2026-09-01, Version 22.23.3 'Jod' (LTS) - #65448
Open
github-actions[bot] wants to merge 28 commits into
Open
Conversation
Collaborator
|
Review requested:
|
juanarbol
marked this pull request as ready for review
August 21, 2026 13:46
Contributor
|
Please include [email protected] from #64884 if possible, as it resolves a critical severity vulnerability reported for |
Member
Signed-off-by: Stewart X Addison <[email protected]> PR-URL: #64193 Reviewed-By: Antoine du Hamel <[email protected]> Reviewed-By: Richard Lau <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
the binary-upload target uses $(TARNAME)-$(OSTYPE)-$(ARCH).tar.xz as the name to upload whereas it is created by the $(BINARYTAR) target as $(BINARYNAME). Since BINARYNAME includes the optional VARIATION when present this gets missed out int he binary-upload target, for example during a release build for Alpine/musl. This commit changes the binary-upload target to use the same variable for the tarball that is used when the file is created. Signed-off-by: Stewart X Addison <[email protected]> PR-URL: #65282 Reviewed-By: Richard Lau <[email protected]> Reviewed-By: Luigi Pinca <[email protected]> Reviewed-By: Gürgün Dayıoğlu <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #62324 Reviewed-By: Richard Lau <[email protected]> Reviewed-By: Marco Ippolito <[email protected]> Reviewed-By: Luigi Pinca <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Creates a SharedArrayBuffer from externally managed memory. Fixes: #62259 PR-URL: #62623 Reviewed-By: Matteo Collina <[email protected]> Reviewed-By: Chengzhong Wu <[email protected]> Reviewed-By: Vladimir Morozov <[email protected]> Reviewed-By: Robert Nagy <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #62961 Reviewed-By: Colin Ihrig <[email protected]> Reviewed-By: Luigi Pinca <[email protected]> Reviewed-By: Chengzhong Wu <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #62962 Reviewed-By: Luigi Pinca <[email protected]> Reviewed-By: Antoine du Hamel <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #62810 Reviewed-By: Antoine du Hamel <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Antoine du Hamel <[email protected]> PR-URL: #63110 Reviewed-By: James M Snell <[email protected]> Reviewed-By: Richard Lau <[email protected]> Reviewed-By: Marco Ippolito <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: umuoy1 <[email protected]> PR-URL: #62710 Reviewed-By: Chengzhong Wu <[email protected]> Reviewed-By: Vladimir Morozov <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #63375 Reviewed-By: Antoine du Hamel <[email protected]> Reviewed-By: Trivikram Kamat <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
This is the [`certdata.txt`][0] from NSS 3.123.1. This is the version of NSS that shipped in Firefox 151.0.1 on 2026-05-21 Certificates removed: - QuoVadis Root CA 2 - QuoVadis Root CA 3 - DigiCert Assured ID Root CA - DigiCert Global Root CA - DigiCert High Assurance EV Root CA - SwissSign Gold CA - G2 - SecureTrust CA - Secure Global CA - COMODO Certification Authority - Certigna - certSIGN ROOT CA - Izenpe.com - AffirmTrust Commercial - AffirmTrust Networking - AffirmTrust Premium - AffirmTrust Premium ECC - TeliaSonera Root CA v1 - Entrust Root Certification Authority - G2 - Entrust Root Certification Authority - EC1 - Trustwave Global Certification Authority - Trustwave Global ECC P256 Certification Authority - Trustwave Global ECC P384 Certification Authority - GLOBALTRUST 2020 - GTS Root R2 - FIRMAPROFESIONAL CA ROOT-A WEB [0]: https://raw.githubusercontent.com/nss-dev/nss/refs/tags/NSS_3_123_1_RTM/lib/ckfw/builtins/certdata.txt PR-URL: #63527 Reviewed-By: Luigi Pinca <[email protected]> Reviewed-By: Gürgün Dayıoğlu <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Antoine du Hamel <[email protected]> PR-URL: #63515 Reviewed-By: Colin Ihrig <[email protected]> Reviewed-By: Edy Silva <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Filip Skokan <[email protected]> PR-URL: #63938 Refs: nodejs/node-core-utils#1094 Reviewed-By: Antoine du Hamel <[email protected]> Reviewed-By: Mattias Buelens <[email protected]> Reviewed-By: Yagiz Nizipli <[email protected]> Reviewed-By: Daijiro Wachi <[email protected]> Reviewed-By: Luigi Pinca <[email protected]> Reviewed-By: Ethan Arrowood <[email protected]> Reviewed-By: Daeyeon Jeong <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Original commit message:
Fixes #1056
The commit
c-ares/c-ares@1d1b3d4
refactored the function to use wide strings, but didn't touch this
check. Because an empty wide string would now be size 2 and not 1, the
empty string would go on and cause the DNS domain list to be replaced
with nothing.
Signed-off-by: @dankmeme01
Refs: c-ares/c-ares@8ba37af
PR-URL: #64110
Fixes: #62347
Reviewed-By: Luigi Pinca <[email protected]>
Reviewed-By: Tim Perry <[email protected]>
Reviewed-By: Colin Ihrig <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Antoine du Hamel <[email protected]> PR-URL: #64070 Reviewed-By: Marco Ippolito <[email protected]> Reviewed-By: Richard Lau <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Antoine du Hamel <[email protected]> PR-URL: #64259 Reviewed-By: Richard Lau <[email protected]> Reviewed-By: Joyee Cheung <[email protected]> Reviewed-By: Marco Ippolito <[email protected]> Reviewed-By: Filip Skokan <[email protected]> Reviewed-By: Luigi Pinca <[email protected]> Reviewed-By: René <[email protected]> Reviewed-By: Colin Ihrig <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #64330 Reviewed-By: Antoine du Hamel <[email protected]> Reviewed-By: Richard Lau <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #64588 Reviewed-By: René <[email protected]> Reviewed-By: Colin Ihrig <[email protected]> Reviewed-By: Luigi Pinca <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
This is the certdata.txt[0] from NSS 3.125. This is the version of NSS that shipped in Firefox 153.0 on 2026-07-21. Certificates removed: - Entrust Root Certification Authority - SecureSign Root CA12 [0] https://raw.githubusercontent.com/nss-dev/nss/refs/tags/NSS_3_125_RTM/lib/ckfw/builtins/certdata.txt PR-URL: #64746 Reviewed-By: Antoine du Hamel <[email protected]> Reviewed-By: Luigi Pinca <[email protected]> Reviewed-By: Yagiz Nizipli <[email protected]> Reviewed-By: Colin Ihrig <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Synchronize mk-ca-bundle.pl with curl 1.33. This brings in curl's corrected handling of NSS distrust-after metadata. Refs: https://github.com/curl/curl/blob/0ada20387c31c638cfd7f6b4ae7e5cab5b318caf/scripts/mk-ca-bundle.pl Signed-off-by: Archkon <[email protected]> PR-URL: #64753 Fixes: #64752 Reviewed-By: Tim Perry <[email protected]> Reviewed-By: James M Snell <[email protected]> Reviewed-By: René <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Matteo Collina <[email protected]> PR-URL: #64651 Reviewed-By: James M Snell <[email protected]> Reviewed-By: Yagiz Nizipli <[email protected]> Reviewed-By: Filip Skokan <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Hiroki Osame <[email protected]> PR-URL: #65108 Fixes: #65104 Reviewed-By: Chengzhong Wu <[email protected]> Reviewed-By: Aviv Keller <[email protected]> Reviewed-By: Marco Ippolito <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Antoine du Hamel <[email protected]> PR-URL: #65217 Reviewed-By: Yagiz Nizipli <[email protected]> Reviewed-By: Tierney Cyren <[email protected]> Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #62993 Reviewed-By: Richard Lau <[email protected]> Reviewed-By: Rafael Gonzaga <[email protected]> Reviewed-By: Jacob Smith <[email protected]> Signed-off-by: Antoine du Hamel <[email protected]>
Mark the session as receiving around nghttp2_session_mem_recv() and defer RST_STREAM handling while receive is in progress. This prevents closing a stream while nghttp2 still processes it and avoids heap-use-after-free in nghttp2_session_mem_recv2(). Fixes: #64113 Signed-off-by: Evgeniy Gorbanev <[email protected]> PR-URL: #64166 Backport-PR-URL: #65264 Reviewed-By: Antoine du Hamel <[email protected]>
PR-URL: #64884 Reviewed-By: Jordan Harband <[email protected]> Reviewed-By: Aviv Keller <[email protected]> Reviewed-By: Luigi Pinca <[email protected]> Reviewed-By: Mike McCready <[email protected]> Reviewed-By: Trivikram Kamat <[email protected]> Reviewed-By: Juan José Arboleda <[email protected]>
Original commit message:
[logging] Use RecursiveMutex for Logger
Logger::allows_code_compaction might be called from within a
CodeCreateEvent where initializing line script line ends might trigger
a GC. During compaction we check if code compaction is allowed which
calls back into the above Logger method.
Bug: 41497149
Change-Id: Ifd1b740df8600584780341d8214e995832e663b4
Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/5572952
Reviewed-by: Victor Gomes <[email protected]>
Commit-Queue: Camillo Bruni <[email protected]>
Cr-Commit-Position: refs/heads/main@{#94140}
Refs: v8/v8@a6eaf75
PR-URL: #65402
Fixes: #65140
Reviewed-By: Richard Lau <[email protected]>
juanarbol
force-pushed
the
v22.23.3-proposal
branch
from
August 26, 2026 20:19
9fe685a to
dacd551
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
2026-09-01, Version 22.23.3 'Jod' (LTS), @juanarbol
Notable Changes
fe2a6b2be8] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #6474671feba6b69] - crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527Commits
44cf27b8fa] - build: update binary-upload to use correct tarball name (Stewart X Addison) #65282fe2a6b2be8] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #6474671feba6b69] - crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #635273376e27de2] - deps: V8: cherry-pick a6eaf7574109 (Camillo Bruni) #65402b816fc8958] - deps: upgrade npm to 10.9.9 (npm team) #648844e4bd1b104] - deps: update timezone to 2026c (Node.js GitHub Bot) #645887d82841b4e] - deps: update c-ares to 1.34.8 (Node.js GitHub Bot) #6433001855a19d3] - deps: c-ares: cherry-pick 8ba37af8e3fb (René) #6411023fb398c3d] - deps: update corepack to 0.35.0 (Node.js GitHub Bot) #633755286330365] - deps: update corepack to 0.34.7 (Node.js GitHub Bot) #628106d6c3c98b1] - deps: update timezone to 2026b (Node.js GitHub Bot) #62962e306521444] - deps: update icu to 78.3 (Node.js GitHub Bot) #62324d9cb8468a3] - doc: clarifyfilteroption ofsqlite.database.applyChangeset(Antoine du Hamel) #63515c9c5662d91] - doc: add sxa GPG key (ed25519) (Stewart X Addison) #641937c2df5dd96] - http2: avoid uaf while receiving and sending rst_stream (esgor) #641663909ff2c4a] - node-api: support SharedArrayBuffer in napi_create_typedarray (Yilong Li) #6271066de6349ad] - node-api: add napi_create_external_sharedarraybuffer (Ben Noordhuis) #62623ce9139107f] - src: escape Windows environment variables in task runner (Antoine du Hamel) #6521702cafc479f] - tools: fix commit linter for semver-major release proposals (Antoine du Hamel) #629936f6cd3768d] - tools: sync mk-ca-bundle.pl with curl (Archkon) #64753bc5753d438] - tools: removeenvinfofrom our workflows (Antoine du Hamel) #64259d68ee9f8a5] - tools: validate version number in release proposal commit message lint (Antoine du Hamel) #6407038ee2e895f] - tools: avoid test/fixtures/wpt/README.md conflicts (Filip Skokan) #63938fdc65e489f] - tools: use different branch for tool updates on staging branches (Antoine du Hamel) #63110e5a6fde002] - tools: update gyp-next to 0.22.1 (Node.js GitHub Bot) #629615fbbad6e82] - url: handle unparsable serialized URLs in setters (Matteo Collina) #64651ed019e4854] - util: preserve function names without source map names (Hiroki Osame) #65108