Uh oh!
There was an error while loading. Please reload this page.
Release proposal: v0.10.41 - #2805
Conversation
othiym23
commented
Sep 11, 2015
Has there been discussion or a decision about nodejs/Release#37? It would be nice to get a less broken npm into 0.10 at some point. |
rvagg
commented
Sep 11, 2015
@othiym23 @nodejs/lts let's get that question sorted out at next week's meeting and make sure the results of that make it into this release |
Fishrock123
commented
Sep 11, 2015
Rubber stamp LGTM. Would like to discuss npm also. |
bnoordhuis
commented
Sep 11, 2015
The release should wait for the new libuv v0.10 release. |
jasnell
commented
Sep 11, 2015
Unless there were updates I missed while I was in Waterford, three are only 8 open PRs against v0.10. We should attempt to close those before cutting a new v0.10.41 |
rvagg
commented
Sep 12, 2015
|
jasnell
commented
Sep 12, 2015
Some of these can likely be closed straight off, but a few represent long standing bugs. |
See https://github.com/npm/npm/releases/tag/v1.4.29 for details. Encourage users to upgrade to a newer npm, and lays the groundwork for getting npm@2 into Node 0.10 LTS. PR-URL: #3639 Reviewed-By: Rod Vagg <rod@vagg.org> Reviewed-By: James M Snell <jasnell@gmail.com>
bfae860 to
bce11edComparervagg
commented
Nov 23, 2015
Using the work in #3965 combined with the |
evanlucas
commented
Nov 23, 2015
the pkg for OS X looks good |
4473495 to
0365803Comparervagg
commented
Dec 3, 2015
Updated to match current #3965 which should be close to final. Preparing for OpenSSL upgrade. Unfortunately we can't do a simple OpenSSL-commits-only release for v0.10 because our build infra won't allow it and when you start pulling in commits to support our infra you end up with a large chunk of the commits staged on v0.10 anyway. So I'm suggesting we just move ahead with v0.10.41 with all pending commits as soon as we have the OpenSSL 1.0.1 upgrade ready. /cc @nodejs/security |
Contains fixes for: * CVE-2015-3194 Certificate verify crash with missing PSS parameter * CVE-2015-3195 X509_ATTRIBUTE memory leak fixup! character encoding noise fixup! update opensslconf.h PR-URL: #4132 Reviewed-By: Fedor Indutny <fedor@indutny.com> Reviewed-By: Shigeki Ohtsu <ohtsu@iij.ad.jp>
PR-URL: #3965 Reviewed-By: Alexis Campailla <orangemocha@nodejs.org> Reviewed-By: Johan Bergström <bugs@bergstroem.nu>
PR-URL: #3965 Reviewed-By: Alexis Campailla <orangemocha@nodejs.org> Reviewed-By: Johan Bergström <bugs@bergstroem.nu>
PR-URL: #3965 Reviewed-By: Alexis Campailla <orangemocha@nodejs.org> Reviewed-By: Johan Bergström <bugs@bergstroem.nu>
Security Update Notable items: * build: Add support for Microsoft Visual Studio 2015 * npm: Upgrade to v1.4.29 from v1.4.28. A special one-off release as part of the strategy to get a version of npm into Node.js v0.10.x that works with the current registry (nodejs/Release#37). This version of npm prints out a banner each time it is run. The banner warns that the next standard release of Node.js v0.10.x will ship with a version of npm v2. * openssl: Upgrade to 1.0.1q, containing fixes CVE-2015-3194 "Certificate verify crash with missing PSS parameter", a potential denial-of-service vector for Node.js TLS servers; TLS clients are also impacted. Details are available at <http://openssl.org/news/secadv/20151203.txt>. (Ben Noordhuis) #4133 PR-URL: nodejs-private/node-private#15
rvagg
commented
Dec 3, 2015
https://ci.nodejs.org/job/node-test-pull-request/916/ Incorporated the OpenSSL fixes and the updated build fixes, updated commits list in OP, release notes now starts with: 2015-12-04, Version 0.10.41 (Maintenance), @rvagg Security Update Notable items:
|
Technically we can't do this with our new Jenkins setup and new nodejs.org server, we still have jenkins.nodejs.org and the original nodejs.org server in place to serve for emergencies but this release needs to come out of our new infra so there's work for @nodejs/build to do. Some details on that here: nodejs/build#164