From 2a2df65531d0dc1ae273ca033c36ec7be99e7a3c Mon Sep 17 00:00:00 2001 From: factory-maintainer <> Date: Apr 18 2021 19:49:14 +0000 Subject: Update nodejs10 to version 10.24.1 / rev 38 via SR 885430 https://build.opensuse.org/request/show/885430 by user factory-maintainer + dimstar_suse Automatic submission by obs-autosubmit --- diff --git a/.files b/.files index 7e10b1c..afd9169 100644 Binary files a/.files and b/.files differ diff --git a/.rev b/.rev index c5ac06f..df2790e 100644 --- a/.rev +++ b/.rev @@ -488,4 +488,12 @@ test-worker-stdio (bsc#1183155)</comment> <requestid>877765</requestid> </revision> + <revision rev="38" vrev="1"> + <srcmd5>740254fcc59a7535eaf8616936a45eed</srcmd5> + <version>10.24.1</version> + <time>1618775054</time> + <user>dimstar_suse</user> + <comment>Automatic submission by obs-autosubmit</comment> + <requestid>885430</requestid> + </revision> </revisionlist> diff --git a/SHASUMS256.txt b/SHASUMS256.txt index 46b3d5a..44b59b4 100644 --- a/SHASUMS256.txt +++ b/SHASUMS256.txt @@ -1,36 +1,36 @@ -59bdb393035c605627bf4ba64ad8edcc74f067043790c7edc545333cca8630c4 node-v10.24.0-aix-ppc64.tar.gz -265ccad26fdfdcd86d6571b0bf5f1815b55f6a4a9b367816ad0369790501f55e node-v10.24.0-darwin-x64.tar.gz -ba749262eb5599360cdfe5edf7516a98269defcb6d2de56a9bbfd95a76366a7d node-v10.24.0-darwin-x64.tar.xz -165ca4182bcfa952d2405e53f480525dfe62c3fd453a893bc34df6cbb8fc6740 node-v10.24.0-headers.tar.gz -c7afbb814018f2bed87e85b2aa71c864c961a3754b0733bcfd077fbb068cfd76 node-v10.24.0-headers.tar.xz -65e6255c6f95b6dcf87f13c21994bc80205b4bd7c7d9a3fe1f8f2a18daec576d node-v10.24.0-linux-arm64.tar.gz -41bbf035512a72d073e93440458ad6e48586853fc0a5b6396ded80a2d45cb49c node-v10.24.0-linux-arm64.tar.xz -5a5dcc02bfd0ddcbeb2ef68f116bb72e416149f15f12767864bde77edd7f39d1 node-v10.24.0-linux-armv6l.tar.gz -076d387b1e9345c675745a453f642b6819b07b21cf21d6824f33c8d508f71559 node-v10.24.0-linux-armv6l.tar.xz -02feb052d0e1eb77c9beea5cfe3b67b90d5209ab509797f4f6c892c75cc30fda node-v10.24.0-linux-armv7l.tar.gz -0b01cb43903bc2d06f0ea3bb6753da4c91fd9533f1bd74e8bd2ee55b470a9084 node-v10.24.0-linux-armv7l.tar.xz -227338ffe74d2c2a87bd1bd77f4c74d21d8027e8eff78eb8e7f686a470b83fbe node-v10.24.0-linux-ppc64le.tar.gz -1d5b9c5a6ffb7027bbf9cf608d919c280039cea1f1f0308324aca871d874fca7 node-v10.24.0-linux-ppc64le.tar.xz -5a4478e6602c6c6fb28bc01b5356215e714ef0d3917fb1ede487c9b93e88741e node-v10.24.0-linux-s390x.tar.gz -322d9faf2d724de4596cc021e5eb37553ceafc07fccd2f39afede8c56dde7432 node-v10.24.0-linux-s390x.tar.xz -d8d7ecb0667a9b86b7ce1994731f9c9d313b46f04de59f724259a6fda685617a node-v10.24.0-linux-x64.tar.gz -a937fb43225289ada54c6c3272a2ad18e1e33b8c7d6211c289d421b5051fdbd0 node-v10.24.0-linux-x64.tar.xz -347004459f040a83bf7f1cb663dd9ba846df8def8967a9572801484768b8a754 node-v10.24.0.pkg -c5233cea13d3ce560cda1cdda873c2054bd3b5621da466fb4965668ef4259b93 node-v10.24.0-sunos-x64.tar.gz -2b43e85f73a0dbc1ec0e64394c2607cbfe53045aaa11f3d9a65ceb4cc6ee8394 node-v10.24.0-sunos-x64.tar.xz -c8d0a56279be77a9033b5f89603c6c491060a661c607fbf82bbe931ca662996e node-v10.24.0.tar.gz -158273af66f891b2fca90aec7336c42f7574f467affad02c14e80ca163cb3acc node-v10.24.0.tar.xz -bf839f4d96e1cb105c271a1ccb7a728ff8ce7dfd34a260afaf02e349b00831d2 node-v10.24.0-win-x64.7z -abf0aa48f642aa9ef6cc0021d2fe0275a60feece603664a76c31a812adc710bb node-v10.24.0-win-x64.zip -7e0e4c6b43935ce194456bbf066bb72fad49427fa08bfd4e7fc9818b4f312d3c node-v10.24.0-win-x86.7z -6e32b8c513ba209ae7ac2058c106d0b83b4c14c3472d3f1ad956fd3462691799 node-v10.24.0-win-x86.zip -a2c5dd02e43715127248d8533d260a9d4359b9f2d6ba6958df65631b8bf627cf node-v10.24.0-x64.msi -afcfa989c331e92ed02aeb88b0865ac2264b7bc297685ea46de48d5a945d46c0 node-v10.24.0-x86.msi -58c529834cbc65363d07e1ee59bb577cc76f527a2b0db80d0784e9b6e3c7e6da win-x64/node.exe +fc9ba4f3ba0be4a4495dd4fc7aa1e608f74a1440264518da760b246417077c3f node-v10.24.1-aix-ppc64.tar.gz +8088968a896e17c21b98187f8083291df9c88d0baa100a6cb9553e53c4fb17f8 node-v10.24.1-darwin-x64.tar.gz +8edae5060c7513de8e764cdbb61daea5ae652b7a3a457d412a7e08c04e5202da node-v10.24.1-darwin-x64.tar.xz +d38ae7bed508836129fac4163f3db5a0df5ea1dd26bf4a66f88146cbe770b788 node-v10.24.1-headers.tar.gz +1149f00ce0cec044e60deb723d1c1e682083c9ec6edc05cd1326f2031412a68e node-v10.24.1-headers.tar.xz +0ae4931d0ea779ecb237c1fc9f4a27271b0054b1efabc783863478913fe6caa6 node-v10.24.1-linux-arm64.tar.gz +b11ce837867e50d1b2bf09da6a85336bedfa257bf92f34712aeb94360c0bcd6e node-v10.24.1-linux-arm64.tar.xz +cf19f1965bca6b4ade9396e31f9490448ded2402713fdfe2d43410da037d9b5c node-v10.24.1-linux-armv6l.tar.gz +01c992bb0ec60552dbe3c96b5333bc0bb0c0eda9077af532c8869f82d49a63c8 node-v10.24.1-linux-armv6l.tar.xz +5b156bbd04adfaad2184b4d1e8324b21b546b40fb46e7105fa39f5ad2f34ddf3 node-v10.24.1-linux-armv7l.tar.gz +0d2c8991598c15f1efe31d6986f50d46016f74876194c257d7d0108c2c9de2da node-v10.24.1-linux-armv7l.tar.xz +8dc58449fe7b0368c417bb6ead8197bf1549e4502b42e62f3e51dce11b37fcd0 node-v10.24.1-linux-ppc64le.tar.gz +e99c2e7115361ab02e320053d2ee3619445349fa02b5082a12560014c0decf6a node-v10.24.1-linux-ppc64le.tar.xz +7ec1bd172b58bc9d7782d2d4428a298167b7297b8f1812a21eb6e4285bbe9ef2 node-v10.24.1-linux-s390x.tar.gz +aff7f704dc27da4bb6c0b8df83d0eeac2cf4c97825be0994fbdc14319da7a29c node-v10.24.1-linux-s390x.tar.xz +7a70083a73719a3c7846533923d5c4e955405c2b4ba1c1abd95ed21ae8b52775 node-v10.24.1-linux-x64.tar.gz +a3b9b97c23bcdc64334be6b02422e9014f040d59dcf604563ffda48003419356 node-v10.24.1-linux-x64.tar.xz +49f4e193b049a401a2f1fd98e3a7471d038418d81a37df2b64e88543f43b08a9 node-v10.24.1.pkg +20f0a296f544b5f5cb4122cb1c2aa080d83f0212c279147df4373d988b466657 node-v10.24.1-sunos-x64.tar.gz +3daf48c796f3edfc67cd25516fe7ff3a2a33c4da449f5c5c29dce98ba5e51834 node-v10.24.1-sunos-x64.tar.xz +95c7cfc4b5ad0b5a62bd553b30840db66f21217fbeb769ab27dac8019a4ebe5d node-v10.24.1.tar.gz +d72fc2c244603b4668da94081dc4d6067d467fdfa026e06a274012f16600480c node-v10.24.1.tar.xz +af98dda863785269a2db1bea8c3931e34d53f495f21d27fe8472154ee9a67cc4 node-v10.24.1-win-x64.7z +ae0af1b5e0c131dd0df1b3e4713c36e5d7f652ab6ca273ce46d39d4df8522bb0 node-v10.24.1-win-x64.zip +746db6e34b0d46695789fed30962f570fb5ee699590627459148d6e639eed55e node-v10.24.1-win-x86.7z +e39380da3a5f859f98b5a07e153e062c7fca852077693f99ad528705f5c0deb5 node-v10.24.1-win-x86.zip +dab263436eeda26c9c4809ba4d93e607dcffb3735b9a1866c77afb242a832dbd node-v10.24.1-x64.msi +dbddbb2e29da2e4c060510d3a466895555f458b5eb090756c9aad52858a9d61b node-v10.24.1-x86.msi +6664cc00232d95f73e050f25b1dd1000b44f63e35f051734c9bee478cd3574c7 win-x64/node.exe 7688ed23318d253aa98ee198f94983e4b563fab188e6fd9dd32955e77111096a win-x64/node.lib -2ae5424c759a3eb7aabfbb5d21ce8227f43d27150fbf6e1dd89173eeae9a4f8c win-x64/node_pdb.7z -7a68fa70295977484f1b1dcffa7d590c5b5f84b28d0ea51ffea734850307933a win-x64/node_pdb.zip -121c6d54aa31bb43a042e7cdedf0bdc916c39895f0f46c34cac76c3990895381 win-x86/node.exe +3bff6336aa859467f7710aad3286706306d165041af5ea2daaec3e1fa0fe86c7 win-x64/node_pdb.7z +36d49e29a33ee0fbb229fb2abee8bf093b3ea7fe70e7b31215c38f64900d435e win-x64/node_pdb.zip +6f1cf2bc2b17d51478f9f17db6ae51e1cc4126bc7f5a967a95c5ab5c8d9a26c0 win-x86/node.exe de1f3445597cbbee2e5eac435651f5dcab049a2d8bd3636877ab5803a87e269e win-x86/node.lib -2e218cafa528cd3a35dd58ba621b3f182498db7f235c072f14d1426043cf2eb8 win-x86/node_pdb.7z -2e4d6d1c72a90bdff03412d525b764a445edc108cd0503c4baf7da708b081a6e win-x86/node_pdb.zip +4d3f9bd319fe33f8a5991712264d3feb0247caa1bc9da2f47f6cb83386baf1bd win-x86/node_pdb.7z +9bd12506802cc20fbaa398c5dcc6ba4a72bffca9cc7cd526f7c69582eb526b53 win-x86/node_pdb.zip diff --git a/SHASUMS256.txt.sig b/SHASUMS256.txt.sig index b440a40..5e1a3ee 100644 Binary files a/SHASUMS256.txt.sig and b/SHASUMS256.txt.sig differ diff --git a/node-v10.24.0.tar.xz b/node-v10.24.0.tar.xz deleted file mode 120000 index 025c296..0000000 --- a/node-v10.24.0.tar.xz +++ /dev/null @@ -1 +0,0 @@ -/ipfs/bafybeib6nsho6sbacpqntnfebc2hcgkt3fpofcdriltmpbe7c5idlqvnhm \ No newline at end of file diff --git a/node-v10.24.1.tar.xz b/node-v10.24.1.tar.xz new file mode 120000 index 0000000..587c279 --- /dev/null +++ b/node-v10.24.1.tar.xz @@ -0,0 +1 @@ +/ipfs/bafybeiepd4gwmpydphhdwjxodbtshe2q6tdirbi5ztr7ywqx5rkvarttha \ No newline at end of file diff --git a/nodejs.keyring b/nodejs.keyring index 8693f08..05ec84d 100644 Binary files a/nodejs.keyring and b/nodejs.keyring differ diff --git a/nodejs10.changes b/nodejs10.changes index ddc3377..9e6f5ac 100644 --- a/nodejs10.changes +++ b/nodejs10.changes @@ -1,4 +1,17 @@ ------------------------------------------------------------------- +Wed Apr 7 14:25:13 UTC 2021 - Adam Majer <adam.majer@suse.de> + +- New upstream LTS version 10.24.1: + * CVE-2021-3450: OpenSSL - CA certificate check bypass with + X509_V_FLAG_X509_STRICT (High). (bsc#1183851) + * CVE-2021-3449: OpenSSL - NULL pointer deref in + signature_algorithms processing (High) (bsc#1183852) + * CVE-2020-7774: npm - Update y18n to fix Prototype-Pollution + (bsc#1184450) + +- versioned.patch: refreshed + +------------------------------------------------------------------- Mon Mar 8 14:54:19 UTC 2021 - Adam Majer <adam.majer@suse.de> - limit_worker_stdio_memsize.patch: reduce memory footprint of diff --git a/nodejs10.spec b/nodejs10.spec index df7de63..0ba999d 100644 --- a/nodejs10.spec +++ b/nodejs10.spec @@ -26,9 +26,13 @@ ########################################################### Name: nodejs10 -Version: 10.24.0 +Version: 10.24.1 Release: 0 +# Double DWZ memory limits +%define _dwz_low_mem_die_limit 20000000 +%define _dwz_max_die_limit 100000000 + %define node_version_number 10 %if %node_version_number >= 12 @@ -254,7 +258,7 @@ BuildRequires: openssl-devel >= %{openssl_req_ver} %endif %else -Provides: bundled(openssl) = 1.1.1j +Provides: bundled(openssl) = 1.1.1k %endif %if ! 0%{with intree_cares} @@ -341,7 +345,7 @@ Requires: nodejs10 = %{version} Provides: nodejs-npm = %{version} Obsoletes: nodejs-npm < 4.0.0 Provides: npm = %{version} -Provides: npm(npm) = 6.14.11 +Provides: npm(npm) = 6.14.12 %if 0%{?suse_version} >= 1500 %if %{node_version_number} >= 10 Requires: group(nobody) @@ -737,7 +741,7 @@ Provides: bundled(node-wrappy) = 1.0.2 Provides: bundled(node-write-file-atomic) = 2.4.3 Provides: bundled(node-xdg-basedir) = 3.0.0 Provides: bundled(node-xtend) = 4.0.1 -Provides: bundled(node-y18n) = 4.0.0 +Provides: bundled(node-y18n) = 4.0.1 Provides: bundled(node-yallist) = 2.1.2 Provides: bundled(node-yallist) = 3.0.3 Provides: bundled(node-yargs) = 14.2.3 diff --git a/versioned.patch b/versioned.patch index a5f83d6..16eab5f 100644 --- a/versioned.patch +++ b/versioned.patch @@ -8,10 +8,10 @@ management via update_alternatives. This is also important for generation of binary modules for multiple versions of NodeJS -Index: node-v10.23.3/Makefile +Index: node-v10.24.1/Makefile =================================================================== ---- node-v10.23.3.orig/Makefile -+++ node-v10.23.3/Makefile +--- node-v10.24.1.orig/Makefile ++++ node-v10.24.1/Makefile @@ -43,7 +43,7 @@ BUILDTYPE_LOWER := $(shell echo $(BUILDT EXEEXT := $(shell $(PYTHON) -c \ "import sys; print('.exe' if sys.platform == 'win32' else '')") @@ -21,10 +21,10 @@ Index: node-v10.23.3/Makefile NODE ?= ./$(NODE_EXE) NODE_G_EXE = node_g$(EXEEXT) NPM ?= ./deps/npm/bin/npm-cli.js -Index: node-v10.23.3/tools/install.py +Index: node-v10.24.1/tools/install.py =================================================================== ---- node-v10.23.3.orig/tools/install.py -+++ node-v10.23.3/tools/install.py +--- node-v10.24.1.orig/tools/install.py ++++ node-v10.24.1/tools/install.py @@ -77,7 +77,7 @@ def install(paths, dst): map(lambda path def uninstall(paths, dst): map(lambda path: try_remove(path, dst), paths) @@ -125,10 +125,10 @@ Index: node-v10.23.3/tools/install.py def run(args): global node_prefix, install_path, target_defaults, variables -Index: node-v10.23.3/doc/node.1 +Index: node-v10.24.1/doc/node.1 =================================================================== ---- node-v10.23.3.orig/doc/node.1 -+++ node-v10.23.3/doc/node.1 +--- node-v10.24.1.orig/doc/node.1 ++++ node-v10.24.1/doc/node.1 @@ -30,24 +30,24 @@ .Dt NODE 1 . @@ -158,10 +158,10 @@ Index: node-v10.23.3/doc/node.1 .Op Fl -v8-options . .