Hello community, here is the log from the commit of package nodejs6 for openSUSE:Factory checked in at 2019-03-06 15:49:00 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/nodejs6 (Old) and /work/SRC/openSUSE:Factory/.nodejs6.new.28833 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Package is "nodejs6" Wed Mar 6 15:49:00 2019 rev:30 rq:681821 version:6.17.0 Changes: -------- --- /work/SRC/openSUSE:Factory/nodejs6/nodejs6.changes 2019-01-11 14:06:39.991728964 +0100 +++ /work/SRC/openSUSE:Factory/.nodejs6.new.28833/nodejs6.changes 2019-03-06 15:49:03.560424234 +0100 @@ -1,0 +2,28 @@ +Thu Feb 28 13:28:56 UTC 2019 - Adam Majer <adam.majer@suse.de> + +- New upstream LTS release 6.17.0: + * deps: OpenSSL has been upgraded to 1.0.2r. Under certain + circumstances, a TLS server can be forced to respond differently + to a client if a zero-byte record is received with an + invalid padding compared to a zero-byte record with an + invalid MAC. This can be used as the basis of a padding + oracle attack to decrypt data. + (CVE-2019-1559, bsc#1127080) + + * http: + + Backport server.keepAliveTimeout to prevent keep-alive + HTTP and HTTPS connections remaining open and inactive for + an extended period of time, leading to a potential + Denial of Service (DoS). (CVE-2019-5739, bsc#1127533) + + Further prevention of "Slowloris" attacks on HTTP and HTTPS + connections by consistently applying the receive timeout set + by server.headersTimeout to connections in keep-alive mode. + (CVE-2019-5737, bsc#1127532) + +------------------------------------------------------------------- +Fri Feb 1 12:40:17 UTC 2019 - adam.majer@suse.de + +- nodejs.keyring: update keyring to today's list as per + https://github.com/nodejs/node + +------------------------------------------------------------------- Old: ---- node-v6.16.0.tar.xz New: ---- node-v6.17.0.tar.xz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ nodejs6.spec ++++++ --- /var/tmp/diff_new_pack.lPnyAc/_old 2019-03-06 15:49:04.556424343 +0100 +++ /var/tmp/diff_new_pack.lPnyAc/_new 2019-03-06 15:49:04.560424343 +0100 @@ -26,7 +26,7 @@ ########################################################### Name: nodejs6 -Version: 6.16.0 +Version: 6.17.0 Release: 0 %define node_version_number 6 ++++++ SHASUMS256.txt ++++++ --- /var/tmp/diff_new_pack.lPnyAc/_old 2019-03-06 15:49:04.584424347 +0100 +++ /var/tmp/diff_new_pack.lPnyAc/_new 2019-03-06 15:49:04.588424347 +0100 @@ -1,42 +1,42 @@ -2defd3ab3f4628cade7d4b415be013fa0ad8e6ec4ee7da556affc3209b6eb0a4 node-v6.16.0-aix-ppc64.tar.gz -12167a8d26f323191b79e37cc9ab042b929ddd5bec4210aa9bd0dbf2c6a3bc5d node-v6.16.0-darwin-x64.tar.gz -9767fe05ffd33ce42070c56cb61a12c73a6d886ba32fbbbbedb2ca90e0bba525 node-v6.16.0-darwin-x64.tar.xz -f799b143375a0f9d70dac394da0ffd201657c911fe16a0341ff0687af2ce5cdc node-v6.16.0-headers.tar.gz -f5449926ce150c386090542b3e9ee369b19bc6148ab2f552e9fcb1024f14391e node-v6.16.0-headers.tar.xz -6b94c3c0e807f5350f4e973cece77f373d637f7d7c3c24f90e583407beee916a node-v6.16.0-linux-arm64.tar.gz -10507ebca2f736064dd325854f5b2e1f60f24b2e6a78fadcd7933d8edb978b70 node-v6.16.0-linux-arm64.tar.xz -260547033a9710a5d09807ae2e06c6b9f73636b814c156aac0b7e8c9ed3bfd98 node-v6.16.0-linux-armv6l.tar.gz -ef123b5ce4a4214774adc46d33f8aa5d3ac5cab8679e417b44531ae14b310304 node-v6.16.0-linux-armv6l.tar.xz -a70487b82e4a50ea0a8e10b5b6f922d52a870b15a5e34a8102d93e0765ea8ee1 node-v6.16.0-linux-armv7l.tar.gz -fe3b6d712c1b762ed35782c2f4fc4977711b61435998b89850dad309e38eb0bb node-v6.16.0-linux-armv7l.tar.xz -1c6c30d8d795f8d888526ae97e3dfd0a332fdbf2e703f1696679879fda8a1c62 node-v6.16.0-linux-ppc64le.tar.gz -30085079ee1c039e04bf6533023fe62191ee46d19ddc999f5593324177d12fa4 node-v6.16.0-linux-ppc64le.tar.xz -6f2a3f7713a05ec726af209d5bfe7945c5be6d99a2e2f4a561301c36f5998db8 node-v6.16.0-linux-ppc64.tar.gz -5fb8ef8cd31b15c03101c6e4d04e11accf1ae1b34aeae9007d1cb6a7a51a27d2 node-v6.16.0-linux-ppc64.tar.xz -58d90689ca1d41843532ef098b91e1860530f8a4c131f498b46facecce492c5f node-v6.16.0-linux-s390x.tar.gz -5edd1552bf369bc7eb9643b479d12a25e04a605b8176add2ead7e99802014b43 node-v6.16.0-linux-s390x.tar.xz -7f26cd9a2845df23773755a428d61b74fd80d48a991e964d12e85ae90ced81a0 node-v6.16.0-linux-x64.tar.gz -56c701b19777ffd122832ead132bf0590c9b6280a5cabe19e7642441167f7262 node-v6.16.0-linux-x64.tar.xz -93e47d1bc0dcbe98288247302c65708104d882cc61fe7d0ce2d68a78cdd555db node-v6.16.0-linux-x86.tar.gz -d35a33dcf043d7b30228d423e3a295be7aa9d4fb07f647acf2442cd53d9edcb1 node-v6.16.0-linux-x86.tar.xz -af45957ea17e5358eaa361476648817a4d68e7ae7d1e8f7f0b097cf02f389757 node-v6.16.0.pkg -80bc70012bce0a95284ac09045edb937f3c2da61d7d76f952cb4ccd280b81b44 node-v6.16.0-sunos-x64.tar.gz -6141555dd7bb1fd2d4df7d91121b9c4750d027c2ef9f64d6ea65ebad83866acf node-v6.16.0-sunos-x64.tar.xz -4fc09dfcd0cf5b18db3c829de9703968c9b3e5b806fe51d05ee59aa1f105527f node-v6.16.0-sunos-x86.tar.gz -4b2e2b827d0e1c044d436cdd231829aa0dc333fdfb386bd9b74295fdc5d75556 node-v6.16.0-sunos-x86.tar.xz -5432c6cba59bfef5794951193e93dbbd1707960b6c722925afcdb4517f4dc742 node-v6.16.0.tar.gz -0d0882a9da1ccc217518d3d1a60dd238da9f52bed0c7daac42b8dc3d83bd7546 node-v6.16.0.tar.xz -7e5c93340e966a16bd4659bd827867d3116611b55e9c194c00a7a578830f917e node-v6.16.0-win-x64.7z -03807861d364e0a2b09f475aa073022b49b277a51bd79cd255cf3c37611354e7 node-v6.16.0-win-x64.zip -734dd3b3baba0f142904c79b757abc841eb6d8ff5b0109ce8caa4aeffed2d1ea node-v6.16.0-win-x86.7z -885d6316b4852472cfb04a4fb7dad9f5ae0f08e3b3fd3f554c893b0b871e9f0b node-v6.16.0-win-x86.zip -cd58a0467828c34a59aa0ab8d10099cf928cb30adcf313bda8ec08939e91e56a node-v6.16.0-x64.msi -5e2424b372a40db42775e747a98e11979bc0dfc7bd3d1d87a49f9e19f087bf93 node-v6.16.0-x86.msi -e7532234c07e6a0d90842fbe530daad29e3000a4282514948846b3cb905d3e53 win-x64/node.exe -7524268fe5d2756a31efb62851f4fc7863ace64c3e08245bcd93d24612be9274 win-x64/node.lib -43b3fabc7c5f70412660aae27cf3928b2bc09a46c0b467e8f216135bb32bbd93 win-x64/node_pdb.7z -cf08f786f1d2276e3d11114bf9686f9c1e115f6d9f00db44510bd5f3969f5695 win-x64/node_pdb.zip -75d6d30a32afd0a6304441ac74e1099b31c0e5d8435f389b9c956afbd64b2be2 win-x86/node.exe -e42ded01468ee7d3cc68fb77c13430a08ed7502dfc90c1edda65c82ea3cd913e win-x86/node.lib -eea89a8e40707628135e6f7473da3f38109d02aad21798c2c820916833c6675a win-x86/node_pdb.7z -485817339eb96dd33ea7b2a5547942e4108a4c5b3f8821e700013bc289976407 win-x86/node_pdb.zip +9eb3b9f5e754d803b5e0cdcd406cc2ef8e6656f6bdcf1a3bb1eab14b3ffd9cb2 node-v6.17.0-aix-ppc64.tar.gz +1d4f0a24c09e8e3ed1ac0e4b62aba0cb86e9a293eef6c7a63876ba120b760583 node-v6.17.0-darwin-x64.tar.gz +cc72836d5c351dd1c47ac431f496fcaac4185aefa9f35a994716dd0d79f602cc node-v6.17.0-darwin-x64.tar.xz +a1051c5529511b343acfc9cfb02515b7cd40e820fec571cff70d9afd4c48435e node-v6.17.0-headers.tar.gz +b53e3886514be3674125617caf5c761b849f197f0b64aeabb2821b2de30a241c node-v6.17.0-headers.tar.xz +443f7656c541ba66b4aa50a5fa81e34e38714851006194ed63fee9cf48936c73 node-v6.17.0-linux-arm64.tar.gz +427f6c0ad02d2ad8e203a2c4959fadeaaa6043ba8caf2e1978c4a4d5b38737ab node-v6.17.0-linux-arm64.tar.xz +40b3791472e581e7caa6f0d19cfe01d94654b7d0f2300302376f071f8fef468c node-v6.17.0-linux-armv6l.tar.gz +94b8cac4800b7a0000548b69d38421398d222ee939a94af4add4a56369ba1158 node-v6.17.0-linux-armv6l.tar.xz +ad3ea3925fb4d74c2d7d3fa7b23d48b97b01846e31ac6bf0a70ab6f2eaa67f65 node-v6.17.0-linux-armv7l.tar.gz +a3fea75b0b052327a8f7b1042b794d797a54b7f39280194037f82b78e8624570 node-v6.17.0-linux-armv7l.tar.xz +2a959dd29f8a0fe52bbe3a0e287dfe306fb6ed4a90d4bb61b3bf856ec11d4c33 node-v6.17.0-linux-ppc64le.tar.gz +7d832b04af7eb3cd233e686ed3fe40fd96b116b8dc9d3a0961a64572cfa8c0f4 node-v6.17.0-linux-ppc64le.tar.xz +53f5995fe09548eaef4869b26fe3c0415236a2e07b312cb4082bd6aa84868e14 node-v6.17.0-linux-ppc64.tar.gz +85a6cab4354ca4e62f4bc5ff1ef14111e3d193444fb6cf97cb5e918b8ede90fb node-v6.17.0-linux-ppc64.tar.xz +b3ae1a97ea093490c74c5a0ff8f0d8a9591c33545e06b176d3bce875e2a5ba9f node-v6.17.0-linux-s390x.tar.gz +b62dec10c48bc68786611788998bcfa4f2e7df4cf54e0188e601c647871a0fa3 node-v6.17.0-linux-s390x.tar.xz +547422724489a5391d4a137cd130020c73f8f8c721754c67c7692003fe2b6015 node-v6.17.0-linux-x64.tar.gz +a5b2be71bcb1f182e143748007ee2f7cae624eb3b84263d7d7ea004b33b27399 node-v6.17.0-linux-x64.tar.xz +5e0ac63b07c5dcf34c78d25400f1e6a3b6f41eae94e0a6a0571f60369d2e5534 node-v6.17.0-linux-x86.tar.gz +a09c05f8ea60406f44ef4a140d182c353c5679f693c08a5247811deac678f6eb node-v6.17.0-linux-x86.tar.xz +fa7a4f497bb81ecdb4e077d0bf429845649376581ffab89ab07b82c211c04832 node-v6.17.0.pkg +94b168a55c32e466407fa459df7f245f7ef7fefaf42cfeed9326e936716e308f node-v6.17.0-sunos-x64.tar.gz +4c4928e84afbbcf7ffb731b74f7d1dfa73f8f6cb17c0023e7f87cc009b1f4f08 node-v6.17.0-sunos-x64.tar.xz +707134900d321b331cea8c76959bf07239fed62998f04f8aa1e3fa76ca785b32 node-v6.17.0-sunos-x86.tar.gz +044f1e1226c7830af19d156090f9593269d9e2d755c842107407b3c1be39d072 node-v6.17.0-sunos-x86.tar.xz +ef7b5cdffd110c194ef25fe14e455e0dea0fd894550ba33aadb90b0da8e14be2 node-v6.17.0.tar.gz +c1dac78ea71c2e622cea6f94ba97a4be49329a1d36cd05945a1baf1ae8652748 node-v6.17.0.tar.xz +4757a015153d9beae528417a3259688be725dbffc9e0eb6458118845427d213b node-v6.17.0-win-x64.7z +c03cb9ff76c34c41d3e193ab5aa589d40dfaeb80cb0ee24662e547e1a35b1e3c node-v6.17.0-win-x64.zip +65108ba51eb52dcdca98f7d7846869a460926644ebcf377ec87bd55f9ae704c4 node-v6.17.0-win-x86.7z +e8f235072b90f374b6d46fe38cfc5ffd8f317aa0d42c4c9a31cc7b5c9f6dd240 node-v6.17.0-win-x86.zip +3a9171ab366ba45accc2ec898b50390d0020797b1cf16a16e9f3e105fcfdc95a node-v6.17.0-x64.msi +e3478fcf22e3395a41f34cf7e64527e6cc532c109e5a8d67ab1de213e53f780c node-v6.17.0-x86.msi +fdccb67349c2c558349097c204522297478acdaa50f2b916393d1ea4b23b4f23 win-x64/node.exe +858cd16b0124543466d663df5058abe3aeaa08f0e396a0619af749f8880f3f3b win-x64/node.lib +a2785a1878a13b0a4945ce1ec6db409164c3c50d8c8315d710b8b7b89c8205e8 win-x64/node_pdb.7z +c25956040e9b7717976d61896cfdadaa56dfee26a6066a83b3f4dc566a99ccf0 win-x64/node_pdb.zip +3f877b57a1e1384a64888ad30e92ae57eedc8bc83563eefa06ab6af37846744d win-x86/node.exe +3ab1236a78694e3e66dbf24d25016d03afefbce47be0d82cc80e454a0b089724 win-x86/node.lib +39306b9f993ebd672064b2c305eb48f003ab0ab5bfe9dfa62259ed98f80f33c2 win-x86/node_pdb.7z +c3f05efcf553c326e644c079efbbacffe704012109584527a052ae6dab04a610 win-x86/node_pdb.zip ++++++ SHASUMS256.txt.sig ++++++ Binary files /var/tmp/diff_new_pack.lPnyAc/_old and /var/tmp/diff_new_pack.lPnyAc/_new differ ++++++ node-v6.16.0.tar.xz -> node-v6.17.0.tar.xz ++++++ /work/SRC/openSUSE:Factory/nodejs6/node-v6.16.0.tar.xz /work/SRC/openSUSE:Factory/.nodejs6.new.28833/node-v6.17.0.tar.xz differ: char 27, line 1 ++++++ nodejs.keyring ++++++ Binary files /var/tmp/diff_new_pack.lPnyAc/_old and /var/tmp/diff_new_pack.lPnyAc/_new differ