{
  "schema_version": 1,
  "app_id": "io.thepeoples.ProtonMail",
  "slug": "proton-mail",
  "version": "1.13.4",
  "scanned_at": "2026-09-02T06:50:56Z",
  "scanner": {
    "name": "trivy",
    "version": "0.73.0",
    "db_updated_at": "2026-09-01T19:20:44Z"
  },
  "input": {
    "kind": "rpm",
    "filename": "ProtonMail-desktop-1.13.4.rpm",
    "sha256": "3a6d2cbee27e728d0ad5c7c367318178d6425e3002929832ed0a4b62ed709cae",
    "extracted_without_scripts": true
  },
  "gate": {
    "result": "pass",
    "fail_on": "wrap CRITICAL"
  },
  "counts": {
    "wrap": {
      "critical": 0,
      "high": 0,
      "medium": 0,
      "low": 0,
      "unknown": 0
    },
    "vendor": {
      "critical": 0,
      "high": 1,
      "medium": 1,
      "low": 0,
      "unknown": 0
    }
  },
  "coverage": {
    "packages_seen": 12,
    "wrap": {
      "status": "inventoried",
      "packages_seen": 0,
      "notes": []
    },
    "vendor": {
      "status": "inventoried",
      "packages_seen": 12,
      "notes": [
        "electron version file present (40.10.1)",
        "electron asar",
        "package.json uses yarn workspace protocol",
        "electron 40.10.1 from version file",
        "electron 40.10.1 from package.json",
        "skipped workspace protocol package.json deps",
        "read 1 package.json file(s)",
        "trivy sbom on 12 derived PURLs"
      ]
    }
  },
  "findings": [
    {
      "id": "CVE-2026-70606",
      "severity": "MEDIUM",
      "pkg": "electron",
      "installed": "40.10.1",
      "fixed": "43.0.0, 42.5.1, 41.9.1, 40.10.6",
      "class": "vendor",
      "title": "Electron: ProtocolResponse.url reuses the default session cache instead of the registering session"
    },
    {
      "id": "CVE-2026-70608",
      "severity": "HIGH",
      "pkg": "electron",
      "installed": "40.10.1",
      "fixed": "42.0.1, 41.10.3, 39.8.10",
      "class": "vendor",
      "title": "Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path"
    }
  ]
}
