Skip to content

chore(deps): bump node.js to v24#236

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/node-24.x
Open

chore(deps): bump node.js to v24#236
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/node-24.x

Conversation

@renovate

@renovate renovate Bot commented Oct 28, 2025

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Age Adoption Passing Confidence
node (source) major 2024 age adoption passing confidence
@types/node (source) devDependencies major 20.x.x24.x age adoption passing confidence

Release Notes

nodejs/node (node)

v24.18.0: 2026-06-23, Version 24.18.0 'Krypton' (LTS), @​richardlau prepared by @​sxa

Compare Source

Notable Changes
  • [e07e7a31e1] - crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #​63527
  • [44c8ebcbd6] - http: avoid stream listeners on idle agent sockets (Matteo Collina) #​64004
  • [d3ef4122ee] - (SEMVER-MINOR) buffer: increase Buffer.poolSize default to 64 KiB (Matteo Collina) #​63597
  • [bb2857b85a] - (SEMVER-MINOR) crypto: align key argument names in docs and error messages (Filip Skokan) #​62527
  • [b9d5e87880] - (SEMVER-MINOR) crypto: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) #​62527
  • [ccd756d61e] - (SEMVER-MINOR) crypto: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) #​62183
  • [4c9251fc09] - (SEMVER-MINOR) http: add writeInformation to send arbitrary 1xx status codes (Tim Perry) #​63155
  • [8c989ec4a3] - (SEMVER-MINOR) inspector: expose precise coverage start to JS runtime (sangwook) #​63079
  • [3f54c8ba32] - Revert "stream: noop pause/resume on destroyed streams" (Stewart X Addison) #​63834
Commits

v24.17.0: 2026-06-18, Version 24.17.0 'Krypton' (LTS), @​aduh95

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High
  • (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High
  • (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium
  • (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium
  • (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium
  • (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium
  • (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium
  • (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 – Medium
  • (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low
  • (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low
  • (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low
Commits

v24.16.0: 2026-05-21, Version 24.16.0 'Krypton' (LTS), @​aduh95

Compare Source

Notable Changes
  • [b267f6bca3] - (SEMVER-MINOR) crypto: implement randomUUIDv7() (nabeel378) #​62553
  • [ec2451b9cd] - (SEMVER-MINOR) debugger: add edit-free runtime expression probes to node inspect (Joyee Cheung) #​62713
  • [9705f628d9] - (SEMVER-MINOR) fs: add signal option to fs.stat() (Mert Can Altin) #​57775
  • [40ccfdecf9] - (SEMVER-MINOR) fs: expose frsize field in statfs (Jinho Jang) #​62277
  • [d7188af5c9] - (SEMVER-MINOR) http: harden ClientRequest options merge (Matteo Collina) #​63082
  • [aa1d8a9afc] - (SEMVER-MINOR) http: add req.signal to IncomingMessage (Akshat) #​62541
  • [6f37f7e240] - (SEMVER-MINOR) stream: propagate destruction in duplexPair (Ahmed Elhor) #​61098
  • [d14029be7f] - (SEMVER-MINOR) test_runner: support test order randomization (Pietro Marchini) #​61747
  • [d142c584cd] - (SEMVER-MINOR) test_runner: align mock timeout api (sangwook) #​62820
  • [01a9552585] - (SEMVER-MINOR) test_runner: add mock-timers support for AbortSignal.timeout (DeveloperViraj) #​60751
  • [00705a459a] - (SEMVER-MINOR) util: colorize text with hex colors (Guilherme Araújo) #​61556
Commits

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/node-24.x branch from 961406f to ccc455b Compare October 28, 2025 22:53
@renovate renovate Bot changed the title build(deps-dev): bump @types/node to v24 chore(deps): bump node.js to v24 Oct 28, 2025
@renovate
renovate Bot force-pushed the renovate/node-24.x branch from ccc455b to 73c6972 Compare November 3, 2025 05:40
@renovate
renovate Bot force-pushed the renovate/node-24.x branch 2 times, most recently from 82fcdc2 to 70d2e2a Compare November 18, 2025 22:36
@renovate
renovate Bot force-pushed the renovate/node-24.x branch from 70d2e2a to 65a201a Compare November 25, 2025 13:40
@renovate
renovate Bot force-pushed the renovate/node-24.x branch 3 times, most recently from f760330 to 403aa2b Compare December 14, 2025 01:01
@renovate
renovate Bot force-pushed the renovate/node-24.x branch 5 times, most recently from 7d62119 to bdb5999 Compare January 15, 2026 17:27
@renovate
renovate Bot force-pushed the renovate/node-24.x branch 4 times, most recently from 0d25d78 to e20edfc Compare February 8, 2026 01:00
@renovate
renovate Bot force-pushed the renovate/node-24.x branch 3 times, most recently from 97e0464 to 273b34b Compare February 12, 2026 11:57
@renovate
renovate Bot force-pushed the renovate/node-24.x branch 2 times, most recently from 477d704 to c43d07d Compare February 24, 2026 20:08
@renovate
renovate Bot force-pushed the renovate/node-24.x branch from c43d07d to 872df95 Compare February 26, 2026 03:41
@renovate
renovate Bot force-pushed the renovate/node-24.x branch from 9ba4b71 to b65ad25 Compare March 6, 2026 09:28
@renovate
renovate Bot force-pushed the renovate/node-24.x branch from b65ad25 to ad2e00f Compare March 13, 2026 15:15
@renovate
renovate Bot force-pushed the renovate/node-24.x branch 2 times, most recently from 5a69ab5 to f637154 Compare March 27, 2026 13:04
@renovate
renovate Bot force-pushed the renovate/node-24.x branch 4 times, most recently from 282ef8a to ccc9b5e Compare April 8, 2026 17:28
@renovate
renovate Bot force-pushed the renovate/node-24.x branch from ccc9b5e to 8c7dc39 Compare April 16, 2026 11:39
@renovate
renovate Bot force-pushed the renovate/node-24.x branch from 8c7dc39 to 5e313fa Compare April 29, 2026 10:56
@renovate
renovate Bot force-pushed the renovate/node-24.x branch 2 times, most recently from 32fa6f5 to 622c862 Compare May 12, 2026 00:44
@renovate
renovate Bot force-pushed the renovate/node-24.x branch 2 times, most recently from a922bae to e1842e4 Compare May 21, 2026 14:34
@renovate
renovate Bot force-pushed the renovate/node-24.x branch 3 times, most recently from 24f33d6 to 39d6f65 Compare June 4, 2026 10:27
Comment thread pnpm-lock.yaml
resolution: {integrity: sha512-PMSmkqxr106Xa156c2M265Z+FTrPl+oxd/rgOQy2tijQeK5TxQ43psO1ZCwhVOSdnn+RzkzlRz/eY4BgJBYVpg==}
hasBin: true

js-yaml@3.6.1:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Medium severity vulnerability may affect your project—review required:
Line 558 lists a dependency (js-yaml) with a known Medium severity vulnerability.

ℹ️ Why this matters

Affected versions of js-yaml are vulnerable to Uncontrolled Resource Consumption. js-yaml is vulnerable to denial of service when parsing untrusted YAML: a document that uses nested arrays as mapping keys combined with anchors and aliases triggers exponential string expansion during parsing, stalling the Node.js process and exhausting memory. Any call to a js-yaml load function (load, loadAll, safeLoad, safeLoadAll) on attacker-controlled input is affected.

References: GHSA

To resolve this comment:
Check if you are using js-yaml on the CLI.

  • If you're affected, upgrade this dependency to at least version 3.13.0 at pnpm-lock.yaml.
  • If you're not affected, comment /fp we don't use this [condition]
💬 Ignore this finding

To ignore this, reply with:

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

You can view more details on this finding in the Semgrep AppSec Platform here.

Comment thread pnpm-lock.yaml
resolution: {integrity: sha512-PMSmkqxr106Xa156c2M265Z+FTrPl+oxd/rgOQy2tijQeK5TxQ43psO1ZCwhVOSdnn+RzkzlRz/eY4BgJBYVpg==}
hasBin: true

js-yaml@3.6.1:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Medium severity vulnerability may affect your project—review required:
Line 558 lists a dependency (js-yaml) with a known Medium severity vulnerability.

ℹ️ Why this matters

Affected versions of js-yaml are vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'). js-yaml is vulnerable to prototype pollution through its YAML merge key (<<) handling. When parsing untrusted YAML with load, loadAll, safeLoad, or safeLoadAll, a crafted document containing a __proto__ key inside a merged mapping can modify the prototype of the resulting object, leading to integrity violations in the application.

References: GHSA, CVE

To resolve this comment:
Check if you are using js-yaml on the CLI.

  • If you're affected, upgrade this dependency to at least version 3.14.2 at pnpm-lock.yaml.
  • If you're not affected, comment /fp we don't use this [condition]
💬 Ignore this finding

To ignore this, reply with:

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

You can view more details on this finding in the Semgrep AppSec Platform here.

@renovate
renovate Bot force-pushed the renovate/node-24.x branch 2 times, most recently from 88c8341 to 33c1fb9 Compare June 10, 2026 22:36
@socket-security

socket-security Bot commented Jun 10, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​types/​node@​24.13.31001008195100

View full report

@renovate
renovate Bot force-pushed the renovate/node-24.x branch 2 times, most recently from 4bb666a to 303d012 Compare June 24, 2026 00:41
@renovate
renovate Bot force-pushed the renovate/node-24.x branch 2 times, most recently from 653706c to a04019c Compare July 12, 2026 13:18
@renovate
renovate Bot force-pushed the renovate/node-24.x branch from a04019c to 6c795ab Compare July 16, 2026 17:14
@socket-security

socket-security Bot commented Jul 16, 2026

Copy link
Copy Markdown

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate
renovate Bot force-pushed the renovate/node-24.x branch from 6c795ab to 5ac1581 Compare July 20, 2026 22:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants