|
|
|
|
Changelog for rh-nodejs14-npm-6.14.17-14.20.1.2.el7.x86_64.rpm :
Fri Oct 7 14:00:00 2022 Jan Staněk - 14.20.1-2 - Record additional fixes included in current version Resolves: CVE-2021-44531 CVE-2021-44532 CVE-2021-44533 CVE-2022-21824 Resolves: CVE-2022-0235 CVE-2021-44906
Thu Sep 29 14:00:00 2022 Jan Staněk - 14.20.1-1 - Rebase to version 14.20.1 Resolves: CVE-2022-35256
Tue Jul 26 14:00:00 2022 Jan Staněk - 14.20.0-2 - Disable corepack
Tue Jul 12 14:00:00 2022 Jan Staněk - 14.20.0-1 - Rebase to 14.20.0 Resolves: CVE-2022-32212 CVE-2022-32213 CVE-2022-32214 CVE-2022-32215
Thu Dec 9 13:00:00 2021 Jan Staněk - 14.18.2-1 - Rebase to 14.18.2 Resolves: rhbz#2031770 rhbz#2031774
Mon Nov 1 13:00:00 2021 Jan Staněk - 14.18.1-1 - Rebase to 14.18.1 Resolves: rhbz#2031773 rhbz#2031772
Wed Sep 1 14:00:00 2021 Jan Staněk - 14.17.6-1 - Rebase to 14.17.6 Resolves: rhbz#2031767 rhbz#2031769 - Drop CVE-2021-23343-path-parse-redos.patch: fixed upstream
Thu Aug 19 14:00:00 2021 Zuzana Svetlikova - 14.17.5-1.1 - Fix parallel builds
Thu Aug 12 14:00:00 2021 Jan Staněk - 14.17.5-1 - Rebase to 14.17.5 Resolves: CVE-2021-22931 CVE-2021-22939 CVE-2021-22940
Thu Aug 5 14:00:00 2021 Jan Staněk - 14.17.4-1 - Rebase to 14.17.4 with additional fixes (update-handling-on-rst_stream-frames.patch) Resolves: CVE-2021-22930 - Patch bundled(nodejs-path-parse) for CVE-2021-23343 Resolves: rhbz#1986745
Wed Jul 7 14:00:00 2021 Jan Staněk - 14.17.2-1 - Rebase to 14.17.2 Resolves: CVE-2021-22918, CVE-2021-23362, CVE-2021-27290, CVE-2021-33502 - Remove upstreamed deps-y18n-CVE-2020-7774.patch
Tue Feb 23 13:00:00 2021 Jan Staněk - 14.16.0-1 - Rebase to 14.16.0 - Resolves: CVE-2021-22883 CVE-2021-22884
Wed Jan 27 13:00:00 2021 Jan Staněk - 14.15.4-2 - Patch bundled y18n for CVE-2020-7774 - Resolves: CVE-2020-7774
Tue Jan 5 13:00:00 2021 Jan Staněk - 14.15.4-1 - Rebase to 14.15.4 - Resolves: CVE-2020-8265 CVE-2020-8287
Thu Oct 29 13:00:00 2020 Jan Staněk - 14.15.0-1 - Rebase to 14.15.0
Wed Sep 16 14:00:00 2020 Jan Staněk - 14.11.0-1 - Rebase to 14.11.0
Thu Aug 27 14:00:00 2020 Jan Staněk - 14.8.0-1 - Rebase to 14.8.0 - Enable FIPS when building (--openssl-is-fips)
Wed Jul 29 14:00:00 2020 Jan Staněk - 14.6.0-1 - Rebase to 14.6.0
Tue Jun 30 14:00:00 2020 Jan Staněk - 12.18.2-1 - Rebase to 12.18.2
Wed Jun 24 14:00:00 2020 Jan Staněk - 12.18.1-1 - Rebase to 12.18.1 - Use devtoolset-9
Wed Feb 19 13:00:00 2020 Zuzana Svetlikova - 12.16.1 - Resolves: RHBZ#1800404, RHBZ#1800403, RHBZ#1800378, RHBZ#1774113 - Resolves: RHBZ#1803154, RHBZ#1803157, RHBZ#1803160 (nmp CVEs) - also 1793482 - use devtoolset-8, build with -j4 - added uvwasi bundled dependency - revert more features #23188, #30637, #29598, #29292, #29489, #30055, #30053
Thu Jan 16 13:00:00 2020 Jan Staněk - 12.14.1-1 - Rebase to 12.14.1
Thu Nov 14 13:00:00 2019 Jan Staněk - 12.10.0-4 - Patch more OpenSSL features - Adjust test suite to (mostly) pass without patched OpenSSL features
Thu Oct 10 14:00:00 2019 Jan Staněk - 12.10.0-3 - Revert statx utilization in libuv to workaround s390x container issue - Resolves: rhbz#1760184
Sat Oct 5 14:00:00 2019 Zuzana Svetlikova - 12.10.0-2 - Add some missing flags, merge patches into one
Sat Oct 5 14:00:00 2019 Honza Horak - 12.10.0-1.1 - Rebase to 12.10.0 and apply patches for openssl compatibility (patches prepared by Zuzana and Jan)
Tue Aug 13 14:00:00 2019 Zuzana Svetlikova - 12.8.0-1 - Resolves: RHBZ#1717846 - update to v12.x - build without crypto for now
Thu Apr 4 14:00:00 2019 Jan Staněk - 10.10.0-3 - Rebuild with bundled zlib - Resolves: rhbz#1677710
Wed Oct 31 13:00:00 2018 Zuzana Svetlikova - 10.10.0-2 - Resolves: RHBZ#1584252 - comment out native.req file to prevent conflict with other Node.js - installations (rhbz#1637922)
Fri Sep 14 14:00:00 2018 Zuzana Svetlikova - 10.10.0-1 - rebase to v10.10.0 - update patches for openssl - TODO: remove useless comments, fix failing tests, update bundled provides
Thu Jul 19 14:00:00 2018 Zuzana Svetlikova - 10.1.0-1 - Initial v10 packaging - patch crypto/openssl 1.1.0 -> 1.0.2 - remove scl prefixes from bundled dependencies - TODO: update patches and dependencies
Tue Feb 6 13:00:00 2018 Zuzana Svetlikova - 8.9.4-2 - Resolves: RHBZ#1513560 #1542079 - fix outdated minizlib dependency in npm node_modules tree - https://github.com/nodejs/node/pull/16509
Mon Jan 15 13:00:00 2018 Zuzana Svetlikova - 8.9.4-1 - Resolves: RHBZ#1513560 - rebase to LTS
Wed Sep 27 14:00:00 2017 Zuzana Svetlikova - 8.6.0-1 - Resolves: RHBZ#1490389 - Update, v8.5.0 contains a CVE
Thu Sep 21 14:00:00 2017 Zuzana Svetlikova - 8.5.0-1 - Resolves: RHBZ#1490389 - Update to latest version, bundle nghttp2
Thu Aug 10 14:00:00 2017 Zuzana Svetlikova - 8.3.0-2 - Handle failing test in better manner - run more tests
Thu Aug 10 14:00:00 2017 Zuzana Svetlikova - 8.3.0-1 - Update to 8.3.0 - update V8 to 6.0 - update libuv to 1.13.1 - add bundled provides for npm modules - enable aarch64 builds
Mon Jul 24 14:00:00 2017 Zuzana Svetlikova - 8.2.1-1 - Update to 8.2.1 - update npm to 5.3.0, add npx command
Wed Jul 12 14:00:00 2017 Zuzana Svetlikova - 8.1.4-1 - Security update (https://nodejs.org/en/blog/vulnerability/july-2017-security-releases/) - Fixes RHBZ#1463132 and RHBZ#1469706
Wed Jun 28 14:00:00 2017 Joe Orton - 8.1.2-7 - disable debug build on aarch64
Wed Jun 28 14:00:00 2017 Zuzana Svetlikova - 8.1.2-6 - Build aarm64 without icu - switch to dts 7
Tue Jun 27 14:00:00 2017 Zuzana Svetlikova - 8.1.2-5 - Switch to DTS
Tue Jun 27 14:00:00 2017 Zuzana Svetlikova - 8.1.2-4 - Add %BuildArch
Sat Jun 24 14:00:00 2017 Zuzana Svetlikova - 8.1.2-3 - Patch CVE-2017-1000381
Fri Jun 23 14:00:00 2017 Zuzana Svetlikova - 8.1.2-2 - some clean up after fedora
Mon Jun 19 14:00:00 2017 Zuzana Svetlikova - 8.1.2-1 - Initial v8.x build, npmAATT5.0.3 - remove merged certs patch - build with updated system openssl - use fedora-style packaging, bundle npm and dependencies - bootstrap is modularity conditional to bundle http-parser - missing from base-runtime/shared-userspace - RHSCL 3.0 should be built for more arches
Wed Jan 11 13:00:00 2017 Zuzana Svetlikova - 6.9.1-2 - Rebuild from zvetlik/rh-nodejs6 - newer releases have problems with debug - add procps-ng for tests - remove unused patches
Thu Nov 3 13:00:00 2016 Zuzana Svetlikova - 6.9.1-1 - Update to 6.9.1
Wed Oct 19 14:00:00 2016 Zuzana Svetlikova - 6.9.0-1 - update to v6.9.0 LTS
Tue Oct 4 14:00:00 2016 Zuzana Svetlikova - 6.7.0-5 - Disable failing crypto tests
Tue Oct 4 14:00:00 2016 Zuzana Svetlikova - 6.7.0-4 - Require openssl
Tue Oct 4 14:00:00 2016 Zuzana Svetlikova - 6.7.0-2 - Build with shared openssl with EPEL7 patch
Mon Oct 3 14:00:00 2016 Zuzana Svetlikova - 6.7.0-1 - Update to 6.7.0
Wed Aug 31 14:00:00 2016 Zuzana Svetlikova - 6.5.0-1 - Update to 6.5.0, meanwhile built with bundled openssl - update system-certs patch
Wed Apr 6 14:00:00 2016 Tomas Hrcka - 4.4.2-1 - Rebase to latest upstream LTS release 4.4.2 - https://nodejs.org/en/blog/release/v4.4.1/
Tue Apr 5 14:00:00 2016 Tomas Hrcka - 4.4.1-2 - Rebase to latest upstream LTS release 4.4.1 - https://nodejs.org/en/blog/release/v4.4.1/
Thu Mar 17 13:00:00 2016 Tomas Hrcka - 4.4.0-1 - Rebase to latest upstream LTS release 4.4.0
Tue Mar 1 13:00:00 2016 Tomas Hrcka - 4.3.0-5 - New upstream release 4.3.0 - https://nodejs.org/en/blog/release/v4.3.0/ - Build with bundled openssl, this will be reverted ASAP - Unbundled http-parser
Thu Jul 16 14:00:00 2015 Tomas Hrcka - 0.10.40-1 - Rebase to latest upstream release
Wed Jul 1 14:00:00 2015 Tomas Hrcka - 0.10.39-1 - Rebase to latest upstream release
Wed Mar 25 13:00:00 2015 Tomas Hrcka - 0.10.35-4 - Enable tests during build time
Tue Mar 17 13:00:00 2015 Tomas Hrcka - 0.10.35-2 - Reflect dependency on specific ABI changes in v8 - RHBZ#1197110
Wed Jan 7 13:00:00 2015 Tomas Hrcka - 0.10.35-1 - New upstream release 0.10.35
Sun Feb 2 13:00:00 2014 Tomas Hrcka - 0.10.25-1 - New upstream release 0.10.25
Tue Jan 14 13:00:00 2014 Tomas Hrcka - 0.10.24-1 - new upstream release 0.10.24
Tue Nov 26 13:00:00 2013 Tomas Hrcka - 0.10.21-3 - rebuilt with v8314 collection
Tue Nov 12 13:00:00 2013 T.C. Hollingsworth - 0.10.22-1 - new upstream release 0.10.22 http://blog.nodejs.org/2013/11/12/node-v0-10-22-stable/
Mon Oct 21 14:00:00 2013 Tomas Hrcka - 0.10.21-2 - Build with system wide c-ares
Fri Oct 18 14:00:00 2013 T.C. Hollingsworth - 0.10.21-1 - new upstream release 0.10.21 http://blog.nodejs.org/2013/10/18/node-v0-10-21-stable/ - resolves an undisclosed security vulnerability in the http module
Tue Oct 1 14:00:00 2013 T.C. Hollingsworth - 0.10.20-1 - new upstream release 0.10.20 http://blog.nodejs.org/2013/09/30/node-v0-10-20-stable/
Wed Sep 25 14:00:00 2013 T.C. Hollingsworth - 0.10.19-1 - new upstream release 0.10.19 http://blog.nodejs.org/2013/09/24/node-v0-10-19-stable/
