Skip to content

⬆️ Upgrade Node.js to v22 - #1186

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/node-22.x
Open

⬆️ Upgrade Node.js to v22#1186
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/node-22.x

Conversation

@renovate

@renovate renovate Bot commented Mar 3, 2025

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Update Change
node (source) major 20.12.222.23.2

Release Notes

nodejs/node (node)

v22.23.2: 2026-07-29, Version 22.23.2 'Jod' (LTS), @​marco-ippolito

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High
  • (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
  • (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
  • (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
  • (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
  • (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
  • (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
  • (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
  • (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
  • (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
  • deps: update llhttp to 9.4.3 (Paolo Insogna)
  • deps: update undici to 6.28.0 (Node.js GitHub Bot)
Commits

v22.23.1: 2026-06-23, Version 22.23.1 'Jod' (LTS), @​RafaelGSS

Compare Source

This release includes a fix for an unexpected behavior introduced
by the recent security release (22.23.0).

Commits

v22.23.0: 2026-06-18, Version 22.23.0 'Jod' (LTS), @​aduh95

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High
  • (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High
  • (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 – Medium
  • (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium
  • (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium
  • (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium
  • (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium
  • (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium
  • (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low
  • (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low
  • (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low
Commits

v22.22.3: 2026-05-13, Version 22.22.3 'Jod' (LTS), @​marco-ippolito

Compare Source

Commits

v22.22.2

Compare Source

v22.22.1: 2026-03-05, Version 22.22.1 'Jod' (LTS)

Compare Source

Notable Changes
Commits

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Europe/Paris)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/node-22.x branch from 7d38602 to 8b2b95f Compare April 16, 2025 01:06
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from 8b2b95f to eb57910 Compare April 29, 2025 01:03
@renovate
renovate Bot force-pushed the renovate/node-22.x branch 2 times, most recently from e4adf21 to 6251fa5 Compare May 27, 2025 01:22
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from 6251fa5 to f4e3610 Compare July 2, 2025 00:51
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from f4e3610 to d9fb410 Compare July 22, 2025 00:29
@renovate
renovate Bot force-pushed the renovate/node-22.x branch 3 times, most recently from d9719ec to bef0282 Compare August 10, 2025 15:32
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from bef0282 to 10332ab Compare September 4, 2025 00:14
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from 10332ab to b5fda6f Compare October 1, 2025 03:49
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from b5fda6f to d899c6f Compare October 27, 2025 03:38
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from d899c6f to b027e99 Compare November 4, 2025 03:28
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from b027e99 to 9a73a62 Compare January 19, 2026 04:00
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from 9a73a62 to de6b950 Compare March 11, 2026 01:54
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from de6b950 to 5139441 Compare March 31, 2026 02:46
@renovate renovate Bot removed the dependencies label May 13, 2026
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from 5139441 to 414857a Compare May 20, 2026 03:06
@renovate
renovate Bot force-pushed the renovate/node-22.x branch 2 times, most recently from 6f41a7b to 7f44abe Compare June 29, 2026 05:34
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from 7f44abe to 4570554 Compare August 4, 2026 03:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants