Package node: Information

    Source package: node
    Version: 16.19.1-alt0.c9.1
    Build time:  Mar 22, 2023, 09:28 PM in the task #316989
    Report package bug
    Home page: http://nodejs.org/

    License: MIT
    Summary: Evented I/O for V8 Javascript
    Description: 
    Node.js is a server-side JavaScript environment that uses an asynchronous
    event-driven model.  Node's goal is to provide an easy way to build scalable
    network programs.

    List of rpms provided by this srpm:
    node (x86_64, ppc64le, i586, armh, aarch64)
    node-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
    node-devel (x86_64, ppc64le, i586, armh, aarch64)
    node-doc (noarch)

    Maintainer: Vitaly Lipatov


      1. libnghttp2-devel >= 1.41.0
      2. curl
      3. python3-devel
      4. python3-module-simplejson
      5. libcares-devel >= 1.18.1-alt1
      6. gyp >= 0.10.0
      7. gcc-c++
      8. openssl
      9. openssl-devel >= 1.1.1s
      10. rpm-build-intro >= 2.1.14
      11. rpm-macros-nodejs
      12. libbrotli-devel
      13. libicu-devel >= 6.5
      14. zlib-devel
      15. libuv-devel >= 1.43.0-alt1

    Last changed


    March 19, 2023 Andrey Cherepanov 16.19.1-alt0.c9.1
    - backport to c9 branch new version
    March 13, 2023 Vitaly Lipatov 16.19.1-alt1
    - new version 16.19.1 (with rpmrb script)
    - CVE-2023-23918: Node.js Permissions policies can be bypassed via process.mainModule (High)
    - CVE-2023-23919: Node.js OpenSSL error handling issues in nodejs crypto library (Medium)
    - CVE-2023-23920: Node.js insecure loading of ICU data through ICU\_DATA environment variable (Low)
    - CVE-2023-23936: Fetch API in Node.js did not protect against CRLF injection in host headers (Medium)
    - CVE-2023-24807: Regular Expression Denial of Service in Headers in Node.js fetch API (Low)
    - set openssl >= 1.1.1s
    - set npm >= 8.19.3
    Nov. 25, 2022 Andrey Cherepanov 16.18.1-alt0.c9.1
    - backport to c9 branch new version