2026-09-01, Version 22.23.3 'Jod' (LTS) - #65443
Closed
github-actions[bot] wants to merge 25 commits into
Closed
Conversation
Signed-off-by: Stewart X Addison <[email protected]> PR-URL: #64193 Reviewed-By: Antoine du Hamel <[email protected]> Reviewed-By: Richard Lau <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
the binary-upload target uses $(TARNAME)-$(OSTYPE)-$(ARCH).tar.xz as the name to upload whereas it is created by the $(BINARYTAR) target as $(BINARYNAME). Since BINARYNAME includes the optional VARIATION when present this gets missed out int he binary-upload target, for example during a release build for Alpine/musl. This commit changes the binary-upload target to use the same variable for the tarball that is used when the file is created. Signed-off-by: Stewart X Addison <[email protected]> PR-URL: #65282 Reviewed-By: Richard Lau <[email protected]> Reviewed-By: Luigi Pinca <[email protected]> Reviewed-By: Gürgün Dayıoğlu <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #62324 Reviewed-By: Richard Lau <[email protected]> Reviewed-By: Marco Ippolito <[email protected]> Reviewed-By: Luigi Pinca <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Creates a SharedArrayBuffer from externally managed memory. Fixes: #62259 PR-URL: #62623 Reviewed-By: Matteo Collina <[email protected]> Reviewed-By: Chengzhong Wu <[email protected]> Reviewed-By: Vladimir Morozov <[email protected]> Reviewed-By: Robert Nagy <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #62961 Reviewed-By: Colin Ihrig <[email protected]> Reviewed-By: Luigi Pinca <[email protected]> Reviewed-By: Chengzhong Wu <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #62962 Reviewed-By: Luigi Pinca <[email protected]> Reviewed-By: Antoine du Hamel <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #62810 Reviewed-By: Antoine du Hamel <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Antoine du Hamel <[email protected]> PR-URL: #63110 Reviewed-By: James M Snell <[email protected]> Reviewed-By: Richard Lau <[email protected]> Reviewed-By: Marco Ippolito <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: umuoy1 <[email protected]> PR-URL: #62710 Reviewed-By: Chengzhong Wu <[email protected]> Reviewed-By: Vladimir Morozov <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #63375 Reviewed-By: Antoine du Hamel <[email protected]> Reviewed-By: Trivikram Kamat <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
This is the [`certdata.txt`][0] from NSS 3.123.1. This is the version of NSS that shipped in Firefox 151.0.1 on 2026-05-21 Certificates removed: - QuoVadis Root CA 2 - QuoVadis Root CA 3 - DigiCert Assured ID Root CA - DigiCert Global Root CA - DigiCert High Assurance EV Root CA - SwissSign Gold CA - G2 - SecureTrust CA - Secure Global CA - COMODO Certification Authority - Certigna - certSIGN ROOT CA - Izenpe.com - AffirmTrust Commercial - AffirmTrust Networking - AffirmTrust Premium - AffirmTrust Premium ECC - TeliaSonera Root CA v1 - Entrust Root Certification Authority - G2 - Entrust Root Certification Authority - EC1 - Trustwave Global Certification Authority - Trustwave Global ECC P256 Certification Authority - Trustwave Global ECC P384 Certification Authority - GLOBALTRUST 2020 - GTS Root R2 - FIRMAPROFESIONAL CA ROOT-A WEB [0]: https://raw.githubusercontent.com/nss-dev/nss/refs/tags/NSS_3_123_1_RTM/lib/ckfw/builtins/certdata.txt PR-URL: #63527 Reviewed-By: Luigi Pinca <[email protected]> Reviewed-By: Gürgün Dayıoğlu <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Antoine du Hamel <[email protected]> PR-URL: #63515 Reviewed-By: Colin Ihrig <[email protected]> Reviewed-By: Edy Silva <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Filip Skokan <[email protected]> PR-URL: #63938 Refs: nodejs/node-core-utils#1094 Reviewed-By: Antoine du Hamel <[email protected]> Reviewed-By: Mattias Buelens <[email protected]> Reviewed-By: Yagiz Nizipli <[email protected]> Reviewed-By: Daijiro Wachi <[email protected]> Reviewed-By: Luigi Pinca <[email protected]> Reviewed-By: Ethan Arrowood <[email protected]> Reviewed-By: Daeyeon Jeong <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Original commit message:
Fixes #1056
The commit
c-ares/c-ares@1d1b3d4
refactored the function to use wide strings, but didn't touch this
check. Because an empty wide string would now be size 2 and not 1, the
empty string would go on and cause the DNS domain list to be replaced
with nothing.
Signed-off-by: @dankmeme01
Refs: c-ares/c-ares@8ba37af
PR-URL: #64110
Fixes: #62347
Reviewed-By: Luigi Pinca <[email protected]>
Reviewed-By: Tim Perry <[email protected]>
Reviewed-By: Colin Ihrig <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Antoine du Hamel <[email protected]> PR-URL: #64070 Reviewed-By: Marco Ippolito <[email protected]> Reviewed-By: Richard Lau <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Antoine du Hamel <[email protected]> PR-URL: #64259 Reviewed-By: Richard Lau <[email protected]> Reviewed-By: Joyee Cheung <[email protected]> Reviewed-By: Marco Ippolito <[email protected]> Reviewed-By: Filip Skokan <[email protected]> Reviewed-By: Luigi Pinca <[email protected]> Reviewed-By: René <[email protected]> Reviewed-By: Colin Ihrig <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #64330 Reviewed-By: Antoine du Hamel <[email protected]> Reviewed-By: Richard Lau <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Mark the session as receiving around nghttp2_session_mem_recv() and defer RST_STREAM handling while receive is in progress. This prevents closing a stream while nghttp2 still processes it and avoids heap-use-after-free in nghttp2_session_mem_recv2(). Fixes: #64113 Signed-off-by: Evgeniy Gorbanev <[email protected]> PR-URL: #64166 Reviewed-By: Matteo Collina <[email protected]> Reviewed-By: Tim Perry <[email protected]> Reviewed-By: Rafael Gonzaga <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #64588 Reviewed-By: René <[email protected]> Reviewed-By: Colin Ihrig <[email protected]> Reviewed-By: Luigi Pinca <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
This is the certdata.txt[0] from NSS 3.125. This is the version of NSS that shipped in Firefox 153.0 on 2026-07-21. Certificates removed: - Entrust Root Certification Authority - SecureSign Root CA12 [0] https://raw.githubusercontent.com/nss-dev/nss/refs/tags/NSS_3_125_RTM/lib/ckfw/builtins/certdata.txt PR-URL: #64746 Reviewed-By: Antoine du Hamel <[email protected]> Reviewed-By: Luigi Pinca <[email protected]> Reviewed-By: Yagiz Nizipli <[email protected]> Reviewed-By: Colin Ihrig <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Synchronize mk-ca-bundle.pl with curl 1.33. This brings in curl's corrected handling of NSS distrust-after metadata. Refs: https://github.com/curl/curl/blob/0ada20387c31c638cfd7f6b4ae7e5cab5b318caf/scripts/mk-ca-bundle.pl Signed-off-by: Archkon <[email protected]> PR-URL: #64753 Fixes: #64752 Reviewed-By: Tim Perry <[email protected]> Reviewed-By: James M Snell <[email protected]> Reviewed-By: René <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Matteo Collina <[email protected]> PR-URL: #64651 Reviewed-By: James M Snell <[email protected]> Reviewed-By: Yagiz Nizipli <[email protected]> Reviewed-By: Filip Skokan <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Hiroki Osame <[email protected]> PR-URL: #65108 Fixes: #65104 Reviewed-By: Chengzhong Wu <[email protected]> Reviewed-By: Aviv Keller <[email protected]> Reviewed-By: Marco Ippolito <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Antoine du Hamel <[email protected]> PR-URL: #65217 Reviewed-By: Yagiz Nizipli <[email protected]> Reviewed-By: Tierney Cyren <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Collaborator
|
Review requested:
|
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
2026-09-01, Version 22.23.3 'Jod' (LTS), @juanarbol
Notable Changes
18ff63c4fd] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #6474604778301f8] - crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527Commits
8db060a85b] - build: update binary-upload to use correct tarball name (Stewart X Addison) #6528218ff63c4fd] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #6474604778301f8] - crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527c48840017b] - deps: update timezone to 2026c (Node.js GitHub Bot) #645887ffe4be13d] - deps: update c-ares to 1.34.8 (Node.js GitHub Bot) #643304ca6a50e36] - deps: c-ares: cherry-pick 8ba37af8e3fb (René) #6411010426f1dfd] - deps: update corepack to 0.35.0 (Node.js GitHub Bot) #6337526f3d51710] - deps: update corepack to 0.34.7 (Node.js GitHub Bot) #6281070edbbb729] - deps: update timezone to 2026b (Node.js GitHub Bot) #62962cb7a58a914] - deps: update icu to 78.3 (Node.js GitHub Bot) #623242f20379369] - doc: clarifyfilteroption ofsqlite.database.applyChangeset(Antoine du Hamel) #63515734907f9d1] - doc: add sxa GPG key (ed25519) (Stewart X Addison) #641937369d77af0] - http2: avoid uaf while receiving and sending rst_stream (esgor) #641668f9e0c45bd] - node-api: support SharedArrayBuffer in napi_create_typedarray (Yilong Li) #6271001c0498d85] - node-api: add napi_create_external_sharedarraybuffer (Ben Noordhuis) #626237bd96e36c1] - src: escape Windows environment variables in task runner (Antoine du Hamel) #65217086b893bdf] - tools: sync mk-ca-bundle.pl with curl (Archkon) #647531c1dab612d] - tools: removeenvinfofrom our workflows (Antoine du Hamel) #64259ecd4a1b4be] - tools: validate version number in release proposal commit message lint (Antoine du Hamel) #64070c54a8c1994] - tools: avoid test/fixtures/wpt/README.md conflicts (Filip Skokan) #63938b8510b08dc] - tools: use different branch for tool updates on staging branches (Antoine du Hamel) #6311062b77a1bee] - tools: update gyp-next to 0.22.1 (Node.js GitHub Bot) #62961589a8d4807] - url: handle unparsable serialized URLs in setters (Matteo Collina) #646513436da1002] - util: preserve function names without source map names (Hiroki Osame) #65108