Subject: CVS commit: pkgsrc/lang/nodejs12
From: Adam Ciarcinski
Date: 2020-06-03 10:42:41
Message id: 20200603084241.9D99EFB27@cvs.NetBSD.org

Log Message:
nodejs12: updated to 12.18.0

Version 12.18.0 'Erbium' (LTS)

Notable changes

This is a security release.

Vulnerabilities fixed:

CVE-2020-8172: TLS session reuse can lead to host certificate verification \ 
bypass (High).
CVE-2020-11080: HTTP/2 Large Settings Frame DoS (Low).
CVE-2020-8174: napi_get_value_string_*() allows various kinds of memory \ 
corruption (High).

Commits

- crypto: update root certificates
- (SEMVER-MINOR) deps: update nghttp2 to 1.41.0
- (SEMVER-MINOR) http2: implement support for max settings entries
- napi: fix memory corruption vulnerability
- tls: emit session after verifying certificate
- tools: update certdata.txt

Files:
RevisionActionfile
1.18modifypkgsrc/lang/nodejs12/Makefile
1.7modifypkgsrc/lang/nodejs12/buildlink3.mk
1.12modifypkgsrc/lang/nodejs12/distinfo