theQRL / qrl-wallet

QRL Wallet
https://wallet.theqrl.org
MIT License
48 stars 27 forks source link

Update Electron version to resolve Snky vulnerabilities. #179

Closed scottdonaldau closed 6 years ago

scottdonaldau commented 6 years ago

These issues do not affect the QRL Wallet repo, however we should update regardless.

Issues identified as vulnerabilities below, with justification as to why we are not vulnerable.

https://snyk.io/vuln/npm:electron:20180307 / https://snyk.io/vuln/npm:electron:20180123

https://snyk.io/vuln/npm:electron:20180323

https://snyk.io/vuln/npm:shelljs:20140723

Other low severity items skipped from this issue though will be addressed.

scottdonaldau commented 6 years ago

Two vulnerabilities patched in #180

Future PR will ignore https://snyk.io/vuln/npm:shelljs:20140723 from Snky reports as this component is only executed in CircleCI / Teamcity environments to build Electron Clients.

scottdonaldau commented 6 years ago

Resolved in 69aaf4062d9fabaf4577a32baa228c6ed5a0badc, 3233249b3c107a60a1359c1e4dfef8fdac45fa9f and 1e81a4e3c769ac0c2bf5f6a1513c716617c83ea8