Installations
npm install @faltermj/electron-updater
Developer Guide
Typescript
No
Module System
CommonJS
Node Version
14.20.0
NPM Version
6.14.17
Score
72.3
Supply Chain
74.4
Quality
75.1
Maintenance
100
Vulnerability
98.9
License
Releases
Contributors
Languages
TypeScript (91.19%)
NSIS (6.4%)
JavaScript (1.54%)
Shell (0.48%)
Dockerfile (0.34%)
Smarty (0.03%)
CSS (0.02%)
Love this project? Help keep it running — sponsor us today! 🚀
Developer
Download Statistics
Total Downloads
1,235
Last Day
2
Last Week
5
Last Month
25
Last Year
181
GitHub Statistics
MIT License
13,831 Stars
3,287 Commits
1,751 Forks
149 Watchers
46 Branches
555 Contributors
Updated on Feb 12, 2025
Package Meta Information
Latest Version
4.3.9-debug1
Package Id
@faltermj/electron-updater@4.3.9-debug1
Unpacked Size
415.96 kB
Size
101.16 kB
File Count
90
NPM Version
6.14.17
Node Version
14.20.0
Total Downloads
Cumulative downloads
Total Downloads
1,235
Last Day
100%
2
Compared to previous day
Last Week
-37.5%
5
Compared to previous week
Last Month
-16.7%
25
Compared to previous month
Last Year
-59.2%
181
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
electron-updater
This module allows you to automatically update your application. You only need to install this module and write two lines of code! To publish your updates you just need simple file hosting, it does not require a dedicated server.
See Auto Update for more information.
Supported OS:
- macOS (Squirrel.Mac).
- Windows (NSIS).
- Linux (AppImage).
Credits
Thanks to Evolve Labs for donating the npm package name.

No vulnerabilities found.
Reason
30 commit(s) and 16 issue activity found in the last 90 days -- score normalized to 10
Reason
no dangerous workflow patterns detected
Reason
license file detected
Details
- Info: project has a license file: LICENSE:0
- Info: FSF or OSI recognized license: MIT License: LICENSE:0
Reason
packaging workflow detected
Details
- Info: Project packages its releases by way of GitHub Actions.: .github/workflows/deploy-docker.yml:23
Reason
binaries present in source code
Details
- Warn: binary detected: test/fixtures/test-app-symlink-framework/hello-world/lib/Release/Hello.framework/Versions/A/Hello:1
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Info: jobLevel 'contents' permission set to 'read': .github/workflows/pr-labeler.yml:11
- Warn: jobLevel 'contents' permission set to 'write': .github/workflows/pr-release.yml:15
- Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/pr-semantic.yml:16
- Warn: jobLevel 'statuses' permission set to 'write': .github/workflows/pr-semantic.yml:17
- Info: topLevel 'contents' permission set to 'read': .github/workflows/deploy-docker.yml:12
- Info: topLevel 'contents' permission set to 'read': .github/workflows/deploy-netlify.yml:10
- Warn: topLevel 'statuses' permission set to 'write': .github/workflows/deploy-netlify.yml:11
- Info: topLevel 'contents' permission set to 'read': .github/workflows/docker-build.yml:7
- Info: topLevel 'contents' permission set to 'read': .github/workflows/pr-labeler.yml:6
- Info: topLevel 'contents' permission set to 'read': .github/workflows/pr-netlify.yml:10
- Warn: topLevel 'statuses' permission set to 'write': .github/workflows/pr-netlify.yml:11
- Info: found token with 'none' permissions: .github/workflows/pr-release.yml:1
- Info: topLevel 'contents' permission set to 'read': .github/workflows/pr-semantic.yml:11
- Warn: no topLevel permission defined: .github/workflows/stale.yml:1
- Info: topLevel 'contents' permission set to 'read': .github/workflows/test.yaml:22
Reason
SAST tool is not run on all commits -- score normalized to 6
Details
- Warn: 18 commits out of 29 are checked with a SAST tool
Reason
Found 11/21 approved changesets -- score normalized to 5
Reason
dependency not pinned by hash detected -- score normalized to 4
Details
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-release.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/electron-userland/electron-builder/pr-release.yml/master?enable=pin
- Warn: containerImage not pinned by hash: docker/base/Dockerfile:3: pin your Docker image by updating buildpack-deps:22.04-curl to buildpack-deps:22.04-curl@sha256:33a46dfd834f4a61b5866da863063dccd1160f248bbfab92581f4ace71be51de
- Warn: containerImage not pinned by hash: docker/node/Dockerfile:2
- Warn: containerImage not pinned by hash: docker/wine-chrome/Dockerfile:2
- Warn: containerImage not pinned by hash: docker/wine-mono/Dockerfile:2
- Warn: containerImage not pinned by hash: docker/wine/Dockerfile:2
- Warn: containerImage not pinned by hash: mkdocs-dockerfile:1: pin your Docker image by updating squidfunk/mkdocs-material:9.5 to squidfunk/mkdocs-material:9.5@sha256:41942f7a2f5163aacd0e866e076d95db4f26550b97d76c1594c04250cbb580e9
- Warn: downloadThenRun not pinned by hash: docker/base/Dockerfile:8-22
- Warn: npmCommand not pinned by hash: docker/node/Dockerfile:11
- Warn: pipCommand not pinned by hash: mkdocs-dockerfile:2
- Info: 15 out of 15 GitHub-owned GitHubAction dependencies pinned
- Info: 8 out of 9 third-party GitHubAction dependencies pinned
- Info: 0 out of 6 containerImage dependencies pinned
- Info: 0 out of 1 downloadThenRun dependencies pinned
- Info: 0 out of 1 npmCommand dependencies pinned
- Info: 0 out of 1 pipCommand dependencies pinned
Reason
9 existing vulnerabilities detected
Details
- Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg
- Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275
- Warn: Project is vulnerable to: GHSA-67mh-4wv8-2f99
- Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv
- Warn: Project is vulnerable to: GHSA-gxpj-cx7g-858c
- Warn: Project is vulnerable to: GHSA-p7v2-p9m8-qqg7
- Warn: Project is vulnerable to: GHSA-7x97-j373-85x5
- Warn: Project is vulnerable to: GHSA-7m48-wc93-9g85
- Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
security policy file not detected
Details
- Warn: no security policy file detected
- Warn: no security file to analyze
- Warn: no security file to analyze
- Warn: no security file to analyze
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Score
6.1
/10
Last Scanned on 2025-02-10
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More