Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump node from 20.14.0 to 20.16.0 #874

Merged
merged 1 commit into from
Aug 19, 2024

Conversation

mazi-renovate[bot]
Copy link
Contributor

@mazi-renovate mazi-renovate bot commented Aug 5, 2024

This PR contains the following updates:

Package Type Update Change OpenSSF
node (source) minor 20.14.0 -> 20.16.0 OpenSSF Scorecard
@types/node (source) devDependencies minor 20.14.13 -> 20.16.0 OpenSSF Scorecard

Release Notes

nodejs/node (node)

v20.16.0: 2024-07-24, Version 20.16.0 'Iron' (LTS), @​marco-ippolito

Compare Source

process: add process.getBuiltinModule(id)

process.getBuiltinModule(id) provides a way to load built-in modules
in a globally available function. ES Modules that need to support
other environments can use it to conditionally load a Node.js built-in
when it is run in Node.js, without having to deal with the resolution
error that can be thrown by import in a non-Node.js environment or
having to use dynamic import() which either turns the module into
an asynchronous module, or turns a synchronous API into an asynchronous one.

if (globalThis.process?.getBuiltinModule) {
  // Run in Node.js, use the Node.js fs module.
  const fs = globalThis.process.getBuiltinModule('fs');
  // If `require()` is needed to load user-modules, use createRequire()
  const module = globalThis.process.getBuiltinModule('module');
  const require = module.createRequire(import.meta.url);
  const foo = require('foo');
}

If id specifies a built-in module available in the current Node.js process,
process.getBuiltinModule(id) method returns the corresponding built-in
module. If id does not correspond to any built-in module, undefined
is returned.

process.getBuiltinModule(id) accepts built-in module IDs that are recognized
by module.isBuiltin(id).

The references returned by process.getBuiltinModule(id) always point to
the built-in module corresponding to id even if users modify
require.cache so that require(id) returns something else.

Contributed by Joyee Cheung in #​52762

doc: doc-only deprecate OpenSSL engine-based APIs

OpenSSL 3 deprecated support for custom engines with a recommendation to switch to its new provider model.
The clientCertEngine option for https.request(), tls.createSecureContext(), and tls.createServer(); the privateKeyEngine and privateKeyIdentifier for tls.createSecureContext(); and crypto.setEngine() all depend on this functionality from OpenSSL.

Contributed by Richard Lau in #​53329

inspector: fix disable async hooks on Debugger.setAsyncCallStackDepth

Debugger.setAsyncCallStackDepth was previously calling the enable function by mistake. As a result, when profiling using Chrome DevTools, the async hooks won't be turned off properly after receiving Debugger.setAsyncCallStackDepth with depth 0.

Contributed by Joyee Cheung in #​53473

Other Notable Changes
  • [09e2191432] - (SEMVER-MINOR) buffer: add .bytes() method to Blob (Matthew Aitken) #​53221
  • [394e00f41c] - (SEMVER-MINOR) doc: add context.assert docs (Colin Ihrig) #​53169
  • [a8601efa5e] - (SEMVER-MINOR) doc: improve explanation about built-in modules (Joyee Cheung) #​52762
  • [5e76c258f7] - doc: add StefanStojanovic to collaborators (StefanStojanovic) #​53118
  • [5e694026f1] - doc: add Marco Ippolito to TSC (Rafael Gonzaga) #​53008
  • [f3ba1eb72f] - (SEMVER-MINOR) net: add new net.server.listen tracing channel (Paolo Insogna) #​53136
  • [2bcce3255b] - (SEMVER-MINOR) src,permission: --allow-wasi & prevent WASI exec (Rafael Gonzaga) #​53124
  • [a03a4c7bdd] - (SEMVER-MINOR) test_runner: add context.fullName (Colin Ihrig) #​53169
  • [69b828f5a5] - (SEMVER-MINOR) util: support --no- for argument with boolean type for parseArgs (Zhenwei Jin) #​53107
Commits

v20.15.1: 2024-07-08, Version 20.15.1 'Iron' (LTS), @​RafaelGSS

Compare Source

This is a security release.

Notable Changes
  • CVE-2024-36138 - Bypass incomplete fix of CVE-2024-27980 (High)
  • CVE-2024-22020 - Bypass network import restriction via data URL (Medium)
  • CVE-2024-22018 - fs.lstat bypasses permission model (Low)
  • CVE-2024-36137 - fs.fchown/fchmod bypasses permission model (Low)
  • CVE-2024-37372 - Permission model improperly processes UNC paths (Low)
Commits

v20.15.0: 2024-06-20, Version 20.15.0 'Iron' (LTS), @​marco-ippolito

Compare Source

test_runner: support test plans

It is now possible to count the number of assertions and subtests that are expected to run within a test. If the number of assertions and subtests that run does not match the expected count, the test will fail.

test('top level test', (t) => {
  t.plan(2);
  t.assert.ok('some relevant assertion here');
  t.subtest('subtest', () => {});
});

Contributed by Colin Ihrig in #​52860

inspector: introduce the --inspect-wait flag

This release introduces the --inspect-wait flag, which allows debugger to wait for attachement. This flag is useful when you want to debug the code from the beginning. Unlike --inspect-brk, which breaks on the first line, this flag waits for debugger to be connected and then runs the code as soon as a session is established.

Contributed by Kohei Ueno in #​52734

zlib: expose zlib.crc32()

This release exposes the crc32() function from zlib to user-land.

It computes a 32-bit Cyclic Redundancy Check checksum of data. If
value is specified, it is used as the starting value of the checksum,
otherwise, 0 is used as the starting value.

The CRC algorithm is designed to compute checksums and to detect error
in data transmission. It's not suitable for cryptographic authentication.

const zlib = require('node:zlib');
const { Buffer } = require('node:buffer');

let crc = zlib.crc32('hello');  // 907060870
crc = zlib.crc32('world', crc);  // 4192936109

crc = zlib.crc32(Buffer.from('hello', 'utf16le'));  // 1427272415
crc = zlib.crc32(Buffer.from('world', 'utf16le'), crc);  // 4150509955

Contributed by Joyee Cheung in #​52692

cli: allow running wasm in limited vmem with --disable-wasm-trap-handler

By default, Node.js enables trap-handler-based WebAssembly bound
checks. As a result, V8 does not need to insert inline bound checks
int the code compiled from WebAssembly which may speedup WebAssembly
execution significantly, but this optimization requires allocating
a big virtual memory cage (currently 10GB). If the Node.js process
does not have access to a large enough virtual memory address space
due to system configurations or hardware limitations, users won't
be able to run any WebAssembly that involves allocation in this
virtual memory cage and will see an out-of-memory error.

$ ulimit -v 5000000
$ node -p "new WebAssembly.Memory({ initial: 10, maximum: 100 });"
[eval]:1
new WebAssembly.Memory({ initial: 10, maximum: 100 });
^

RangeError: WebAssembly.Memory(): could not allocate memory
    at [eval]:1:1
    at runScriptInThisContext (node:internal/vm:209:10)
    at node:internal/process/execution:118:14
    at [eval]-wrapper:6:24
    at runScript (node:internal/process/execution:101:62)
    at evalScript (node:internal/process/execution:136:3)
    at node:internal/main/eval_string:49:3

--disable-wasm-trap-handler disables this optimization so that
users can at least run WebAssembly (with a less optimial performance)
when the virtual memory address space available to their Node.js
process is lower than what the V8 WebAssembly memory cage needs.

Contributed by Joyee Cheung in #​52766

Other Notable Changes
Commits

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot. - View logs

Copy link
Contributor

github-actions bot commented Aug 5, 2024

Latest commit: c7b7c92 ( base: cf15ec2 + head: d20cd5d )
Status: ✅  Deploy successful!
Preview URL: https://8bbd8549.github-test-15v.pages.dev
PR Preview URL: https://pull-874-merge.github-test-15v.pages.dev

View workflow logs
View Cloudflare logs

@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from a412ea4 to cc0a2d3 Compare August 5, 2024 15:15
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from cc0a2d3 to a4ca68d Compare August 5, 2024 15:18
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from a4ca68d to d009193 Compare August 5, 2024 20:01
@mazi-renovate mazi-renovate bot changed the title chore(deps-dev): bump @types/node from 20.14.13 to 20.14.14 chore(deps): bump node from 20.14.0 to 20.16.0 Aug 5, 2024
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from d009193 to 1c13c8b Compare August 5, 2024 20:13
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from 1c13c8b to ba9408d Compare August 5, 2024 20:16
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from ba9408d to fcf9716 Compare August 5, 2024 20:50
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from fcf9716 to 9114a8c Compare August 5, 2024 20:55
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from 9114a8c to 180b639 Compare August 6, 2024 16:30
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from 180b639 to 4cffc8c Compare August 6, 2024 16:32
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from 4cffc8c to f950ab1 Compare August 6, 2024 16:54
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from f950ab1 to ea2ba87 Compare August 6, 2024 17:25
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from 55bd159 to caa3e64 Compare August 18, 2024 05:44
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from caa3e64 to afe9e4a Compare August 18, 2024 07:19
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from afe9e4a to 7f8fa53 Compare August 18, 2024 07:26
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from 7f8fa53 to 345c965 Compare August 18, 2024 07:29
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from 345c965 to 3afcee6 Compare August 18, 2024 07:45
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from 3afcee6 to fa4209d Compare August 18, 2024 07:51
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from fa4209d to dc8ff17 Compare August 18, 2024 08:14
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from dc8ff17 to a46f2c6 Compare August 18, 2024 09:03
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from a46f2c6 to 184fc71 Compare August 18, 2024 09:11
@mazi-renovate mazi-renovate bot force-pushed the renovate/node-20.x branch from 184fc71 to 5751458 Compare August 18, 2024 09:33
| datasource   | package     | from     | to       |
| ------------ | ----------- | -------- | -------- |
| node-version | node        | v20.14.0 | v20.16.0 |
| npm          | @types/node | 20.14.13 | 20.16.0  |
@mazi-renovate mazi-renovate bot merged commit feecd61 into main Aug 19, 2024
92 checks passed
@mazi-renovate mazi-renovate bot deleted the renovate/node-20.x branch August 19, 2024 00:28
@mazi-release mazi-release bot mentioned this pull request Aug 19, 2024
@mazi-release mazi-release bot mentioned this pull request Aug 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant