chore(deps): update all non-major packages >= 1.0 (#1522)Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: Avery Harnish <[email protected]> #1522
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
18.14.0
->18.14.1
9.4.2
->9.5.0
Release Notes
nodejs/node
v18.14.1
: 2023-02-16, Version 18.14.1 'Hydrogen' (LTS), @RafaelGSS prepared by @juanarbolCompare Source
This is a security release.
Notable Changes
The following CVEs are fixed in this release:
More detailed information on each of the vulnerabilities can be found in February 2023 Security Releases blog post.
This security release includes OpenSSL security updates as outlined in the recent
OpenSSL security advisory.
Commits
8393ebc72d
] - build: build ICU with ICU_NO_USER_DATA_OVERRIDE (RafaelGSS) nodejs-private/node-private#379004e34d046
] - crypto: clear OpenSSL error on invalid ca cert (RafaelGSS) #465725e0142a852
] - deps: cherry-pick Windows ARM64 fix for openssl (Richard Lau) #46572f71fe278a6
] - deps: update archs files for quictls/openssl-3.0.8+quic (RafaelGSS) #465722c6817e42b
] - deps: upgrade openssl sources to quictls/openssl-3.0.8+quic (RafaelGSS) #46572f0afa0bfe5
] - deps: update undici to 5.19.1 (Node.js GitHub Bot) #46634c26a34c13e
] - deps: update undici to 5.18.0 (Node.js GitHub Bot) #46634db93ee4a15
] - deps: update undici to 5.17.1 (Node.js GitHub Bot) #46634b4e49fb02c
] - deps: update undici to 5.16.0 (Node.js GitHub Bot) #4663490994e6a2c
] - deps: update undici to 5.15.1 (Node.js GitHub Bot) #4663400302fc7ac
] - deps: update undici to 5.15.0 (Node.js GitHub Bot) #466340e3b796cc5
] - lib: makeRequireFunction patch when experimental policy (RafaelGSS) nodejs-private/node-private#3717cccd5565f
] - policy: makeRequireFunction on mainModule.require (RafaelGSS) nodejs-private/node-private#371npm/cli
v9.5.0
Compare Source
Features
79bfd03
#6153 audit signatures verifies attestations (@feelepxyz)5fc6473
add provenance attestation (@bdehamer)Bug Fixes
53f75a4
#6158 gracefully fallback from auth-type=web (#6158) (@MylesBorins)ed59aae
#6162 refactor error reporting in audit command (@bdehamer)Dependencies
fad0473
[email protected]
678c6bf
[email protected]
9b4b366
[email protected]
d20ee2a
[email protected]
[email protected]
[email protected]
Configuration
📅 Schedule: Branch creation - "every weekend" in timezone America/Los_Angeles, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate. View repository job log here.