Debian Package Tracker
Register | Log in
Subscribe

node-rollup

ES6 module bundler for JavaScript

Choose email to subscribe with

general
  • source: node-rollup (main)
  • version: 3.29.5-1
  • maintainer: Debian Javascript Maintainers (archive) (DMD)
  • uploaders: Pirate Praveen [DMD] – Sruthi Chandran [DMD] – Bastien Roucariès [DMD]
  • arch: all
  • std-ver: 4.7.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 0.50.0-6
  • oldstable: 2.38.4-1
  • stable: 3.15.0-1+deb12u1
  • testing: 3.29.5-1
  • unstable: 3.29.5-1
versioned links
  • 0.50.0-6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.38.4-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.15.0-1+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.29.5-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • rollup (2 bugs: 0, 1, 1, 0)
action needed
A new upstream version is available: 4.41.1 high
A new upstream version 4.41.1 is available, you should consider packaging it.
Created: 2023-08-26 Last update: 2025-05-28 17:00
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2024-47068: (needs triaging) Rollup is a module bundler for JavaScript. Versions prior to 2.79.2, 3.29.5, and 4.22.4 are susceptible to a DOM Clobbering vulnerability when bundling scripts with properties from `import.meta` (e.g., `import.meta.url`) in `cjs`/`umd`/`iife` format. The DOM Clobbering gadget can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., an `img` tag with an unsanitized `name` attribute) are present. Versions 2.79.2, 3.29.5, and 4.22.4 contain a patch for the vulnerability.

You can find information about how to handle this issue in the security team's documentation.

Created: 2024-09-24 Last update: 2025-03-15 11:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.7.0).
Created: 2025-02-21 Last update: 2025-02-27 13:25
news
[rss feed]
  • [2025-02-19] Accepted node-rollup 3.15.0-1+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Jérémy Lal)
  • [2024-09-30] node-rollup 3.29.5-1 MIGRATED to testing (Debian testing watch)
  • [2024-09-25] Accepted node-rollup 3.29.5-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2023-12-14] node-rollup 3.29.4-3 MIGRATED to testing (Debian testing watch)
  • [2023-12-14] node-rollup 3.29.4-3 MIGRATED to testing (Debian testing watch)
  • [2023-12-12] Accepted node-rollup 3.29.4-3 (source) into unstable (Jérémy Lal)
  • [2023-11-04] node-rollup 3.29.4-2 MIGRATED to testing (Debian testing watch)
  • [2023-11-02] Accepted node-rollup 3.29.4-2 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2023-11-02] Accepted node-rollup 3.29.4-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2023-08-25] node-rollup 3.28.0-2 MIGRATED to testing (Debian testing watch)
  • [2023-08-18] Accepted node-rollup 3.28.0-2 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2023-08-15] Accepted node-rollup 3.28.0-1 (source) into experimental (Yadd) (signed by: Xavier Guimard)
  • [2023-07-19] node-rollup 3.15.0-2 MIGRATED to testing (Debian testing watch)
  • [2023-07-16] Accepted node-rollup 3.15.0-2 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2023-02-27] node-rollup 3.15.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-02-17] Accepted node-rollup 3.15.0-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2023-02-02] node-rollup 3.12.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-01-31] Accepted node-rollup 3.12.0-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2023-01-25] node-rollup 3.10.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-01-19] Accepted node-rollup 3.10.0-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2022-12-23] node-rollup 3.7.5-1 MIGRATED to testing (Debian testing watch)
  • [2022-12-17] Accepted node-rollup 3.7.5-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2022-12-15] node-rollup 3.7.3-1 MIGRATED to testing (Debian testing watch)
  • [2022-12-12] Accepted node-rollup 3.7.3-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2022-12-11] Accepted node-rollup 3.7.2-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2022-12-09] Accepted node-rollup 3.7.0-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2022-11-24] node-rollup 3.4.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-11-22] Accepted node-rollup 3.4.0-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2022-11-19] node-rollup 3.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-11-14] Accepted node-rollup 3.3.0-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • 1
  • 2
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 1
  • M&W: 1
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.29.5-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing