node: bump to v20.12.2
authorHirokazu MORIKAWA <morikw2@gmail.com>
Wed, 24 Apr 2024 01:38:27 +0000 (10:38 +0900)
committerTianling Shen <cnsztl@gmail.com>
Wed, 24 Apr 2024 09:53:22 +0000 (17:53 +0800)
This is a security release.

Notable Changes
* CVE-2024-27980 - Command injection via args parameter of child_process.spawn without shell option enabled on Windows

Signed-off-by: Hirokazu MORIKAWA <morikw2@gmail.com>
lang/node/Makefile

index 369f3bbe86ff10c06e6e25f4f7b63f71e24101d8..2f091a62fa99a4486469a2dd3c5e1f07584643ad 100644 (file)
@@ -8,12 +8,12 @@
 include $(TOPDIR)/rules.mk
 
 PKG_NAME:=node
-PKG_VERSION:=v20.12.1
+PKG_VERSION:=v20.12.2
 PKG_RELEASE:=1
 
 PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.gz
 PKG_SOURCE_URL:=https://nodejs.org/dist/$(PKG_VERSION)
-PKG_HASH:=b9bef0314e12773ef004368ee56a2db509a948d4170b9efb07441bac1f1407a0
+PKG_HASH:=bc57ee721a12cc8be55bb90b4a9a2f598aed5581d5199ec3bd171a4781bfecda
 
 PKG_MAINTAINER:=Hirokazu MORIKAWA <morikw2@gmail.com>, Adrian Panella <ianchi74@outlook.com>
 PKG_LICENSE:=MIT