electron^36, used by @vue/devtools-electron, has 20+ vulnerabilities as of now, 7 high. I realize although this PR updates that dependency #1083, upgrading electron major versions would likely be considered a breaking change in this package and possibly alot more work than a simply dependency update to ensure no functionality is broken with this devtools package.

What is the general guidance on vulnerabilities as it relates to electron? is it not prioritized because this is a standalone devtools app for your local computer? Or is the goal to eventually merge that PR and release a new major version for @vue/devtools-electron?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions