Closed renovate[bot] closed 3 weeks ago
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
Package | New capabilities | Transitives | Size | Publisher |
---|---|---|---|---|
npm/electron@30.1.0 | Transitive: environment, filesystem, network | +21 |
2.34 MB |
🚮 Removed packages: npm/electron@27.3.11
🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎
To accept the risk, merge this PR and you will not be notified again.
Alert | Package | Note |
---|---|---|
Install scripts | npm/electron@27.3.11 |
|
Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.
Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.
Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.
If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.
To ignore an alert, reply with a comment starting with @SocketSecurity ignore
followed by a space separated list of ecosystem/package-name@version
specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0
or ignore all packages with @SocketSecurity ignore-all
@SocketSecurity ignore npm/electron@27.3.11
This PR contains the following updates:
27.3.11
->30.1.0
Release Notes
electron/electron (electron)
### [`v30.1.0`](https://togithub.com/electron/electron/releases/tag/v30.1.0): electron v30.1.0 [Compare Source](https://togithub.com/electron/electron/compare/v30.0.9...v30.1.0) ### Release Notes for v30.1.0 #### Fixes - BrowserWindow.show() now correctly restores focus to inactive apps on macOS. [#42306](https://togithub.com/electron/electron/pull/42306) (Also in [31](https://togithub.com/electron/electron/pull/42305)) - Fixed BrowserWindow vibrancy on macOS. [#42263](https://togithub.com/electron/electron/pull/42263) - Fixed an issue where `BrowserView` `webContents` were getting destroyed even when `preventDefault` was being set on the owning `BrowserWindow`'s `close` event. [#42371](https://togithub.com/electron/electron/pull/42371) - Fixed an issue where dialogs did not work if they were parented to a BaseWindow and not a BrowserWindow. [#42327](https://togithub.com/electron/electron/pull/42327) (Also in [31](https://togithub.com/electron/electron/pull/42326)) - Fixed an issue where some calls to WebUSB methods could crash. [#42364](https://togithub.com/electron/electron/pull/42364) (Also in [29](https://togithub.com/electron/electron/pull/42363), [31](https://togithub.com/electron/electron/pull/42365)) #### Other Changes - Updated Chromium to 124.0.6367.243. [#42328](https://togithub.com/electron/electron/pull/42328) - Updated Node.js to v20.14.0. [#42294](https://togithub.com/electron/electron/pull/42294) ### [`v30.0.9`](https://togithub.com/electron/electron/releases/tag/v30.0.9): electron v30.0.9 [Compare Source](https://togithub.com/electron/electron/compare/v30.0.8...v30.0.9) ### Release Notes for v30.0.9 #### Fixes - Fixed the type of `WebviewTag.webpreferences` back to `string`. [#42280](https://togithub.com/electron/electron/pull/42280) (Also in [31](https://togithub.com/electron/electron/pull/42279)) #### Other Changes - Updated Chromium to 124.0.6367.233. [#42269](https://togithub.com/electron/electron/pull/42269) ### [`v30.0.8`](https://togithub.com/electron/electron/releases/tag/v30.0.8): electron v30.0.8 [Compare Source](https://togithub.com/electron/electron/compare/v30.0.7...v30.0.8) ### Release Notes for v30.0.8 #### Other Changes - Backported fix for [`3416635`](https://togithub.com/electron/electron/commit/341663589). [#42255](https://togithub.com/electron/electron/pull/42255) - Updated Chromium to 124.0.6367.230. [#42246](https://togithub.com/electron/electron/pull/42246) ### [`v30.0.7`](https://togithub.com/electron/electron/releases/tag/v30.0.7): electron v30.0.7 [Compare Source](https://togithub.com/electron/electron/compare/v30.0.6...v30.0.7) ### Release Notes for v30.0.7 #### Fixes - Fixed an issue where non-English IME users would see app hangs on a second monitor. [#42249](https://togithub.com/electron/electron/pull/42249) - Fixed an issue where the window could be incorrectly centered in some circumstances when calling `BrowserWindow.center()`. [#42196](https://togithub.com/electron/electron/pull/42196) (Also in [31](https://togithub.com/electron/electron/pull/42197)) #### Other Changes - Updated Chromium to 124.0.6367.221. [#42208](https://togithub.com/electron/electron/pull/42208) ### [`v30.0.6`](https://togithub.com/electron/electron/releases/tag/v30.0.6): electron v30.0.6 [Compare Source](https://togithub.com/electron/electron/compare/v30.0.5...v30.0.6) ### Release Notes for v30.0.6 #### Fixes - Fixed a potential issue with Linux layout invalidation. [#42189](https://togithub.com/electron/electron/pull/42189) ### [`v30.0.5`](https://togithub.com/electron/electron/releases/tag/v30.0.5): electron v30.0.5 [Compare Source](https://togithub.com/electron/electron/compare/v30.0.4...v30.0.5) ### Release Notes for v30.0.5 #### Fixes - Fixed an issue where `setTitleBarOverlay` didn't work as expected when called on `BaseWindow`. [#42151](https://togithub.com/electron/electron/pull/42151) - Fixed an issue where `webContents.navigationHistory` was not an enumerable property. [#42181](https://togithub.com/electron/electron/pull/42181) - Fixed crash on window maximize on X11. [#42185](https://togithub.com/electron/electron/pull/42185) (Also in [31](https://togithub.com/electron/electron/pull/42184)) - `BrowserWindow.focus()` now correctly restore focus to inactive apps on macOS. [#42187](https://togithub.com/electron/electron/pull/42187) (Also in [31](https://togithub.com/electron/electron/pull/42186)) #### Other Changes - Backported fix for [`3402211`](https://togithub.com/electron/electron/commit/340221135). [#42174](https://togithub.com/electron/electron/pull/42174) - Updated Chromium to 124.0.6367.207. [#42166](https://togithub.com/electron/electron/pull/42166) ### [`v30.0.4`](https://togithub.com/electron/electron/releases/tag/v30.0.4): electron v30.0.4 [Compare Source](https://togithub.com/electron/electron/compare/v30.0.3...v30.0.4) ### Release Notes for v30.0.4 #### Fixes - Fixed a crash in `addChildView` if a view is added as its own child. [#42107](https://togithub.com/electron/electron/pull/42107) (Also in [31](https://togithub.com/electron/electron/pull/42108)) - Fixed a crash when the same `WebContentsView` is added via `addChildView` multiple times. [#42115](https://togithub.com/electron/electron/pull/42115) (Also in [31](https://togithub.com/electron/electron/pull/42116)) - Fixed an error when calling `setAutoResize` on a `BrowserView`. [#42137](https://togithub.com/electron/electron/pull/42137) (Also in [31](https://togithub.com/electron/electron/pull/42138)) - Fixed an inconsistent crash on maximizing window and relayout in Ubuntu. [#42145](https://togithub.com/electron/electron/pull/42145) (Also in [31](https://togithub.com/electron/electron/pull/42146)) - Fixed an issue where calling `window.center()` on Windows and Linux incorrectly centered the window. [#42100](https://togithub.com/electron/electron/pull/42100) (Also in [31](https://togithub.com/electron/electron/pull/42101)) #### Other Changes - Backported fix for [`3394581`](https://togithub.com/electron/electron/commit/339458194). [#42122](https://togithub.com/electron/electron/pull/42122) - Updated Chromium to 124.0.6367.201. [#42117](https://togithub.com/electron/electron/pull/42117) ### [`v30.0.3`](https://togithub.com/electron/electron/releases/tag/v30.0.3): electron v30.0.3 [Compare Source](https://togithub.com/electron/electron/compare/v30.0.2...v30.0.3) ### Release Notes for v30.0.3 #### Fixes - Fixed an issue where `document.requestFullscreen` didn't work when calling it from a `webContents` inside `WebContentsView`. [#41996](https://togithub.com/electron/electron/pull/41996) (Also in [31](https://togithub.com/electron/electron/pull/41995)) - Fixed an issue where `fs.createWriteStream` could write out of order. [#42046](https://togithub.com/electron/electron/pull/42046) - Fixed an issue where `recentDOcuments` wasn't populating properly on macOS. [#41992](https://togithub.com/electron/electron/pull/41992) (Also in [29](https://togithub.com/electron/electron/pull/41994), [31](https://togithub.com/electron/electron/pull/41993)) - Fixed crash after upgrade on Linux. [#42064](https://togithub.com/electron/electron/pull/42064) (Also in [29](https://togithub.com/electron/electron/pull/42065), [31](https://togithub.com/electron/electron/pull/42062)) #### Other Changes - Backported fix for [`3307568`](https://togithub.com/electron/electron/commit/330756841). [#42068](https://togithub.com/electron/electron/pull/42068) - Backported fix for [`3392667`](https://togithub.com/electron/electron/commit/339266700). [#42096](https://togithub.com/electron/electron/pull/42096) - Updated Chromium to 124.0.6367.119. [#42020](https://togithub.com/electron/electron/pull/42020) ### [`v30.0.2`](https://togithub.com/electron/electron/releases/tag/v30.0.2): electron v30.0.2 [Compare Source](https://togithub.com/electron/electron/compare/v30.0.1...v30.0.2) ### Release Notes for v30.0.2 #### Fixes - Electron doesn't paint on offscreen-render mode after gpu process crashed. [#41925](https://togithub.com/electron/electron/pull/41925) (Also in [29](https://togithub.com/electron/electron/pull/41923), [31](https://togithub.com/electron/electron/pull/41924)) - Fixed data corruption when protocol.handle() processed incoming data asynchronously. [#41933](https://togithub.com/electron/electron/pull/41933) (Also in [31](https://togithub.com/electron/electron/pull/41932)) - Fixed nativeImage.createThumbnailFromPath and shell.openExternal not resolving when called in the renderer process. [#41909](https://togithub.com/electron/electron/pull/41909) (Also in [31](https://togithub.com/electron/electron/pull/41908)) #### Other Changes - Updated Chromium to 124.0.6367.91. [#41976](https://togithub.com/electron/electron/pull/41976) #### Documentation - Documentation changes: [#41883](https://togithub.com/electron/electron/pull/41883) ### [`v30.0.1`](https://togithub.com/electron/electron/releases/tag/v30.0.1): electron v30.0.1 [Compare Source](https://togithub.com/electron/electron/compare/v30.0.0...v30.0.1) ### Release Notes for v30.0.1 #### Other Changes - Updated Chromium to 124.0.6367.60. [#41867](https://togithub.com/electron/electron/pull/41867) ### [`v30.0.0`](https://togithub.com/electron/electron/releases/tag/v30.0.0): electron v30.0.0 [Compare Source](https://togithub.com/electron/electron/compare/v29.4.2...v30.0.0) ### Release Notes for v30.0.0 #### Stack Upgrades - Chromium `124.0.6367.49` - [New in 124](https://developer.chrome.com/blog/new-in-chrome-124/) - [New in 123](https://developer.chrome.com/blog/new-in-chrome-123/) - Node `20.11.1` - [Node 20.11.1 blog post](https://nodejs.org/en/blog/release/v20.11.1/) - V8 `12.4` #### Breaking Changes - Added `WebContentsView` and `BaseWindow`, replacing the now-deprecated `BrowserView` APIs. [#35658](https://togithub.com/electron/electron/pull/35658) (Also in [29](https://togithub.com/electron/electron/pull/40759)) - Added Windows support for the ASAR Integrity fuse. [#40504](https://togithub.com/electron/electron/pull/40504) - Updated Chromium to 122.0.6194.0. (Behavior Changed: cross-origin iframes now use Permission Policy to access features) [#40750](https://togithub.com/electron/electron/pull/40750) - Updated Chromium to 122.0.6236.2. (Removed: The --disable-color-correct-rendering switch) [#40871](https://togithub.com/electron/electron/pull/40871) - The `inputFieldType` property in the `context-menu` params has been removed. [#41440](https://togithub.com/electron/electron/pull/41440) - Updated Chromium to 124.0.6323.0 (Removed: process.getIOCounters()) [#41412](https://togithub.com/electron/electron/pull/41412) #### Features ##### Additions - Added a `transparent` webpreference to webviews. [#40301](https://togithub.com/electron/electron/pull/40301) - Added a new instance property `navigationHistory` on webContents API with `navigationHistory.getEntryAtIndex` method, enabling applications to retrieve the URL and title of any navigation entry within the browsing history.[#41662](https://togithub.com/electron/electron/pull/41662) (Also in [29](https://togithub.com/electron/electron/pull/41661)) - Added a new method `BrowserWindow.isOccluded()` to allow apps to check occlusion status. [#38982](https://togithub.com/electron/electron/pull/38982) - Added net module to utility process. [#40017](https://togithub.com/electron/electron/pull/40017) (Also in [27](https://togithub.com/electron/electron/pull/40968), [28](https://togithub.com/electron/electron/pull/40967), [29](https://togithub.com/electron/electron/pull/40890)) - Added proxy configuring support for requests made with net module from utility process. [#41417](https://togithub.com/electron/electron/pull/41417) (Also in [28](https://togithub.com/electron/electron/pull/41744), [29](https://togithub.com/electron/electron/pull/41416)) - Added support for Bluetooth ports being requested by service class ID in `navigator.serial`. [#41734](https://togithub.com/electron/electron/pull/41734) (Also in [29](https://togithub.com/electron/electron/pull/41735)) - Added support for `NODE_EXTRA_CA_CERTS`. [#41822](https://togithub.com/electron/electron/pull/41822) - Implemented support for the File System API. [#41827](https://togithub.com/electron/electron/pull/41827) ##### Removed/Deprecated - Removed extraneous dlls from Windows zip files. [#41120](https://togithub.com/electron/electron/pull/41120) (Also in [28](https://togithub.com/electron/electron/pull/41128), [29](https://togithub.com/electron/electron/pull/41129)) #### Fixes - Fixed