| Newsgroups |
gmane.linux.lfs.beyond.devel |
| Message-ID |
<[email protected]> |
On 1/24/25 7:00 AM, Rainer Fiebig ([email protected] via blfs-dev Mailing
List) wrote:
> Am 23.01.25 um 21:00 schrieb Joe Locash ([email protected] via blfs-dev
> Mailing List):
>> On 1/23/25 12:20 AM, "Zeckma" ([email protected] via blfs-dev
>> Mailing List) wrote:
>>> On 1/22/25 17:51, "Zeckma" ([email protected] via blfs-dev Mailing
>>> List) wrote:
>>>> Hmm, I think it might be an issue with system libuv being outdated
>>>> and must be updated. Going to do further testing. Current version is
>>>> 1.50.0, and I tested the build using 1.49.2. Going to check if 1.50.0
>>>> works, and if so, will edit the SA to account for that.
>>> Edited SA-12.2-068 to include a note saying to upgrade libuv if it is
>>> installed, as the FTBFS issue originates from having an outdated libuv
>>> installed on the system. libuv-1.50.0 works fine with Node.js-22.13.1.
>> The SA says to update libuv but doesn't state why or to what version.
>> The way it's worded you make it seem like libuv also needs to be updated
>> because node.js was.
> If "Zeckma" doesn't want to edit the SA according to your suggestion,
> you should post it on blfs-support. I let you go first here but if you
> don't do it then I will.
>
> Node-v20.18.2 built fine here with libuv-v1.48.0, too.
>
> This is a security issue of "high" priority and fixing it should be made
> as easy and simple as possible. At least for those who do not need to
> have the latest and greatest software installed.
>
> Rainer
>
Good morning Rainer and Joe,
I will make some tweaks to the security advisory later today. I'll
reformat it to be similar to Spidermonkey, where we note that you need
to update another package - unless you want to stay with the previous
LTS version.
In some ways, Node is just like Python and Ruby, where newer major
versions have breaking changes which can cause some code to be
incompatible. For that reason, it's definitely best to document the
previous LTS in the advisory as an option, especially if a user is using
BLFS for developing applications using Node. Another example of where we
do this is for PostgreSQL, where updating the database between major
versions requires special care that some users will not want to go
through to fix a security issue.
Thank you both for bringing this up, and thank you Zeckma for
determining that it's an issue with system libuv being outdated!
Please check the advisory again in a few hours! Note that I will be
filing a couple of SAs again later as well which you may want to keep an
eye out for, it'll be for abseil-cpp and OpenJDK.
- Doug
--
http://lists.linuxfromscratch.org/sympa/info/blfs-dev
Unsubscribe: See the above information page