Skip to content

chore(deps): update node.js to v22 - #137

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-22-node.js
Open

chore(deps): update node.js to v22#137
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-22-node.js

Conversation

@renovate

@renovate renovate Bot commented Aug 2, 2025

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change OpenSSF
@types/node (source) devDependencies major <=18.11<=22.23 OpenSSF Scorecard

Release Notes

nodejs/node (@​types/node)

v22.23.2: 2026-07-29, Version 22.23.2 'Jod' (LTS), @​marco-ippolito

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High
  • (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
  • (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
  • (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
  • (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
  • (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
  • (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
  • (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
  • (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
  • (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
  • deps: update llhttp to 9.4.3 (Paolo Insogna)
  • deps: update undici to 6.28.0 (Node.js GitHub Bot)
Commits

v22.23.1: 2026-06-23, Version 22.23.1 'Jod' (LTS), @​RafaelGSS

Compare Source

This release includes a fix for an unexpected behavior introduced
by the recent security release (22.23.0).

Commits

v22.23.0: 2026-06-18, Version 22.23.0 'Jod' (LTS), @​aduh95

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High
  • (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High
  • (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 – Medium
  • (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium
  • (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium
  • (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium
  • (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium
  • (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium
  • (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low
  • (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low
  • (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low
Commits

v22.22.3: 2026-05-13, Version 22.22.3 'Jod' (LTS), @​marco-ippolito

Compare Source

Commits

v22.22.2

Compare Source

v22.22.1: 2026-03-05, Version 22.22.1 'Jod' (LTS)

Compare Source

Notable Changes
Commits

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between day 24 and 31 of the month, only in October (* * 24-31 10 *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/major-22-node.js branch 21 times, most recently from b504cc4 to db5ab6f Compare August 7, 2025 12:45
@renovate
renovate Bot force-pushed the renovate/major-22-node.js branch 7 times, most recently from 3704d24 to fc9ec6b Compare August 11, 2025 15:04
@renovate
renovate Bot force-pushed the renovate/major-22-node.js branch 2 times, most recently from e21eb8e to b34e238 Compare October 21, 2025 00:38
@renovate
renovate Bot force-pushed the renovate/major-22-node.js branch 6 times, most recently from 6bde14f to 2aab30d Compare November 28, 2025 14:43
@renovate
renovate Bot force-pushed the renovate/major-22-node.js branch from 2aab30d to b464c65 Compare December 3, 2025 17:34
@renovate
renovate Bot force-pushed the renovate/major-22-node.js branch 2 times, most recently from 8385cc7 to 81282da Compare January 18, 2026 05:03
@renovate
renovate Bot force-pushed the renovate/major-22-node.js branch 2 times, most recently from e03bfcc to 5946890 Compare January 28, 2026 22:37
@renovate
renovate Bot force-pushed the renovate/major-22-node.js branch 7 times, most recently from 1f4c7d9 to 3ce718d Compare March 21, 2026 15:58
@renovate
renovate Bot force-pushed the renovate/major-22-node.js branch 4 times, most recently from cea6c7b to 32bfc87 Compare April 29, 2026 16:28
@renovate
renovate Bot force-pushed the renovate/major-22-node.js branch 5 times, most recently from 85f91db to 242f4d0 Compare May 20, 2026 22:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant