[Snyk] Security upgrade electron from 25.2.0 to 25.4.0#24119
[Snyk] Security upgrade electron from 25.2.0 to 25.4.0#24119MonilBhavsar merged 1 commit intomainfrom
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-ELECTRON-5812138 - https://snyk.io/vuln/SNYK-JS-ELECTRON-5812149 - https://snyk.io/vuln/SNYK-JS-ELECTRON-5812567
|
@MonilBhavsar Please copy/paste the Reviewer Checklist from here into a new comment on this PR and complete it. If you have the K2 extension, you can simply click: [this button] |
|
@MonilBhavsar issue here- #24120 I think we can upgrade this. No c+ required. |
MonilBhavsar
left a comment
There was a problem hiding this comment.
Don't we need to test for regression?
|
Okay, I can help with that today then |
Reviewer Checklist
Screenshots/VideosDesktopScreen.Recording.2023-08-06.at.00.28.19.movScreen.Recording.2023-08-06.at.00.26.54.mov |
|
🎯 @rushatgabhane, thanks for reviewing and testing this PR! 🎉 An E/App issue has been created to issue payment here: #24182. |
MonilBhavsar
left a comment
There was a problem hiding this comment.
Thanks! Looks good to me
|
✋ This PR was not deployed to staging yet because QA is ongoing. It will be automatically deployed to staging after the next production release. |
|
🚀 Deployed to staging by https://github.com/MonilBhavsar in version: 1.3.52-0 🚀
|
|
🚀 Deployed to staging by https://github.com/MonilBhavsar in version: 1.3.52-0 🚀
|
|
🚀 Deployed to production by https://github.com/puneetlath in version: 1.3.52-5 🚀
|
Details
Vulnerabilities that will be fixed
With an upgrade:
SNYK-JS-ELECTRON-5812138
SNYK-JS-ELECTRON-5812149
SNYK-JS-ELECTRON-5812567
Check the changes in this PR to ensure they won't cause issues with your project.
Fixed Issues
$
PROPOSAL:
Tests
Offline tests
QA Steps
PR Author Checklist
### Fixed Issuessection aboveTestssectionOffline stepssectionQA stepssectiontoggleReportand notonIconClick)myBool && <MyComponent />.src/languages/*files and using the translation methodWaiting for Copylabel for a copy review on the original GH to get the correct copy.STYLE.md) were followedAvatar, I verified the components usingAvatarare working as expected)/** comment above it */thisproperly so there are no scoping issues (i.e. foronClick={this.submit}the methodthis.submitshould be bound tothisin the constructor)thisare necessary to be bound (i.e. avoidthis.submit = this.submit.bind(this);ifthis.submitis never passed to a component event handler likeonClick)StyleUtils.getBackgroundAndBorderStyle(themeColors.componentBG))Avataris modified, I verified thatAvataris working as expected in all cases)ScrollViewcomponent to make it scrollable when more elements are added to the page.mainbranch was merged into this PR after a review, I tested again and verified the outcome was still expected according to theTeststeps.Screenshots/Videos
Web
Mobile Web - Chrome
Mobile Web - Safari
Desktop
iOS
Android