From e0ee2631de88a2bb9880488f578258023998cbdb Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Juan=20Jos=C3=A9=20Arboleda?= Date: Tue, 1 Nov 2022 15:15:53 -0500 Subject: [PATCH] doc: nov-2022 sec release pre-announcement --- .../november-2022-security-releases.md | 38 +++++++++++++++++++ locale/en/site.json | 8 ++-- 2 files changed, 42 insertions(+), 4 deletions(-) create mode 100644 locale/en/blog/vulnerability/november-2022-security-releases.md diff --git a/locale/en/blog/vulnerability/november-2022-security-releases.md b/locale/en/blog/vulnerability/november-2022-security-releases.md new file mode 100644 index 0000000000000..b31960151053b --- /dev/null +++ b/locale/en/blog/vulnerability/november-2022-security-releases.md @@ -0,0 +1,38 @@ +--- +date: 2022-11-01T21:00:00.000Z +category: vulnerability +title: Nov 3 2022 Security Releases +slug: november-2022-security-releases +layout: blog-post.hbs +author: Juan José Arboleda +--- + +# Summary + +The Node.js project will release new versions of the 14.x, 16.x, 18.x, 19.x +releases lines on or shortly after Thursday, November 3, 2022 in order to address: + +* One medium severity issues. +* Two high severity issues that affect OpenSSL as per [secadv/20221101.txt](https://www.openssl.org/news/secadv/20221101.txt) + +These security releases are driven by the OpenSSL security release as announced in [OpenSSL November Security Release](https://nodejs.org/en/blog/vulnerability/openssl-november-2022/) as well as an additional vulnerability that affects all supported release lines. + +## Impact + +The 19.x release line of Node.js is vulnerable to one medium severity issue and two high severity issues. + +The 18.x release line of Node.js is vulnerable to one medium severity issue and two high severity issues. + +The 16.x release line of Node.js is vulnerable to one medium severity issue. + +The 14.x release line of Node.js is vulnerable to one medium severity issue. + +## Release timing + +Releases will be available on, or shortly after, Thursday, November 3rd, 2022. + +## Contact and future updates + +The current Node.js security policy can be found at https://nodejs.org/en/security/. Please follow the process outlined in https://github.com/nodejs/node/blob/master/SECURITY.md if you wish to report a vulnerability in Node.js. + +Subscribe to the low-volume announcement-only nodejs-sec mailing list at https://groups.google.com/forum/#!forum/nodejs-sec to stay up to date on security vulnerabilities and security-related releases of Node.js and the projects maintained in the nodejs GitHub organization. diff --git a/locale/en/site.json b/locale/en/site.json index 4cda96f0894d9..4b21661dfa492 100644 --- a/locale/en/site.json +++ b/locale/en/site.json @@ -131,10 +131,10 @@ }, "banners": { "index": { - "startDate": "2022-10-18T16:00:00.000Z", - "endDate": "2022-10-25T16:00:00.000Z", - "html": "Node.js 19 is now live!", - "link": "https://nodejs.org/en/blog/announcements/v19-release-announce/" + "startDate": "2022-11-01T16:00:00.000Z", + "endDate": "2022-11-14T16:00:00.000Z", + "text": "New security releases to be made available November 3rd, 2022", + "link": "https://nodejs.org/en/blog/vulnerability/november-2022-security-releases/" }, "blacklivesmatter": { "visible": false,