Uh oh!
There was an error while loading. Please reload this page.
2017-01-31, Version 6.9.5 'Boron' (LTS) - #11081
Merged
Merged
Conversation
MylesBorins
commented
Jan 31, 2017
ContributorAuthor
MylesBorins
commented
Jan 31, 2017
ContributorAuthor
/cc @nodejs/github-bot no auto labelling... is that bot down? |
mscdex
commented
Jan 31, 2017
Contributor
@MylesBorins Doesn't appear to be, the webhook notifications were delivered successfully. Might need @phillipj to look at the local bot logs. |
jasnell
approved these changes
Jan 31, 2017
This is a security release of the 'Boron' release line to upgrade OpenSSL to version 1.0.2k Although the OpenSSL team have determined a maximum severity rating of "moderate", the Node.js crypto team (Ben Noordhuis, Shigeki Ohtsu and Fedor Indutny) have determined the impact to Node users is "low". Details on this determination can be found on the Nodejs.org website https://nodejs.org/en/blog/vulnerability/openssl-january-2017/ Notable Changes: * deps: - upgrade openssl sources to 1.0.2k (Shigeki Ohtsu) #11021 PR-URL: #11081
MylesBorinsforce-pushed
the
v6.9.5-proposal
branch
from
January 31, 2017 18:29
6b60d19 to
37a8051Comparephillipj
commented
Jan 31, 2017
Member
It got a 404 error when requesting the list of files this PR has changed :/ Looks like a temporary GitHub glitch because similar requests has succeeded afterwards. |
MylesBorins
commented
Jan 31, 2017
ContributorAuthor
Failures look unrelated to change. Moving forward with release |
MylesBorins added a commit
that referenced
this pull request
Jan 31, 2017
This is a security release of the 'Boron' release line to upgrade OpenSSL to version 1.0.2k Although the OpenSSL team have determined a maximum severity rating of "moderate", the Node.js crypto team (Ben Noordhuis, Shigeki Ohtsu and Fedor Indutny) have determined the impact to Node users is "low". Details on this determination can be found on the Nodejs.org website https://nodejs.org/en/blog/vulnerability/openssl-january-2017/ Notable Changes: * deps: - upgrade openssl sources to 1.0.2k (Shigeki Ohtsu) #11021 PR-URL: #11081
imyller added a commit
to imyller/meta-nodejs
that referenced
this pull request
Mar 2, 2017
This is a security release of the 'Boron' release line to upgrade OpenSSL to version 1.0.2k Although the OpenSSL team have determined a maximum severity rating of "moderate", the Node.js crypto team (Ben Noordhuis, Shigeki Ohtsu and Fedor Indutny) have determined the impact to Node users is "low". Details on this determination can be found on the Nodejs.org website https://nodejs.org/en/blog/vulnerability/openssl-january-2017/ Notable Changes: * deps: - upgrade openssl sources to 1.0.2k (Shigeki Ohtsu) nodejs/node#11021 PR-URL: nodejs/node#11081 Signed-off-by: Ilkka Myller <ilkka.myller@nodefield.com>
imyller added a commit
to imyller/meta-nodejs
that referenced
this pull request
Mar 2, 2017
This is a security release of the 'Boron' release line to upgrade OpenSSL to version 1.0.2k Although the OpenSSL team have determined a maximum severity rating of "moderate", the Node.js crypto team (Ben Noordhuis, Shigeki Ohtsu and Fedor Indutny) have determined the impact to Node users is "low". Details on this determination can be found on the Nodejs.org website https://nodejs.org/en/blog/vulnerability/openssl-january-2017/ Notable Changes: * deps: - upgrade openssl sources to 1.0.2k (Shigeki Ohtsu) nodejs/node#11021 PR-URL: nodejs/node#11081 Signed-off-by: Ilkka Myller <ilkka.myller@nodefield.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
2017-01-31, Version 6.9.5 'Boron' (LTS), @MylesBorins
This is a security release of the 'Boron' release line to upgrade OpenSSL to version 1.0.2k
Although the OpenSSL team have determined a maximum severity rating of "moderate", the Node.js
crypto team (Ben Noordhuis, Shigeki Ohtsu and Fedor Indutny) have determined the impact to Node
users is "low". Details on this determination can be found
on the Nodejs.org website.
Notable Changes
Commits
87ac44974a] - deps: update openssl asm and asm_obsolete files (Shigeki Ohtsu) #11021a4b43a7ef9] - deps: add -no_rand_screen to openssl s_client (Shigeki Ohtsu) nodejs/io.js#1836f5b77fdf8d] - deps: fix asm build error of openssl in x86_win32 (Shigeki Ohtsu) iojs/io.js#138958fae148fa] - deps: fix openssl assembly error on ia32 win32 (Fedor Indutny) iojs/io.js#1389d623e8c5b9] - deps: copy all openssl header files to include dir (Shigeki Ohtsu) #110213f2bef60b8] - deps: upgrade openssl sources to 1.0.2k (Shigeki Ohtsu) #11021c4678d2f9a] - openssl: fix keypress requirement in apps on win32 (Shigeki Ohtsu) iojs/io.js#1389