Closed renovate[bot] closed 1 year ago
This PR has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
This PR has been automatically closed because it has not had recent activity. You can reopen it by clicking on Reopen pull request
. Thank you for your contributions.
This PR contains the following updates:
18.17.4
->18.17.6
18.2.19
->18.2.20
18.17.0
->18.17.1
0.82.0
->0.82.1
Release Notes
nodejs/node (node)
### [`v18.17.1`](https://togithub.com/nodejs/node/releases/tag/v18.17.1): 2023-08-09, Version 18.17.1 'Hydrogen' (LTS), @RafaelGSS [Compare Source](https://togithub.com/nodejs/node/compare/v18.17.0...v18.17.1) This is a security release. ##### Notable Changes The following CVEs are fixed in this release: - [CVE-2023-32002](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32002): Policies can be bypassed via Module.\_load (High) - [CVE-2023-32006](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32006): Policies can be bypassed by module.constructor.createRequire (Medium) - [CVE-2023-32559](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32559): Policies can be bypassed via process.binding (Medium) - OpenSSL Security Releases - [OpenSSL security advisory 14th July](https://mta.openssl.org/pipermail/openssl-announce/2023-July/000264.html). - [OpenSSL security advisory 19th July](https://mta.openssl.org/pipermail/openssl-announce/2023-July/000265.html). - [OpenSSL security advisory 31st July](https://mta.openssl.org/pipermail/openssl-announce/2023-July/000267.html) More detailed information on each of the vulnerabilities can be found in [August 2023 Security Releases](https://nodejs.org/en/blog/vulnerability/august-2023-security-releases/) blog post. ##### Commits - \[[`fe3abdf82e`](https://togithub.com/nodejs/node/commit/fe3abdf82e)] - **deps**: update archs files for openssl-3.0.10+quic1 (Node.js GitHub Bot) [#49036](https://togithub.com/nodejs/node/pull/49036) - \[[`2c5a522d9c`](https://togithub.com/nodejs/node/commit/2c5a522d9c)] - **deps**: upgrade openssl sources to quictls/openssl-3.0.10+quic1 (Node.js GitHub Bot) [#49036](https://togithub.com/nodejs/node/pull/49036) - \[[`15bced0bde`](https://togithub.com/nodejs/node/commit/15bced0bde)] - **policy**: handle Module.constructor and main.extensions bypass (RafaelGSS) [nodejs-private/node-private#417](https://togithub.com/nodejs-private/node-private/pull/417) - \[[`d4570fae35`](https://togithub.com/nodejs/node/commit/d4570fae35)] - **policy**: disable process.binding() when enabled (Tobias Nießen) [nodejs-private/node-private#460](https://togithub.com/nodejs-private/node-private/pull/460)PlasmoHQ/plasmo (plasmo)
### [`v0.82.1`](https://togithub.com/PlasmoHQ/plasmo/releases/tag/v0.82.1) [Compare Source](https://togithub.com/PlasmoHQ/plasmo/compare/v0.82.0...v0.82.1) #### ✨ What's Changed - Add `ai` package to `knownEsmPackageSet` by [@atgctg](https://togithub.com/atgctg) in [https://github.com/PlasmoHQ/plasmo/pull/723](https://togithub.com/PlasmoHQ/plasmo/pull/723) - chore: bump dependencies by [@louisgv](https://togithub.com/louisgv) in [https://github.com/PlasmoHQ/plasmo/pull/724](https://togithub.com/PlasmoHQ/plasmo/pull/724) - chore: Remove Svelte resolver hack (as upstream merge has been fixed) #### 🥷 New Contributors - [@atgctg](https://togithub.com/atgctg) made their first contribution in [https://github.com/PlasmoHQ/plasmo/pull/723](https://togithub.com/PlasmoHQ/plasmo/pull/723) #### 🤝 Sponsors - [@jqphu](https://togithub.com/jqphu) - https://github.com/jqphu - [@nahtnam](https://togithub.com/nahtnam) - https://nahtnam.com - [@Eversmile12](https://togithub.com/Eversmile12) - https://github.com/Eversmile12 **Full Changelog**: https://github.com/PlasmoHQ/plasmo/compare/v0.82.0...v0.82.1Configuration
📅 Schedule: Branch creation - "on friday and saturday" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate. View repository job log here.