Описание
ELSA-2026-7896: nodejs:20 security update (IMPORTANT)
nodejs [1:20.20.2-1]
- Update to version 20.20.2 Patch nghttp2 to version 1.68.1 and disable tests which would fail due to this change. Resolves: RHEL-164336 Fixes: CVE-2026-27135 CVE-2026-27904 CVE-2026-26996 CVE-2026-25547 CVE-2026-21710
nodejs-nodemon [3.0.1-1]
- Rebase to 3.0.1
- Resolves: CVE-2022-25883
[2.0.20-2]
- Patch bundled glob-parent
- Resolves: CVE-2021-35065
[2.0.20-1]
- Rebase to 2.0.20 Resolves: CVE-2022-3517
[2.0.15-1]
- Resolves: RHBZ#2005419
- Resolves CVE-2020-28469
- Rebase to newest version
- Change source to npmjs.com
nodejs-packaging [2021.06-6]
- Properly handle @group/package deps in nodejs-symlink-deps Resolves: RHEL-121579
[2021.06-5]
- nodejs.req to properly detect bundled deps
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
Module nodejs:20 is enabled
nodejs
20.20.2-1.module+el9.7.0+90874+6d84790f
nodejs-devel
20.20.2-1.module+el9.7.0+90874+6d84790f
nodejs-docs
20.20.2-1.module+el9.7.0+90874+6d84790f
nodejs-full-i18n
20.20.2-1.module+el9.7.0+90874+6d84790f
nodejs-nodemon
3.0.1-1.module+el9.7.0+90874+6d84790f
nodejs-packaging
2021.06-6.module+el9.7.0+90874+6d84790f
nodejs-packaging-bundler
2021.06-6.module+el9.7.0+90874+6d84790f
npm
10.8.2-1.20.20.2.1.module+el9.7.0+90874+6d84790f
Oracle Linux x86_64
Module nodejs:20 is enabled
nodejs
20.20.2-1.module+el9.7.0+90874+6d84790f
nodejs-devel
20.20.2-1.module+el9.7.0+90874+6d84790f
nodejs-docs
20.20.2-1.module+el9.7.0+90874+6d84790f
nodejs-full-i18n
20.20.2-1.module+el9.7.0+90874+6d84790f
nodejs-nodemon
3.0.1-1.module+el9.7.0+90874+6d84790f
nodejs-packaging
2021.06-6.module+el9.7.0+90874+6d84790f
nodejs-packaging-bundler
2021.06-6.module+el9.7.0+90874+6d84790f
npm
10.8.2-1.20.20.2.1.module+el9.7.0+90874+6d84790f