Skip to content

Add a warning on EOL versions #1401

Description

@RafaelGSS

I was talking with @marco-ippolito and we were discussing having ways for people to know when they are using an insecure version of Node.js. Instead of having a flag (#852), what if we release a patch version after one or two months of EOL alerting users they are using an EOL version?

I mean, if they pin the version and don't get the last release, they won't see the warning, but I assume it will affect most users. We could try to do it to non-LTS versions first, and then we expand the coverage to all EOL versions (starting this year, of course).

cc: @nodejs/security-wg @nodejs/tsc

Activity

  1. mhdawson commented on Nov 20, 2024

    @mhdawson
    Member

    @RafaelGSS as you mentioned if they pin they won't get a warning.

    If instead we published as CVE indicating the release was EOL they would get if they are running CVE scans. I suspect this would be a more reliable way of having it be recognized as a risk.

  2. marco-ippolito commented on Nov 20, 2024

    @marco-ippolito
    Member

    The CVE could be for weakness CWE-1104 or CWE-1329
    which would make sense

  3. RafaelGSS commented on Nov 20, 2024

    @RafaelGSS
    MemberAuthor

    I think we could do both, issue a single CVE alerting EOL (after a sec release) and create a patch release with a warning?

  4. mhdawson commented on Nov 20, 2024

    @mhdawson
    Member

    I think doing both makes sense to me, provide we have a volunteer to do the patch release (as I think that's more work that doing the CVE).

  5. mhdawson commented on Nov 20, 2024

    @mhdawson
    Member

    In terms of the CVE's I think I prefer CWE-1104 as it is possible to update Node.js, you just need to move to a later Major so CWE-1329 does not seem like as good a fit to me.

  6. RafaelGSS commented on Nov 26, 2024

    @RafaelGSS
    MemberAuthor

    Right, how can we move forward with it? Should we open a PR to document it somewhere?

  7. ljharb commented on Nov 26, 2024

    @ljharb
    SponsorMember

    For the warning, presumably there'd be an env/NODE_OPTIONS way to disable it, so as to not break CI and child process workflows?

  8. RafaelGSS commented on Nov 26, 2024

    @RafaelGSS
    MemberAuthor

    Yes, we can use the same --security-revert CLI

  9. mcollina commented on Dec 1, 2024

    @mcollina
    SponsorMember

    I'm not entirely convinced a warning is needed, but the idea of a cve is great.

    Can we start by issuing one for all past releases?

  10. marco-ippolito commented on Dec 1, 2024

    @marco-ippolito
    Member

    I'm not entirely convinced a warning is needed, but the idea of a cve is great.

    Can we start by issuing one for all past releases?

    I think so, I think it needs to go through a H1 report

  11. RafaelGSS commented on Dec 1, 2024

    @RafaelGSS
    MemberAuthor

    Let's do it for v16.x, v19.x, and v21.x. I can take care of it early this week.

  12. RafaelGSS commented on Dec 2, 2024

    @RafaelGSS
    MemberAuthor

    I've been talking with @rginn who suggested announcing on Node.js social before making this move. I asked her to provide some details about openjs health here.

  13. RafaelGSS commented on Dec 10, 2024

    @RafaelGSS
    MemberAuthor

    FYI I'm going to create an "announcement" (https://github.com/orgs/nodejs/discussions/categories/announcements) informing Node.js collaborators that next week we'll be issuing a CVE for Node.js 16, 19 and 21, then I'll ask @nodejs/social to share a post that I can create or the official account can create informing our users.

  14. mcollina commented on Dec 10, 2024

    @mcollina
    SponsorMember

    @RafaelGSS please write a public blog post instead, and set the date on or after the 7th of January. Doing this right before the holidays is not helping anyone.

  15. 15 remaining items

  16. github-actions commented on Apr 24, 2025

    @github-actions
    Contributor

    This issue has been inactive for 90 days. It will be closed in 14 days unless there is further activity or the stale label is taken off.

  17. github-actions commented on Jul 24, 2025

    @github-actions
    Contributor

    This issue has been inactive for 90 days. It will be closed in 14 days unless there is further activity or the stale label is taken off.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions