Skip to content

Conversation

@mend-for-mygithub.libinneed.workers.dev
Copy link
Contributor

@mend-for-mygithub.libinneed.workers.dev mend-for-mygithub.libinneed.workers.dev bot commented Apr 14, 2024

This PR contains the following updates:

Package Update Change
node (source) patch v18.20.0 -> 18.20.8

Release Notes

nodejs/node (node)

v18.20.8: 2025-03-27, Version 18.20.8 'Hydrogen' (LTS), @​richardlau

Compare Source

Notable Changes

This release updates OpenSSL to 3.0.16 and root certificates to NSS 3.108.

Commits

v18.20.7: 2025-02-20, Version 18.20.7 'Hydrogen' (LTS), @​aduh95

Compare Source

Notable Changes
Commits

v18.20.6: 2025-01-21, Version 18.20.6 'Hydrogen' (LTS), @​RafaelGSS

Compare Source

This is a security release.

Notable Changes
  • CVE-2025-23085 - src: fix HTTP2 mem leak on premature close and ERR_PROTO (Medium)
  • CVE-2025-23084 - path: fix path traversal in normalize() on Windows (Medium)

Dependency update:

  • CVE-2025-22150 - Use of Insufficiently Random Values in undici fetch() (Medium)
Commits

v18.20.5: 2024-11-12, Version 18.20.5 'Hydrogen' (LTS), @​aduh95

Compare Source

Notable Changes
  • [ac37e554a5] - esm: mark import attributes and JSON module as stable (Nicolò Ribaudo) #​55333
Commits

v18.20.4: 2024-07-08, Version 18.20.4 'Hydrogen' (LTS), @​RafaelGSS

Compare Source

This is a security release.

Notable Changes
Commits

v18.20.3: 2024-05-21, Version 18.20.3 'Hydrogen' (LTS), @​richardlau

Compare Source

Notable Changes

This release fixes a regression introduced in Node.js 18.19.0 where http.server.close() was incorrectly closing idle connections.

A fix has also been included for compiling Node.js from source with newer versions of Clang.

The list of keys used to sign releases has been synchronized with the current list from the main branch.

Updated dependencies
  • acorn updated to 8.11.3.
  • acorn-walk updated to 8.3.2.
  • ada updated to 2.7.8.
  • c-ares updated to 1.28.1.
  • corepack updated to 0.28.0.
  • nghttp2 updated to 1.61.0.
  • ngtcp2 updated to 1.3.0.
  • npm updated to 10.7.0. Includes a fix from npm@​10.5.1 to limit the number of open connections npm/cli#7324.
  • simdutf updated to 5.2.4.
  • zlib updated to 1.3.0.1-motley-7d77fb7.
Commits

v18.20.2: 2024-04-10, Version 18.20.2 'Hydrogen' (LTS), @​RafaelGSS

Compare Source

This is a security release.

Notable Changes
  • CVE-2024-27980 - Command injection via args parameter of child_process.spawn without shell option enabled on Windows
Commits

v18.20.1: 2024-04-03, Version 18.20.1 'Hydrogen' (LTS), @​RafaelGSS

Compare Source

This is a security release.

Notable Changes
  • CVE-2024-27983 - Assertion failed in node::http2::Http2Session::~Http2Session() leads to HTTP/2 server crash- (High)
  • CVE-2024-27982 - HTTP Request Smuggling via Content Length Obfuscation - (Medium)
  • llhttp version 9.2.1
  • undici version 5.28.4
Commits

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

@mend-for-mygithub.libinneed.workers.dev mend-for-mygithub.libinneed.workers.dev bot changed the title Update dependency node to v18.20.2 Update dependency node to v18.20.3 May 22, 2024
@mend-for-mygithub.libinneed.workers.dev mend-for-mygithub.libinneed.workers.dev bot changed the title Update dependency node to v18.20.3 Update dependency node to v18.20.4 Jul 9, 2024
@mend-for-mygithub.libinneed.workers.dev mend-for-mygithub.libinneed.workers.dev bot changed the title Update dependency node to v18.20.4 Update dependency node to v18.20.5 Nov 13, 2024
@mend-for-mygithub.libinneed.workers.dev mend-for-mygithub.libinneed.workers.dev bot changed the title Update dependency node to v18.20.5 Update Node.js to v18.20.5 Dec 19, 2024
@mend-for-mygithub.libinneed.workers.dev mend-for-mygithub.libinneed.workers.dev bot changed the title Update Node.js to v18.20.5 Update Node.js to v18.20.6 Jan 22, 2025
@mend-for-mygithub.libinneed.workers.dev mend-for-mygithub.libinneed.workers.dev bot changed the title Update Node.js to v18.20.6 Update Node.js to v18.20.7 Feb 21, 2025
@mend-for-mygithub.libinneed.workers.dev mend-for-mygithub.libinneed.workers.dev bot changed the title Update Node.js to v18.20.7 Update Node.js to v18.20.8 Mar 28, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant