[SECURITY] Fedora 19 Update: node-gyp-0.10.6-1.fc19

updates at fedoraproject.org updates at fedoraproject.org
Tue Jul 23 01:04:54 UTC 2013


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2013-12908
2013-07-13 00:22:15
--------------------------------------------------------------------------------

Name        : node-gyp
Product     : Fedora 19
Version     : 0.10.6
Release     : 1.fc19
URL         : https://github.com/TooTallNate/node-gyp
Summary     : Node.js native addon build tool
Description :
node-gyp is a cross-platform command-line tool written in Node.js for compiling
native addon modules for Node.js, which takes away the pain of dealing with the
various differences in build platforms. It is the replacement to the node-waf
program which is removed for node v0.8.

--------------------------------------------------------------------------------
Update Information:

Update to the latest version of npm, fixing several bugs including a minor security bug.

For more information about recent changes in npm, see the changelog at GitHub:
https://github.com/isaacs/npm/commits/v1.3.3
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul 12 2013 T.C. Hollingsworth <tchollingsworth at gmail.com> - 0.10.6-1
- new upstream release 0.10.6
* Sat Jun 22 2013 T.C. Hollingsworth <tchollingsworth at gmail.com> - 0.10.1-1
- new upstream release 0.10.1
* Sat Jun 22 2013 T.C. Hollingsworth <tchollingsworth at gmail.com> - 0.9.5-3
- restrict to compatible arches
* Mon Apr 15 2013 T.C. Hollingsworth <tchollingsworth at gmail.com> - 0.9.5-2
- add macro for EPEL6 dependency generation
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #983918 - npm: CVE-2013-4116 npm: Insecure temporary directory generation [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=983918
  [ 2 ] Bug #984202 - nodejs-npmlog must be updated because of new npm-1.3.3
        https://bugzilla.redhat.com/show_bug.cgi?id=984202
  [ 3 ] Bug #985305 - Dependency problem when updating to nodejs-lru-cache-2.3.0
        https://bugzilla.redhat.com/show_bug.cgi?id=985305
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update node-gyp' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list