Subject: CVS commit: pkgsrc/lang/nodejs
From: Adam Ciarcinski
Date: 2023-10-16 21:15:17
Message id: 20231016191517.36767FADC@cvs.NetBSD.org

Log Message:
nodejs: updated to 20.8.1

Version 20.8.1 (Current)

This is a security release.

Notable Changes

The following CVEs are fixed in this release:

CVE-2023-44487: nghttp2 Security Release (High)
CVE-2023-45143: undici Security Release (High)
CVE-2023-39332: Path traversal through path stored in Uint8Array (High)
CVE-2023-39331: Permission model improperly protects against path traversal (High)
CVE-2023-38552: Integrity checks according to policies can be circumvented (Medium)
CVE-2023-39333: Code injection via WebAssembly export names (Low)

Files:
RevisionActionfile
1.275modifypkgsrc/lang/nodejs/Makefile
1.247modifypkgsrc/lang/nodejs/distinfo