Skip to content
  • Rod Vagg's avatar
    2016-03-31 Version 0.10.44 (Maintenance) Release · d6859151
    Rod Vagg authored
    Notable changes:
    
    * npm: Upgrade to v2.15.1. IMPORTANT: This is a major upgrade to npm
      v2 LTS from the previously deprecated npm v1. (Forrest L Norvell)
    * npm: Upgrade to v2.15.1. Fixes a security flaw in the use of
      authentication tokens in HTTP requests that would allow an attacker
      to set up a server that could collect tokens from users of the
      command-line interface. Authentication tokens have previously been
      sent with every request made by the CLI for logged-in users,
      regardless of the destination of the request. This update fixes this
      by only including those tokens for requests made against the
      registry or registries used for the current install. IMPORTANT:
      This is a major upgrade to npm v2 LTS from the previously deprecated
      npm v1. (Forrest L Norvell) https://github.com/nodejs/node/pull/5967
    * openssl: OpenSSL v1.0.1s disables the EXPORT and LOW ciphers as they
      are obsolete and not considered safe. This release of Node.js turns
      on `OPENSSL_NO_WEAK_SSL_CIPHERS` to fully disable the 27 ciphers
      included in these lists which can be used in SSLv3 and higher. Full
      details can be found in our LTS discussion on the matter
      (https://github.com/nodejs/LTS/issues/85).
      (Shigeki Ohtsu) https://github.com/nodejs/node/pull/5712
    
    PR-URL: https://github.com/nodejs/node/pull/5968
    d6859151
Loading