fix: upgrade electron to 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8 (CVE-2026-34769)#8188
fix: upgrade electron to 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8 (CVE-2026-34769)#8188orbisai0security wants to merge 1 commit into
Pull Request #8188 Alerts: Complete with warnings
| Report | Status | Message |
|---|---|---|
| PR #8188 Alerts | Found 1 project alert |
Pull request alerts notify when new issues are detected between the diff of the pull request and it's target branch.
Details
Warning
Review the following alerts detected in dependencies.
According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
| Action | Severity | Alert (click "▶" to expand/collapse) |
|---|---|---|
| Warn | High CVE: Electron: Use-after-free in offscreen child window paint callbackCVE: GHSA-532v-xpq5-8h95 Electron: Use-after-free in offscreen child window paint callback (HIGH) Affected versions: < 39.8.1; >= 40.0.0-alpha.1 < 40.7.0; >= 41.0.0-alpha.1 < 41.0.0 Patched version: 39.8.1 From: package.json → ℹ Read more on: This package | This alert | What is a CVE?
|