Debian Package Tracker
Register | Log in
Subscribe

node-min-document

Node.js library to provide a minimal DOM implementation

Choose email to subscribe with

general
  • source: node-min-document (main)
  • version: 2.19.0+~cs2.20.2-2
  • maintainer: Debian Javascript Maintainers (archive) (DMD)
  • uploaders: Yadd [DMD] – Roland Mas [DMD]
  • arch: all
  • std-ver: 4.6.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 2.19.0+~cs2.20.2-2
  • testing: 2.19.0+~cs2.20.2-2
  • unstable: 2.19.0+~cs2.20.2-2
versioned links
  • 2.19.0+~cs2.20.2-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • node-min-document
action needed
Problems while searching for a new upstream version high
uscan had problems while searching for a new upstream version:
Unable to read ./package.json, skipping current version
Created: 2023-05-09 Last update: 2025-11-07 16:00
A new upstream version is available: 2.19.0+~cs2.20.4 high
A new upstream version 2.19.0+~cs2.20.4 is available, you should consider packaging it.
Created: 2025-06-29 Last update: 2025-11-07 16:00
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2025-57352: A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespace operations in the removeAttributeNS method. By processing malicious input involving the __proto__ property, an attacker can manipulate the prototype chain of JavaScript objects, leading to denial of service or arbitrary code execution. This issue arises from insufficient validation of attribute namespace removal operations, allowing unintended modification of critical object prototypes. The vulnerability remains unaddressed in the latest available version.
Created: 2025-09-25 Last update: 2025-10-06 19:01
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2025-57352: A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespace operations in the removeAttributeNS method. By processing malicious input involving the __proto__ property, an attacker can manipulate the prototype chain of JavaScript objects, leading to denial of service or arbitrary code execution. This issue arises from insufficient validation of attribute namespace removal operations, allowing unintended modification of critical object prototypes. The vulnerability remains unaddressed in the latest available version.
Created: 2025-09-25 Last update: 2025-10-06 19:01
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • node-min-document could be marked Multi-Arch: foreign
Created: 2023-05-09 Last update: 2025-11-07 18:00
3 new commits since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit 3a4a0a4f08ff7d377353541b4e99c2c46ae15430
Author: Yadd <yadd@debian.org>
Date:   Sat Oct 25 20:50:29 2025 +0200

    debian/watch version 5

commit 929a4fbabeaec762bcdbefbf7cf3383118b9fa4f
Author: Yadd <yadd@debian.org>
Date:   Sat Oct 25 20:50:04 2025 +0200

    Drop "Rules-Requires-Root: no"

commit d07f30208981f0bd08aa6e2fd22b88d6b0073170
Author: Yadd <yadd@debian.org>
Date:   Sat Oct 25 20:50:04 2025 +0200

    Declare compliance with policy 4.7.2
Created: 2025-10-25 Last update: 2025-10-31 23:47
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2025-57352: (needs triaging) A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespace operations in the removeAttributeNS method. By processing malicious input involving the __proto__ property, an attacker can manipulate the prototype chain of JavaScript objects, leading to denial of service or arbitrary code execution. This issue arises from insufficient validation of attribute namespace removal operations, allowing unintended modification of critical object prototypes. The vulnerability remains unaddressed in the latest available version.

You can find information about how to handle this issue in the security team's documentation.

Created: 2025-09-25 Last update: 2025-10-06 19:01
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.6.2).
Created: 2024-04-07 Last update: 2025-02-27 13:24
news
[rss feed]
  • [2023-06-13] node-min-document 2.19.0+~cs2.20.2-2 MIGRATED to testing (Debian testing watch)
  • [2023-05-06] Accepted node-min-document 2.19.0+~cs2.20.2-2 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2023-05-06] Accepted node-min-document 2.19.0+~cs2.20.2-1 (source all) into unstable (Debian FTP Masters) (signed by: Xavier Guimard)
bugs [bug history graph]
  • all: 1
  • RC: 1
  • I&N: 0
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.19.0+~cs2.20.2-2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing