Hello community, here is the log from the commit of package nodejs for openSUSE:Factory checked in at 2016-09-30 15:34:44 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/nodejs (Old) and /work/SRC/openSUSE:Factory/.nodejs.new (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "nodejs" Changes: -------- --- /work/SRC/openSUSE:Factory/nodejs/nodejs.changes 2016-09-20 13:27:24.000000000 +0200 +++ /work/SRC/openSUSE:Factory/.nodejs.new/nodejs.changes 2016-09-30 15:34:57.000000000 +0200 @@ -1,0 +2,28 @@ +Thu Sep 29 02:22:42 UTC 2016 - qantas94he...@gmail.com + +- Fix incorrect SHASUMS256.txt.asc file that prevented package update + being accepted into Factory + +------------------------------------------------------------------- +Wed Sep 28 08:37:49 UTC 2016 - adam.ma...@suse.de + +- enable usage of system certificate store on SLE11SP4 by + requiring openssl1 (boo#1000036) +- new upstream version 6.7.0 + * openssl update (not applicable for SLE12SP2, Leap 42.2 and later) + + upgrade to 1.0.2j (CVE-2016-6304, CVE-2016-2183, CVE-2016-2178, + CVE-2016-6306, CVE-2016-7052) + + remove support for dynamic 3rd party engine modules + * http: Properly validate for allowable characters in input + user data. This introduces a new case where throw may occur + when configuring HTTP responses, users should already + be adopting try/catch here. (CVE-2016-5325, bnc#985201) + * tls: properly validate wildcard certificates + (CVE-2016-7099, bnc#1001652) + * v8: Fix regression where a regex on a frozen object was broken + * buffer: Zero-fill excess bytes in new Buffer objects created + with Buffer.concat() + * src: Fix regression where passing an empty password and/or + salt to crypto.pbkdf2() would cause a fatal error + +------------------------------------------------------------------- Old: ---- node-v6.6.0.tar.xz New: ---- node-v6.7.0.tar.xz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ nodejs.spec ++++++ --- /var/tmp/diff_new_pack.inQMak/_old 2016-09-30 15:34:59.000000000 +0200 +++ /var/tmp/diff_new_pack.inQMak/_new 2016-09-30 15:34:59.000000000 +0200 @@ -18,7 +18,7 @@ %define npm_version 3.10.3 Name: nodejs -Version: 6.6.0 +Version: 6.7.0 Release: 0 %if 0%{?suse_version} > 1320 || 0%{?sle_version} >= 120200 @@ -94,6 +94,13 @@ #this corresponds to the "engine" requirement in package.json Provides: nodejs(engine) = %{version} +# For SLE11, to be able to use the certificate store we need to have properly +# symlinked certificates. The compatability symlinks are provided by the +# openssl1 library in the Security Module +%if 0%{?suse_version} == 1110 +Requires: openssl1 +%endif + #building nodejs makes sense only on v8 archs ExclusiveArch: %{ix86} x86_64 armv7hl aarch64 ppc ppc64 ppc64le s390x BuildRoot: %{_tmppath}/%{name}-%{version}-build ++++++ SHASUMS256.txt.asc ++++++ --- /var/tmp/diff_new_pack.inQMak/_old 2016-09-30 15:35:00.000000000 +0200 +++ /var/tmp/diff_new_pack.inQMak/_new 2016-09-30 15:35:00.000000000 +0200 @@ -1,61 +1,62 @@ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 -c8d1fe38eb794ca46aacf6c8e90676eec7a8aeec83b4b09f57ce503509e7a19f node-v6.6.0-darwin-x64.tar.gz -e5e6248714618a81595cc2c04d3420535cd8a26d74274013a0eb61e0b3d23f5f node-v6.6.0-darwin-x64.tar.xz -60b81c7276105a51e71ad8bc7f59163105e7c5dd1d992b173b5b66449b6df3fc node-v6.6.0-headers.tar.gz -b3b6989c12cdf3652253c1b87d4328d151576a2ff4b189e05ebcba99ed84896c node-v6.6.0-headers.tar.xz -9abae64e411d8ea1541a4776e78d9cf53ad8e20e8b34cf77d9b3579e8edb6f65 node-v6.6.0-linux-arm64.tar.gz -fce02f2fc7bdc79899de4696395d02f3e7209e4ab4053336db790b8f58cce385 node-v6.6.0-linux-arm64.tar.xz -d311754cddc9b387a2798226ecb5487e515c555e050fdd08ef3d6665c3c0d336 node-v6.6.0-linux-armv6l.tar.gz -b6a5dce140b0795da61a9936454670887b431922e56326b53f1900e72e2ac48d node-v6.6.0-linux-armv6l.tar.xz -e4dc3295f6602b0f4cd3433a6e520294743e2c342692b4fad388d33910cdd465 node-v6.6.0-linux-armv7l.tar.gz -a3a1aac41c21d216ef380269b80225c658188f9182fc087e1823afe66935e3e1 node-v6.6.0-linux-armv7l.tar.xz -b38ff6058f0213567d31a5d194d669ce75894336f6d0324426f01722c989d3c4 node-v6.6.0-linux-ppc64le.tar.gz -c25c106ee0540f13cd119e47b85191f8a362e48d636a9e8398f5db42ac30d755 node-v6.6.0-linux-ppc64le.tar.xz -90d483c63fdbc6594185b3e143bf8d5627812288a029f02f578363d6dd505285 node-v6.6.0-linux-ppc64.tar.gz -3a2cbd56384217df585ad81eff7ddb92cf3601374152b05eafe27a2c7ef02fa9 node-v6.6.0-linux-ppc64.tar.xz -a2f109eb0fec81d90206e9c0bca05327c706b244b5d7c5bd247ac140f811e54e node-v6.6.0-linux-s390x.tar.gz -aa181bdba1a4f8d06e61fb5496be202c271dadc46a0ef6ecb4b7b4454f1909c4 node-v6.6.0-linux-s390x.tar.xz -c22ab0dfa9d0b8d9de02ef7c0d860298a5d1bf6cae7413fb18b99e8a3d25648a node-v6.6.0-linux-x64.tar.gz -fdf4377ea4dc9ba2f09d81d9ad1eae42e7eb870c4b1b69f2761f22f28cb5ba31 node-v6.6.0-linux-x64.tar.xz -05f3bfdfe8e1911e66b4bf645a439480212767e71664b8c97f0cba46671e8160 node-v6.6.0-linux-x86.tar.gz -e6fcca4783491c7b5866e7f969e93b66f47380e9cc92c08607d7683cfa200775 node-v6.6.0-linux-x86.tar.xz -7a9af7bf1eb98f8c206037a0dbbcd797c5684e2570d6acc8d915351bad4a5571 node-v6.6.0.pkg -21b05b3664c338b76ec8c139a7ae80fb9b1c65215ee2da6d899dcbd6c6d67554 node-v6.6.0-sunos-x64.tar.gz -b57733493ca428b859ca6f371f6fc0f93bca77926e81e80ddabe1c5d240431e8 node-v6.6.0-sunos-x64.tar.xz -ffa81fc834a7f24958b3c1bf07dc668f6d0e0cda48582a23bc749abca42cae8c node-v6.6.0-sunos-x86.tar.gz -3572cbe039cb4a791d4f1db3ed855250cb06c4136a5af0eb277aa27a75469c29 node-v6.6.0-sunos-x86.tar.xz -11b957de855a392ceaa8b300ec66236d6f9c6baa184837d00bdaba2da4aefe91 node-v6.6.0.tar.gz -640485d2b672d3313203eae164576539e61f1e55d68122ff2c7fb59896e21a33 node-v6.6.0.tar.xz -92d708377519f9c4cb6b6006ab50118fe98ea3b7fa49ecb8a1c02f2c13c8ab92 node-v6.6.0-win-x64.7z -5b1c49f8fd36bd9c277259773f42832db74c41f87033deaccfbd82e15330bae4 node-v6.6.0-win-x64.zip -3a3eaa4690ead41631e761f24f0e0cf2d66d1378f07a59153e397abdf470273d node-v6.6.0-win-x86.7z -95862922b8469e00a7ae5f1f82d51c739fdc6ee12a8e1d46c0f100f2ea18c082 node-v6.6.0-win-x86.zip -675f5088021b99c53136d9f7306ba93f2a126df75777f0b97fb6013da2e5c539 node-v6.6.0-x64.msi -8ce48431e7d0182d21efc398fcc478f8852b96df8a7287dd40db9ef53cca01a3 node-v6.6.0-x86.msi -1cd746e30ce1af03495858ee3f8c3e1c18350b8a8259e560b5ac25e95bc5b5de win-x64/node.exe -efd924b61fe3f6ba67c28ac605c13304ac16976e020a57480f555cffd0a9741d win-x64/node.lib -84b27e00d6c562dbc6d68f32c9755874c7f29932ebc04a57580cc05aac64d78b win-x64/node_pdb.7z -238b24d1b7c24ab7ba3c964fda775500965dbcf1dd1484fa3397eded5e9d3d94 win-x64/node_pdb.zip -708a825e7c5fdb1015ea3ca56e257c74fc5ec602a83e8794ea3ab4e100c38f0b win-x86/node.exe -461fd40ecd79bbea9710d0a940f4d143fc344ffff62309cd86ee414ccfd3916c win-x86/node.lib -7161b5361d67279a74d2564195be9bf5a9bb2d332d9c9dde6b59a2926bfb1636 win-x86/node_pdb.7z -2394477a698c40ae08bcb9ec01ea7ed7efe9f32498212c511bd9d67103662acc win-x86/node_pdb.zip +132855c123efdfa43dc4a256f15728f1bbd3f9996a4b9e29cd31908248be6bf2 node-v6.7.0-aix-ppc64.tar.gz +69fab7a1ebeee54d5e3160eb9366e88a61500731fad86dee98c79c4a14b56bc6 node-v6.7.0-darwin-x64.tar.gz +b10270f028be73771fa8536f0c69b33f30e1bb1fd15d9a493a7365cde56af0d2 node-v6.7.0-darwin-x64.tar.xz +42f0fdcd937409842d76a5852782acfdb0b6fa8e3520df6694f2abaa7c9e942c node-v6.7.0-headers.tar.gz +f6ddea52f8b13bcece38c965d13f6073bd7980dadcfd903b8c1872f6d8bbacb7 node-v6.7.0-headers.tar.xz +45ffd727bcab41a544ad7862fe985f6beac4fcd96c63e116ca467d1147ba6454 node-v6.7.0-linux-arm64.tar.gz +87f59a19d9a44ff938a553425c5c82a46be1f0cd43bf7c256e1c4fb61833a82a node-v6.7.0-linux-arm64.tar.xz +0f8e0dbaa6bcccd22db75077fed1afb28c2b225b6cdc185913178ae395a68ef9 node-v6.7.0-linux-armv6l.tar.gz +bf07229d718ebe3a8d8bc59cbf06d945b89045285e44f36f516c8e0f65a5302b node-v6.7.0-linux-armv6l.tar.xz +1e7e138ba8c54d7a0fbf5e3f188442a14a70409dc154b74b17635bcff74e4a81 node-v6.7.0-linux-armv7l.tar.gz +18b6d9df3e2aaba2d72e1f4c3cfdd3b963c23faa64d3ad72d5690959bc3dde08 node-v6.7.0-linux-armv7l.tar.xz +de8e4ca71caa8be6eaf80e65b89de2a6d152fa4ce08efcbc90ce7e1bfdf130e7 node-v6.7.0-linux-ppc64le.tar.gz +bc5fdfbe25a8fb0367ea7bf5b639ffb9bfd27ceb15f9d27579d6471ca585ff75 node-v6.7.0-linux-ppc64le.tar.xz +e8ce540b592d337304a10f4eb19bb4efee889c6676c5f188d072bfb2a8089927 node-v6.7.0-linux-ppc64.tar.gz +6ee874b6567f7f06708f6ccb66a27dc7317b4c493b7a6c3bb49c1e53c4bdf31e node-v6.7.0-linux-ppc64.tar.xz +e0f2616b4beb4c2505edb19e3cbedbf3d1c958441517cc9a1e918f6feaa4b95b node-v6.7.0-linux-s390x.tar.gz +647bacc68bd0101b04074d5740492a6511dee69e23a7ff03765674d7a9fa93df node-v6.7.0-linux-s390x.tar.xz +abe81b4150917cdbbeebc6c6b85003b80c972d32c8f5dfd2970d32e52a6877af node-v6.7.0-linux-x64.tar.gz +09263a844c31933c6f31e576e580faf01d3bbb056efb8713388dc8d09674f8c2 node-v6.7.0-linux-x64.tar.xz +fa94c93a4a3600d68e003a399f5cf5e109c2d10505b4d9456373c25953eb9bf5 node-v6.7.0-linux-x86.tar.gz +e89a77020bd579186adbc46f6a668d3524f980c5fc75f63e1d5b5362423bcebb node-v6.7.0-linux-x86.tar.xz +c5d46d0f105ed652c9a353d8411558c9c4610db874f01ef07e57ad613e5d4237 node-v6.7.0.pkg +33f240dac58a1293a08b66ecd01a70849c693e3a9e58a94cb7ee92126a894984 node-v6.7.0-sunos-x64.tar.gz +9df8f3d1048065fccb1c1746cfd1f3a22ef46075399e7dc92d38949e37607de7 node-v6.7.0-sunos-x64.tar.xz +80dacf34a5e17f3eeabe15e212005daeaa189caa424a83a23f302a9fa5996565 node-v6.7.0-sunos-x86.tar.gz +14bdf36ae5510a6565af69e1db651d34e75d2846a363610b6669b8c78e404b2a node-v6.7.0-sunos-x86.tar.xz +02b8ee1719a11b9ab22bef9279519efaaf31dd0d39cba4c3a1176ccda400b8d6 node-v6.7.0.tar.gz +ceb028324aab1ee8c7ea6a62026f036f3ea71f5ef5212593d0f833f999dd3be5 node-v6.7.0.tar.xz +2eb013b15c718ec2b26768e6a325e73571ed1d2028af411307a1bbd549f709ed node-v6.7.0-win-x64.7z +59971f8ea9fb1ac4c55ca36303fe32a0714049cf8a10843dbb5924a5d0624659 node-v6.7.0-win-x64.zip +8b4448e56223aed8c316b67336fdd1d94aeee71033934fb6bc071a358c5c8719 node-v6.7.0-win-x86.7z +d75bebea562a1da0965adc8f94d2c5a38a22cfc57959d37c5c1aeec4ea9f1c83 node-v6.7.0-win-x86.zip +2185a16f8a32087b75708b08d7e482a14597765c41d6b3711a8e6ed3a3358213 node-v6.7.0-x64.msi +0801c283200ac263cc0ca014f5d8e0ee531e1ebec6e99645a0bdd04b996c1605 node-v6.7.0-x86.msi +7ab8714273a9a1fa464ded6b543b52b6fb56c7d2c3d08ebe312b1c1be72a1477 win-x64/node.exe +17c521d3b19886f826f818b9806bb4d2af4615d5bf850c257dcdaef897e8ccaa win-x64/node.lib +fa2f32b9f8ac97d26bb58da59c8a7299de5bd9f25b8879f8787ecd0ffbd36c3b win-x64/node_pdb.7z +815d202704373b9894c5dc113d2a2812be5e73431f8061707e0fd012cbc0b8cc win-x64/node_pdb.zip +a2e58867917250e013a49c4210b36aba04715159a71edcfb510c6225e3dab184 win-x86/node.exe +641503fd3d41c1bc04a95ee38e6dc2ffd9c9e5a35b3f5bfecb25965c963f2d17 win-x86/node.lib +36265c44782a8456b289c4776bf5de5ed648982f2b8dc97e17acd76258e249cf win-x86/node_pdb.7z +2d8a25ba8e212715050ee03e4b0b9f547163ffaeb75288c9508a06e469677ff6 win-x86/node_pdb.zip -----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org -iQIcBAEBCgAGBQJX2wmcAAoJEEX17r2BPa6OkcEP/AqvpLT+XmIHd+2S5NguUNqu -iIZIBmw/iNBomfR5X3b92+TU0zMAmiakAWR8KgiHIdausbokITWv3Qia7lWro1ue -IFuXbsP9JcN+AMHi3/JKOekcg5IBqRDrzXxfHACwLokBwY5e+PwyYtEHPBx+Ls55 -QuKcR24Jo70UQ1lkXNSJPSZdn85EcQ1Dw1kdhO3Mi87n4nitTRmWnFLKeJA46Ey2 -ejDRUy+xt0jsy7sDeGEKDFu5ajajIRLnaaGsr21gxpjsbPH7Tg1c0gUUbs9fhrvn -gAc8R+5iXsRi24FrlaaLkfvnhF6/7uTN4YG3fbAexT9bPftd9pn7iwHKkKaTrnw/ -w+n1bgH4Ogs6w8x0SX1DcvHONj5WqoIgRWRLCnju9GpjkfJQ33qNLHBTXx4qqrb2 -J2mJzmvo5T9WyrEV7aWA3Laa8Fwk6MLZe4Cu/mLT9pJ3kNj/5WXCGjpWUS90jSxn -OXWY8XXY8B3e6y0AYT4J26sKd7rIv5ux0PLor/xJT5SYH4XeKbVAn8HfhakIDvR7 -oIZW2UJxd/spfIbHSeODEisS5YqDrWyzAxSJfJzt1R2oI299EEtZRIzmiWXsEEXv -ee31irYPSVg0aF+Qbps+ojeOQzbukp2HMrh2K3orVvf0PzifP1Gh76nrw4BLiKLi -sY3xYr5CG0AIAjpSw0w3 -=xwUE +iQIcBAEBCgAGBQJX7DJDAAoJELY7U1pMIGypeM8QAL3jLz92a++LhnwGQl5FPtaB +XorribOTM8nYLHla3cwyAgdSPLG33wIHKF4pG8rMYIZ4K4wYD4wFh2CWBiLgmcRi +h7uhB6TrH2hSy7rIMNRW8C2atVL78MdaHPxmKwqFcsfKtbu5CD4eh2sbRwbrbSkp +WUg6TNub7ZxQkOjlxb6KZq4C59FjhQuyhciK8Pk9lTbnIOtzQ0GL3bXUgbTVgjji +pdztRUDDqCrNLdnRaY4PK3S0qhXoyIBH2RA5kJtjT4qdIBtecVTfxtlff1SscX8l +zOokRGVsQLPzXE5UuC7UPEYi7pIkFVXRJDwe0f7NTmTngnkKElIIjEeppm13ZYaR +VfaifDaCCjJpdEHJWYmmaopGw3QLkm1jAtU5nR36oYyZvKx3eb4QU8j8OgtChznh +rGqWzOk6AdcXpIdmO5N6aNyvC5dM/nnpTOnNJhKp6EVKzLTLHghst6qNb1XSsW5l +8eZeEKyLl0JaXk4w+FXlKbymrhA8dOa1TaZ27ATtTFhYfzk2hb6zir1vmON4YvI0 +2dMqRy0YcduoO+gz8DeDjyPouOrng4WZ9iF5JevM1lswrBkAL4P2AIcQ0E8Z0I6B +3HZY4YJt0RcEBydFYtlRxEzbYo0hig2BRRP0OqT5o2pt+YK+NjxPvmfS2nlFYpJ6 +ujvlLislHyyZVDUbnvjh +=taAg -----END PGP SIGNATURE----- ++++++ node-v6.6.0.tar.xz -> node-v6.7.0.tar.xz ++++++ /work/SRC/openSUSE:Factory/nodejs/node-v6.6.0.tar.xz /work/SRC/openSUSE:Factory/.nodejs.new/node-v6.7.0.tar.xz differ: char 27, line 1