Page MenuHomeFreeBSD

www/node16: Update to 16.17.1
ClosedPublic

Authored by otis on Sep 25 2022, 5:57 AM.
Tags
None
Referenced Files
Unknown Object (File)
Tue, Apr 28, 11:29 PM
Unknown Object (File)
Tue, Apr 28, 11:25 PM
Unknown Object (File)
Tue, Apr 28, 3:12 AM
Unknown Object (File)
Tue, Apr 28, 3:06 AM
Unknown Object (File)
Mon, Apr 27, 2:51 PM
Unknown Object (File)
Fri, Apr 24, 10:32 PM
Unknown Object (File)
Fri, Apr 24, 1:42 AM
Unknown Object (File)
Tue, Apr 21, 9:37 AM

Details

Summary

Changelog: https://github.com/nodejs/node/releases/tag/v16.17.1

The following CVEs are fixed in this release:

CVE-2022-32212: DNS rebinding in --inspect on macOS
CVE-2022-32213: bypass via obs-fold mechanic
CVE-2022-35255: Weak randomness in WebCrypto keygen
CVE-2022-35256: HTTP Request Smuggling - Incorrect Parsing of Header Fields

Diff Detail

Repository
rP FreeBSD ports repository
Lint
No Lint Coverage
Unit
No Test Coverage
Build Status
Buildable 47519
Build 44406: arc lint + arc unit

Event Timeline

otis requested review of this revision.Sep 25 2022, 5:57 AM
otis added a subscriber: bhughes.

Adding relevant reviewers.

@bhughes is not responding in a timely manner and we need to do these updates sooner than after eventual maintainer timeout.

This revision was not accepted when it landed; it landed in state Needs Review.Oct 16 2022, 4:20 PM
This revision was automatically updated to reflect the committed changes.