Skip to content

chore(deps): update dependency node to v24.14.1#249

Open
renovate[bot] wants to merge 2 commits intomainfrom
renovate/node-24.x
Open

chore(deps): update dependency node to v24.14.1#249
renovate[bot] wants to merge 2 commits intomainfrom
renovate/node-24.x

Conversation

@renovate
Copy link
Copy Markdown

@renovate renovate bot commented Mar 25, 2026

This PR contains the following updates:

Package Type Update Change OpenSSF
node uses-with patch 24.14.024.14.1 OpenSSF Scorecard
node stage patch 24.14.0-alpine3.2324.14.1-alpine3.23 OpenSSF Scorecard

Release Notes

actions/node-versions (node)

v24.14.1: 24.14.1

Compare Source

Node.js 24.14.1

nodejs/node (node)

v24.14.1: 2026-03-24, Version 24.14.1 'Krypton' (LTS), @​RafaelGSS prepared by @​juanarbol

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-21710) use null prototype for headersDistinct/trailersDistinct (Matteo Collina) - High
  • (CVE-2026-21637) wrap SNICallback invocation in try/catch (Matteo Collina) - High
  • (CVE-2026-21717) test array index hash collision (Joyee Cheung) - Medium
  • (CVE-2026-21713) use timing-safe comparison in Web Cryptography HMAC and KMAC (Filip Skokan) - Medium
  • (CVE-2026-21714) handle NGHTTP2_ERR_FLOW_CONTROL error code (RafaelGSS) - Medium
  • (CVE-2026-21712) handle url crash on different url formats (RafaelGSS) - Medium
  • (CVE-2026-21716) include permission check on lib/fs/promises (RafaelGSS) - Low
  • (CVE-2026-21715) add permission check to realpath.native (RafaelGSS) - Low
Commits

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the renovate label Mar 25, 2026
@renovate renovate bot requested a review from a team as a code owner March 25, 2026 04:40
@renovate renovate bot removed the request for review from a team March 25, 2026 04:40
@renovate renovate bot added the renovate label Mar 25, 2026
@renovate renovate bot requested a review from janishorsts March 25, 2026 04:40
@github-actions
Copy link
Copy Markdown

github-actions bot commented Mar 25, 2026

➖ Are we earthbuild yet?

No change in "earthly" occurrences

📈 Overall Progress

Branch Total Count
main 7
This PR 7
Difference +0

Keep up the great work migrating from Earthly to Earthbuild! 🚀

💡 Tips for finding more occurrences

Run locally to see detailed breakdown:

./.github/scripts/count-earthly.sh

Note that the goal is not to reach 0.
There is anticipated to be at least some occurences of earthly in the source code due to backwards compatibility with config files and language constructs.

@renovate renovate bot force-pushed the renovate/node-24.x branch from 1d7ee5b to 2e724f5 Compare March 26, 2026 10:00
@renovate
Copy link
Copy Markdown
Author

renovate bot commented Mar 26, 2026

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@gilescope gilescope enabled auto-merge (squash) March 26, 2026 13:05
gilescope pushed a commit that referenced this pull request Mar 28, 2026
Roll up open Renovate PRs into a single update:
- node 24.14.0 → 24.14.1 (#249)
- npm 11.11.0 → 11.12.0 (#243)
- eslint 10.0.3 → 10.1.0 (#247)
- typescript-eslint 8.57.0 → 8.57.2 (#246)
- vitest 4.0.18 → 4.1.1, @vitest/coverage-v8 4.0.18 → 4.1.1 (#244)
- lock file maintenance (#245)

Note: typescript 6.0.2 (#250) excluded due to peer dependency
conflict with typescript-eslint 8.57.x (requires typescript <6.0.0).

https://claude.ai/code/session_01GjSzPRr2nXe4J4XLh925ck
gilescope pushed a commit that referenced this pull request Mar 28, 2026
The digest from Renovate PR #249 was a single-platform digest that
didn't match any platform in the manifest. Replace with the correct
multi-arch index digest.

https://claude.ai/code/session_01GjSzPRr2nXe4J4XLh925ck
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant