Skip to content
This repository has been archived by the owner on Jan 3, 2024. It is now read-only.

patches: bump to Node 12.22.2, 14.17.2 and 16.4.1 #203

Merged
merged 6 commits into from
Jul 2, 2021

Conversation

jesec
Copy link
Contributor

@jesec jesec commented Jun 24, 2021

No description provided.

@jesec
Copy link
Contributor Author

jesec commented Jun 30, 2021

@leerob , @robertsLando :

I decided to wait for the imminent security releases: https://nodejs.org/en/blog/vulnerability/july-2021-security-releases .

As such, this PR is not going to be merged in its current form. Instead, I will update it with the new versions that contain the security patches.

Just a heads up, it is preferable that we can complete the full cycle (update patches -> release pkg-fetch -> release pkg) ASAP when there are security updates.

By the way, I think we probably should deprecate and issue security advisories for older versions of pkg-fetch. Recent versions are probably still OK, but legacy ones (pre-3.0) miss a lot of Node.js security updates (many are critical). IMHO we don't have to match the severity of Node.js, but even a "low" or "moderate" advisory can allow users to notice the issue, and bump the version. What do you think?

@jesec jesec force-pushed the pr/patches-14.17.1-16.4.0 branch from c31db7a to 159bce9 Compare July 1, 2021 17:11
@jesec jesec changed the title patches: bump to Node 14.17.1 and 16.4.0 patches: bump to Node 12.22.2, 14.17.2 and 16.4.1 Jul 1, 2021
@jesec jesec merged commit afea48f into main Jul 2, 2021
@jesec jesec deleted the pr/patches-14.17.1-16.4.0 branch July 2, 2021 05:05
@jesec
Copy link
Contributor Author

jesec commented Jul 2, 2021

@leerob

Please publish 3.2.2 to npm when you have time. 👍

@leerob
Copy link
Member

leerob commented Jul 2, 2021

Done!

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants