Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Node.js to v14.17.6 #321

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open

Update Node.js to v14.17.6 #321

wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jul 29, 2021

Mend Renovate

This PR contains the following updates:

Package Update Change
node patch 14.17.3 -> 14.17.6

Release Notes

nodejs/node

v14.17.6: 2021-08-31, Version 14.17.6 'Fermium' (LTS), @​MylesBorins

Compare Source

This is a security release.

Notable Changes

These are vulnerabilities in the node-tar, arborist, and npm cli modules which
are related to the initial reports and subsequent remediation of node-tar
vulnerabilities CVE-2021-32803
and CVE-2021-32804.
Subsequent internal security review of node-tar and additional external bounty
reports have resulted in another 5 CVE being remediated in core npm CLI
dependencies including node-tar, and npm arborist.

You can read more about it in:

Commits

v14.17.5: 2021-08-11, Version 14.17.5 'Fermium' (LTS), @​BethGriggs

Compare Source

This is a security release.

Notable Changes
  • CVE-2021-3672/CVE-2021-22931: Improper handling of untypical characters in domain names (High)
    • Node.js was vulnerable to Remote Code Execution, XSS, application crashes due to missing input validation of hostnames returned by Domain Name Servers in the Node.js DNS library which can lead to the output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library. You can read more about it at https://nvd.nist.gov/vuln/detail/CVE-2021-22931.
  • CVE-2021-22940: Use after free on close http2 on stream canceling (High)
  • CVE-2021-22939: Incomplete validation of rejectUnauthorized parameter (Low)
    • If the Node.js HTTPS API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted. You can read more about it at https://nvd.nist.gov/vuln/detail/CVE-2021-22939.
Commits

v14.17.4: 2021-07-29, Version 14.17.4 'Fermium' (LTS), @​richardlau

Compare Source

This is a security release.

Notable Changes

This releases also fixes some regressions with internationalization introduced by the ICU updates in Node.js 14.17.0 and 14.17.1.

Commits

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the Renovate label Jul 29, 2021
@renovate renovate bot force-pushed the renovate/node-14.17.x branch from 848b4c0 to b0bd58c Compare August 11, 2021 16:42
@renovate renovate bot changed the title Update Node.js to v14.17.4 Update Node.js to v14.17.5 Aug 11, 2021
@renovate renovate bot changed the title Update Node.js to v14.17.5 Update Node.js to v14.17.5 - autoclosed Aug 31, 2021
@renovate renovate bot closed this Aug 31, 2021
@renovate renovate bot deleted the renovate/node-14.17.x branch August 31, 2021 00:22
@renovate renovate bot changed the title Update Node.js to v14.17.5 - autoclosed Update Node.js to v14.17.5 Aug 31, 2021
@renovate renovate bot restored the renovate/node-14.17.x branch August 31, 2021 01:37
@renovate renovate bot reopened this Aug 31, 2021
@renovate renovate bot force-pushed the renovate/node-14.17.x branch from b0bd58c to d3e73c6 Compare August 31, 2021 15:42
@renovate renovate bot changed the title Update Node.js to v14.17.5 Update Node.js to v14.17.6 Aug 31, 2021
@renovate
Copy link
Contributor Author

renovate bot commented Mar 24, 2023

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant