SEARCH
NEW RPMS
DIRECTORIES
ABOUT
FAQ
VARIOUS
BLOG

 
 
Changelog for rh-nodejs14-npm-6.14.17-14.20.1.2.el7.x86_64.rpm :
Fri Oct 7 14:00:00 2022 Jan Staněk - 14.20.1-2
- Record additional fixes included in current version
Resolves: CVE-2021-44531 CVE-2021-44532 CVE-2021-44533 CVE-2022-21824
Resolves: CVE-2022-0235 CVE-2021-44906

Thu Sep 29 14:00:00 2022 Jan Staněk - 14.20.1-1
- Rebase to version 14.20.1
Resolves: CVE-2022-35256

Tue Jul 26 14:00:00 2022 Jan Staněk - 14.20.0-2
- Disable corepack

Tue Jul 12 14:00:00 2022 Jan Staněk - 14.20.0-1
- Rebase to 14.20.0
Resolves: CVE-2022-32212 CVE-2022-32213 CVE-2022-32214 CVE-2022-32215

Thu Dec 9 13:00:00 2021 Jan Staněk - 14.18.2-1
- Rebase to 14.18.2
Resolves: rhbz#2031770 rhbz#2031774

Mon Nov 1 13:00:00 2021 Jan Staněk - 14.18.1-1
- Rebase to 14.18.1
Resolves: rhbz#2031773 rhbz#2031772

Wed Sep 1 14:00:00 2021 Jan Staněk - 14.17.6-1
- Rebase to 14.17.6
Resolves: rhbz#2031767 rhbz#2031769
- Drop CVE-2021-23343-path-parse-redos.patch: fixed upstream

Thu Aug 19 14:00:00 2021 Zuzana Svetlikova - 14.17.5-1.1
- Fix parallel builds

Thu Aug 12 14:00:00 2021 Jan Staněk - 14.17.5-1
- Rebase to 14.17.5
Resolves: CVE-2021-22931 CVE-2021-22939 CVE-2021-22940

Thu Aug 5 14:00:00 2021 Jan Staněk - 14.17.4-1
- Rebase to 14.17.4 with additional fixes (update-handling-on-rst_stream-frames.patch)
Resolves: CVE-2021-22930
- Patch bundled(nodejs-path-parse) for CVE-2021-23343
Resolves: rhbz#1986745

Wed Jul 7 14:00:00 2021 Jan Staněk - 14.17.2-1
- Rebase to 14.17.2
Resolves: CVE-2021-22918, CVE-2021-23362, CVE-2021-27290, CVE-2021-33502
- Remove upstreamed deps-y18n-CVE-2020-7774.patch

Tue Feb 23 13:00:00 2021 Jan Staněk - 14.16.0-1
- Rebase to 14.16.0
- Resolves: CVE-2021-22883 CVE-2021-22884

Wed Jan 27 13:00:00 2021 Jan Staněk - 14.15.4-2
- Patch bundled y18n for CVE-2020-7774
- Resolves: CVE-2020-7774

Tue Jan 5 13:00:00 2021 Jan Staněk - 14.15.4-1
- Rebase to 14.15.4
- Resolves: CVE-2020-8265 CVE-2020-8287

Thu Oct 29 13:00:00 2020 Jan Staněk - 14.15.0-1
- Rebase to 14.15.0

Wed Sep 16 14:00:00 2020 Jan Staněk - 14.11.0-1
- Rebase to 14.11.0

Thu Aug 27 14:00:00 2020 Jan Staněk - 14.8.0-1
- Rebase to 14.8.0
- Enable FIPS when building (--openssl-is-fips)

Wed Jul 29 14:00:00 2020 Jan Staněk - 14.6.0-1
- Rebase to 14.6.0

Tue Jun 30 14:00:00 2020 Jan Staněk - 12.18.2-1
- Rebase to 12.18.2

Wed Jun 24 14:00:00 2020 Jan Staněk - 12.18.1-1
- Rebase to 12.18.1
- Use devtoolset-9

Wed Feb 19 13:00:00 2020 Zuzana Svetlikova - 12.16.1
- Resolves: RHBZ#1800404, RHBZ#1800403, RHBZ#1800378, RHBZ#1774113
- Resolves: RHBZ#1803154, RHBZ#1803157, RHBZ#1803160 (nmp CVEs)
- also 1793482
- use devtoolset-8, build with -j4
- added uvwasi bundled dependency
- revert more features #23188, #30637, #29598, #29292, #29489, #30055, #30053

Thu Jan 16 13:00:00 2020 Jan Staněk - 12.14.1-1
- Rebase to 12.14.1

Thu Nov 14 13:00:00 2019 Jan Staněk - 12.10.0-4
- Patch more OpenSSL features
- Adjust test suite to (mostly) pass without patched OpenSSL features

Thu Oct 10 14:00:00 2019 Jan Staněk - 12.10.0-3
- Revert statx utilization in libuv to workaround s390x container issue
- Resolves: rhbz#1760184

Sat Oct 5 14:00:00 2019 Zuzana Svetlikova - 12.10.0-2
- Add some missing flags, merge patches into one

Sat Oct 5 14:00:00 2019 Honza Horak - 12.10.0-1.1
- Rebase to 12.10.0 and apply patches for openssl compatibility
(patches prepared by Zuzana and Jan)

Tue Aug 13 14:00:00 2019 Zuzana Svetlikova - 12.8.0-1
- Resolves: RHBZ#1717846
- update to v12.x
- build without crypto for now

Thu Apr 4 14:00:00 2019 Jan Staněk - 10.10.0-3
- Rebuild with bundled zlib
- Resolves: rhbz#1677710

Wed Oct 31 13:00:00 2018 Zuzana Svetlikova - 10.10.0-2
- Resolves: RHBZ#1584252
- comment out native.req file to prevent conflict with other Node.js
- installations (rhbz#1637922)

Fri Sep 14 14:00:00 2018 Zuzana Svetlikova - 10.10.0-1
- rebase to v10.10.0
- update patches for openssl
- TODO: remove useless comments, fix failing tests, update bundled provides

Thu Jul 19 14:00:00 2018 Zuzana Svetlikova - 10.1.0-1
- Initial v10 packaging
- patch crypto/openssl 1.1.0 -> 1.0.2
- remove scl prefixes from bundled dependencies
- TODO: update patches and dependencies

Tue Feb 6 13:00:00 2018 Zuzana Svetlikova - 8.9.4-2
- Resolves: RHBZ#1513560 #1542079
- fix outdated minizlib dependency in npm node_modules tree
- https://github.com/nodejs/node/pull/16509

Mon Jan 15 13:00:00 2018 Zuzana Svetlikova - 8.9.4-1
- Resolves: RHBZ#1513560
- rebase to LTS

Wed Sep 27 14:00:00 2017 Zuzana Svetlikova - 8.6.0-1
- Resolves: RHBZ#1490389
- Update, v8.5.0 contains a CVE

Thu Sep 21 14:00:00 2017 Zuzana Svetlikova - 8.5.0-1
- Resolves: RHBZ#1490389
- Update to latest version, bundle nghttp2

Thu Aug 10 14:00:00 2017 Zuzana Svetlikova - 8.3.0-2
- Handle failing test in better manner
- run more tests

Thu Aug 10 14:00:00 2017 Zuzana Svetlikova - 8.3.0-1
- Update to 8.3.0
- update V8 to 6.0
- update libuv to 1.13.1
- add bundled provides for npm modules
- enable aarch64 builds

Mon Jul 24 14:00:00 2017 Zuzana Svetlikova - 8.2.1-1
- Update to 8.2.1
- update npm to 5.3.0, add npx command

Wed Jul 12 14:00:00 2017 Zuzana Svetlikova - 8.1.4-1
- Security update (https://nodejs.org/en/blog/vulnerability/july-2017-security-releases/)
- Fixes RHBZ#1463132 and RHBZ#1469706

Wed Jun 28 14:00:00 2017 Joe Orton - 8.1.2-7
- disable debug build on aarch64

Wed Jun 28 14:00:00 2017 Zuzana Svetlikova - 8.1.2-6
- Build aarm64 without icu
- switch to dts 7

Tue Jun 27 14:00:00 2017 Zuzana Svetlikova - 8.1.2-5
- Switch to DTS

Tue Jun 27 14:00:00 2017 Zuzana Svetlikova - 8.1.2-4
- Add %BuildArch

Sat Jun 24 14:00:00 2017 Zuzana Svetlikova - 8.1.2-3
- Patch CVE-2017-1000381

Fri Jun 23 14:00:00 2017 Zuzana Svetlikova - 8.1.2-2
- some clean up after fedora

Mon Jun 19 14:00:00 2017 Zuzana Svetlikova - 8.1.2-1
- Initial v8.x build, npmAATT5.0.3
- remove merged certs patch
- build with updated system openssl
- use fedora-style packaging, bundle npm and dependencies
- bootstrap is modularity conditional to bundle http-parser
- missing from base-runtime/shared-userspace
- RHSCL 3.0 should be built for more arches

Wed Jan 11 13:00:00 2017 Zuzana Svetlikova - 6.9.1-2
- Rebuild from zvetlik/rh-nodejs6
- newer releases have problems with debug
- add procps-ng for tests
- remove unused patches

Thu Nov 3 13:00:00 2016 Zuzana Svetlikova - 6.9.1-1
- Update to 6.9.1

Wed Oct 19 14:00:00 2016 Zuzana Svetlikova - 6.9.0-1
- update to v6.9.0 LTS

Tue Oct 4 14:00:00 2016 Zuzana Svetlikova - 6.7.0-5
- Disable failing crypto tests

Tue Oct 4 14:00:00 2016 Zuzana Svetlikova - 6.7.0-4
- Require openssl

Tue Oct 4 14:00:00 2016 Zuzana Svetlikova - 6.7.0-2
- Build with shared openssl with EPEL7 patch

Mon Oct 3 14:00:00 2016 Zuzana Svetlikova - 6.7.0-1
- Update to 6.7.0

Wed Aug 31 14:00:00 2016 Zuzana Svetlikova - 6.5.0-1
- Update to 6.5.0, meanwhile built with bundled openssl
- update system-certs patch

Wed Apr 6 14:00:00 2016 Tomas Hrcka - 4.4.2-1
- Rebase to latest upstream LTS release 4.4.2
- https://nodejs.org/en/blog/release/v4.4.1/

Tue Apr 5 14:00:00 2016 Tomas Hrcka - 4.4.1-2
- Rebase to latest upstream LTS release 4.4.1
- https://nodejs.org/en/blog/release/v4.4.1/

Thu Mar 17 13:00:00 2016 Tomas Hrcka - 4.4.0-1
- Rebase to latest upstream LTS release 4.4.0

Tue Mar 1 13:00:00 2016 Tomas Hrcka - 4.3.0-5
- New upstream release 4.3.0
- https://nodejs.org/en/blog/release/v4.3.0/
- Build with bundled openssl, this will be reverted ASAP
- Unbundled http-parser

Thu Jul 16 14:00:00 2015 Tomas Hrcka - 0.10.40-1
- Rebase to latest upstream release

Wed Jul 1 14:00:00 2015 Tomas Hrcka - 0.10.39-1
- Rebase to latest upstream release

Wed Mar 25 13:00:00 2015 Tomas Hrcka - 0.10.35-4
- Enable tests during build time

Tue Mar 17 13:00:00 2015 Tomas Hrcka - 0.10.35-2
- Reflect dependency on specific ABI changes in v8
- RHBZ#1197110

Wed Jan 7 13:00:00 2015 Tomas Hrcka - 0.10.35-1
- New upstream release 0.10.35

Sun Feb 2 13:00:00 2014 Tomas Hrcka - 0.10.25-1
- New upstream release 0.10.25

Tue Jan 14 13:00:00 2014 Tomas Hrcka - 0.10.24-1
- new upstream release 0.10.24

Tue Nov 26 13:00:00 2013 Tomas Hrcka - 0.10.21-3
- rebuilt with v8314 collection

Tue Nov 12 13:00:00 2013 T.C. Hollingsworth - 0.10.22-1
- new upstream release 0.10.22
http://blog.nodejs.org/2013/11/12/node-v0-10-22-stable/

Mon Oct 21 14:00:00 2013 Tomas Hrcka - 0.10.21-2
- Build with system wide c-ares

Fri Oct 18 14:00:00 2013 T.C. Hollingsworth - 0.10.21-1
- new upstream release 0.10.21
http://blog.nodejs.org/2013/10/18/node-v0-10-21-stable/
- resolves an undisclosed security vulnerability in the http module

Tue Oct 1 14:00:00 2013 T.C. Hollingsworth - 0.10.20-1
- new upstream release 0.10.20
http://blog.nodejs.org/2013/09/30/node-v0-10-20-stable/

Wed Sep 25 14:00:00 2013 T.C. Hollingsworth - 0.10.19-1
- new upstream release 0.10.19
http://blog.nodejs.org/2013/09/24/node-v0-10-19-stable/

Fri Sep 6 14:00:00 2013 T.C. Hollingsworth - 0.10.18-1
- new upstream release 0.10.18
http://blog.nodejs.org/2013/09/04/node-v0-10-18-stable/

Tue Aug 27 14:00:00 2013 T.C. Hollingsworth - 0.10.17-1
- new upstream release 0.10.17
http://blog.nodejs.org/2013/08/21/node-v0-10-17-stable/

Sat Aug 17 14:00:00 2013 T.C. Hollingsworth - 0.10.16-1
- new upstream release 0.10.16
http://blog.nodejs.org/2013/08/16/node-v0-10-16-stable/
- add v8-devel to -devel Requires
- restrict -devel Requires to the same architecture

Wed Aug 14 14:00:00 2013 T.C. Hollingsworth - 0.10.14-3
- fix typo in _isa macro in v8 Requires

Wed Aug 7 14:00:00 2013 Tomas Hrcka - 0.10.5-6
- Remove badly licensed fonts in script instead of patch

Thu Jul 25 14:00:00 2013 T.C. Hollingsworth - 0.10.14-1
- new upstream release 0.10.14
http://blog.nodejs.org/2013/07/25/node-v0-10-14-stable/

Wed Jul 10 14:00:00 2013 T.C. Hollingsworth - 0.10.13-1
- new upstream release 0.10.13
http://blog.nodejs.org/2013/07/09/node-v0-10-13-stable/
- remove RPM macros, etc. now that they\'ve migrated to nodejs-packaging

Wed Jun 19 14:00:00 2013 Tomas Hrcka - 0.10.5-5
- added patch to remove badly licensed web fonts

Wed Jun 19 14:00:00 2013 Tomas Hrcka - 0.10.5-5
- added patch to remove badly licensed web fonts

Wed Jun 19 14:00:00 2013 Tomas Hrcka - 0.10.5-4
- strip openssl from the tarball it contains prohibited code (RHBZ#967736)
- patch makefile so it do not use bundled deps
- new stripped tarball

Wed Jun 19 14:00:00 2013 T.C. Hollingsworth - 0.10.12-1
- new upstream release 0.10.12
http://blog.nodejs.org/2013/06/18/node-v0-10-12-stable/
- split off a -packaging subpackage with RPM macros, etc.
- build -docs as noarch
- copy mutiple version logic from nodejs-packaging SRPM for now

Fri May 31 14:00:00 2013 T.C. Hollingsworth - 0.10.9-1
- new upstream release 0.10.9
http://blog.nodejs.org/2013/05/30/node-v0-10-9-stable/

Wed May 29 14:00:00 2013 T.C. Hollingsworth - 0.10.8-1
- new upstream release 0.10.8
http://blog.nodejs.org/2013/05/24/node-v0-10-8-stable/

Wed May 29 14:00:00 2013 T.C. Hollingsworth - 0.10.7-1
- new upstream release 0.10.7
http://blog.nodejs.org/2013/05/17/node-v0-10-7-stable/
- strip openssl from the tarball; it contains prohibited code (RHBZ#967736)
- patch Makefile so we can just remove all bundled deps completely

Wed May 15 14:00:00 2013 T.C. Hollingsworth - 0.10.6-1
- new upstream release 0.10.6
http://blog.nodejs.org/2013/05/14/node-v0-10-6-stable/

Tue May 14 14:00:00 2013 Tomas Hrcka - 0.10.5-3.1
- updated to latest upstream stable release

Mon May 6 14:00:00 2013 T.C. Hollingsworth - 0.10.5-3
- nodejs-fixdep: work properly when a package has no dependencies

Mon Apr 29 14:00:00 2013 T.C. Hollingsworth - 0.10.5-2
- nodejs-symlink-deps: make it work when --check is used and just
devDependencies exist

Wed Apr 24 14:00:00 2013 T.C. Hollingsworth - 0.10.5-1
- new upstream release 0.10.5
http://blog.nodejs.org/2013/04/23/node-v0-10-5-stable/

Mon Apr 15 14:00:00 2013 T.C. Hollingsworth - 0.10.4-1
- new upstream release 0.10.4
http://blog.nodejs.org/2013/04/11/node-v0-10-4-stable/
- drop dependency generator files not supported on EL6
- port nodejs_default_filter to EL6
- add nodejs_find_provides_and_requires macro to invoke dependency generator
- invoke the standard RPM provides and requires generators from the Node.js ones
- write native module Requires from nodejs.req
- change the c-ares-devel Requires in -devel to match the BuildRequires

Tue Apr 9 14:00:00 2013 Stephen Gallagher - 0.10.3-2.1
- Build against c-ares 1.9

Mon Apr 8 14:00:00 2013 Stanislav Ochotnicky - 0.10.3-3
- Add support for software collections
- Move rpm macros and tooling to separate package
- add no-op macro to permit spec compatibility with EPEL

Thu Apr 4 14:00:00 2013 T.C. Hollingsworth - 0.10.3-2
- nodejs-symlink-deps: symlink unconditionally in the buildroot

Wed Apr 3 14:00:00 2013 T.C. Hollingsworth - 0.10.3-1
- new upstream release 0.10.3
http://blog.nodejs.org/2013/04/03/node-v0-10-3-stable/
- nodejs-symlink-deps: only create symlink if target exists
- nodejs-symlink-deps: symlink devDependencies when --check is used

Sun Mar 31 14:00:00 2013 T.C. Hollingsworth - 0.10.2-1
- new upstream release 0.10.2
http://blog.nodejs.org/2013/03/28/node-v0-10-2-stable/
- remove %nodejs_arches macro since it will only be useful if it is present in
the redhat-rpm-config package
- add default filtering macro to remove unwanted Provides from native modules
- nodejs-symlink-deps now supports multiple modules in one SRPM properly
- nodejs-symlink-deps also now supports a --check argument that works in the
current working directry instead of the buildroot

Fri Mar 22 13:00:00 2013 T.C. Hollingsworth - 0.10.1-1
- new upstream release 0.10.1
http://blog.nodejs.org/2013/03/21/node-v0-10-1-stable/

Wed Mar 20 13:00:00 2013 T.C. Hollingsworth - 0.10.0-4
- fix escaping in dependency generator regular expressions (RHBZ#923941)

Wed Mar 13 13:00:00 2013 T.C. Hollingsworth - 0.10.0-3
- add virtual ABI provides for node and v8 so binary module\'s deps break when
binary compatibility is broken
- automatically add matching Requires to nodejs binary modules
- add %nodejs_arches macro to future-proof ExcluseArch stanza in dependent
packages

Tue Mar 12 13:00:00 2013 Stephen Gallagher - 0.10.0-2
- Fix up documentation subpackage

Mon Mar 11 13:00:00 2013 Stephen Gallagher - 0.10.0-1
- Update to stable 0.10.0 release
- https://raw.github.com/joyent/node/v0.10.0/ChangeLog

