Skip to content

build: update dependency node to v24.14.1#3570

Open
angular-robot wants to merge 1 commit intoangular:mainfrom
angular-robot:ng-renovate/node-24-x
Open

build: update dependency node to v24.14.1#3570
angular-robot wants to merge 1 commit intoangular:mainfrom
angular-robot:ng-renovate/node-24-x

Conversation

@angular-robot
Copy link
Contributor

@angular-robot angular-robot commented Mar 25, 2026

This PR contains the following updates:

Package Update Change
node (source) patch 24.14.024.14.1

  • If you want to rebase/retry this PR, check this box

Release Notes

nodejs/node (node)

v24.14.1: 2026-03-24, Version 24.14.1 'Krypton' (LTS), @​RafaelGSS prepared by @​juanarbol

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-21710) use null prototype for headersDistinct/trailersDistinct (Matteo Collina) - High
  • (CVE-2026-21637) wrap SNICallback invocation in try/catch (Matteo Collina) - High
  • (CVE-2026-21717) test array index hash collision (Joyee Cheung) - Medium
  • (CVE-2026-21713) use timing-safe comparison in Web Cryptography HMAC and KMAC (Filip Skokan) - Medium
  • (CVE-2026-21714) handle NGHTTP2_ERR_FLOW_CONTROL error code (RafaelGSS) - Medium
  • (CVE-2026-21712) handle url crash on different url formats (RafaelGSS) - Medium
  • (CVE-2026-21716) include permission check on lib/fs/promises (RafaelGSS) - Low
  • (CVE-2026-21715) add permission check to realpath.native (RafaelGSS) - Low
Commits

@angular-robot angular-robot added action: merge The PR is ready for merge by the caretaker area: build & ci Related the build and CI infrastructure of the project target: automation This PR is targeted to only merge into the branch defined in Github [bot use only] labels Mar 25, 2026
Copy link

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the Node.js version from 24.14.0 to 24.14.1 across the .nvmrc file, MODULE.bazel configuration, and MODULE.bazel.lock file. A suggestion was made to improve maintainability in MODULE.bazel by defining the Node.js version as a constant to simplify future updates and reduce potential errors.

See associated pull request for more information.
@angular-robot angular-robot force-pushed the ng-renovate/node-24-x branch from d06c976 to 783a115 Compare March 25, 2026 06:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action: merge The PR is ready for merge by the caretaker area: build & ci Related the build and CI infrastructure of the project target: automation This PR is targeted to only merge into the branch defined in Github [bot use only]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant