Skip to content

Update .node-version #6676

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 8 commits into from
Apr 5, 2024
Merged

Update .node-version #6676

merged 8 commits into from
Apr 5, 2024

Conversation

puneethrai
Copy link
Contributor

This is to fix security vulnerability mentioned in https://www.hkcert.org/security-bulletin/node-js-multiple-vulnerabilities_20231016

Fixes #
Update Node version to 18.19.1 to fix vulnerabilities in NodeJS

@puneethrai puneethrai requested a review from a team as a code owner February 15, 2024 03:49
@code-asher
Copy link
Member

Thank you for the PR! We keep our version is sync with upstream so we will need to wait for them to update. https://github.com/microsoft/vscode/blob/main/remote/.yarnrc

@puneethrai
Copy link
Contributor Author

@code-asher any idea when can the update be possible ?

@code-asher
Copy link
Member

They follow Electron, and the next Electron update appears to be 28, scheduled for Februrary. Electron 28 uses Node 18.18.2 so I think that will be the next version. I am not sure about 18.19.1 though.

@puneethrai
Copy link
Contributor Author

Thanks for the update @code-asher . So this is my first time PR for this repo, If you could guide if the PR is fine

I'll change the version to 18.18.2 if that is what we upgrade to and I believe changelog will be maintained by you

@code-asher
Copy link
Member

Yeah I will handle the changelog. I believe we can update to 18.18.2 once VS Code 1.87.0 comes out.

@puneethrai
Copy link
Contributor Author

Thanks @code-asher . I've made the appropriate changes. Will keep an eye on VSCode 1.87.0 release. Looking forward for my first PR merge

@code-asher
Copy link
Member

Apparently I was wrong about the Node version, looks like they are going to update it in 1.88, not 1.87.

@puneethrai
Copy link
Contributor Author

That would add another month or so right ? We will be dealing with vulnerabilities much longer.

@code-asher
Copy link
Member

code-asher commented Mar 5, 2024

That would add another month or so right ?

Yup, that is right.

@code-asher
Copy link
Member

The time has finally come!

@code-asher code-asher merged commit bae6854 into coder:main Apr 5, 2024
yiliang114 pushed a commit to yiliang114/code-server that referenced this pull request Jan 23, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants