From 0ee2016cbabad0281044b814bd457c17a9e2164c Mon Sep 17 00:00:00 2001 From: adam Date: Wed, 14 Feb 2024 21:26:59 +0000 Subject: [PATCH] nodejs18: updated to 18.19.1 Version 18.19.1 'Hydrogen' (LTS) Notable changes CVE-2024-21892 - Code injection and privilege escalation through Linux capabilities- (High) CVE-2024-22019 - http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks- (High) CVE-2023-46809 - Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) - (Medium) CVE-2024-22025 - Denial of Service by resource exhaustion in fetch() brotli decoding - (Medium) undici version 5.28.3 npm version 10.2.4 --- lang/nodejs18/Makefile | 4 +- lang/nodejs18/PLIST | 101 ++++++++++++++++++++++++++--------------- lang/nodejs18/distinfo | 8 ++-- 3 files changed, 71 insertions(+), 42 deletions(-) diff --git a/lang/nodejs18/Makefile b/lang/nodejs18/Makefile index 2d58c45bd33f..252b0f8e5e00 100644 --- a/lang/nodejs18/Makefile +++ b/lang/nodejs18/Makefile @@ -1,6 +1,6 @@ -# $NetBSD: Makefile,v 1.26 2024/01/11 09:42:46 adam Exp $ +# $NetBSD: Makefile,v 1.27 2024/02/14 21:26:59 adam Exp $ -DISTNAME= node-v18.19.0 +DISTNAME= node-v18.19.1 EXTRACT_SUFX= .tar.xz USE_LANGUAGES= c gnu++17 diff --git a/lang/nodejs18/PLIST b/lang/nodejs18/PLIST index 3026ac119ff5..67dce1c2dc49 100644 --- a/lang/nodejs18/PLIST +++ b/lang/nodejs18/PLIST @@ -1,4 +1,4 @@ -@comment $NetBSD: PLIST,v 1.5 2024/01/11 09:42:46 adam Exp $ +@comment $NetBSD: PLIST,v 1.6 2024/02/14 21:26:59 adam Exp $ bin/corepack bin/node bin/npm @@ -523,9 +523,6 @@ lib/node_modules/npm/node_modules/@isaacs/cliui/build/index.cjs lib/node_modules/npm/node_modules/@isaacs/cliui/build/index.d.cts lib/node_modules/npm/node_modules/@isaacs/cliui/build/lib/index.js lib/node_modules/npm/node_modules/@isaacs/cliui/index.mjs -lib/node_modules/npm/node_modules/@isaacs/cliui/node_modules/ansi-regex/index.js -lib/node_modules/npm/node_modules/@isaacs/cliui/node_modules/ansi-regex/license -lib/node_modules/npm/node_modules/@isaacs/cliui/node_modules/ansi-regex/package.json lib/node_modules/npm/node_modules/@isaacs/cliui/node_modules/emoji-regex/LICENSE-MIT.txt lib/node_modules/npm/node_modules/@isaacs/cliui/node_modules/emoji-regex/RGI_Emoji.js lib/node_modules/npm/node_modules/@isaacs/cliui/node_modules/emoji-regex/es2015/RGI_Emoji.js @@ -537,9 +534,6 @@ lib/node_modules/npm/node_modules/@isaacs/cliui/node_modules/emoji-regex/text.js lib/node_modules/npm/node_modules/@isaacs/cliui/node_modules/string-width/index.js lib/node_modules/npm/node_modules/@isaacs/cliui/node_modules/string-width/license lib/node_modules/npm/node_modules/@isaacs/cliui/node_modules/string-width/package.json -lib/node_modules/npm/node_modules/@isaacs/cliui/node_modules/strip-ansi/index.js -lib/node_modules/npm/node_modules/@isaacs/cliui/node_modules/strip-ansi/license -lib/node_modules/npm/node_modules/@isaacs/cliui/node_modules/strip-ansi/package.json lib/node_modules/npm/node_modules/@isaacs/cliui/package.json lib/node_modules/npm/node_modules/@isaacs/string-locale-compare/LICENSE lib/node_modules/npm/node_modules/@isaacs/string-locale-compare/index.js @@ -550,17 +544,6 @@ lib/node_modules/npm/node_modules/@npmcli/agent/lib/errors.js lib/node_modules/npm/node_modules/@npmcli/agent/lib/index.js lib/node_modules/npm/node_modules/@npmcli/agent/lib/options.js lib/node_modules/npm/node_modules/@npmcli/agent/lib/proxy.js -lib/node_modules/npm/node_modules/@npmcli/agent/node_modules/agent-base/dist/helpers.js -lib/node_modules/npm/node_modules/@npmcli/agent/node_modules/agent-base/dist/index.js -lib/node_modules/npm/node_modules/@npmcli/agent/node_modules/agent-base/package.json -lib/node_modules/npm/node_modules/@npmcli/agent/node_modules/http-proxy-agent/LICENSE -lib/node_modules/npm/node_modules/@npmcli/agent/node_modules/http-proxy-agent/dist/index.js -lib/node_modules/npm/node_modules/@npmcli/agent/node_modules/http-proxy-agent/package.json -lib/node_modules/npm/node_modules/@npmcli/agent/node_modules/https-proxy-agent/dist/index.js -lib/node_modules/npm/node_modules/@npmcli/agent/node_modules/https-proxy-agent/dist/parse-proxy-response.js -lib/node_modules/npm/node_modules/@npmcli/agent/node_modules/https-proxy-agent/package.json -lib/node_modules/npm/node_modules/@npmcli/agent/node_modules/socks-proxy-agent/dist/index.js -lib/node_modules/npm/node_modules/@npmcli/agent/node_modules/socks-proxy-agent/package.json lib/node_modules/npm/node_modules/@npmcli/agent/package.json lib/node_modules/npm/node_modules/@npmcli/arborist/LICENSE.md lib/node_modules/npm/node_modules/@npmcli/arborist/README.md @@ -645,6 +628,9 @@ lib/node_modules/npm/node_modules/@npmcli/config/lib/umask.js lib/node_modules/npm/node_modules/@npmcli/config/package.json lib/node_modules/npm/node_modules/@npmcli/disparity-colors/LICENSE lib/node_modules/npm/node_modules/@npmcli/disparity-colors/lib/index.js +lib/node_modules/npm/node_modules/@npmcli/disparity-colors/node_modules/ansi-styles/index.js +lib/node_modules/npm/node_modules/@npmcli/disparity-colors/node_modules/ansi-styles/license +lib/node_modules/npm/node_modules/@npmcli/disparity-colors/node_modules/ansi-styles/package.json lib/node_modules/npm/node_modules/@npmcli/disparity-colors/package.json lib/node_modules/npm/node_modules/@npmcli/fs/LICENSE.md lib/node_modules/npm/node_modules/@npmcli/fs/lib/common/get-options.js @@ -836,6 +822,9 @@ lib/node_modules/npm/node_modules/abort-controller/dist/abort-controller.umd.js lib/node_modules/npm/node_modules/abort-controller/package.json lib/node_modules/npm/node_modules/abort-controller/polyfill.js lib/node_modules/npm/node_modules/abort-controller/polyfill.mjs +lib/node_modules/npm/node_modules/agent-base/dist/helpers.js +lib/node_modules/npm/node_modules/agent-base/dist/index.js +lib/node_modules/npm/node_modules/agent-base/package.json lib/node_modules/npm/node_modules/aggregate-error/index.js lib/node_modules/npm/node_modules/aggregate-error/license lib/node_modules/npm/node_modules/aggregate-error/package.json @@ -937,6 +926,12 @@ lib/node_modules/npm/node_modules/clean-stack/package.json lib/node_modules/npm/node_modules/cli-columns/color.js lib/node_modules/npm/node_modules/cli-columns/index.js lib/node_modules/npm/node_modules/cli-columns/license +lib/node_modules/npm/node_modules/cli-columns/node_modules/ansi-regex/index.js +lib/node_modules/npm/node_modules/cli-columns/node_modules/ansi-regex/license +lib/node_modules/npm/node_modules/cli-columns/node_modules/ansi-regex/package.json +lib/node_modules/npm/node_modules/cli-columns/node_modules/strip-ansi/index.js +lib/node_modules/npm/node_modules/cli-columns/node_modules/strip-ansi/license +lib/node_modules/npm/node_modules/cli-columns/node_modules/strip-ansi/package.json lib/node_modules/npm/node_modules/cli-columns/package.json lib/node_modules/npm/node_modules/cli-columns/test.js lib/node_modules/npm/node_modules/cli-table3/LICENSE @@ -973,6 +968,12 @@ lib/node_modules/npm/node_modules/columnify/LICENSE lib/node_modules/npm/node_modules/columnify/Makefile lib/node_modules/npm/node_modules/columnify/columnify.js lib/node_modules/npm/node_modules/columnify/index.js +lib/node_modules/npm/node_modules/columnify/node_modules/ansi-regex/index.js +lib/node_modules/npm/node_modules/columnify/node_modules/ansi-regex/license +lib/node_modules/npm/node_modules/columnify/node_modules/ansi-regex/package.json +lib/node_modules/npm/node_modules/columnify/node_modules/strip-ansi/index.js +lib/node_modules/npm/node_modules/columnify/node_modules/strip-ansi/license +lib/node_modules/npm/node_modules/columnify/node_modules/strip-ansi/package.json lib/node_modules/npm/node_modules/columnify/package.json lib/node_modules/npm/node_modules/columnify/utils.js lib/node_modules/npm/node_modules/columnify/width.js @@ -1149,6 +1150,12 @@ lib/node_modules/npm/node_modules/gauge/lib/template-item.js lib/node_modules/npm/node_modules/gauge/lib/theme-set.js lib/node_modules/npm/node_modules/gauge/lib/themes.js lib/node_modules/npm/node_modules/gauge/lib/wide-truncate.js +lib/node_modules/npm/node_modules/gauge/node_modules/ansi-regex/index.js +lib/node_modules/npm/node_modules/gauge/node_modules/ansi-regex/license +lib/node_modules/npm/node_modules/gauge/node_modules/ansi-regex/package.json +lib/node_modules/npm/node_modules/gauge/node_modules/strip-ansi/index.js +lib/node_modules/npm/node_modules/gauge/node_modules/strip-ansi/license +lib/node_modules/npm/node_modules/gauge/node_modules/strip-ansi/package.json lib/node_modules/npm/node_modules/gauge/package.json lib/node_modules/npm/node_modules/glob/LICENSE lib/node_modules/npm/node_modules/glob/README.md @@ -1224,9 +1231,10 @@ lib/node_modules/npm/node_modules/graceful-fs/polyfills.js lib/node_modules/npm/node_modules/has-unicode/LICENSE lib/node_modules/npm/node_modules/has-unicode/index.js lib/node_modules/npm/node_modules/has-unicode/package.json -lib/node_modules/npm/node_modules/has/LICENSE-MIT -lib/node_modules/npm/node_modules/has/package.json -lib/node_modules/npm/node_modules/has/src/index.js +lib/node_modules/npm/node_modules/hasown/LICENSE +lib/node_modules/npm/node_modules/hasown/index.js +lib/node_modules/npm/node_modules/hasown/package.json +lib/node_modules/npm/node_modules/hasown/tsconfig.json lib/node_modules/npm/node_modules/hosted-git-info/LICENSE lib/node_modules/npm/node_modules/hosted-git-info/lib/from-url.js lib/node_modules/npm/node_modules/hosted-git-info/lib/hosts.js @@ -1236,6 +1244,12 @@ lib/node_modules/npm/node_modules/hosted-git-info/package.json lib/node_modules/npm/node_modules/http-cache-semantics/LICENSE lib/node_modules/npm/node_modules/http-cache-semantics/index.js lib/node_modules/npm/node_modules/http-cache-semantics/package.json +lib/node_modules/npm/node_modules/http-proxy-agent/LICENSE +lib/node_modules/npm/node_modules/http-proxy-agent/dist/index.js +lib/node_modules/npm/node_modules/http-proxy-agent/package.json +lib/node_modules/npm/node_modules/https-proxy-agent/dist/index.js +lib/node_modules/npm/node_modules/https-proxy-agent/dist/parse-proxy-response.js +lib/node_modules/npm/node_modules/https-proxy-agent/package.json lib/node_modules/npm/node_modules/iconv-lite/LICENSE lib/node_modules/npm/node_modules/iconv-lite/encodings/dbcs-codec.js lib/node_modules/npm/node_modules/iconv-lite/encodings/dbcs-data.js @@ -1397,12 +1411,10 @@ lib/node_modules/npm/node_modules/libnpmversion/lib/version.js lib/node_modules/npm/node_modules/libnpmversion/lib/write-json.js lib/node_modules/npm/node_modules/libnpmversion/package.json lib/node_modules/npm/node_modules/lru-cache/LICENSE -lib/node_modules/npm/node_modules/lru-cache/dist/cjs/index.js -lib/node_modules/npm/node_modules/lru-cache/dist/cjs/index.min.js -lib/node_modules/npm/node_modules/lru-cache/dist/cjs/package.json -lib/node_modules/npm/node_modules/lru-cache/dist/mjs/index.js -lib/node_modules/npm/node_modules/lru-cache/dist/mjs/index.min.js -lib/node_modules/npm/node_modules/lru-cache/dist/mjs/package.json +lib/node_modules/npm/node_modules/lru-cache/dist/commonjs/index.js +lib/node_modules/npm/node_modules/lru-cache/dist/commonjs/package.json +lib/node_modules/npm/node_modules/lru-cache/dist/esm/index.js +lib/node_modules/npm/node_modules/lru-cache/dist/esm/package.json lib/node_modules/npm/node_modules/lru-cache/package.json lib/node_modules/npm/node_modules/make-fetch-happen/LICENSE lib/node_modules/npm/node_modules/make-fetch-happen/lib/cache/entry.js @@ -1951,6 +1963,8 @@ lib/node_modules/npm/node_modules/smart-buffer/build/smartbuffer.js lib/node_modules/npm/node_modules/smart-buffer/build/utils.js lib/node_modules/npm/node_modules/smart-buffer/docs/ROADMAP.md lib/node_modules/npm/node_modules/smart-buffer/package.json +lib/node_modules/npm/node_modules/socks-proxy-agent/dist/index.js +lib/node_modules/npm/node_modules/socks-proxy-agent/package.json lib/node_modules/npm/node_modules/socks/LICENSE lib/node_modules/npm/node_modules/socks/build/client/socksclient.js lib/node_modules/npm/node_modules/socks/build/common/constants.js @@ -1987,15 +2001,30 @@ lib/node_modules/npm/node_modules/ssri/lib/index.js lib/node_modules/npm/node_modules/ssri/package.json lib/node_modules/npm/node_modules/string-width-cjs/index.js lib/node_modules/npm/node_modules/string-width-cjs/license +lib/node_modules/npm/node_modules/string-width-cjs/node_modules/ansi-regex/index.js +lib/node_modules/npm/node_modules/string-width-cjs/node_modules/ansi-regex/license +lib/node_modules/npm/node_modules/string-width-cjs/node_modules/ansi-regex/package.json +lib/node_modules/npm/node_modules/string-width-cjs/node_modules/strip-ansi/index.js +lib/node_modules/npm/node_modules/string-width-cjs/node_modules/strip-ansi/license +lib/node_modules/npm/node_modules/string-width-cjs/node_modules/strip-ansi/package.json lib/node_modules/npm/node_modules/string-width-cjs/package.json lib/node_modules/npm/node_modules/string-width/index.js lib/node_modules/npm/node_modules/string-width/license +lib/node_modules/npm/node_modules/string-width/node_modules/ansi-regex/index.js +lib/node_modules/npm/node_modules/string-width/node_modules/ansi-regex/license +lib/node_modules/npm/node_modules/string-width/node_modules/ansi-regex/package.json +lib/node_modules/npm/node_modules/string-width/node_modules/strip-ansi/index.js +lib/node_modules/npm/node_modules/string-width/node_modules/strip-ansi/license +lib/node_modules/npm/node_modules/string-width/node_modules/strip-ansi/package.json lib/node_modules/npm/node_modules/string-width/package.json lib/node_modules/npm/node_modules/string_decoder/LICENSE lib/node_modules/npm/node_modules/string_decoder/lib/string_decoder.js lib/node_modules/npm/node_modules/string_decoder/package.json lib/node_modules/npm/node_modules/strip-ansi-cjs/index.js lib/node_modules/npm/node_modules/strip-ansi-cjs/license +lib/node_modules/npm/node_modules/strip-ansi-cjs/node_modules/ansi-regex/index.js +lib/node_modules/npm/node_modules/strip-ansi-cjs/node_modules/ansi-regex/license +lib/node_modules/npm/node_modules/strip-ansi-cjs/node_modules/ansi-regex/package.json lib/node_modules/npm/node_modules/strip-ansi-cjs/package.json lib/node_modules/npm/node_modules/strip-ansi/index.js lib/node_modules/npm/node_modules/strip-ansi/license @@ -2127,15 +2156,18 @@ lib/node_modules/npm/node_modules/wide-align/align.js lib/node_modules/npm/node_modules/wide-align/package.json lib/node_modules/npm/node_modules/wrap-ansi-cjs/index.js lib/node_modules/npm/node_modules/wrap-ansi-cjs/license +lib/node_modules/npm/node_modules/wrap-ansi-cjs/node_modules/ansi-regex/index.js +lib/node_modules/npm/node_modules/wrap-ansi-cjs/node_modules/ansi-regex/license +lib/node_modules/npm/node_modules/wrap-ansi-cjs/node_modules/ansi-regex/package.json +lib/node_modules/npm/node_modules/wrap-ansi-cjs/node_modules/ansi-styles/index.js +lib/node_modules/npm/node_modules/wrap-ansi-cjs/node_modules/ansi-styles/license +lib/node_modules/npm/node_modules/wrap-ansi-cjs/node_modules/ansi-styles/package.json +lib/node_modules/npm/node_modules/wrap-ansi-cjs/node_modules/strip-ansi/index.js +lib/node_modules/npm/node_modules/wrap-ansi-cjs/node_modules/strip-ansi/license +lib/node_modules/npm/node_modules/wrap-ansi-cjs/node_modules/strip-ansi/package.json lib/node_modules/npm/node_modules/wrap-ansi-cjs/package.json lib/node_modules/npm/node_modules/wrap-ansi/index.js lib/node_modules/npm/node_modules/wrap-ansi/license -lib/node_modules/npm/node_modules/wrap-ansi/node_modules/ansi-regex/index.js -lib/node_modules/npm/node_modules/wrap-ansi/node_modules/ansi-regex/license -lib/node_modules/npm/node_modules/wrap-ansi/node_modules/ansi-regex/package.json -lib/node_modules/npm/node_modules/wrap-ansi/node_modules/ansi-styles/index.js -lib/node_modules/npm/node_modules/wrap-ansi/node_modules/ansi-styles/license -lib/node_modules/npm/node_modules/wrap-ansi/node_modules/ansi-styles/package.json lib/node_modules/npm/node_modules/wrap-ansi/node_modules/emoji-regex/LICENSE-MIT.txt lib/node_modules/npm/node_modules/wrap-ansi/node_modules/emoji-regex/RGI_Emoji.js lib/node_modules/npm/node_modules/wrap-ansi/node_modules/emoji-regex/es2015/RGI_Emoji.js @@ -2147,9 +2179,6 @@ lib/node_modules/npm/node_modules/wrap-ansi/node_modules/emoji-regex/text.js lib/node_modules/npm/node_modules/wrap-ansi/node_modules/string-width/index.js lib/node_modules/npm/node_modules/wrap-ansi/node_modules/string-width/license lib/node_modules/npm/node_modules/wrap-ansi/node_modules/string-width/package.json -lib/node_modules/npm/node_modules/wrap-ansi/node_modules/strip-ansi/index.js -lib/node_modules/npm/node_modules/wrap-ansi/node_modules/strip-ansi/license -lib/node_modules/npm/node_modules/wrap-ansi/node_modules/strip-ansi/package.json lib/node_modules/npm/node_modules/wrap-ansi/package.json lib/node_modules/npm/node_modules/write-file-atomic/LICENSE.md lib/node_modules/npm/node_modules/write-file-atomic/lib/index.js diff --git a/lang/nodejs18/distinfo b/lang/nodejs18/distinfo index 4e7d3193838e..278e29a592e3 100644 --- a/lang/nodejs18/distinfo +++ b/lang/nodejs18/distinfo @@ -1,8 +1,8 @@ -$NetBSD: distinfo,v 1.15 2024/01/11 09:42:46 adam Exp $ +$NetBSD: distinfo,v 1.16 2024/02/14 21:26:59 adam Exp $ -BLAKE2s (node-v18.19.0.tar.xz) = 9a2ad817bcc034db6b4a96b885cde0fed791de647c72e4dde754c7693f6ecee2 -SHA512 (node-v18.19.0.tar.xz) = db2f1342f028e5cd2ab0a3719b4c822e22439aa097b59df768fb7f6aa581394f81af6f51f7764b99d119ea2c849b55c02897af8caafab7c0f9d0112608a8867f -Size (node-v18.19.0.tar.xz) = 41248748 bytes +BLAKE2s (node-v18.19.1.tar.xz) = 518b4d945b48126122dce9b77e3e4c77c084ac3f8f5540316f835678b549e615 +SHA512 (node-v18.19.1.tar.xz) = 2ce39b2fccc05c8d5f255b88f07f58b164d84d27d88a337f93a8c13b0f3d692dada28e96df74a0a340310cf1a3d95bd0729f25752e6eaf2f7a1af7ed5a88c22b +Size (node-v18.19.1.tar.xz) = 41250068 bytes SHA1 (patch-common.gypi) = 333fffbc32b36391c347c6cb9ef00d66ca5d6341 SHA1 (patch-configure) = b1ac7b6baa594bb49f04dad9705e9f38fe9ed13d SHA1 (patch-configure.py) = f31cd2349806d49148eeeb08b428a9b021185604