Skip to content

Update dependency node to v22.23.2 - #1

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/node-22.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/node-22.x

Conversation

@renovate

@renovate renovate Bot commented Dec 3, 2025

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Update Change
node (source) minor 22.15.022.23.2

Release Notes

nodejs/node (node)

v22.23.2: 2026-07-29, Version 22.23.2 'Jod' (LTS), @​marco-ippolito

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High
  • (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
  • (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
  • (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
  • (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
  • (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
  • (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
  • (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
  • (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
  • (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
  • deps: update llhttp to 9.4.3 (Paolo Insogna)
  • deps: update undici to 6.28.0 (Node.js GitHub Bot)
Commits

v22.23.1: 2026-06-23, Version 22.23.1 'Jod' (LTS), @​RafaelGSS

Compare Source

This release includes a fix for an unexpected behavior introduced
by the recent security release (22.23.0).

Commits

v22.23.0: 2026-06-18, Version 22.23.0 'Jod' (LTS), @​aduh95

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High
  • (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High
  • (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 – Medium
  • (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium
  • (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium
  • (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium
  • (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium
  • (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium
  • (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low
  • (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low
  • (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low
Commits

v22.22.3: 2026-05-13, Version 22.22.3 'Jod' (LTS), @​marco-ippolito

Compare Source

Commits

v22.22.2

Compare Source

v22.22.1: 2026-03-05, Version 22.22.1 'Jod' (LTS)

Compare Source

Notable Changes
Commits

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/node-22.x branch from fb0ec0f to d2abb9e Compare January 14, 2026 03:44
@renovate renovate Bot changed the title Update dependency node to v22.21.1 Update dependency node to v22.22.0 Jan 14, 2026
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from d2abb9e to d95d363 Compare March 8, 2026 10:03
@renovate renovate Bot changed the title Update dependency node to v22.22.0 Update dependency node to v22.22.1 Mar 8, 2026
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from d95d363 to 8125f58 Compare March 31, 2026 11:56
@renovate renovate Bot changed the title Update dependency node to v22.22.1 Update dependency node to v22.22.2 Mar 31, 2026
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from 8125f58 to d78c440 Compare May 14, 2026 08:14
@renovate renovate Bot changed the title Update dependency node to v22.22.2 Update dependency node to v22.22.3 May 14, 2026
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from d78c440 to 031dc26 Compare June 20, 2026 07:57
@renovate renovate Bot changed the title Update dependency node to v22.22.3 Update dependency node to v22.23.0 Jun 20, 2026
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from 031dc26 to 698ead3 Compare June 24, 2026 08:11
@renovate renovate Bot changed the title Update dependency node to v22.23.0 Update dependency node to v22.23.1 Jun 24, 2026
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from 698ead3 to 90811d1 Compare August 1, 2026 07:41
@renovate renovate Bot changed the title Update dependency node to v22.23.1 Update dependency node to v22.23.2 Aug 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants