Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

2017-01-31, Version 6.9.5 'Boron' (LTS) #11081

Merged
merged 1 commit into from
Jan 31, 2017
Merged

2017-01-31, Version 6.9.5 'Boron' (LTS) #11081

merged 1 commit into from
Jan 31, 2017

Conversation

MylesBorins
Copy link
Contributor

2017-01-31, Version 6.9.5 'Boron' (LTS), @MylesBorins

This is a security release of the 'Boron' release line to upgrade OpenSSL to version 1.0.2k

Although the OpenSSL team have determined a maximum severity rating of "moderate", the Node.js
crypto team (Ben Noordhuis, Shigeki Ohtsu and Fedor Indutny) have determined the impact to Node
users is "low". Details on this determination can be found
on the Nodejs.org website.

Notable Changes

  • deps: upgrade openssl sources to 1.0.2k (Shigeki Ohtsu) #11021

Commits

@MylesBorins
Copy link
Contributor Author

@MylesBorins MylesBorins added meta Issues and PRs related to the general management of the project. v6.x labels Jan 31, 2017
@MylesBorins
Copy link
Contributor Author

/cc @nodejs/github-bot no auto labelling... is that bot down?

@mscdex
Copy link
Contributor

mscdex commented Jan 31, 2017

@MylesBorins Doesn't appear to be, the webhook notifications were delivered successfully. Might need @phillipj to look at the local bot logs.

This is a security release of the 'Boron' release line to upgrade
OpenSSL to version 1.0.2k

Although the OpenSSL team have determined a maximum severity rating
of "moderate", the Node.js crypto team (Ben Noordhuis, Shigeki Ohtsu
and Fedor Indutny) have determined the impact to Node users is "low".
Details on this determination can be found on the Nodejs.org website

https://nodejs.org/en/blog/vulnerability/openssl-january-2017/

Notable Changes:

* deps:
  - upgrade openssl sources to 1.0.2k (Shigeki Ohtsu)
		#11021

PR-URL: #11081
@phillipj
Copy link
Member

/cc @nodejs/github-bot no auto labelling... is that bot down?

It got a 404 error when requesting the list of files this PR has changed :/ Looks like a temporary GitHub glitch because similar requests has succeeded afterwards.

@MylesBorins
Copy link
Contributor Author

Failures look unrelated to change. Moving forward with release

@MylesBorins MylesBorins merged commit 37a8051 into v6.x Jan 31, 2017
MylesBorins added a commit that referenced this pull request Jan 31, 2017
MylesBorins added a commit that referenced this pull request Jan 31, 2017
This is a security release of the 'Boron' release line to upgrade
OpenSSL to version 1.0.2k

Although the OpenSSL team have determined a maximum severity rating
of "moderate", the Node.js crypto team (Ben Noordhuis, Shigeki Ohtsu
and Fedor Indutny) have determined the impact to Node users is "low".
Details on this determination can be found on the Nodejs.org website

https://nodejs.org/en/blog/vulnerability/openssl-january-2017/

Notable Changes:

* deps:
  - upgrade openssl sources to 1.0.2k (Shigeki Ohtsu)
		#11021

PR-URL: #11081
imyller added a commit to imyller/meta-nodejs that referenced this pull request Mar 2, 2017
    This is a security release of the 'Boron' release line to upgrade
    OpenSSL to version 1.0.2k

    Although the OpenSSL team have determined a maximum severity rating
    of "moderate", the Node.js crypto team (Ben Noordhuis, Shigeki Ohtsu
    and Fedor Indutny) have determined the impact to Node users is "low".
    Details on this determination can be found on the Nodejs.org website

    https://nodejs.org/en/blog/vulnerability/openssl-january-2017/

    Notable Changes:

    * deps:
      - upgrade openssl sources to 1.0.2k (Shigeki Ohtsu)
                    nodejs/node#11021

    PR-URL: nodejs/node#11081

Signed-off-by: Ilkka Myller <ilkka.myller@nodefield.com>
imyller added a commit to imyller/meta-nodejs that referenced this pull request Mar 2, 2017
    This is a security release of the 'Boron' release line to upgrade
    OpenSSL to version 1.0.2k

    Although the OpenSSL team have determined a maximum severity rating
    of "moderate", the Node.js crypto team (Ben Noordhuis, Shigeki Ohtsu
    and Fedor Indutny) have determined the impact to Node users is "low".
    Details on this determination can be found on the Nodejs.org website

    https://nodejs.org/en/blog/vulnerability/openssl-january-2017/

    Notable Changes:

    * deps:
      - upgrade openssl sources to 1.0.2k (Shigeki Ohtsu)
                    nodejs/node#11021

    PR-URL: nodejs/node#11081

Signed-off-by: Ilkka Myller <ilkka.myller@nodefield.com>
@sam-github sam-github deleted the v6.9.5-proposal branch March 6, 2017 16:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
meta Issues and PRs related to the general management of the project.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants