Open melvin-bot[bot] opened 3 weeks ago
This is a Snyk issue. Snyk is a tool that automatically tracks our repositories' dependencies and reports associated security vulnerabilities. It also automatically create PRs to fix these vulnerabilities.
C+: Please follow these steps to test the linked PR before running through the reviewer checklist:
- [ ] The first step is to understand the PR: what dependency is it upgrading, for which vulnerability, how it impacts our product & end users.
- [ ] If the issue is not worth fixing, please add your reasoning in the issue and have the internal engineer review it.
- [ ] Check the change log (which should be included in the PR description) to see all changes. We want to identify any breaking changes. If it is a minor version bump, it's unlikely that there are any breaking changes.
- [ ] Test our feature(s) that make use of this package. If it does not work, we should understand what broke it. It is also a good idea to check our main flows to make sure they are not broken that you can add in the checklist screenshots/videos.
This issue has not been updated in over 15 days. eroding to Monthly issue.
P.S. Is everyone reading this sure this is really a near-term priority? Be brave: if you disagree, go ahead and close it out. If someone disagrees, they'll reopen it, and if they don't: one less thing to do!
Snyk has created this PR to upgrade electron-updater from 6.3.8 to 6.3.9.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 1 version ahead of your current version.
The recommended version was released on 25 days ago.
Release notes
Package name: electron-updater
Patch Changes
#8541
b6d6ea993fd3b368d28786c259bb50486aaac417
Thanks @ beyondkmp! - fix: Unable to copy file for caching: ENOENT#8545
fc3a78e4e61f916058fca9b15fc16f076c3fabd1
Thanks @ mmaietta! - chore(deps): update devDependencies, including typescriptUpdated dependencies [
fc3a78e4e61f916058fca9b15fc16f076c3fabd1
]:Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: