Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient. Node.js' package ecosystem, npm, is the largest ecosystem of open source libraries in the world.



    2016-10-28 - - New upstream LTS version 4.6.1 * c-ares: + CVE-2016-5180: fix for single-byte buffer overwrite

    2016-09-29 - - New upstream LTS version 4.6.0 * openssl update (not applicable for SLE12SP2, Leap 42.2 and later) + upgrade to 1.0.2j (CVE-2016-6304, CVE-2016-2183, CVE-2016-2178, CVE-2016-6306, CVE-2016-7052) + remove support for dynamic 3rd party engine modules * http: Properly validate for allowable characters in input user data. This introduces a new case where throw may occur when configuring HTTP responses, users should already be adopting try/catch here. (CVE-2016-5325, bnc#985201) * tls: properly validate wildcard certificates (CVE-2016-7099, bnc#1001652) * buffer: Zero-fill excess bytes in new Buffer objects created with Buffer.concat() - changes in LTS version 4.5.0 * buffer: + backport new buffer constructor APIs to v4.x + backport --zero-fill-buffers cli option + ignore negative allocation lengths * build + add Intel Vtune profiling support * repl + copying tabs shouldn't trigger completion * src + add node::FreeEnvironment public API * test + run v8 tests from node tree * V8 + Add post mortem data to improve object inspection and function's context variables inspection * upgrade libuv to 1.9.1 * upgrade npm to 2.15.9 - changes in version 4.4.7 * debugger: + All properties of an array (aside from length) can now be printed in the repl * Upgrade npm to 2.15.8 (Rebecca Turner) * Fix for a bug that became more prevalent with the stream changes that landed in v4.4.5. (Anna Henningsen). 'reset awaitDrain after manual .resume()' * V8: + Fix for a bug in crankshaft that was causing crashes on arm64 (Myles Borins) + Add missing classes to postmortem info such as JSMap and JSSet (evan.lucas) - changes in version 4.4.6 + fix buffer overflow vulnerability discovered in v8 (CVE-2016-1669). incorporates 134c3b39.patch - node-gyp-addon-gypi.patch: refreshed

    2016-07-08 - - 134c3b39.patch: * fix buffer overflow in v8 (CVE-2016-1669, bsc#987919)