Skip to content

upgrade(deps): update Node.js to 22.23 - #398

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/node-22.x
Open

upgrade(deps): update Node.js to 22.23#398
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/node-22.x

Conversation

@renovate

@renovate renovate Bot commented Oct 2, 2025

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Update Change
node (source) minor 22.1122.23

Release Notes

nodejs/node (node)

v22.23.2: 2026-07-29, Version 22.23.2 'Jod' (LTS), @​marco-ippolito

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High
  • (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
  • (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
  • (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
  • (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
  • (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
  • (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
  • (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
  • (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
  • (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
  • deps: update llhttp to 9.4.3 (Paolo Insogna)
  • deps: update undici to 6.28.0 (Node.js GitHub Bot)
Commits

v22.23.1: 2026-06-23, Version 22.23.1 'Jod' (LTS), @​RafaelGSS

Compare Source

This release includes a fix for an unexpected behavior introduced
by the recent security release (22.23.0).

Commits

v22.23.0: 2026-06-18, Version 22.23.0 'Jod' (LTS), @​aduh95

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High
  • (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High
  • (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 – Medium
  • (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium
  • (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium
  • (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium
  • (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium
  • (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium
  • (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low
  • (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low
  • (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low
Commits

v22.22.3: 2026-05-13, Version 22.22.3 'Jod' (LTS), @​marco-ippolito

Compare Source

Commits

v22.22.2

Compare Source

v22.22.1: 2026-03-05, Version 22.22.1 'Jod' (LTS)

Compare Source

Notable Changes
Commits

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Europe/Paris)

  • Branch creation
    • "before 8am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Oct 2, 2025
@vercel

vercel Bot commented Oct 2, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
gautier Ignored Ignored Preview Jul 29, 2026 6:28pm

@renovate
renovate Bot force-pushed the renovate/node-22.x branch from 121d561 to b56c217 Compare October 21, 2025 00:51
@renovate renovate Bot changed the title upgrade(deps): update Node.js to 22.20 upgrade(deps): update Node.js to 22.21 Oct 21, 2025
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from b56c217 to f3b759e Compare October 28, 2025 21:53
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from f3b759e to e381390 Compare January 13, 2026 15:05
@renovate renovate Bot changed the title upgrade(deps): update Node.js to 22.21 upgrade(deps): update Node.js to 22.22 Jan 13, 2026
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from e381390 to ba88c30 Compare February 2, 2026 15:32
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from ba88c30 to dd9959d Compare March 24, 2026 21:52
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from dd9959d to 2e08f47 Compare May 13, 2026 20:44
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from 2e08f47 to ba35d3f Compare June 22, 2026 00:04
@renovate renovate Bot changed the title upgrade(deps): update Node.js to 22.22 upgrade(deps): update Node.js to 22.23 Jun 22, 2026
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from ba35d3f to 7a4c4ae Compare June 23, 2026 19:02
@renovate
renovate Bot force-pushed the renovate/node-22.x branch from 7a4c4ae to dc8ca0c Compare July 29, 2026 18:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants