From patchwork Sun Jul 5 17:43:23 2015 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Yann E. MORIN" X-Patchwork-Id: 491342 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Received: from silver.osuosl.org (smtp3.osuosl.org [140.211.166.136]) by ozlabs.org (Postfix) with ESMTP id 6320C140D5F for ; Mon, 6 Jul 2015 03:43:46 +1000 (AEST) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b=RFznpI0v; dkim-atps=neutral Received: from localhost (localhost [127.0.0.1]) by silver.osuosl.org (Postfix) with ESMTP id 7A3EB32FD4; Sun, 5 Jul 2015 17:43:45 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from silver.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jTW7DUJwGULa; Sun, 5 Jul 2015 17:43:37 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by silver.osuosl.org (Postfix) with ESMTP id 2A44C32FD9; Sun, 5 Jul 2015 17:43:35 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from hemlock.osuosl.org (smtp2.osuosl.org [140.211.166.133]) by ash.osuosl.org (Postfix) with ESMTP id 12CC91BF863 for ; Sun, 5 Jul 2015 17:43:32 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by hemlock.osuosl.org (Postfix) with ESMTP id 101149507C for ; Sun, 5 Jul 2015 17:43:32 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from hemlock.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FZiwQkczGgxi for ; Sun, 5 Jul 2015 17:43:31 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.7.6 Received: from mail-wi0-f174.google.com (mail-wi0-f174.google.com [209.85.212.174]) by hemlock.osuosl.org (Postfix) with ESMTPS id 178379507B for ; Sun, 5 Jul 2015 17:43:31 +0000 (UTC) Received: by widjy10 with SMTP id jy10so143359784wid.1 for ; Sun, 05 Jul 2015 10:43:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=sender:from:to:cc:subject:date:message-id:in-reply-to:references; bh=/NfaZwLVacO8GW3aDiKf9D5h4sGasnLxbRvy3Dsz/iM=; b=RFznpI0vhad1fUQ9Yy1zTopG3CN7heRuBwiq+iVP2TK4lRI2QwY3/ju9dYSKpfkG/C 09rW1cplnByC18GzIG9Odvj9ak0qkYN8xgvSKtDKgI6XgfibHFbn8ZSJCGqi+jt0bjEJ lqxMiUujhruzL8WVm9i3ttQDmc8j74yc5CqU5R8QaCnv13yZulZmk+pRs0Vzerr+isRx Lp+ZIDPjgqay4RA4D3wvPYTqO6VUqWHxfsmGpFC0XAN3TV+j0HA6Sw/zPz96o307z5E4 ApnNbPnGZnWaxxNWaI7YAHAEMxzl0jcZyzbWQC8yzcvRxO/6lS2phoOVOZxD0OflVxpR 8FsQ== X-Received: by 10.194.175.65 with SMTP id by1mr94798858wjc.152.1436118209726; Sun, 05 Jul 2015 10:43:29 -0700 (PDT) Received: from gourin.bzh.lan (ns304657.ip-46-105-103.eu. [46.105.103.66]) by mx.google.com with ESMTPSA id q4sm23740024wju.14.2015.07.05.10.43.27 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Sun, 05 Jul 2015 10:43:28 -0700 (PDT) From: "Yann E. MORIN" To: buildroot@buildroot.org Date: Sun, 5 Jul 2015 19:43:23 +0200 Message-Id: <7521a4379f6888a5f5269441914ecd71fc5b1560.1436118128.git.yann.morin.1998@free.fr> X-Mailer: git-send-email 1.9.1 In-Reply-To: References: Cc: Thomas Petazzoni , "Yann E. MORIN" Subject: [Buildroot] [PATCH 2/2] package/nodejs: security bump X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" Critical security flaw: https://medium.com/@iojs/important-security-upgrades-for-node-js-and-io-js-8ac14ece5852 Fixes #8201. Reported-by: Chris Becker Signed-off-by: "Yann E. MORIN" Cc: Thomas Petazzoni --- .../0001-Remove-dependency-on-Python-bz2-module.patch | 0 .../{0.12.5 => 0.12.6}/0002-gyp-force-link-command-to-use-CXX.patch | 0 .../0003-Use-a-python-variable-instead-of-hardcoding-Python.patch | 0 .../0004-fix-build-error-without-OpenSSL-support.patch | 0 package/nodejs/Config.in | 4 ++-- package/nodejs/nodejs.hash | 4 ++-- 6 files changed, 4 insertions(+), 4 deletions(-) rename package/nodejs/{0.12.5 => 0.12.6}/0001-Remove-dependency-on-Python-bz2-module.patch (100%) rename package/nodejs/{0.12.5 => 0.12.6}/0002-gyp-force-link-command-to-use-CXX.patch (100%) rename package/nodejs/{0.12.5 => 0.12.6}/0003-Use-a-python-variable-instead-of-hardcoding-Python.patch (100%) rename package/nodejs/{0.12.5 => 0.12.6}/0004-fix-build-error-without-OpenSSL-support.patch (100%) diff --git a/package/nodejs/0.12.5/0001-Remove-dependency-on-Python-bz2-module.patch b/package/nodejs/0.12.6/0001-Remove-dependency-on-Python-bz2-module.patch similarity index 100% rename from package/nodejs/0.12.5/0001-Remove-dependency-on-Python-bz2-module.patch rename to package/nodejs/0.12.6/0001-Remove-dependency-on-Python-bz2-module.patch diff --git a/package/nodejs/0.12.5/0002-gyp-force-link-command-to-use-CXX.patch b/package/nodejs/0.12.6/0002-gyp-force-link-command-to-use-CXX.patch similarity index 100% rename from package/nodejs/0.12.5/0002-gyp-force-link-command-to-use-CXX.patch rename to package/nodejs/0.12.6/0002-gyp-force-link-command-to-use-CXX.patch diff --git a/package/nodejs/0.12.5/0003-Use-a-python-variable-instead-of-hardcoding-Python.patch b/package/nodejs/0.12.6/0003-Use-a-python-variable-instead-of-hardcoding-Python.patch similarity index 100% rename from package/nodejs/0.12.5/0003-Use-a-python-variable-instead-of-hardcoding-Python.patch rename to package/nodejs/0.12.6/0003-Use-a-python-variable-instead-of-hardcoding-Python.patch diff --git a/package/nodejs/0.12.5/0004-fix-build-error-without-OpenSSL-support.patch b/package/nodejs/0.12.6/0004-fix-build-error-without-OpenSSL-support.patch similarity index 100% rename from package/nodejs/0.12.5/0004-fix-build-error-without-OpenSSL-support.patch rename to package/nodejs/0.12.6/0004-fix-build-error-without-OpenSSL-support.patch diff --git a/package/nodejs/Config.in b/package/nodejs/Config.in index 5b871ea..ff7f56c 100644 --- a/package/nodejs/Config.in +++ b/package/nodejs/Config.in @@ -34,7 +34,7 @@ config BR2_BR2_PACKAGE_NODEJS_0_10_X # V8 included with v0.12.5 requires at least ARMv6 config BR2_BR2_PACKAGE_NODEJS_0_12_X - bool "v0.12.5" + bool "v0.12.6" depends on !BR2_ARM_CPU_ARMV5 endchoice @@ -42,7 +42,7 @@ endchoice config BR2_PACKAGE_NODEJS_VERSION_STRING string default "0.10.39" if BR2_BR2_PACKAGE_NODEJS_0_10_X - default "0.12.5" if BR2_BR2_PACKAGE_NODEJS_0_12_X + default "0.12.6" if BR2_BR2_PACKAGE_NODEJS_0_12_X menu "Module Selection" diff --git a/package/nodejs/nodejs.hash b/package/nodejs/nodejs.hash index 816d602..f3b2831 100644 --- a/package/nodejs/nodejs.hash +++ b/package/nodejs/nodejs.hash @@ -1,5 +1,5 @@ # From upstream URL: http://nodejs.org/dist/v0.10.39/SHASUMS256.txt sha256 68f8d8f9515c4e77e2a06034b742e19e9848c1fee5bcadedc1d68f3e4302df37 node-v0.10.39.tar.gz -# From upstream URL: http://nodejs.org/dist/v0.12.5/SHASUMS256.txt -sha256 4bc1e25f4c62ac65324d3cf4aa9de2d801cd708757c3567b6ad2ced7df30cdd2 node-v0.12.5.tar.gz +# From upstream URL: http://nodejs.org/dist/v0.12.6/SHASUMS256.txt +sha256 7a3b5ac351973a9dee8edbf0684bc8d0dea44b231e42274ffb008141ffa19ad2 node-v0.12.6.tar.gz