[Pkg-javascript-devel] Bug#989266: Version has known security issues, and soon to be unmaintained by upstream

Henning Sprang henning.sprang at gmail.com
Sun May 30 19:31:34 BST 2021


Package: nodejs
Version: 12.21.0~dfsg-4
Severity: important

This version has security issues, which have been fixed with 12.21.1 -
see https://github.com/nodejs/node/blob/master/doc/changelogs/CHANGELOG_V12.md#12.22.1

Also, the upstream maintenance support for Version 12 will end in
April 2022, meaning,  the Debian Security Team and/or maintainer will
have the sole responsibility to keep this package secure from then on,
with no support from upstream, if it will be delivered like this with
bullseye.

Version 12 of nodejs exists since 2019, and the recommended current
version to be used as recommended by upstream is 14.x, which is
available since April 2020.



More information about the Pkg-javascript-devel mailing list