From: Peter Korsgaard <peter@korsgaard.com>
To: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Cc: Daniel Price <daniel.price@gmail.com>,
Martin Bark <martin@barkynet.com>,
Marcus Hoffmann <buildroot@bubu1.eu>,
Thomas Petazzoni <thomas.petazzoni@bootlin.com>,
buildroot@buildroot.org
Subject: Re: [Buildroot] [PATCH 1/1] package/nodejs: security bump to version 20.11.1
Date: Sat, 24 Feb 2024 11:16:15 +0100 [thread overview]
Message-ID: <875xyeupzk.fsf@48ers.dk> (raw)
In-Reply-To: <20240221220343.1228278-1-fontaine.fabrice@gmail.com> (Fabrice Fontaine's message of "Wed, 21 Feb 2024 23:03:43 +0100")
>>>>> "Fabrice" == Fabrice Fontaine <fontaine.fabrice@gmail.com> writes:
> - Fix CVE-2024-21892, CVE-2024-22019, CVE-2024-21896, CVE-2024-22017,
> CVE-2023-46809, CVE-2024-21891, CVE-2024-21890 and CVE-2024-22025
> - LICENSE hash changed due to two things:
> * c-ares vendored dependency license got updated [1]. This is unused
> by buildroot though anyway
> * base64 vendored library license updated copyright years and sorted
> contributor names [2], [3]
> - This bump will fix the following build failure raised since bump of
> python to version 3.12.1 in commit 36e635d2d5c0166476858aa239ccbe78e8f2af14
> thanks to
> https://github.com/nodejs/node/commit/95534ad82f4e33f53fd50efe633d43f8da70cba6
> https://github.com/nodejs/node/commit/6557c1c9b1206a85bb7d8e7450e8c3a4cff7c84b:
> Traceback (most recent call last):
> File "/home/autobuild/autobuild/instance-2/output-1/build/host-nodejs-src-20.9.0/configure.py", line 17, in <module>
> from distutils.version import StrictVersion
> ModuleNotFoundError: No module named 'distutils'
> https://github.com/nodejs/node/blob/v20.11.1/CHANGELOG.md
> [1] https://github.com/c-ares/c-ares/pull/556
> [2] https://github.com/aklomp/base64/commit/2e8ad2aec2065f258dc1aec9402aedd3604cfbcd
> [3] https://github.com/aklomp/base64/commit/d7bca2bb2928de6c4fe496e6defe8b3affa35d1b
> Fixes: 36e635d2d5c0166476858aa239ccbe78e8f2af14
> - http://autobuild.buildroot.org/results/8b38bc4b7879a0349c1305e2fcb458a0cfd04a93
> Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Committed, thanks.
--
Bye, Peter Korsgaard
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
next prev parent reply other threads:[~2024-02-24 10:16 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-02-21 22:03 [Buildroot] [PATCH 1/1] package/nodejs: security bump to version 20.11.1 Fabrice Fontaine
2024-02-22 13:07 ` Marcus Hoffmann via buildroot
2024-02-24 10:16 ` Peter Korsgaard [this message]
2024-03-17 13:03 ` Peter Korsgaard
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=875xyeupzk.fsf@48ers.dk \
--to=peter@korsgaard.com \
--cc=buildroot@bubu1.eu \
--cc=buildroot@buildroot.org \
--cc=daniel.price@gmail.com \
--cc=fontaine.fabrice@gmail.com \
--cc=martin@barkynet.com \
--cc=thomas.petazzoni@bootlin.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox