Hello community, here is the log from the commit of package nodejs10 for openSUSE:Leap:15.2 checked in at 2020-02-29 17:15:25 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Leap:15.2/nodejs10 (Old) and /work/SRC/openSUSE:Leap:15.2/.nodejs10.new.26092 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "nodejs10" Sat Feb 29 17:15:25 2020 rev:10 rq:779883 version:10.19.0 Changes: -------- --- /work/SRC/openSUSE:Leap:15.2/nodejs10/nodejs10.changes 2020-01-17 12:05:16.740605458 +0100 +++ /work/SRC/openSUSE:Leap:15.2/.nodejs10.new.26092/nodejs10.changes 2020-02-29 17:15:34.292934574 +0100 @@ -1,0 +2,25 @@ +Fri Feb 7 13:05:56 UTC 2020 - Adam Majer <[email protected]> + +- New upstream LTS version 10.19.0: + * fixes a remotely triggerable assertion on a TLS server via a + crafted certificate string (CVE-2019-15604, bsc#1163104) + * fixes an HTTP request smuggling vulnerability via malformed + Transfer-Encoding header (CVE-2019-15605, bsc#1163102) + * trim HTTP header values of optional white space + (CVE-2019-15606, bsc#1163103) + * enabled stricter HTTP header parsing by default. + +------------------------------------------------------------------- +Fri Jan 10 15:01:47 UTC 2020 - Adam Majer <[email protected]> + +- New upstream LTS version 10.18.1: + * http2: fix session memory accounting after pausing + * n-api: correct bug in napi_get_last_error + * tools: update tzdata to 2019c + +------------------------------------------------------------------- +Tue Jan 7 13:12:10 UTC 2020 - Guillaume GARDET <[email protected]> + +- Really disable LTO when required (nodejs < 12) + +------------------------------------------------------------------- Old: ---- node-v10.18.0.tar.xz New: ---- node-v10.19.0.tar.xz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ nodejs10.spec ++++++ --- /var/tmp/diff_new_pack.u551ii/_old 2020-02-29 17:15:36.512939150 +0100 +++ /var/tmp/diff_new_pack.u551ii/_new 2020-02-29 17:15:36.516939158 +0100 @@ -1,7 +1,7 @@ # # spec file for package nodejs10 # -# Copyright (c) 2019 SUSE LINUX GmbH, Nuernberg, Germany. +# Copyright (c) 2020 SUSE LLC # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -26,7 +26,7 @@ ########################################################### Name: nodejs10 -Version: 10.18.0 +Version: 10.19.0 Release: 0 %define node_version_number 10 @@ -42,7 +42,16 @@ %endif %bcond_with valgrind_tests + +%if %{node_version_number} >= 12 %bcond_without nodejs_lto +%else +%bcond_with nodejs_lto +%endif + +%if !0%{?with nodejs_lto} +%define _lto_cflags %{nil} +%endif %if 0%{?suse_version} == 1110 %define _libexecdir %{_exec_prefix}/lib @@ -319,6 +328,12 @@ %setup -q -n node-%{version} %endif +%if %{node_version_number} == 6 +# Update NPM +rm -r deps/npm +tar Jxvf %{SOURCE10} +%endif + %if %{node_version_number} >= 10 tar Jxvf %{SOURCE11} %endif # node_version_number @@ -376,6 +391,7 @@ # script, so we'll do it thus: export CFLAGS="%{optflags}" export CXXFLAGS="%{optflags} -Wno-class-memaccess -Wno-error=return-type" +export LDFLAGS="%{?build_ldflags}" %if 0%{?cc_exec:1} export CC=%{?cc_exec} @@ -387,7 +403,7 @@ ./configure \ --prefix=%{_prefix} \ -%if 0%{?with nodejs_lto} && %{node_version_number} >= 12 +%if 0%{?with nodejs_lto} --enable-lto \ %endif %if ! 0%{with intree_openssl} ++++++ SHASUMS256.txt ++++++ --- /var/tmp/diff_new_pack.u551ii/_old 2020-02-29 17:15:36.544939215 +0100 +++ /var/tmp/diff_new_pack.u551ii/_new 2020-02-29 17:15:36.544939215 +0100 @@ -1,36 +1,36 @@ -1e8604a930d732eef94362c8e5b204cb7272bbd14171582043ee8436caeb7fd4 node-v10.18.0-aix-ppc64.tar.gz -a7af53e3363e8ab654b97387bc7cf352dddb324562404c1d35fe10cba3f27e0f node-v10.18.0-darwin-x64.tar.gz -5bb643fce1024aa6fc2031e6812f82548f0ba9107d5483ef1f7d863300ff9525 node-v10.18.0-darwin-x64.tar.xz -ac81511946bb3f7d41ef0ca010f234a221393242d87c77543e58f59ce9b355e0 node-v10.18.0-headers.tar.gz -af790b0f5281550fef68453ad89d918a51060798f248617dc7a637f9291b857d node-v10.18.0-headers.tar.xz -3f9d6c5e7f5781518fb46e9f86081c03e97fb052ff397345be1acc658997174a node-v10.18.0-linux-arm64.tar.gz -b2b34dd43ea3979890663afa270e09e09c219f046e39e8e439eeda2821cc9643 node-v10.18.0-linux-arm64.tar.xz -42433a115710e7b3b62a7b8fe0a9918742e5c50c9100dc38909bcd7b33eb4f58 node-v10.18.0-linux-armv6l.tar.gz -7acfdae8ed545c0b24f6d9de5053faf02dff5c7375f6132a4f629b3527657bc2 node-v10.18.0-linux-armv6l.tar.xz -4af4cde33af3d756e10a1aaa74054d75116840617911baa48ee0c9c44af0933c node-v10.18.0-linux-armv7l.tar.gz -668f94a5c71d95bd6a3bb6c232de604896de146d896fa9e8fae988e53cd8c1fe node-v10.18.0-linux-armv7l.tar.xz -b688c204140e2feac15d445262c8e9aff2234c8caddcfa0cf31c744f61f8c106 node-v10.18.0-linux-ppc64le.tar.gz -6e65a87c00efce2824c694caa5e0da44751a4fff8a7c226534cbee4445c84720 node-v10.18.0-linux-ppc64le.tar.xz -d2a80abd7cca59dac6bf0cd856f885571646e6b1ea0157e5f057ac852657d72b node-v10.18.0-linux-s390x.tar.gz -4a66ff1212c64645971497c76df6a359bdb041095284a5b46044d663a9a31e68 node-v10.18.0-linux-s390x.tar.xz -78a46d1e1f6db68c0732981fc9a1fe8583eabb4e232f1ed742f7dedc5bed3ddd node-v10.18.0-linux-x64.tar.gz -eac160acfc2c5b6fca021baa9943341fea50859f19c7ccbd56669b1fe04e691e node-v10.18.0-linux-x64.tar.xz -dc7841a447d4aca4754941532667f30e920123d35f74d1b5aec2be5a15794e94 node-v10.18.0.pkg -3ef868fa55234d1b1cff520cfa83207e5343c88fbf44ac2499a173dae74aa0af node-v10.18.0-sunos-x64.tar.gz -e8a956bf121057890aca07287ed8dcfa618fc235628367bcae0c214ba12a4550 node-v10.18.0-sunos-x64.tar.xz -f9c8785c5d5ba0e5412dada04a89ab3fe32531423c47232217aad79757a769e7 node-v10.18.0.tar.gz -0b2662ab849713dea708d3f74fe5e63fe2d0e869d1dc06b9e9f178ed1c66fede node-v10.18.0.tar.xz -e87d68365264c4136d618fe4f36c44a2655f2e2c173c0fd9162fc967d6daa9c8 node-v10.18.0-win-x64.7z -56afcc9c191dfc99017725be92ac1331e23afb1930913446eb91852cb02a8687 node-v10.18.0-win-x64.zip -4025560aeea1366e5b867e3a68a191bab27362a0f04435f2e4816e9270096fac node-v10.18.0-win-x86.7z -fdbb1ffb5bbf2b355b82f9df7e34e4e9f617ec5bc8120b6ba3b319025cc492af node-v10.18.0-win-x86.zip -22c58636bef8c7f6f6dd37dba969c60357bbf8f2962bc05a64c2c1c99dbbf0bd node-v10.18.0-x64.msi -b5d0b674c313b9f2175a3270770bcddd8cc708fbccb8c650f964338909e1ccba node-v10.18.0-x86.msi -d323958727d8f64a5f8642e1c5bc5e85fc4e1075295f3ff580c65bd2481b3251 win-x64/node.exe -18da4bd0b611038dac2fb4b6f18e7b35fa2e30857017fc36e5053e7daa8304d5 win-x64/node.lib -ff54905654abd6f71a1d5f53ceb810bc745a6ea116fff78d2ec51ae380f8978b win-x64/node_pdb.7z -845e243819c0bb590705d294fe9049393e99c3106f2a74840e7bc200c29f5f18 win-x64/node_pdb.zip -b148d60470a36dbc61ff8a1fa6c5add9987331b5e8663339786ccdc8281394bf win-x86/node.exe -fea7d0c5a94fc834a78b44b7da206f0e60ef11dd20d84dc0d49d57ee77e20e16 win-x86/node.lib -3fe0e2974f2e189d5accde8e8dcbdbe6ff4ec0d56f070871a2fdf07dcc30c10c win-x86/node_pdb.7z -6005a4eec09fbaef9e77620e2e4b1dd41eccad9278ba97ab33aa7f622c6bb626 win-x86/node_pdb.zip +9040615d614cf4039f4abbd62c799877c3c2efd517e4100d6f13064d368a25a0 node-v10.19.0-aix-ppc64.tar.gz +b16328570651be44213a2303c1f9515fc506e0a96a273806f71ed000e3ca3cb3 node-v10.19.0-darwin-x64.tar.gz +91725d2ed64e4ccd265259e3e29a0e64a4d26d9d1cd9ba390e0cdec13ea7b02f node-v10.19.0-darwin-x64.tar.xz +e664f44dae563abdf9fa1eda0ce404dcc2109eb4d3cb3d5305516dca29f4c3b5 node-v10.19.0-headers.tar.gz +82a1796cc87ce66db92cdaa0e54f67c1e0c130ec4549a9591b9ff0edff618d10 node-v10.19.0-headers.tar.xz +3510172797b63bb6a7247f62a241bdfcf51fef8b1134eb7d3a27973e2008e482 node-v10.19.0-linux-arm64.tar.gz +77bdbf859fc38e6e860efd479b0a7b7b6bd3e7cb05337e5cc5638251eb5d3a59 node-v10.19.0-linux-arm64.tar.xz +96fa937b8d9a8a4e3c606b33e2d71a971f2069dc3fe6a9a038e7fa74f9444568 node-v10.19.0-linux-armv6l.tar.gz +6f650dc7610d7fee1cb6b5bd7339e94858d8d10ab324e17afc4d551008b36f0a node-v10.19.0-linux-armv6l.tar.xz +838a92c63c0bf7d5bb63fbd62b5902e1281ea4bcccbd2de65a8d57edd9b003a1 node-v10.19.0-linux-armv7l.tar.gz +7eeddc7815885f665ecbfe2cf8ae2e71fab601eefece229673126ef8da2965f5 node-v10.19.0-linux-armv7l.tar.xz +65f9cf15490b33b45dff08e984a0786cf82dba7e7e9bbd74a2cffb63506061d5 node-v10.19.0-linux-ppc64le.tar.gz +6a0701f1b03321fb5789c0d6d6ccd5b11579001ad56635354b89fc423b080de0 node-v10.19.0-linux-ppc64le.tar.xz +273e264ee6338a7a520dd739620cb3b5388c86f522a77a1bfff011c55a3a2984 node-v10.19.0-linux-s390x.tar.gz +014c3fac92b0e3546a4d3de3b05bb00f3d6839f529455419cccc554f4c40409e node-v10.19.0-linux-s390x.tar.xz +36d90bc58f0418f31dceda5b18eb260019fcc91e59b0820ffa66700772a8804b node-v10.19.0-linux-x64.tar.gz +34127c7c6b1ba02d6d4dc3a926f38a5fb88bb37fc7f051349005ce331c7a53c6 node-v10.19.0-linux-x64.tar.xz +60eeec991f02e5564d4047387117c6c1884aa8d247c538dc93c51e134eec467f node-v10.19.0.pkg +eb883a9c32b1352e42dafc503797a088fa881896a933785aff1b2e49643bde1f node-v10.19.0-sunos-x64.tar.gz +015f31e0b2adb742021bd61c0566b5bdbf95e0275200d609d9f64944779a4ae7 node-v10.19.0-sunos-x64.tar.xz +db85b9992f1ec66629731d82f690987883dd2989abb4cc136eb65dd720b1bda8 node-v10.19.0.tar.gz +622721bc3e6b65faf7eb6a22bfb6e3e31817e42212aa6bf5a7991ea7d9b6f169 node-v10.19.0.tar.xz +46bdca8ce90ac091590c3473ed9ac9d7e0ae2010696ffb93474c272f4db218ba node-v10.19.0-win-x64.7z +210efd45a7f79cf4c350d8f575f990becdd3833cd922796a4c83b27996f5679e node-v10.19.0-win-x64.zip +8e90b780567178244c0716af43604f3ac4475e8cf21246f9c63386acddf7f841 node-v10.19.0-win-x86.7z +afd176d4f022b6a5dbd4a908d42c6d85d4f739c040f65430ab3bf60b8f3b9a96 node-v10.19.0-win-x86.zip +6151538702d4bd106b66d28ce606f9faa2a8fc8baa50762bea0baec564b5e79e node-v10.19.0-x64.msi +eae8dc6511bd467729fef043167a18ca0843c9d1bab17c31a20b197b44d06251 node-v10.19.0-x86.msi +00047df9589b6a860886d653ed9f817852615211a53b9a2563ff3c56a5090fbf win-x64/node.exe +bfc277d24ebc27c87642b9f8fd2b4a312feaadf57a4a27e81734bcb49752163d win-x64/node.lib +3782acd379b59bca0009debdaa1bea3b28772518d7134c56279485c0a076d207 win-x64/node_pdb.7z +6de35811191c919c09cc11192a151ac0ecd76e3f5ec7f5f3f44d2a7d5feb177e win-x64/node_pdb.zip +5480ed6bb4c83a4284737ffeb4bfe27b5d342f182f2a52939bf0eee8d9c4fac4 win-x86/node.exe +3484dacb6a6aa89ec532eb9150e0a45a6c55453814cc2f32660504f120c7a42a win-x86/node.lib +a1953bc23236083e508c9e42672c457c3a21dd5a97addad7729481a965696c69 win-x86/node_pdb.7z +12c7d6b8a6c138dd36063c939867ef98713b16ad89d277f319ffdc9ec3932f6d win-x86/node_pdb.zip ++++++ SHASUMS256.txt.sig ++++++ Binary files /var/tmp/diff_new_pack.u551ii/_old and /var/tmp/diff_new_pack.u551ii/_new differ ++++++ node-v10.18.0.tar.xz -> node-v10.19.0.tar.xz ++++++ /work/SRC/openSUSE:Leap:15.2/nodejs10/node-v10.18.0.tar.xz /work/SRC/openSUSE:Leap:15.2/.nodejs10.new.26092/node-v10.19.0.tar.xz differ: char 26, line 1
