Debian Package Tracker
Register | Log in
Subscribe

node-request

simplified HTTP request client module for Node.js

Choose email to subscribe with

general
  • source: node-request (main)
  • version: 2.88.1-6
  • maintainer: Debian Javascript Maintainers (archive) (DMD)
  • uploaders: Pirate Praveen [DMD] – Jérémy Lal [DMD]
  • arch: all
  • std-ver: 4.6.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.88.1-2
  • o-o-bpo: 2.88.1-5~bpo10+1
  • oldstable: 2.88.1-5
  • stable: 2.88.1-6
  • testing: 2.88.1-6
  • unstable: 2.88.1-6
versioned links
  • 2.88.1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.88.1-5~bpo10+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.88.1-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.88.1-6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • node-request (1 bugs: 1, 0, 0, 0)
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2023-28155: ** UNSUPPORTED WHEN ASSIGNED ** The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Created: 2023-06-11 Last update: 2023-06-12 07:00
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2023-28155: ** UNSUPPORTED WHEN ASSIGNED ** The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Created: 2023-03-20 Last update: 2023-06-12 07:00
2 new commits since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit e281b660efdc538d0d3c0a9f2d5640a94d5d9be6
Author: Debian Janitor <janitor@jelmer.uk>
Date:   Wed Nov 16 01:52:06 2022 +0000

    Set upstream metadata fields: Bug-Database, Bug-Submit, Repository-Browse.
    
    Changes-By: lintian-brush

commit d20e52e713ff5e90ff2d022932534fffb3819d55
Author: Yadd <yadd@debian.org>
Date:   Thu Nov 10 12:12:01 2022 +0100

    Drop useless dependency version constraints
Created: 2021-04-15 Last update: 2023-09-27 15:30
1 low-priority security issue in bullseye low

There is 1 open security issue in bullseye.

1 issue left for the package maintainer to handle:
  • CVE-2023-28155: (needs triaging) ** UNSUPPORTED WHEN ASSIGNED ** The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

You can find information about how to handle this issue in the security team's documentation.

Created: 2023-03-20 Last update: 2023-06-12 07:00
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2023-28155: (needs triaging) ** UNSUPPORTED WHEN ASSIGNED ** The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

You can find information about how to handle this issue in the security team's documentation.

Created: 2023-06-10 Last update: 2023-06-12 07:00
debian/patches: 1 patch to forward upstream low

Among the 3 debian patches available in version 2.88.1-6 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2023-02-26 15:54
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.2 instead of 4.6.1).
Created: 2022-12-17 Last update: 2022-12-17 19:18
news
[rss feed]
  • [2022-11-12] node-request 2.88.1-6 MIGRATED to testing (Debian testing watch)
  • [2022-11-10] Accepted node-request 2.88.1-6 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2020-12-21] Accepted node-request 2.88.1-5~bpo10+1 (source all) into buster-backports, buster-backports (Debian FTP Masters) (signed by: Praveen Arimbrathodiyil)
  • [2020-12-10] node-request 2.88.1-5 MIGRATED to testing (Debian testing watch)
  • [2020-12-07] Accepted node-request 2.88.1-5 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2020-05-26] node-request 2.88.1-4 MIGRATED to testing (Debian testing watch)
  • [2020-04-10] Accepted node-request 2.88.1-4 (source) into unstable (Xavier Guimard)
  • [2020-01-23] node-request 2.88.1-3 MIGRATED to testing (Debian testing watch)
  • [2020-01-21] Accepted node-request 2.88.1-3 (source) into unstable (Xavier Guimard)
  • [2018-12-23] Accepted node-request 2.88.1-2~bpo9+1 (source all) into stretch-backports, stretch-backports (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2018-10-03] node-request 2.88.1-2 MIGRATED to testing (Debian testing watch)
  • [2018-09-30] Accepted node-request 2.88.1-2 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2018-09-24] node-request 2.88.1-1 MIGRATED to testing (Debian testing watch)
  • [2018-09-20] Accepted node-request 2.88.1-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2013-09-13] node-request 2.26.1-1 MIGRATED to testing (Debian testing watch)
  • [2013-08-14] Accepted node-request 2.26.1-1 (source all) (Jérémy Lal)
  • [2012-03-17] Accepted node-request 2.9.153-1 (source all) (David Paleino)
  • [2011-12-31] Accepted node-request 2.9.3-1 (source all) (David Paleino)
  • [2011-11-23] Accepted node-request 2.2.5-2 (source all) (David Paleino)
  • [2011-11-17] Accepted node-request 2.2.5-1 (source all) (David Paleino)
  • [2011-10-16] Accepted node-request 2.1.1-1 (source all) (David Paleino)
bugs [bug history graph]
  • all: 2
  • RC: 1
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.88.1-6

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing