Re: Node.js security advisory

"Rainer Fiebig" ([email protected] via blfs-dev Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.devel
Message-ID <[email protected]>
Am 23.01.25 um 21:00 schrieb Joe Locash ([email protected] via blfs-dev
Mailing List):
> 
> On 1/23/25 12:20 AM, "Zeckma" ([email protected] via blfs-dev
> Mailing List) wrote:
>> On 1/22/25 17:51, "Zeckma" ([email protected] via blfs-dev Mailing
>> List) wrote:
>>> Hmm, I think it might be an issue with system libuv being outdated
>>> and must be updated. Going to do further testing. Current version is
>>> 1.50.0, and I tested the build using 1.49.2. Going to check if 1.50.0
>>> works, and if so, will edit the SA to account for that.
>> Edited SA-12.2-068 to include a note saying to upgrade libuv if it is
>> installed, as the FTBFS issue originates from having an outdated libuv
>> installed on the system. libuv-1.50.0 works fine with Node.js-22.13.1.
> 
> The SA says to update libuv but doesn't state why or to what version.
> The way it's worded you make it seem like libuv also needs to be updated
> because node.js was.
If "Zeckma" doesn't want to edit the SA according to your suggestion,
you should post it on blfs-support.  I let you go first here but if you
don't do it then I will.

Node-v20.18.2 built fine here with libuv-v1.48.0, too.

This is a security issue of "high" priority and fixing it should be made
as easy and simple as possible.  At least for those who do not need to
have the latest and greatest software installed.

Rainer

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-dev
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.