Fri Sep 6 14:00:00 2013 T.C. Hollingsworth - 0.10.18-1 - new upstream release 0.10.18 http://blog.nodejs.org/2013/09/04/node-v0-10-18-stable/
Tue Aug 27 14:00:00 2013 T.C. Hollingsworth - 0.10.17-1 - new upstream release 0.10.17 http://blog.nodejs.org/2013/08/21/node-v0-10-17-stable/
Sat Aug 17 14:00:00 2013 T.C. Hollingsworth - 0.10.16-1 - new upstream release 0.10.16 http://blog.nodejs.org/2013/08/16/node-v0-10-16-stable/ - add v8-devel to -devel Requires - restrict -devel Requires to the same architecture
Wed Aug 14 14:00:00 2013 T.C. Hollingsworth - 0.10.14-3 - fix typo in _isa macro in v8 Requires
Wed Aug 7 14:00:00 2013 Tomas Hrcka - 0.10.5-6 - Remove badly licensed fonts in script instead of patch
Thu Jul 25 14:00:00 2013 T.C. Hollingsworth - 0.10.14-1 - new upstream release 0.10.14 http://blog.nodejs.org/2013/07/25/node-v0-10-14-stable/
Wed Jul 10 14:00:00 2013 T.C. Hollingsworth - 0.10.13-1 - new upstream release 0.10.13 http://blog.nodejs.org/2013/07/09/node-v0-10-13-stable/ - remove RPM macros, etc. now that they\'ve migrated to nodejs-packaging
Wed Jun 19 14:00:00 2013 Tomas Hrcka - 0.10.5-5 - added patch to remove badly licensed web fonts
Wed Jun 19 14:00:00 2013 Tomas Hrcka - 0.10.5-5 - added patch to remove badly licensed web fonts
Wed Jun 19 14:00:00 2013 Tomas Hrcka - 0.10.5-4 - strip openssl from the tarball it contains prohibited code (RHBZ#967736) - patch makefile so it do not use bundled deps - new stripped tarball
Wed Jun 19 14:00:00 2013 T.C. Hollingsworth - 0.10.12-1 - new upstream release 0.10.12 http://blog.nodejs.org/2013/06/18/node-v0-10-12-stable/ - split off a -packaging subpackage with RPM macros, etc. - build -docs as noarch - copy mutiple version logic from nodejs-packaging SRPM for now
Fri May 31 14:00:00 2013 T.C. Hollingsworth - 0.10.9-1 - new upstream release 0.10.9 http://blog.nodejs.org/2013/05/30/node-v0-10-9-stable/
Wed May 29 14:00:00 2013 T.C. Hollingsworth - 0.10.8-1 - new upstream release 0.10.8 http://blog.nodejs.org/2013/05/24/node-v0-10-8-stable/
Wed May 29 14:00:00 2013 T.C. Hollingsworth - 0.10.7-1 - new upstream release 0.10.7 http://blog.nodejs.org/2013/05/17/node-v0-10-7-stable/ - strip openssl from the tarball; it contains prohibited code (RHBZ#967736) - patch Makefile so we can just remove all bundled deps completely
Wed May 15 14:00:00 2013 T.C. Hollingsworth - 0.10.6-1 - new upstream release 0.10.6 http://blog.nodejs.org/2013/05/14/node-v0-10-6-stable/
Tue May 14 14:00:00 2013 Tomas Hrcka - 0.10.5-3.1 - updated to latest upstream stable release
Mon May 6 14:00:00 2013 T.C. Hollingsworth - 0.10.5-3 - nodejs-fixdep: work properly when a package has no dependencies
Mon Apr 29 14:00:00 2013 T.C. Hollingsworth - 0.10.5-2 - nodejs-symlink-deps: make it work when --check is used and just devDependencies exist
Wed Apr 24 14:00:00 2013 T.C. Hollingsworth - 0.10.5-1 - new upstream release 0.10.5 http://blog.nodejs.org/2013/04/23/node-v0-10-5-stable/
Mon Apr 15 14:00:00 2013 T.C. Hollingsworth - 0.10.4-1 - new upstream release 0.10.4 http://blog.nodejs.org/2013/04/11/node-v0-10-4-stable/ - drop dependency generator files not supported on EL6 - port nodejs_default_filter to EL6 - add nodejs_find_provides_and_requires macro to invoke dependency generator - invoke the standard RPM provides and requires generators from the Node.js ones - write native module Requires from nodejs.req - change the c-ares-devel Requires in -devel to match the BuildRequires
Tue Apr 9 14:00:00 2013 Stephen Gallagher - 0.10.3-2.1 - Build against c-ares 1.9
Mon Apr 8 14:00:00 2013 Stanislav Ochotnicky - 0.10.3-3 - Add support for software collections - Move rpm macros and tooling to separate package - add no-op macro to permit spec compatibility with EPEL
Thu Apr 4 14:00:00 2013 T.C. Hollingsworth - 0.10.3-2 - nodejs-symlink-deps: symlink unconditionally in the buildroot
Wed Apr 3 14:00:00 2013 T.C. Hollingsworth - 0.10.3-1 - new upstream release 0.10.3 http://blog.nodejs.org/2013/04/03/node-v0-10-3-stable/ - nodejs-symlink-deps: only create symlink if target exists - nodejs-symlink-deps: symlink devDependencies when --check is used
Sun Mar 31 14:00:00 2013 T.C. Hollingsworth - 0.10.2-1 - new upstream release 0.10.2 http://blog.nodejs.org/2013/03/28/node-v0-10-2-stable/ - remove %nodejs_arches macro since it will only be useful if it is present in the redhat-rpm-config package - add default filtering macro to remove unwanted Provides from native modules - nodejs-symlink-deps now supports multiple modules in one SRPM properly - nodejs-symlink-deps also now supports a --check argument that works in the current working directry instead of the buildroot
Fri Mar 22 13:00:00 2013 T.C. Hollingsworth - 0.10.1-1 - new upstream release 0.10.1 http://blog.nodejs.org/2013/03/21/node-v0-10-1-stable/
Wed Mar 20 13:00:00 2013 T.C. Hollingsworth - 0.10.0-4 - fix escaping in dependency generator regular expressions (RHBZ#923941)
Wed Mar 13 13:00:00 2013 T.C. Hollingsworth - 0.10.0-3 - add virtual ABI provides for node and v8 so binary module\'s deps break when binary compatibility is broken - automatically add matching Requires to nodejs binary modules - add %nodejs_arches macro to future-proof ExcluseArch stanza in dependent packages
Tue Mar 12 13:00:00 2013 Stephen Gallagher - 0.10.0-2 - Fix up documentation subpackage
Mon Mar 11 13:00:00 2013 Stephen Gallagher - 0.10.0-1 - Update to stable 0.10.0 release - https://raw.github.com/joyent/node/v0.10.0/ChangeLog
Thu Feb 14 13:00:00 2013 Fedora Release Engineering - 0.9.5-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
Tue Jan 22 13:00:00 2013 T.C. Hollingsworth - 0.9.5-10 - minor bugfixes to RPM magic - nodejs-symlink-deps: don\'t create an empty node_modules dir when a module has no dependencies - nodes-fixdep: support adding deps when none exist - Add the full set of headers usually bundled with node as deps to nodejs-devel. This way `npm install` for native modules that assume the stuff bundled with node exists will usually \"just work\". -move RPM magic to nodejs-devel as requested by FPC
