build(deps-dev): bump electron from 43.0.0 to 43.5.0 - #473
Conversation
Bumps [electron](https://github.com/electron/electron) from 43.0.0 to 43.5.0. - [Release notes](https://github.com/electron/electron/releases) - [Commits](electron/electron@v43.0.0...v43.5.0) --- updated-dependencies: - dependency-name: electron dependency-version: 43.5.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
All alerts resolved. Learn more about Socket for GitHub. This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. Ignoring alerts on:
|
There was a problem hiding this comment.
LGTM — routine devDependency version bump.
What was reviewed: the yarn.lock diff, confirming it only bumps the electron resolution from 43.0.0 to 43.7.5 and updates the matching checksum, with no other files, source code, or config changed.
Extended reasoning...
The diff touches only yarn.lock, bumping the pinned electron (devDependency) resolution from 43.0.0 to 43.7.5 and its integrity checksum; no source, build, or CI configuration changed. There is no security-sensitive surface exercised by this change itself (it doesn't modify code paths, only a lockfile pin), and the bump is a patch-level dependabot update with no outstanding review objections in the timeline. Given the mechanical, self-contained nature of a lockfile-only version bump, this qualifies for approval per the guidelines.
|
@SocketSecurity ignore npm/electron@43.7.5 |
Bumps electron from 43.0.0 to 43.5.0.
Release notes
Sourced from electron's releases.
... (truncated)
Commits
87cd122fix: serialize the target's values into the Node.js startup snapshot on cross...f835161fix: crash in webRequest proxy for redirected CORS preflights and frameless f...379a50ebuild: update PGO profiles (#53311)42e9db9chore: clean up forward declarations (#53295)fe02d1afix: crash when calling utilityProcess.postMessage() after the process has ex...bb2194efix: dangling WebContents/NativeWindow pointers in debugger, devtools, login,...1002688fix: object lifetime bugs in sharedTexture, service-worker ipcRenderer and ut...eb3528afix: use-after-free when event handlers re-enter chooser, protocol stream and...8a24b57fix: spellcheck failing to initialize on Linux (#52717)fd98d68fix: crash when V8 optimises a call to a node:wasi import (#53265)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.