chore: bump up Node.js to v22.23.2 (#15384)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [node](https://nodejs.org)
([source](https://redirect.github.com/nodejs/node)) | patch | `22.23.1`
→ `22.23.2` |

---

### Release Notes

<details>
<summary>nodejs/node (node)</summary>

###
[`v22.23.2`](https://redirect.github.com/nodejs/node/releases/tag/v22.23.2):
2026-07-29, Version 22.23.2 'Jod' (LTS), @&#8203;marco-ippolito

[Compare
Source](https://redirect.github.com/nodejs/node/compare/v22.23.1...v22.23.2)

This is a security release.

##### Notable Changes

- (CVE-2026-56846) http2: retain header memory in session accounting
(Matteo Collina) – High
- (CVE-2026-56848) http2: defer rst stream while in scope (Matteo
Collina) – High
- (CVE-2026-58043) permission: avoid granting radix split nodes
(RafaelGSS) – High
- (CVE-2026-56850) https: distinguish PFX object-array agent keys
(RafaelGSS) – Medium
- (CVE-2026-58040) https: bind identity checks to session reuse (Matteo
Collina) – Medium
- (CVE-2026-58042) dns: handle large resolveAny address replies
(RafaelGSS) – Medium
- (CVE-2026-58045) zlib: throw on out-of-bounds write buffers
(RafaelGSS) – Medium
- (CVE-2026-56847) permission: enforce fs write permission for trace
events (RafaelGSS) – Low
- (CVE-2026-58039) permission: check final report output path
(RafaelGSS) – Low
- (CVE-2026-58044) http: reject requests exceeding max header count
(Matteo Collina) – Low
- deps: update llhttp to 9.4.3 (Paolo Insogna)
- deps: update undici to 6.28.0 (Node.js GitHub Bot)

##### Commits

-
\[[`4b12ac38a1`](https://redirect.github.com/nodejs/node/commit/4b12ac38a1)]
- **deps**: update llhttp to 9.4.3 (Paolo Insogna)
[nodejs-private/node-private#935](https://redirect.github.com/nodejs-private/node-private/pull/935)
-
\[[`3fd0aa51d0`](https://redirect.github.com/nodejs/node/commit/3fd0aa51d0)]
- **deps**: update undici to 6.28.0 (Node.js GitHub Bot)
[#&#8203;64714](https://redirect.github.com/nodejs/node/pull/64714)
-
\[[`22efc051a3`](https://redirect.github.com/nodejs/node/commit/22efc051a3)]
- **(CVE-2026-58042)** **dns**: handle large resolveAny address replies
(RafaelGSS)
[nodejs-private/node-private#929](https://redirect.github.com/nodejs-private/node-private/pull/929)
-
\[[`c8525ac3a6`](https://redirect.github.com/nodejs/node/commit/c8525ac3a6)]
- **(CVE-2026-58044)** **http**: reject requests exceeding max header
count (Matteo Collina)
[nodejs-private/node-private#932](https://redirect.github.com/nodejs-private/node-private/pull/932)
-
\[[`daa6d25e3d`](https://redirect.github.com/nodejs/node/commit/daa6d25e3d)]
- **(CVE-2026-56848)** **http2**: defer rst stream while in scope
(Matteo Collina)
[nodejs-private/node-private#921](https://redirect.github.com/nodejs-private/node-private/pull/921)
-
\[[`f14d78b9e0`](https://redirect.github.com/nodejs/node/commit/f14d78b9e0)]
- **(CVE-2026-56846)** **http2**: retain header memory in session
accounting (Matteo Collina)
[#&#8203;63752](https://redirect.github.com/nodejs/node/pull/63752)
-
\[[`51123159fe`](https://redirect.github.com/nodejs/node/commit/51123159fe)]
- **(CVE-2026-58040)** **https**: bind identity checks to session reuse
(Matteo Collina)
[nodejs-private/node-private#934](https://redirect.github.com/nodejs-private/node-private/pull/934)
-
\[[`acaf4266b2`](https://redirect.github.com/nodejs/node/commit/acaf4266b2)]
- **(CVE-2026-56850)** **https**: distinguish PFX object-array agent
keys (RafaelGSS)
[nodejs-private/node-private#930](https://redirect.github.com/nodejs-private/node-private/pull/930)
-
\[[`440329f624`](https://redirect.github.com/nodejs/node/commit/440329f624)]
- **(CVE-2026-58043)** **permission**: avoid granting radix split nodes
(RafaelGSS)
[nodejs-private/node-private#911](https://redirect.github.com/nodejs-private/node-private/pull/911)
-
\[[`ed18b9cc07`](https://redirect.github.com/nodejs/node/commit/ed18b9cc07)]
- **(CVE-2026-58039)** **permission**: check final report output path
(RafaelGSS)
[nodejs-private/node-private#926](https://redirect.github.com/nodejs-private/node-private/pull/926)
-
\[[`0566c3cccd`](https://redirect.github.com/nodejs/node/commit/0566c3cccd)]
- **(CVE-2026-56847)** **permission**: enforce fs write permission for
trace events (RafaelGSS)
[nodejs-private/node-private#927](https://redirect.github.com/nodejs-private/node-private/pull/927)
-
\[[`0d072480c3`](https://redirect.github.com/nodejs/node/commit/0d072480c3)]
- **(CVE-2026-58045)** **zlib**: throw on out-of-bounds write buffers
(RafaelGSS)
[nodejs-private/node-private#931](https://redirect.github.com/nodejs-private/node-private/pull/931)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This commit is contained in:
renovate[bot]
2026-07-31 13:51:32 +08:00
committed by GitHub
parent fb647b6003
commit 5c38f1376c
+1 -1
View File
@@ -1 +1 @@
22.23.1
22.23.2