Build-time dependency advisories in electron-builder and vite
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 55/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- typescript, vite
- Domain
- devops
Research direction
Start by reviewing the package manifest and lockfile, then inspect the npm audit dependency paths listed in the issue. Check for fixed versions of electron-builder and vite or whether overrides can address the vulnerable transitive packages. Verify that packaging still works; done means the listed build-time advisories are resolved without breaking packaging.
Written by the indexing model from the issue text.
Description
From SEV-15 of the earlier AUDIT_REPORT.md, re-checked with npm audit on 2026-10-07.
npm audit --omit=dev reports 0 vulnerabilities, so nothing in the shipped app is affected. The full audit reports 2 high and 8 moderate advisories, all in build tooling:
http-cache-semantics4.2.0 (high, GHSA-ch52-4w7c-c8xp) viaelectron-builder→app-builder-lib→@electron/get→got→cacheable-requestsource-map-js1.2.1 (high, GHSA-68fv-2mgg-jv7q) viavite→postcsssprintf-js1.1.3 (moderate, GHSA-hp3w-g68c-fv3c) via@electron/get→global-agent→roarr, plus the moderate parents in theelectron-builderchain
These packages only run while building or downloading Electron, but CI and release builds do run them.
Proposal
Bump electron-builder and vite once fixed versions are available, or add overrides for the vulnerable transitive packages and check that packaging still works. #119 covers adding npm audit to CI so new advisories are noticed.
- Dominant language
- TypeScript
- Stars
- 2
- Forks
- 2
- Avg merge
- 5h 52m
- Merged PRs (30d)
- 18
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from PierrunoYT/patch
-
enhancement priority: low security severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
PierrunoYT/patch#208 ·
Maintainers usually reply within 1 day
-
enhancement platform: windows priority: low severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
PierrunoYT/patch#198 ·
Maintainers usually reply within 1 day
-
bug priority: low severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
PierrunoYT/patch#190 ·
Maintainers usually reply within 1 day
-
Unbounded waits: revokeProjectGrant has no timeout, and timed-out browser waiters are never removedOpenbug priority: low severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
PierrunoYT/patch#188 ·
Maintainers usually reply within 1 day
-
bug priority: medium severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
PierrunoYT/patch#179 ·
Maintainers usually reply within 1 day
All issues in PierrunoYT/patch
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
farbenmeer/tapi#531 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
naver/egjs-flicking#971 ·
-
Renderer treats a sub-pixel width difference as a resize, which cancels the `motion()` entranceOpen
Difficulty 1/5 Under an hour Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
Tenant
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
MTES-MCT/Dossier-Facile-Frontend#2061 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
backnotprop/plannotator#1784 ·
Maintainers usually reply within 1 day