From 741d7d6dcaf3ef9b70a1e9e761abedfb6c4e17df Mon Sep 17 00:00:00 2001 From: Zuzana Svetlikova Date: Thu, 10 Aug 2023 10:25:45 +0200 Subject: [PATCH] Rebase to new security release Address CVE-2023-32002, CVE-2023-32004, CVE-2023-32558 (high) Address CVE-2023-32006, CVE-2023-32559 (medium) Address CVE-2023-32005, CVE-2023-32003 (low) Resolves: #2186718 Resolves RHELPLAN-155624 --- .gitignore | 1 + nodejs.spec | 10 +++++++++- sources | 2 +- 3 files changed, 11 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 919fc26..b5ba176 100644 --- a/.gitignore +++ b/.gitignore @@ -48,3 +48,4 @@ /undici-5.22.1.tar.gz /wasi-sdk-11.0-linux.tar.gz /wasi-sdk-14.0-linux.tar.gz +/node-v20.5.1-stripped.tar.gz diff --git a/nodejs.spec b/nodejs.spec index b56d61b..c908d65 100644 --- a/nodejs.spec +++ b/nodejs.spec @@ -45,7 +45,7 @@ %global nodejs_epoch 1 %global nodejs_major 20 %global nodejs_minor 5 -%global nodejs_patch 0 +%global nodejs_patch 1 %global nodejs_abi %{nodejs_major}.%{nodejs_minor} # nodejs_soversion - from NODE_MODULE_VERSION in src/node_version.h %global nodejs_soversion 115 @@ -720,6 +720,14 @@ end %changelog +* Thu Aug 10 2023 Zuzana Svetlikova - 1:20.5.1-1 +- Rebase to new security release +- Address CVE-2023-32002, CVE-2023-32004, CVE-2023-32558 (high) +- Address CVE-2023-32006, CVE-2023-32559 (medium) +- Address CVE-2023-32005, CVE-2023-32003 (low) +- Resolves: #2186718 +- Resolves RHELPLAN-155624 + * Thu Jul 27 2023 Zuzana Svetlikova - 1:20.5.0-1 - Update to v20.5.0 - Remove dtrace support diff --git a/sources b/sources index 0e3303f..bf2f4ab 100644 --- a/sources +++ b/sources @@ -1,4 +1,4 @@ -SHA512 (node-v20.5.0-stripped.tar.gz) = 46056ee170ef87819e64365a86930d0730b22562250c1d66a214a00e9ab21b4165f7a5d90b10195ae9e216ffdb71ad648b55a1d454db9bed3e1478549abe724a +SHA512 (node-v20.5.1-stripped.tar.gz) = e04ce5702662cfc98d19066da8e8bbef2db89df4a1417d0c43a5fa9da103f4fc6003252a83687c3ac7aad95afe2d401137249740309527fa869c9cf0e68ff8f3 SHA512 (icu4c-73_2-src.tgz) = 76dd782db6205833f289d7eb68b60860dddfa3f614f0ba03fe7ec13117077f82109f0dc1becabcdf4c8a9c628b94478ab0a46134bdb06f4302be55f74027ce62 SHA512 (undici-5.22.1.tar.gz) = d372c6d5b9705901d3377a3d1ab2b42b7b8cb66b0d9d427843ab1f8ca15da7a7b1d5895280c54d71507112534ca9f1d934c647159f74b7868d8bfc876bfeca19 SHA512 (cjs-module-lexer-1.2.2.tar.gz) = 27c666fd5298022236b659c407cfb82a5a014c17ee4f9301be1015dd59b1a7c15e57d575f5a53908f9a3ff2069cbc0a8f3c2d5b28c4a2f933cd31015c20c750e