Skip to content

Comments

chore(deps): updating electron/rebuild tar and form-data#9528

Merged
mmaietta merged 4 commits intomasterfrom
dep-updates
Jan 27, 2026
Merged

chore(deps): updating electron/rebuild tar and form-data#9528
mmaietta merged 4 commits intomasterfrom
dep-updates

Conversation

@mmaietta
Copy link
Collaborator

Also removed request from test suite to clear out a different pnpm audit entry

Then I ran pnpm dedupe

@changeset-bot
Copy link

changeset-bot bot commented Jan 22, 2026

🦋 Changeset detected

Latest commit: 9e302f1

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 9 packages
Name Type
electron-publish Patch
app-builder-lib Patch
dmg-builder Patch
electron-builder-squirrel-windows Patch
electron-builder Patch
electron-forge-maker-appimage Patch
electron-forge-maker-nsis-web Patch
electron-forge-maker-nsis Patch
electron-forge-maker-snap Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@socket-security
Copy link

socket-security bot commented Jan 22, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedelectron@​23.2.0949010098100
Updated@​babel/​preset-typescript@​7.27.0 ⏵ 7.28.51001007392100
Updated@​types/​request@​2.48.12 ⏵ 2.48.131001007381100
Updateddebug@​4.4.1 ⏵ 4.4.310010010083100
Updatedform-data@​4.0.4 ⏵ 4.0.599 +110010089100
Updated@​electron/​rebuild@​4.0.1 ⏵ 4.0.399 +110010089 +5100

View full report

@socket-security
Copy link

socket-security bot commented Jan 22, 2026

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
High CVE: npm semver vulnerable to Regular Expression Denial of Service

CVE: GHSA-c2qf-rxjj-qqgw semver vulnerable to Regular Expression Denial of Service (HIGH)

Affected versions: >= 7.0.0 < 7.5.2; >= 6.0.0 < 6.3.1; < 5.7.2

Patched version: 6.3.1

From: ?npm/electron@23.2.0npm/semver@6.3.0

ℹ Read more on: This package | This alert | What is a CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/semver@6.3.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
High CVE: npm semver vulnerable to Regular Expression Denial of Service

CVE: GHSA-c2qf-rxjj-qqgw semver vulnerable to Regular Expression Denial of Service (HIGH)

Affected versions: >= 7.0.0 < 7.5.2; >= 6.0.0 < 6.3.1; < 5.7.2

Patched version: 7.5.2

From: ?npm/electron@23.2.0npm/semver@7.3.8

ℹ Read more on: This package | This alert | What is a CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/semver@7.3.8. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@mmaietta mmaietta changed the title chore(deps): updating tar and form-data chore(deps): updating electron/rebuild tar and form-data Jan 27, 2026
@mmaietta mmaietta merged commit e46b407 into master Jan 27, 2026
33 checks passed
@mmaietta mmaietta deleted the dep-updates branch January 27, 2026 20:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

npm reports vulnerable dependency versions

1 participant