diff options
author | Jason Schonberg <schonm@gmail.com> | 2025-01-22 19:28:18 -0500 |
---|---|---|
committer | Khem Raj <raj.khem@gmail.com> | 2025-01-24 18:20:07 -0800 |
commit | 1216d76bec441d2c87bef5f9a3985c44266d93a9 (patch) | |
tree | 1e06c5950a1c78f35a017690efd2b7403aefd362 /meta-python/recipes-devtools/python/python3-matplotlib-inline_0.1.7.bb | |
parent | 761ae91279b05b5b40a8274b5d66c0d8a51e9de4 (diff) | |
download | meta-openembedded-1216d76bec441d2c87bef5f9a3985c44266d93a9.tar.gz |
nodejs: upgrade 22.12.0 -> 22.13.1
Changelog for 22.13.0 : https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V22.md#22.13.0
Changelog for 22.13.1 : https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V22.md#22.13.1
The 22.13.1 release is a security fix addressing four CVEs.
CVE-2025-23083 - src,loader,permission: throw on InternalWorker use when permission model is enabled (High)
CVE-2025-23085 - src: fix HTTP2 mem leak on premature close and ERR_PROTO (Medium)
CVE-2025-23084 - path: fix path traversal in normalize() on Windows (Medium)
CVE-2025-22150 - Use of Insufficiently Random Values in undici fetch() (Medium)
I introduce a new patch with this recipe 0001-Do-not-use-glob-in-deps.patch to revert https://github.com/nodejs/node/commit/77e2869ca6
I restored 0001-deps-disable-io_uring-support-in-libuv.patch as suggested here : https://lore.kernel.org/all/20241207140642.181134-1-martin.jansa@gmail.com/
Signed-off-by: Jason Schonberg <schonm@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Diffstat (limited to 'meta-python/recipes-devtools/python/python3-matplotlib-inline_0.1.7.bb')
0 files changed, 0 insertions, 0 deletions