[HIGH] Upgrade nodejs24 to 24.14.1 for CVE-2026-21710, CVE-2026-21637, CVE-2026-21717, CVE-2026-21713, CVE-2026-21714, CVE-2026-21712, CVE-2026-21716, CVE-2026-21715#16403
Conversation
|
This PR has been kept in draft status as the BB results still need to be verified, since the build could not be completed on the local VM due to memory constraints. |
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
nodejs on v24 is on LTS and stable release, 24.14.1 is a security release with CVE-2026-21710, CVE-2026-21637, CVE-2026-21717, CVE-2026-21713, CVE-2026-21714, CVE-2026-21712, CVE-2026-21716, CVE-2026-21715
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
Why have you removed these patches? like CVE-2019-10906
Are these covered in this release?
Updated the spec file. Dropped only |
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
remove the spec file from the folder as well,
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
Taking this release as this contains only bug and security fixes as nodejs24 is on LTS.
|
/azurepipelines run |
|
Azure Pipelines successfully started running 1 pipeline(s). |
kgodara912
left a comment
There was a problem hiding this comment.
Minor version bump of nodejs24 package. The upgrade belongs to same LTS release series and is highly recommended to fixing CVEs. Buddy build is successful. LGTM.
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
What does the PR accomplish, why was it needed?
Upgrade nodejs24 to 24.14.1 for CVE-2026-21710, CVE-2026-21637, CVE-2026-21717, CVE-2026-21713, CVE-2026-21714, CVE-2026-21712, CVE-2026-21716, CVE-2026-21715
perl-WWW-Curlwas added as a BuildRequires becauseopenssl-perlexplicitly depends on the Perl capabilityperl(WWW::Curl::Easy).Change Log
Does this affect the toolchain?
NO
Associated issues
Links to CVEs
Test Methodology