From 2c10d122f3fe52860585583ab1e2e44904458bcb Mon Sep 17 00:00:00 2001 From: Matthew Ruzzi <68619790+mattruzzi@users.noreply.github.com> Date: Sun, 8 Nov 2020 17:29:11 -0800 Subject: [PATCH] Bump default Electron to 10.1.5 (with Chromium 85.0.4183.121) (#1066) Fixes [CVE-2020-15999](https://github.com/advisories/GHSA-pv36-h7jh-qm62) Heap overflow in the freetype library by upgrading to Electron [10.1.5](https://github.com/electron/electron/releases/tag/v10.1.5) https://github.com/electron/electron/pull/26070 --- src/constants.ts | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/constants.ts b/src/constants.ts index eb40216..39ae1f5 100644 --- a/src/constants.ts +++ b/src/constants.ts @@ -3,8 +3,8 @@ import * as path from 'path'; export const DEFAULT_APP_NAME = 'APP'; // Update both together -export const DEFAULT_ELECTRON_VERSION = '10.1.0'; -export const DEFAULT_CHROME_VERSION = '85.0.4183.87'; +export const DEFAULT_ELECTRON_VERSION = '10.1.5'; +export const DEFAULT_CHROME_VERSION = '85.0.4183.121'; export const ELECTRON_MAJOR_VERSION = parseInt( DEFAULT_ELECTRON_VERSION.split('.')[0],