Thu Feb 14 13:00:00 2013 Fedora Release Engineering - 0.9.5-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild

Tue Jan 22 13:00:00 2013 T.C. Hollingsworth - 0.9.5-10
- minor bugfixes to RPM magic
- nodejs-symlink-deps: don\'t create an empty node_modules dir when a module
has no dependencies
- nodes-fixdep: support adding deps when none exist
- Add the full set of headers usually bundled with node as deps to nodejs-devel.
This way `npm install` for native modules that assume the stuff bundled with
node exists will usually \"just work\".
-move RPM magic to nodejs-devel as requested by FPC

Sat Jan 12 13:00:00 2013 T.C. Hollingsworth - 0.9.5-9
- fix brown paper bag bug in requires generation script

Thu Jan 10 13:00:00 2013 Stephen Gallagher - 0.9.5-8
- Build debug binary and install it in the nodejs-devel subpackage

Thu Jan 10 13:00:00 2013 T.C. Hollingsworth - 0.9.5-7
- don\'t use make install since it rebuilds everything

Thu Jan 10 13:00:00 2013 T.C. Hollingsworth - 0.9.5-6
- add %{?isa}, epoch to v8 deps

Wed Jan 9 13:00:00 2013 T.C. Hollingsworth - 0.9.5-5
- add defines to match libuv (#892601)
- make v8 dependency explicit (and thus more accurate)
- add -g to $C(XX)FLAGS instead of patching configure to add it
- don\'t write pointless \'npm(foo) > 0\' deps

Sat Jan 5 13:00:00 2013 T.C. Hollingsworth - 0.9.5-4
- install development headers
- add nodejs_sitearch macro

Wed Jan 2 13:00:00 2013 T.C. Hollingsworth - 0.9.5-3
- make nodejs-symlink-deps actually work

Tue Jan 1 13:00:00 2013 T.C. Hollingsworth - 0.9.5-2
- provide nodejs-devel so modules can BuildRequire it (and be consistent
with other interpreted languages in the distro)

Tue Jan 1 13:00:00 2013 T.C. Hollingsworth - 0.9.5-1
- new upstream release 0.9.5
- provide nodejs-devel for the moment
- fix minor bugs in RPM magic
- add nodejs_fixdep macro so packagers can easily adjust dependencies in
package.json files

Wed Dec 26 13:00:00 2012 T.C. Hollingsworth - 0.9.4-1
- new upstream release 0.9.4
- system library patches are now upstream
- respect optflags
- include documentation in subpackage
- add RPM dependency generation and related magic
- guard libuv depedency so it always gets bumped when nodejs does
- add -devel subpackage with enough to make node-gyp happy

Thu Dec 20 13:00:00 2012 Stephen Gallagher - 0.9.3-9
- Drop requirement on openssl 1.0.1

Wed Dec 19 13:00:00 2012 Dan Horák - 0.9.3-8
- set exclusive arch list to match v8

Tue Dec 18 13:00:00 2012 Stephen Gallagher - 0.9.3-7
- Add remaining changes from code review
- Remove unnecessary BuildRequires on findutils
- Remove %clean section

Fri Dec 14 13:00:00 2012 Stephen Gallagher - 0.9.3-6
- Fixes from code review
- Fix executable permissions
- Correct the License field
- Build debuginfo properly

Thu Dec 13 13:00:00 2012 Stephen Gallagher - 0.9.3-5
- Return back to using the standard binary name
- Temporarily adding a conflict against the ham radio node package until they
complete an agreed rename of their binary.

Wed Nov 28 13:00:00 2012 Stephen Gallagher - 0.9.3-4
- Rename binary and manpage to nodejs

Mon Nov 19 13:00:00 2012 Stephen Gallagher - 0.9.3-3
- Update to latest upstream development release 0.9.3
- Include upstreamed patches to unbundle dependent libraries

Tue Oct 23 14:00:00 2012 Adrian Alves 0.8.12-1
- Fixes and Patches suggested by Matthias Runge

Mon Apr 9 14:00:00 2012 Adrian Alves 0.6.5
- First build.


 
ICM