secure-repo
Electron
secure-repo | Electron | |
---|---|---|
6 | 236 | |
237 | 112,107 | |
2.5% | 0.4% | |
2.8 | 9.8 | |
about 1 month ago | 5 days ago | |
Go | C++ | |
GNU Affero General Public License v3.0 | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
secure-repo
-
Show HN: Secure your public GitHub repository with automated security fixes
I am excited to share Secure-Repo, an open-source project that can easily secure your GitHub repository through automated security fixes. The project aims to automate common security fixes, so developers do not have to wade through documentation.
It does not require any App installation or onboarding steps, you can just enter your public repository and click on a button to improve security through automated pull requests.
I invite you to try Secure-Repo on your public repository using the hosted version at http://app.stepsecurity.io/securerepo and share your feedback.
Important open-source repositories have adopted the tool. Here are a few example pull requests created by the maintainers of Electron, Ruby, and GoogleCloudPlatform using this project.
Electron: https://github.com/electron/electron/pull/36363
-
Securing a GitHub repo is a ton of work
I've found StepSecurity's tooling helpful in getting my repos secured.
* https://app.stepsecurity.io/securerepo
-
Do you maintain a GitHub Action? Contribute to the SecureWorkflows project!
The problem we are trying to solve is to automatically calculate what the minimum GITHUB_TOKEN permissions should be for a given workflow. We are solving this problem by building a knowledge base of permissions needed by each GitHub Action. If you own a GitHub Action, contribute to the SecureWorkflows project by adding a YAML file describing the permissions your Action needs.
-
StepSecurity releases tool that it used to improve security of 30 critical open-source projects (including NodeJS, OpenSSL, Python, Rails, React Native)
List of merged pull requests for the 30 critical projects can be found here: https://github.com/step-security/secure-workflows/issues/462
- Secure GitHub Actions workflows by automatically updating the workflow (YAML) files
Electron
-
Release Radar • February 2024 Edition
The team at Electron have been faithfully shipping new releases almost every single month. I think they had Christmas off 🤔. This popular framework has developers writing cross-platform desktop applications using JavaScript, HTML and CSS. The latest update depreciates some process events, and added new modules, APIs, methods, and more. Read into all the changes in the Electron release notes. This month, Electron also introduced a new formal RFC process.
-
The IDEs we had 30 years ago and we lost
VS Code has been crashing at launch in Wayland since more than eight months ago:
https://github.com/electron/electron/issues/37531
-
Design Systems with Web Components
So we talked a lot about the Atomic Design Principle, but you could just use that in any system and start creating. You could have Angular components, React Components, and Vue Components. But if you notice these don't easily work Everwhere. So the solution is to use Web Components because the modern browser can already understand these, and any Front-End framework can then utilize these components. You can use Electron for desktop (Slack, VSCode), PWA for both Android and iOS, and across all browsers Can I Use.
- Settings · Rulesets · electron/electron
-
How I got Wayland, Vulkan, and hardware acceleration working with Figma on Fedora 39.
I'm noticing a significant boost in performance, crisper text, and better power savings. The only shortcoming is that the window which Figma will run on will lose its shadow. This is due to a technical limitation with frameless windows on Linux.
-
Building Apps with Tauri and Elixir
For the longest time, building desktop apps was a daunting task to web developers. That is, until technologies like Electron made creating these apps more approachable to a wider audience. Today, we’ve got a wide array of native applications built with solutions like Electron, Tauri, Capacitor, and many more. While these are great solutions, sometimes configuration can be tricky and the applications we create can become somewhat bloated in terms of memory usage.
-
MS Teams & Electron libwebp 0-Day Vulnerability
Electron patch for version 27: https://github.com/electron/electron/pull/39823
-
CVE-2023-4863: Heap buffer overflow in WebP (Chrome)
It does, see [0]. Fun fact: Signal desktop, which uses Electron under the hood, is running without sandbox on Linux [1][2].
[0] https://github.com/electron/electron/pull/39824
[1] https://github.com/signalapp/Signal-Desktop/issues/5195
[2] https://github.com/signalapp/Signal-Desktop/pull/4381
-
Capturing at Speed of Thought
Turns out, there is an issue with the electron window not returning focus correctly on mac - https://github.com/electron/electron/issues/5495. The trick to solving is to treat quick capture as a screensaver. When closing, you hide it by setting the opacity to 0 and sending hide: command to the first responder.
-
$Home, Not So Sweet $Home
Open since 2016! https://github.com/electron/electron/issues/8124
What are some alternatives?
machine - Machine is a workflow/pipeline library for processing data
tauri - Build smaller, faster, and more secure desktop applications with a web frontend.
DnsControl - Infrastructure as code for DNS!
dotenv - Loads environment variables from .env for nodejs projects.
Beehive - A flexible event/agent & automation system with lots of bees 🐝
Eel - A little Python library for making simple Electron-like HTML/JS GUI apps
reposaur - Open source compliance tool for development platforms.
puppeteer - Node.js API for Chrome
mysql-actions - MySQL Actions
react-native - A framework for building native applications using React
functions-framework-dotnet - FaaS (Function as a service) framework for writing portable .NET functions
cheerio - The fast, flexible, and elegant library for parsing and manipulating HTML and XML.