Пакет node: Информация

  • Default inline alert: Версия в репозитории: 20.13.1-alt1

Исходный пакет: node
Версия: 20.11.1-alt1
Собран:  27 февраля 2024 г. 9:37
Сообщить об ошибке в пакете
Домашняя страница: http://nodejs.org/

Лицензия: MIT
О пакете: Evented I/O for V8 Javascript
Описание: 
Node.js is a server-side JavaScript environment that uses an asynchronous
event-driven model.  Node's goal is to provide an easy way to build scalable
network programs.

Список rpm-пакетов, предоставляемых данным srpm-пакетом:
node (loongarch64)
node-debuginfo (loongarch64)
node-devel (loongarch64)
node-doc (noarch)
npm (noarch)

Сопровождающий: Vitaly Lipatov


    1. gyp >= 0.14.0
    2. /proc
    3. curl
    4. libbrotli-devel
    5. libcares-devel >= 1.20.1
    6. gcc-c++
    7. libicu-devel >= 7.3
    8. libnghttp2-devel >= 1.57.0
    9. libuv-devel >= 1.48.0
    10. openssl
    11. openssl-devel >= 3.0.8
    12. python3-module-simplejson
    13. rpm-build-intro >= 2.1.14
    14. python3-devel
    15. rpm-macros-features
    16. rpm-macros-nodejs
    17. zlib-devel >= 1.2.13

Последнее изменение


18 февраля 2024 г. Vitaly Lipatov 20.11.1-alt1
- new version 20.11.1 (with rpmrb script)
- enable build npm subpackage
- CVE-2024-21892: Code injection and privilege escalation through Linux capabilities- (High)
- CVE-2024-22019: http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks- (High)
- CVE-2024-21896: Path traversal by monkey-patching Buffer internals- (High)
- CVE-2024-22017: setuid() does not drop all privileges due to io_uring - (High)
- CVE-2023-46809: Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) - (Medium)
- CVE-2024-21891: Multiple permission model bypasses due to improper path traversal sequence sanitization - (Medium)
- CVE-2024-21890: Improper handling of wildcards in --allow-fs-read and --allow-fs-write (Medium)
- CVE-2024-22025: Denial of Service by resource exhaustion in fetch() brotli decoding - (Medium)
- libuv >= 1.48.0
5 февраля 2024 г. Vitaly Lipatov 20.11.0-alt1
- new version 20.11.0 (with rpmrb script)
- set npm >= 10.2.4, c-ares >= 1.20.1
2 ноября 2023 г. Vitaly Lipatov 20.9.0-alt1
- 2023-10-24, Version 20.9.0 'Iron' (LTS)
- set npm >= 10.1.0, libuv >= 1.46.0, libicu >= 7.3, libnghttp2 >= 1.57.0