Skip to content

Conversation

djs-intel
Copy link
Contributor

@djs-intel djs-intel commented Aug 5, 2025

@Copilot Copilot AI review requested due to automatic review settings August 5, 2025 18:35
@djs-intel djs-intel requested a review from a team as a code owner August 5, 2025 18:35
Copy link
Contributor

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the Node.js version 24 from 24.4.0 to 24.5.0 to address CVE-2025-27209, which is a security vulnerability requiring the latest Node.js patch.

  • Updates NODE24_VERSION constant from "24.4.0" to "24.5.0"
Comments suppressed due to low confidence (1)

src/Misc/externals.sh:10

  • Node.js version 24.5.0 does not exist. The latest available version in the 24.x series is 24.4.0. Please verify the correct version number for the security patch addressing CVE-2025-27209.
NODE24_VERSION="24.5.0"

@speelbarrow
Copy link

@djs-intel can you bump Node20 to 20.19.4 to address CVE-2025-27210 as well? Alternately, let me know if I should submit a separate PR for that change and I'll happily do so.

@djs-intel djs-intel changed the title Update Node24 Version 24.5.0 Update Node20 and Node24 to latest Aug 6, 2025
@salmanmkc
Copy link
Contributor

thanks for the updates!

@TingluoHuang TingluoHuang force-pushed the djs-runner-nodeupdate branch from addf328 to 7d0618f Compare August 7, 2025 22:36
@TingluoHuang TingluoHuang enabled auto-merge (squash) August 7, 2025 22:36
@TingluoHuang TingluoHuang merged commit 2d7635a into actions:main Aug 7, 2025
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants