ember-a11y-refocus
ember-a11y-refocus copied to clipboard
chore(deps): update node.js to v14.21.3
This PR contains the following updates:
Package | Type | Update | Change |
---|---|---|---|
node (source) | volta | minor | 14.20.0 -> 14.21.3 |
Release Notes
nodejs/node (node)
v14.21.3
: 2023-02-16, Version 14.21.3 'Fermium' (LTS), @richardlau
This is a security release.
Notable Changes
The following CVEs are fixed in this release:
- CVE-2023-23918: Node.js Permissions policies can be bypassed via process.mainModule (High)
- CVE-2023-23920: Node.js insecure loading of ICU data through ICU_DATA environment variable (Low)
More detailed information on each of the vulnerabilities can be found in February 2023 Security Releases blog post.
This security release includes OpenSSL security updates as outlined in the recent OpenSSL security advisory.
This security release also includes an npm update for Node.js 14 to address a number of CVEs which either do not affect Node.js or are low severity in the context of Node.js. You can get more details for the individual CVEs in nodejs-dependency-vuln-assessments.
Commits
- [
97a0443f13
] - build: build ICU with ICU_NO_USER_DATA_OVERRIDE (RafaelGSS) nodejs-private/node-private#374 - [
9e6221529b
] - deps: cherry-pick Windows ARM64 fix for openssl (Richard Lau) #46566 - [
0d5f86451d
] - deps: update archs files for OpenSSL-1.1.1t (RafaelGSS) #46566 - [
8c11d17b40
] - deps: upgrade openssl sources to 1.1.1t (RafaelGSS) #46566 - [
224e93c9ef
] - deps: upgrade npm to 6.14.18 (Ruy Adorno) #45936 - [
d73ea4de13
] - doc: clarify release notes for Node.js 14.21.2 (Richard Lau) #45846 - [
f7892c16be
] - lib: makeRequireFunction patch when experimental policy (RafaelGSS) nodejs-private/node-private#358 - [
fa115ee8ac
] - module: protect against prototype mutation (Antoine du Hamel) #44007 - [
83975b7fb4
] - policy: makeRequireFunction on mainModule.require (RafaelGSS) nodejs-private/node-private#358 - [
a5f8798d7a
] - test: avoid left behind child processes (Richard Lau) #46276
v14.21.2
: 2022-12-13, Version 14.21.2 'Fermium' (LTS), @richardlau
Notable Changes
OpenSSL 1.1.1s
This update is a bugfix release and does not address any security vulnerabilities.
Root certificates updated to NSS 3.85
Certificates added:
- Autoridad de Certificacion Firmaprofesional CIF
A626340
- Certainly Root E1
- Certainly Root R1
- D-TRUST BR Root CA 1 2020
- D-TRUST EV Root CA 1 2020
- DigiCert TLS ECC P384 Root G5
- DigiCert TLS RSA4096 Root G5
- E-Tugra Global Root CA ECC v3
- E-Tugra Global Root CA RSA v3
- HiPKI Root CA - G1
- ISRG Root X2
- Security Communication ECC RootCA1
- Security Communication RootCA3
- Telia Root CA v2
- vTrus ECC Root CA
- vTrus Root CA
Certificates removed:
- Cybertrust Global Root
- DST Root CA X3
- GlobalSign Root CA - R2
- Hellenic Academic and Research Institutions RootCA 2011
Time zone update to 2022f
Time zone data has been updated to 2022f. This includes changes to Daylight Savings Time (DST) for Fiji and Mexico. For more information, see https://mm.icann.org/pipermail/tz-announce/2022-October/000075.html.
Commits
- [
436a596e99
] - crypto: update root certificates (Luigi Pinca) #45490 - [
4b422d34af
] - deps: V8: cherry-pickd2db7fa
(Richard Lau) #45785 - [
625f4bf3a9
] - deps: update corepack to 0.15.1 (Node.js GitHub Bot) #45331 - [
48a9810de8
] - deps: update corepack to 0.15.0 (Node.js GitHub Bot) #45235 - [
9f4e64b603
] - deps: update timezone to 2022f (Richard Lau) #45521 - [
f297b6bd21
] - deps: update archs files for OpenSSL-1.1.1s (RafaelGSS) #45272 - [
11629fef15
] - deps: upgrade openssl sources to 1.1.1s (RafaelGSS) #45272 - [
c3a90c4b44
] - http2: fix memory leak when nghttp2 hd threshold is reached (rogertyang) #41502 - [
785dc3efee
] - module: cjs-module-lexer WebAssembly fallback (Guy Bedford) #43612 - [
2dbeb889f6
] - node-api: handle no support for external buffers (Michael Dawson) #45181 - [
5b2ea124f3
] - test: add test to validate changelogs for releases (Richard Lau) #45325 - [
f13f889956
] - test: add a test to ensure the correctness of timezone upgrades (Darshan Sen) #45299 - [
5608e6fa72
] - tools: update certdata.txt (Luigi Pinca) #45490 - [
d6f1d7107b
] - tools: have test-asan use ubuntu-20.04 (Filip Skokan) #45581 - [
370a00f737
] - tools: make license-builder.sh comply with shellcheck 0.8.0 (Rich Trott) #41258
v14.21.1
: 2022-11-04, Version 14.21.1 'Fermium' (LTS), @BethGriggs
This is a security release.
Notable changes
The following CVEs are fixed in this release:
- CVE-2022-43548: DNS rebinding in --inspect via invalid octal IP address (Medium)
More detailed information on each of the vulnerabilities can be found in November 2022 Security Releases blog post.
Commits
- [
2b433af094
] - inspector: harden IP address validation again (Tobias Nießen) nodejs-private/node-private#354
v14.21.0
: 2022-11-01, Version 14.21.0 'Fermium' (LTS), @danielleadams
Notable changes
-
deps:
- update corepack to 0.14.2 (Node.js GitHub Bot) #44775
-
src:
- add --openssl-shared-config option (Daniel Bevenius) #43124
Commits
- [
773f587912
] - deps: cherry-pick libuv/libuv@3a7b955
(Ben Noordhuis) #43950 - [
a1dea66956
] - deps: cherry-pick libuv/libuv@abb109f
(Ben Noordhuis) #43950 - [
98c49d81f5
] - deps: update corepack to 0.14.2 (Node.js GitHub Bot) #44775 - [
18c43c8518
] - deps: update timezone to tz2022e (Richard Lau) #45094 - [
a1f8e4db48
] - deps: update corepack to 0.14.1 (Node.js GitHub Bot) #44704 - [
e55389ca86
] - deps: update corepack to 0.14.0 (Node.js GitHub Bot) #44509 - [
0227462418
] - deps: update corepack to 0.13.0 (Node.js GitHub Bot) #44318 - [
ee24c320ea
] - deps: update corepack to 0.12.3 (Node.js GitHub Bot) #44229 - [
28e9891449
] - deps: update corepack to 0.12.2 (Node.js GitHub Bot) #44159 - [
b6972c9df2
] - deps: update corepack to 0.12.1 (Node.js GitHub Bot) #43965 - [
9d6cb3b5f1
] - deps: update corepack to 0.12.0 (Node.js GitHub Bot) #43748 - [
fa6c276b4f
] - deps: update Corepack to 0.11.2 (Maël Nison) #43402 - [
4f83d75626
] - (SEMVER-MAJOR) src,doc,test: add --openssl-shared-config option (Daniel Bevenius) #43124 - [
9487028043
] - test: fix intl tests on small-icu builds (Antoine du Hamel) #41939 - [
a1d52097f8
] - tools: add more options to track flaky tests (Antoine du Hamel) #43954
v14.20.1
: 2022-09-23, Version 14.20.1 'Fermium' (LTS), @bengl
This is a security release.
Notable changes
The following CVEs are fixed in this release:
- CVE-2022-32212: DNS rebinding in --inspect on macOS (High)
- CVE-2022-32213: bypass via obs-fold mechanic (Medium)
- CVE-2022-35256: HTTP Request Smuggling Due to Incorrect Parsing of Header Fields (Medium)
More detailed information on each of the vulnerabilities can be found in September 22nd 2022 Security Releases blog post.
Commits
- [
a9f1146b88
] - http: disable chunked encoding when OBS fold is used (Paolo Insogna) nodejs-private/node-private#341 - [
a1121b456c
] - src: fix IPv4 non routable validation (RafaelGSS) nodejs-private/node-private#337 - [
de80707870
] - src: fix IS_LTS and IS_RELEASE flags (Richard Lau) #43761
Configuration
📅 Schedule: Branch creation - "after 10pm every weekday,before 5am every weekday,every weekend" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
- [ ] If you want to rebase/retry this PR, check this box
This PR has been generated by Mend Renovate. View repository job log here.