Sat Jan 12 13:00:00 2013 T.C. Hollingsworth - 0.9.5-9 - fix brown paper bag bug in requires generation script
Thu Jan 10 13:00:00 2013 Stephen Gallagher - 0.9.5-8 - Build debug binary and install it in the nodejs-devel subpackage
Thu Jan 10 13:00:00 2013 T.C. Hollingsworth - 0.9.5-7 - don\'t use make install since it rebuilds everything
Thu Jan 10 13:00:00 2013 T.C. Hollingsworth - 0.9.5-6 - add %{?isa}, epoch to v8 deps
Wed Jan 9 13:00:00 2013 T.C. Hollingsworth - 0.9.5-5 - add defines to match libuv (#892601) - make v8 dependency explicit (and thus more accurate) - add -g to $C(XX)FLAGS instead of patching configure to add it - don\'t write pointless \'npm(foo) > 0\' deps
Sat Jan 5 13:00:00 2013 T.C. Hollingsworth - 0.9.5-4 - install development headers - add nodejs_sitearch macro
Wed Jan 2 13:00:00 2013 T.C. Hollingsworth - 0.9.5-3 - make nodejs-symlink-deps actually work
Tue Jan 1 13:00:00 2013 T.C. Hollingsworth - 0.9.5-2 - provide nodejs-devel so modules can BuildRequire it (and be consistent with other interpreted languages in the distro)
Tue Jan 1 13:00:00 2013 T.C. Hollingsworth - 0.9.5-1 - new upstream release 0.9.5 - provide nodejs-devel for the moment - fix minor bugs in RPM magic - add nodejs_fixdep macro so packagers can easily adjust dependencies in package.json files
Wed Dec 26 13:00:00 2012 T.C. Hollingsworth - 0.9.4-1 - new upstream release 0.9.4 - system library patches are now upstream - respect optflags - include documentation in subpackage - add RPM dependency generation and related magic - guard libuv depedency so it always gets bumped when nodejs does - add -devel subpackage with enough to make node-gyp happy
Thu Dec 20 13:00:00 2012 Stephen Gallagher - 0.9.3-9 - Drop requirement on openssl 1.0.1
Wed Dec 19 13:00:00 2012 Dan Horák - 0.9.3-8 - set exclusive arch list to match v8
Tue Dec 18 13:00:00 2012 Stephen Gallagher - 0.9.3-7 - Add remaining changes from code review - Remove unnecessary BuildRequires on findutils - Remove %clean section
Fri Dec 14 13:00:00 2012 Stephen Gallagher - 0.9.3-6 - Fixes from code review - Fix executable permissions - Correct the License field - Build debuginfo properly
Thu Dec 13 13:00:00 2012 Stephen Gallagher - 0.9.3-5 - Return back to using the standard binary name - Temporarily adding a conflict against the ham radio node package until they complete an agreed rename of their binary.
Wed Nov 28 13:00:00 2012 Stephen Gallagher - 0.9.3-4 - Rename binary and manpage to nodejs
Mon Nov 19 13:00:00 2012 Stephen Gallagher - 0.9.3-3 - Update to latest upstream development release 0.9.3 - Include upstreamed patches to unbundle dependent libraries
Tue Oct 23 14:00:00 2012 Adrian Alves 0.8.12-1 - Fixes and Patches suggested by Matthias Runge
Mon Apr 9 14:00:00 2012 Adrian Alves 0.6.5 - First build.
|
|
|