\"====================================================================== -Index: node-v10.23.3/src/node.stp +Index: node-v10.24.1/src/node.stp =================================================================== ---- node-v10.23.3.orig/src/node.stp -+++ node-v10.23.3/src/node.stp +--- node-v10.24.1.orig/src/node.stp ++++ node-v10.24.1/src/node.stp @@ -19,7 +19,7 @@ // OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE // USE OR OTHER DEALINGS IN THE SOFTWARE. @@ -234,12 +234,12 @@ Index: node-v10.23.3/src/node.stp { scavenge = 1 << 0; compact = 1 << 1; -Index: node-v10.23.3/deps/npm/man/man1/npm.1 +Index: node-v10.24.1/deps/npm/man/man1/npm.1 =================================================================== ---- node-v10.23.3.orig/deps/npm/man/man1/npm.1 -+++ node-v10.23.3/deps/npm/man/man1/npm.1 +--- node-v10.24.1.orig/deps/npm/man/man1/npm.1 ++++ node-v10.24.1/deps/npm/man/man1/npm.1 @@ -1,11 +1,11 @@ - .TH "NPM" "1" "February 2021" "" "" + .TH "NPM" "1" "March 2021" "" "" .SH "NAME" -\fBnpm\fR \- javascript package manager +\fBnpm10\fR \- javascript package manager @@ -344,10 +344,10 @@ Index: node-v10.23.3/deps/npm/man/man1/npm.1 +npm10 help npmrc .RE -Index: node-v10.23.3/node.gyp +Index: node-v10.24.1/node.gyp =================================================================== ---- node-v10.23.3.orig/node.gyp -+++ node-v10.23.3/node.gyp +--- node-v10.24.1.orig/node.gyp ++++ node-v10.24.1/node.gyp @@ -22,8 +22,8 @@ 'node_shared_openssl%': 'false', 'node_v8_options%': '', @@ -359,10 +359,10 @@ Index: node-v10.23.3/node.gyp 'node_intermediate_lib_type%': 'static_library', 'library_files': [ 'lib/internal/per_context.js', -Index: node-v10.23.3/src/node_main.cc +Index: node-v10.24.1/src/node_main.cc =================================================================== ---- node-v10.23.3.orig/src/node_main.cc -+++ node-v10.23.3/src/node_main.cc +--- node-v10.24.1.orig/src/node_main.cc ++++ node-v10.24.1/src/node_main.cc @@ -119,6 +119,7 @@ int main(int argc, char* argv[]) { #endif // Disable stdio buffering, it interacts poorly with printf() @@ -371,10 +371,10 @@ Index: node-v10.23.3/src/node_main.cc setvbuf(stdout, nullptr, _IONBF, 0); setvbuf(stderr, nullptr, _IONBF, 0); return node::Start(argc, argv); -Index: node-v10.23.3/deps/npm/man/man1/npx.1 +Index: node-v10.24.1/deps/npm/man/man1/npx.1 =================================================================== ---- node-v10.23.3.orig/deps/npm/man/man1/npx.1 -+++ node-v10.23.3/deps/npm/man/man1/npx.1 +--- node-v10.24.1.orig/deps/npm/man/man1/npx.1 ++++ node-v10.24.1/deps/npm/man/man1/npx.1 @@ -1,32 +1,32 @@ .TH "NPX" "1" "July 2020" "npx@10.2.3" "User Commands" .SH "NAME" @@ -459,10 +459,10 @@ Index: node-v10.23.3/deps/npm/man/man1/npx.1 .RE -Index: node-v10.23.3/tools/test.py +Index: node-v10.24.1/tools/test.py =================================================================== ---- node-v10.23.3.orig/tools/test.py -+++ node-v10.23.3/tools/test.py +--- node-v10.24.1.orig/tools/test.py ++++ node-v10.24.1/tools/test.py @@ -893,7 +893,7 @@ class Context(object): if self.vm is not None: return self.vm