Skip to content

deps-dev(deps-dev): bump electron from 38.2.1 to 38.8.6 - #149

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/electron-38.8.6
Open

deps-dev(deps-dev): bump electron from 38.2.1 to 38.8.6#149
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/electron-38.8.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor

Bumps electron from 38.2.1 to 38.8.6.

Commits
  • fbc489c fix: validate protocol scheme names in setAsDefaultProtocolClient (#50157)
  • af4f835 fix: strictly validate sender for internal IPC reply channels (#50160)
  • 9d0c858 fix: validate USB device selection against filtered device list (#50159)
  • e6e8269 fix: potential UAF in OnDownloadPathGenerated (#50150)
  • e17eef4 fix: read nodeIntegrationInWorker from per-frame WebPreferences (#50163)
  • 9ffc255 fix: correct parsing of second-instance additionalData (#50177)
  • 07a1e9c fix: prevent use-after-free in permission request callbacks (#50153)
  • 567435b fix: use requesting frame origin in permission helper and device choosers (#5...
  • 5ee5ace fix: use proper quoting for exe paths and args on Windows (#50146)
  • 2d92886 fix: validate response header names and values before AddHeader (#50130)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [electron](https://github.com/electron/electron) from 38.2.1 to 38.8.6.
- [Release notes](https://github.com/electron/electron/releases)
- [Commits](electron/electron@v38.2.1...v38.8.6)

---
updated-dependencies:
- dependency-name: electron
  dependency-version: 38.8.6
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automated. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits.
Credits must be used to enable repository wide code reviews.

@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/electron 38.8.6 🟢 7.1
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Security-Policy🟢 10security policy file detected
Dependency-Update-Tool🟢 10update tool detected
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 1030 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies🟢 10all dependencies are pinned
CII-Best-Practices🟢 5badge detected: Passing
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Vulnerabilities⚠️ 049 existing vulnerabilities detected
License🟢 10license file detected
Branch-Protection⚠️ -1internal error: error during GetBranch(44-x-y): error during branchesHandler.query: internal error: githubv4.Query: Resource not accessible by integration
Fuzzing⚠️ 0project is not fuzzed
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
CI-Tests🟢 929 out of 30 merged PRs checked by a CI test -- score normalized to 9
Contributors🟢 10project has 90 contributing companies or organizations

Scanned Files

  • package-lock.json

@github-actions

Copy link
Copy Markdown

📦 Bundle Size Report

Component Base PR Change
React 1.4M 1.4M ➡️ No change
Electron 840K 840K ➡️ No change
Total 2.2MiB 2.2MiB ➡️ No change

🤖 This comment will be automatically updated on new commits

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant