# openssl

Published articles for openssl.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Node.js 26.9.0 (Current)

DevFeed: [Node.js 26.9.0 (Current)](<https://devfeed.tech/articles/node-js-26-9-0-current-31549.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/release/v26.9.0>)

Published: 2026-09-16T18:17:42Z

Content type: release

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [crypto](<https://devfeed.tech/tags/crypto.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [node](<https://devfeed.tech/tags/node.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [version](<https://devfeed.tech/tags/version.md>)

### AI overview

Node.js 26.9.0 is a current release with semver-minor additions and fixes across cryptography, module loading, Web Workers, benchmarking, builds, and diagnostics.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Security updates for Wednesday

DevFeed: [Security updates for Wednesday](<https://devfeed.tech/articles/security-updates-for-wednesday-31515.md>)

Original publisher: [Read original article](<https://lwn.net/Articles/1094720/>)

Author: corbet

Published: 2026-09-16T13:40:53Z

Content type: news

Language: en

Sources: [LWN.net](<https://devfeed.tech/sources/lwn-net.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [nginx](<https://devfeed.tech/topics/nginx.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [Python](<https://devfeed.tech/topics/python.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>)

Tags: [debian](<https://devfeed.tech/tags/debian.md>), [linux](<https://devfeed.tech/tags/linux.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

Security updates were issued by AlmaLinux, Debian, Fedora, Oracle, Red Hat, SUSE, and Ubuntu for packages including kernels, nginx, OpenSSL, Python, Perl, Git, Docker, OpenSSH, and other software.

### Source excerpt

Security updates have been issued by AlmaLinux (kernel, kernel-rt, libkcapi, nginx, nginx:1.24, openssl, osbuild-composer, perl, perl:5.32, python-tornado, rsync, and rust), Debian (cjose and nginx), Fedora (environment-modules, erlang, GitPython, knot, perl-Authen-SASL, python-configargparse, ruby, rubygems, and sblim-sfcb), Oracle (firefox, git-lfs, gstreamer1-plugins-base, kernel, libkcapi, nginx, nginx:1.26, openssl, osbuild-composer, perl, perl-YAML-Syck, postgresql18, python-tornado, and rust), Red Hat (fence-agents, git-lfs, microcode_ctl, osbuild-composer, podman, python-pyasn1, and resource-agents), SUSE (389-ds, ant, bson-devel, chirp-20260911, docker, gimp, google-cloud-sap-agent, hauler, kernel, kimi-code, libpcap, python-GitPython, python310, syncthing, yast2-samba-client, and zstd-jni), and Ubuntu (aom, imagemagick, kitty, openssh, phpseclib, policykit-1, python-sql, python-webob, shibboleth-sp, simplesamlphp, snapcast, srt, and suricata-update).

## Security updates for Tuesday

DevFeed: [Security updates for Tuesday](<https://devfeed.tech/articles/security-updates-for-tuesday-26596.md>)

Original publisher: [Read original article](<https://lwn.net/Articles/1094469/>)

Author: jzb

Published: 2026-09-15T13:10:46Z

Content type: news

Language: en

Sources: [LWN.net](<https://devfeed.tech/sources/lwn-net.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [Fedora](<https://devfeed.tech/topics/fedora.md>), [Ubuntu](<https://devfeed.tech/topics/ubuntu.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Grafana](<https://devfeed.tech/topics/grafana.md>), [nginx](<https://devfeed.tech/topics/nginx.md>)

Tags: [debian](<https://devfeed.tech/tags/debian.md>), [grafana](<https://devfeed.tech/tags/grafana.md>), [hat](<https://devfeed.tech/tags/hat.md>), [java](<https://devfeed.tech/tags/java.md>), [linux](<https://devfeed.tech/tags/linux.md>), [mozilla](<https://devfeed.tech/tags/mozilla.md>), [network](<https://devfeed.tech/tags/network.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [php](<https://devfeed.tech/tags/php.md>), [podman](<https://devfeed.tech/tags/podman.md>), [python](<https://devfeed.tech/tags/python.md>), [rust](<https://devfeed.tech/tags/rust.md>), [security](<https://devfeed.tech/tags/security.md>), [systemd](<https://devfeed.tech/tags/systemd.md>), [ubuntu](<https://devfeed.tech/tags/ubuntu.md>), [updates](<https://devfeed.tech/tags/updates.md>), [vim](<https://devfeed.tech/tags/vim.md>)

### AI overview

Debian, Fedora, Mageia, Red Hat, SUSE, and Ubuntu issued security updates for a broad range of packages and components, including Linux-related tools, libraries, servers, programming environments, and desktop software.

### Source excerpt

Security updates have been issued by Debian (network-manager-l2tp and urwid), Fedora (perl-Dancer2, perl-Data-Entropy, perl-DBI, perl-Protocol-HTTP2, podman-tui, rust-lru, and rust-lru0.16), Mageia (bzip2, cups-filters, libcupsfilters, libssh2, perl-Authen-SASL, perl-HTML-FormFu, tar, unzip, and zip), Red Hat (grafana and image-builder), SUSE (389-ds, acl, attr, apache2-mod_auth_openidc, apr-util, aws-nitro-enclaves-cli, bzip2, c-ares, clamav, cpio, curl, dhcpcd, dovecot23, dovecot24, dracut, emacs, fuse-overlayfs, go1.25-openssl, go1.26-openssl, google-cloud-sap-agent, google-osconfig-agent, govulncheck-vulndb, gstreamer-devtools, gzip, helm, java-17-openjdk, java-21-openjdk, java-25-openjdk, jq, libBasicUsageEnvironment2, libgpg-error, libidn, librest, libusb-1_0, libvirt, LibVNCServer, libzypp, zypper, lkl, mcphost, MozillaFirefox, mozilla-nspr, mozilla-nss, rust-cbindgen, MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen, MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen, msgpack-c, multipath-tools, NetworkManager, openexr, openssl-3, perl-Protocol-HTTP2, perl-URI, php-composer2, postgresql14, postgresql15, postgresql16, postgresql17, postgresql18, python-aiohttp, python-cryptography, python-h2, python-ruff, python-sqlparse, python311, python312, python39.SUSE_SLE-15-SP3_Update, rav1e, rpcbind, sssd, systemd, tomcat, tomcat11, ucode-intel, udisks2, vim, and wicked2nm), and Ubuntu (cgit, dracut, freeciv, konsole, libinput, linux-azure, linux-nvidia-7.0, nginx, vips, and yelp).

## New in Symfony 8.2: KeyManagement Component

DevFeed: [New in Symfony 8.2: KeyManagement Component](<https://devfeed.tech/articles/new-in-symfony-8-2-keymanagement-component-26604.md>)

Original publisher: [Read original article](<https://symfony.com/blog/new-in-symfony-8-2-keymanagement-component>)

Author: Javier Eguiluz

Published: 2026-09-15T07:11:00Z

Content type: release

Language: en

Sources: [Symfony Blog](<https://devfeed.tech/sources/symfony-blog.md>)

Topics: [Symfony](<https://devfeed.tech/topics/symfony.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Azure](<https://devfeed.tech/topics/azure.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [api](<https://devfeed.tech/tags/api.md>), [article](<https://devfeed.tech/tags/article.md>), [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [backend](<https://devfeed.tech/tags/backend.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [features](<https://devfeed.tech/tags/features.md>), [google](<https://devfeed.tech/tags/google.md>), [hashicorp-vault](<https://devfeed.tech/tags/hashicorp-vault.md>), [kms](<https://devfeed.tech/tags/kms.md>), [new-features](<https://devfeed.tech/tags/new-features.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [sdk](<https://devfeed.tech/tags/sdk.md>), [symfony](<https://devfeed.tech/tags/symfony.md>)

### AI overview

Symfony 8.2 introduces an experimental KeyManagement component that provides one API for AWS KMS, Azure Key Vault, Google Cloud KMS, and HashiCorp Vault. It supports direct and envelope encryption, local development backends, provider bridges, console commands, debug-toolbar integration, and Doctrine support.

### Source excerpt

This is the first article in a series showcasing the most important new features introduced by Symfony 8.2, which will be released at the end of November 2026. Contributed...

## curl 8.22.0

DevFeed: [curl 8.22.0](<https://devfeed.tech/articles/curl-8-22-0-18904.md>)

Original publisher: [Read original article](<https://daniel.haxx.se/blog/2026/09/02/curl-8-22-0/>)

Author: Daniel Stenberg

Published: 2026-09-02T05:52:46Z

Content type: release

Language: en

Sources: [Daniel Stenberg](<https://devfeed.tech/sources/daniel-stenberg.md>)

Topics: [cURL](<https://devfeed.tech/topics/curl.md>), [Security](<https://devfeed.tech/topics/security.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [API](<https://devfeed.tech/topics/api.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [bugfixes](<https://devfeed.tech/tags/bugfixes.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [curl](<https://devfeed.tech/tags/curl.md>), [curl-and-libcurl](<https://devfeed.tech/tags/curl-and-libcurl.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [http](<https://devfeed.tech/tags/http.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

The curl 8.22.0 release includes six changes, 302 bug fixes, and nine curl/libcurl security fixes plus one wcurl fix. It adds Apple GSS Framework support, API guards, experimental HTTP Message Signatures support, and Apple fast UDP, while blocking NTLM fallback in SPNEGO and dropping TLS-SRP support.

### Source excerpt

Welcome to this new release. Get it as always from https://curl.se. If you rather want a security-patched older release branch, stay tuned for the follow-up Rock-solid curl announcement within a few days. Release presentation Numbers the 276th release6 changes70 days (total: 10,887)302 bugfixes (total: 14,489)525 commits (total: 39,608)0 new public libcurl function (total: 100)4 new ... Continue reading curl 8.22.0 ->

## Announcing Oracle Jipher 10.37: FIPS 140-3 Cryptography for Java

DevFeed: [Announcing Oracle Jipher 10.37: FIPS 140-3 Cryptography for Java](<https://devfeed.tech/articles/announcing-oracle-jipher-10-37-fips-140-3-cryptography-for-java-15127.md>)

Original publisher: [Read original article](<https://inside.java/2026/08/25/jipher-cryptography-for-java/>)

Author: Poonam Parhar

Published: 2026-08-25T00:00:00Z

Content type: release

Language: en

Sources: [Inside Java](<https://devfeed.tech/sources/inside-java.md>)

Topics: [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [fips 140-3](<https://devfeed.tech/topics/fips-140-3.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [Java](<https://devfeed.tech/topics/java.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>)

Tags: [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-140-3](<https://devfeed.tech/tags/fips-140-3.md>), [java](<https://devfeed.tech/tags/java.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [oracle](<https://devfeed.tech/tags/oracle.md>), [security](<https://devfeed.tech/tags/security.md>), [standard](<https://devfeed.tech/tags/standard.md>)

### AI overview

Oracle Jipher 10 packages a FIPS 140-3 validated OpenSSL cryptographic module and exposes cryptographic services through Java Cryptography Architecture (JCA).

### Source excerpt

Oracle Jipher 10 packages a FIPS 140-3 validated OpenSSL cryptographic module, making cryptographic services available through the standard Java Cryptography Architecture (JCA) framework.

## Chainguard FIPS enters 2026 with OpenSSL 3.1.2 and better CMVP visibility

DevFeed: [Chainguard FIPS enters 2026 with OpenSSL 3.1.2 and better CMVP visibility](<https://devfeed.tech/articles/chainguard-fips-enters-2026-with-openssl-3-1-2-and-better-cmvp-visibility-12944.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-fips-enters-2026-with-openssl-3-1-2-and-better-cmvp-visibility>)

Published: 2026-01-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [container images](<https://devfeed.tech/topics/container-images.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-fips](<https://devfeed.tech/tags/chainguard-fips.md>), [cmvp](<https://devfeed.tech/tags/cmvp.md>), [cmvp-sboms](<https://devfeed.tech/tags/cmvp-sboms.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-140-3](<https://devfeed.tech/tags/fips-140-3.md>), [fips-compliance](<https://devfeed.tech/tags/fips-compliance.md>), [fips-containers](<https://devfeed.tech/tags/fips-containers.md>), [fips-validation](<https://devfeed.tech/tags/fips-validation.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [validation](<https://devfeed.tech/tags/validation.md>)

### AI overview

Chainguard updates its FIPS container images to use the Chainguard FIPS provider for OpenSSL 3.1.2, identified by CMVP certificate #5102. The images now expose CMVP and entropy certification numbers through SBOM packages, while future OpenSSL 3.4 and 3.6 upgrades remain under coordination and review with NIST.

### Source excerpt

We updated our FIPS container images with OpenSSL 3.1.2 (CMVP #5102), clearer CMVP visibility in SBOMs, and a roadmap for upcoming FIPS 140-3 cryptography.

## \[Pentesting\] HTTP auth, part I: basic

DevFeed: [\[Pentesting\] HTTP auth, part I: basic](<https://devfeed.tech/articles/pentesting-http-auth-part-i-basic-20539.md>)

Original publisher: [Read original article](<https://yurichev.com/blog/HTTP_auth_1/>)

Published: 2025-11-20T23:00:00Z

Content type: tutorial

Language: en

Sources: [Dennis Yurichev](<https://devfeed.tech/sources/dennis-yurichev.md>)

Topics: [HTTP](<https://devfeed.tech/topics/http.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [openssl](<https://devfeed.tech/topics/openssl.md>)

Tags: [blog-post](<https://devfeed.tech/tags/blog-post.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [http](<https://devfeed.tech/tags/http.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [password](<https://devfeed.tech/tags/password.md>)

### AI overview

A pentesting tutorial explains HTTP Basic Authentication setup with htpasswd and .htaccess, showing the credentials exchanged by a browser. It warns that Basic Authentication is weak without TLS because Base64 is only obfuscation, and discusses salted password hashes, hashcat cracking, and OpenSSL support.

### Source excerpt

[Pentesting] HTTP auth, part I: basic

## Notes to self: Semaphore-UI secrets

DevFeed: [Notes to self: Semaphore-UI secrets](<https://devfeed.tech/articles/notes-to-self-semaphore-ui-secrets-41901.md>)

Original publisher: [Read original article](<https://jpmens.net/2025/10/28/notes-to-self-semaphore-ui-secrets/>)

Author: Jan-Piet Mens

Published: 2025-10-27T23:00:00Z

Content type: article

Language: en

Sources: [Jan-Piet Mens](<https://devfeed.tech/sources/jan-piet-mens.md>)

Topics: [Encryption](<https://devfeed.tech/topics/encryption.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [SQLite](<https://devfeed.tech/topics/sqlite.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [data](<https://devfeed.tech/topics/data.md>), [private key](<https://devfeed.tech/topics/private-key.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [Code](<https://devfeed.tech/topics/code.md>), [ed25519](<https://devfeed.tech/topics/ed25519.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [code](<https://devfeed.tech/tags/code.md>), [database](<https://devfeed.tech/tags/database.md>), [ed25519](<https://devfeed.tech/tags/ed25519.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [environment-variables](<https://devfeed.tech/tags/environment-variables.md>), [jan-piet-mens](<https://devfeed.tech/tags/jan-piet-mens.md>), [jpm](<https://devfeed.tech/tags/jpm.md>), [jpmens](<https://devfeed.tech/tags/jpmens.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [sql](<https://devfeed.tech/tags/sql.md>), [ssh](<https://devfeed.tech/tags/ssh.md>)

### AI overview

The article examines how Semaphore UI stores configured secrets, including variable-group secrets, SSH keys, and login credentials. It describes AES encryption at rest in the database, identifies the nonce placement and authenticated-encryption limitation of openssl enc, and adapts Semaphore UI source code to decrypt the stored values.

### Source excerpt

I've been looking a bit more closely at Semaphore UI and was curious how secrets I can configure for it are stored. There are two distinct kinds of secrets as far as I've been able to ascertain, and they're in either variable groups or in one or more key stores (one key store for the CE edition, more than one for the Pro). I create three such secret values, using the UI: a secret in a variable group; secret environment variables in a variable group are also encrypted and work like "normal" secret variables: an SSH key in a key store into which I paste the SSH key's passphrase and the private key, generated with ssh-keygen -C DemoKey -t ed25519 -f sema1: a login/password combination a playbook can, say, use to login to "something": These values are then encrypted at rest with AES into the database, which is what the documentation states, and an SQL select confirms base64-encoded data in the secret column (id 1 was placed there by the setup routine): sqlite> SELECT id, name, type, SUBSTR(secret, 1, 25) AS secret FROM access_key; ┌────┬──────────────┬────────────────┬───────────────────────────┐ │ id │ name │ type │ secret │ ├────┼──────────────┼────────────────┼───────────────────────────┤ │ 1 │ None │ none │ │ │ 2 │ mug │ string │ cIRZIUUaFCxajOak6I51agLyq │ │ 3 │ dev-hosts │ ssh │ EzLAwD/CB7y23x/XABElWrF9g │ │ 4 │ router-creds │ login_password │ 6in0q49PmW1XrhQ33wTEO/GuG │ └────┴──────────────┴────────────────┴───────────────────────────┘ I spend a futile 20 minutes trying to decrypt the binary data (i.e. after base64 decoding) using openssl enc -d, futile because I only find out later that the nonce is actually in the first 12 bytes of the encrypted blob. I also spend an impossible amount of time consulting a robot which insists on hallucinating and leading me up the garden path until I'm breathless. And then, finally, I read in enc's documentation: This command does not support authenticated encryption modes like CCM and GCM, and will not support such modes in the

## Node.js 22.21.0 (LTS)

DevFeed: [Node.js 22.21.0 (LTS)](<https://devfeed.tech/articles/node-js-22-21-0-lts-2773.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/release/v22.21.0>)

Published: 2025-10-20T23:51:44Z

Content type: release

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Benchmark](<https://devfeed.tech/topics/benchmark.md>), [Security](<https://devfeed.tech/topics/security.md>), [WebAssembly](<https://devfeed.tech/topics/web-assembly.md>)

Tags: [benchmark](<https://devfeed.tech/tags/benchmark.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [http](<https://devfeed.tech/tags/http.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [lts](<https://devfeed.tech/tags/lts.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [npm](<https://devfeed.tech/tags/npm.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [race-condition](<https://devfeed.tech/tags/race-condition.md>), [security](<https://devfeed.tech/tags/security.md>), [webassembly](<https://devfeed.tech/tags/webassembly.md>)

### AI overview

Node.js 22.21.0 is an LTS release adding command-line and HTTP proxy capabilities, server-controlled HTTP upgrades, and built-in proxy support. It also includes dependency updates, OpenSSL upgrades, npm 10.9.4, performance changes, diagnostics fixes, documentation improvements, and security-policy documentation.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Node.js 24.10.0 (Current)

DevFeed: [Node.js 24.10.0 (Current)](<https://devfeed.tech/articles/node-js-24-10-0-current-2809.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/release/v24.10.0>)

Published: 2025-10-11T16:20:00Z

Content type: release

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [servers](<https://devfeed.tech/topics/servers.md>), [Web](<https://devfeed.tech/topics/web.md>), [npm](<https://devfeed.tech/topics/npm.md>), [V8](<https://devfeed.tech/topics/v8.md>)

Tags: [benchmark](<https://devfeed.tech/tags/benchmark.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [cross-platform](<https://devfeed.tech/tags/cross-platform.md>), [doc](<https://devfeed.tech/tags/doc.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [meta](<https://devfeed.tech/tags/meta.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [npm](<https://devfeed.tech/tags/npm.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [servers](<https://devfeed.tech/tags/servers.md>)

### AI overview

Node.js 24.10.0 is a Current release containing minor changes, performance improvements, dependency updates, documentation changes, and maintenance work. Notable updates include per-stream console options, a SQLite authorization API, V8 and npm updates, OpenSSL 3.5.4 upgrades, and improvements to diagnostic channels and priority queues.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Node.js 22.20.0 (LTS)

DevFeed: [Node.js 22.20.0 (LTS)](<https://devfeed.tech/articles/node-js-22-20-0-lts-2772.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/release/v22.20.0>)

Published: 2025-09-24T13:48:52Z

Content type: release

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [servers](<https://devfeed.tech/topics/servers.md>)

Tags: [cpu](<https://devfeed.tech/tags/cpu.md>), [cross-platform](<https://devfeed.tech/tags/cross-platform.md>), [http](<https://devfeed.tech/tags/http.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [lts](<https://devfeed.tech/tags/lts.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [process](<https://devfeed.tech/tags/process.md>), [servers](<https://devfeed.tech/tags/servers.md>), [sqlite](<https://devfeed.tech/tags/sqlite.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

Node.js 22.20.0 is an LTS release that updates the bundled OpenSSL version to 3.5.2, extending support for official and default-configured builds through the planned 2027-04-30 end-of-life date. It also includes HTTP, HTTP/2, stream, test runner, worker profiling, build, crypto, and documentation changes.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## TLS Certificate Cheat Sheet - OpenSSL & Curl

DevFeed: [TLS Certificate Cheat Sheet - OpenSSL & Curl](<https://devfeed.tech/articles/tls-certificate-cheat-sheet-openssl-curl-31866.md>)

Original publisher: [Read original article](<https://www.metachris.dev/2025/09/tls-certificate-cheat-sheet-openssl-curl/>)

Author: Chris Hager

Published: 2025-09-22T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chris Hager](<https://devfeed.tech/sources/chris-hager.md>)

Topics: [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [Cheat sheet](<https://devfeed.tech/topics/cheatsheet.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [cURL](<https://devfeed.tech/topics/curl.md>)

Tags: [certificates](<https://devfeed.tech/tags/certificates.md>), [cheat-sheet](<https://devfeed.tech/tags/cheat-sheet.md>), [curl](<https://devfeed.tech/tags/curl.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [tls](<https://devfeed.tech/tags/tls.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

A cheat sheet for creating, inspecting, signing, validating, and testing TLS certificates and related keys and CSRs using OpenSSL and cURL.

### Source excerpt

https://collective.flashbots.net/t/tls-certificates-know-how-quick-reference/5292

## Announcing Kernel-Independent FIPS for Java

DevFeed: [Announcing Kernel-Independent FIPS for Java](<https://devfeed.tech/articles/announcing-kernel-independent-fips-for-java-12886.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-kernel-independent-fips-for-java>)

Published: 2025-08-14T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Java](<https://devfeed.tech/topics/java.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [amazon](<https://devfeed.tech/tags/amazon.md>), [ato](<https://devfeed.tech/tags/ato.md>), [azure](<https://devfeed.tech/tags/azure.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-fips-images](<https://devfeed.tech/tags/chainguard-fips-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cos](<https://devfeed.tech/tags/cos.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-ato](<https://devfeed.tech/tags/fedramp-ato.md>), [fedramp-containers](<https://devfeed.tech/tags/fedramp-containers.md>), [fips](<https://devfeed.tech/tags/fips.md>), [implementation](<https://devfeed.tech/tags/implementation.md>), [java](<https://devfeed.tech/tags/java.md>), [linux](<https://devfeed.tech/tags/linux.md>), [nist](<https://devfeed.tech/tags/nist.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Chainguard announces Kernel-Independent FIPS availability across its Java FIPS image catalog. The update uses FIPS-validated cryptography and validated userspace entropy, allowing Java FIPS workloads to run with any host kernel and on platforms including GKE with COS, Amazon Bottlerocket, Flatcar Linux, and Azure Linux. It is intended to simplify production deployment and accelerate FedRAMP authorization to operate.

### Source excerpt

Kernel-Independent FIPS is now available across the full catalog of Chainguard FIPS images for Java, simplifying and accelerating compliance for FedRAMP ATO.

## Node.js 24.5.0 (Current)

DevFeed: [Node.js 24.5.0 (Current)](<https://devfeed.tech/articles/node-js-24-5-0-current-2829.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/release/v24.5.0>)

Published: 2025-07-31T21:52:17Z

Content type: release

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [wasm](<https://devfeed.tech/topics/wasm.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Web](<https://devfeed.tech/topics/web.md>), [Web Development](<https://devfeed.tech/topics/web-development.md>)

Tags: [javascript](<https://devfeed.tech/tags/javascript.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [release](<https://devfeed.tech/tags/release.md>), [tls](<https://devfeed.tech/tags/tls.md>), [wasm](<https://devfeed.tech/tags/wasm.md>), [webassembly](<https://devfeed.tech/tags/webassembly.md>)

### AI overview

Node.js 24.5.0 is a current release that updates its OpenSSL distribution, adds WebAssembly module import support, introduces proxy support for the built-in HTTP/HTTPS client, and provides dynamic CA certificate configuration for TLS clients. It also includes several CLI, DNS, networking, worker, benchmark, diagnostics, buffer, and build changes.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Forging Ahead in Federal Compliance: Chainguard's FIPS 140-3 and 186-5 Milestones

DevFeed: [Forging Ahead in Federal Compliance: Chainguard's FIPS 140-3 and 186-5 Milestones](<https://devfeed.tech/articles/forging-ahead-in-federal-compliance-chainguard-s-fips-140-3-and-186-5-milestones-13048.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/forging-ahead-in-federal-compliance-chainguards-fips-140-3-and-186-5-milestones>)

Published: 2025-06-06T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [interoperability](<https://devfeed.tech/topics/interoperability.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-fips](<https://devfeed.tech/tags/chainguard-fips.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [digital-signature](<https://devfeed.tech/tags/digital-signature.md>), [ed25519](<https://devfeed.tech/tags/ed25519.md>), [federal-compliance](<https://devfeed.tech/tags/federal-compliance.md>), [federal-information-processing-standards](<https://devfeed.tech/tags/federal-information-processing-standards.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-140-3](<https://devfeed.tech/tags/fips-140-3.md>), [fips-validation](<https://devfeed.tech/tags/fips-validation.md>), [nist](<https://devfeed.tech/tags/nist.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>), [standards](<https://devfeed.tech/tags/standards.md>), [validation](<https://devfeed.tech/tags/validation.md>)

### AI overview

Chainguard FIPS container images are being upgraded to support current FIPS 140-3 and FIPS 186-5 standards, including OpenSSL with FIPS 140-3 validation and Ed25519 signing support.

### Source excerpt

Chainguard FIPS images have been upgraded to start using the OpenSSL project 3.1.2 module with FIPS 140-3 validation. Learn more about what this means.

## Implementing FIPS compliance in Redpanda

DevFeed: [Implementing FIPS compliance in Redpanda](<https://devfeed.tech/articles/implementing-fips-compliance-in-redpanda-12706.md>)

Original publisher: [Read original article](<https://www.redpanda.com/blog/implementing-fips-compliance>)

Author: Kavya Shivashankar

Published: 2025-05-20T00:00:00Z

Content type: tutorial

Language: en

Sources: [Redpanda](<https://devfeed.tech/sources/redpanda.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [clusters](<https://devfeed.tech/tags/clusters.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [deploying-fips-compliant-redpanda](<https://devfeed.tech/tags/deploying-fips-compliant-redpanda.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-140-2-compliance](<https://devfeed.tech/tags/fips-140-2-compliance.md>), [fips-compliance-redpanda](<https://devfeed.tech/tags/fips-compliance-redpanda.md>), [fips-mode-redpanda-installation](<https://devfeed.tech/tags/fips-mode-redpanda-installation.md>), [fips-validation-for-cryptographic-modules](<https://devfeed.tech/tags/fips-validation-for-cryptographic-modules.md>), [implementing-fips-in-redpanda](<https://devfeed.tech/tags/implementing-fips-in-redpanda.md>), [installation](<https://devfeed.tech/tags/installation.md>), [k8s](<https://devfeed.tech/tags/k8s.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [openssl-3-0-9-fips](<https://devfeed.tech/tags/openssl-3-0-9-fips.md>), [product](<https://devfeed.tech/tags/product.md>), [production](<https://devfeed.tech/tags/production.md>), [red-hat](<https://devfeed.tech/tags/red-hat.md>), [redpanda-enterprise-security-features](<https://devfeed.tech/tags/redpanda-enterprise-security-features.md>), [redpanda-fips-compliant-cluster](<https://devfeed.tech/tags/redpanda-fips-compliant-cluster.md>), [redpanda-openssl-configuration](<https://devfeed.tech/tags/redpanda-openssl-configuration.md>), [redpanda-security-standards](<https://devfeed.tech/tags/redpanda-security-standards.md>), [rhel](<https://devfeed.tech/tags/rhel.md>), [secure-redpanda-clusters](<https://devfeed.tech/tags/secure-redpanda-clusters.md>), [security](<https://devfeed.tech/tags/security.md>), [standards](<https://devfeed.tech/tags/standards.md>)

### AI overview

This tutorial explains FIPS requirements for cryptographic modules and how Redpanda supports FIPS-compliant operation. It covers validated OpenSSL libraries, FIPS mode settings, licensing, deployment limitations, and an example single-node cluster installation on RHEL.

### Source excerpt

Redpanda now supports FIPS, so you can run our clusters in secure environments with strict federal security standards for crypto modules.

## Ekapkgs, a poly-repo fork of Nixpkgs

DevFeed: [Ekapkgs, a poly-repo fork of Nixpkgs](<https://devfeed.tech/articles/ekapkgs-a-poly-repo-fork-of-nixpkgs-32433.md>)

Original publisher: [Read original article](<https://nixcademy.com/posts/ekala-project/>)

Author: Jon Ringer

Published: 2025-03-31T00:00:00Z

Content type: opinion

Language: en

Sources: [Nixcademy Blog](<https://devfeed.tech/sources/nixcademy-blog.md>)

Topics: [Nix](<https://devfeed.tech/topics/nix.md>), [repo](<https://devfeed.tech/topics/repo.md>), [Development](<https://devfeed.tech/topics/development.md>), [Maintainability](<https://devfeed.tech/topics/maintainability.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>)

Tags: [development](<https://devfeed.tech/tags/development.md>), [fork](<https://devfeed.tech/tags/fork.md>), [glibc](<https://devfeed.tech/tags/glibc.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [maintainability](<https://devfeed.tech/tags/maintainability.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [repo](<https://devfeed.tech/tags/repo.md>)

### AI overview

The article presents Ekapkgs as a poly-repository fork of Nixpkgs. It argues that Nixpkgs' monolithic scale, lengthy RFC process, and staging workflow make maintenance, convention changes, and package updates difficult, while separate repositories could enable faster iteration and more focused curation.

### Source excerpt

Ekapkgs forks Nixpkgs, splitting it into repos for faster updates & easier curation. Ditch monolithic development flows & slow RFCs. Innovate freely!

## FuzzSlice: Separating real CVEs from fakes through fuzzing

DevFeed: [FuzzSlice: Separating real CVEs from fakes through fuzzing](<https://devfeed.tech/articles/fuzzslice-separating-real-cves-from-fakes-through-fuzzing-13055.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fuzzslice-separating-real-cves-from-fakes-through-fuzzing>)

Published: 2024-09-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [Security](<https://devfeed.tech/topics/security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [cves](<https://devfeed.tech/tags/cves.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard Labs presents FuzzSlice, a fuzzing technique for determining whether CVEs are exploitable within an application context. In an evaluation of 18 OpenSSL CVEs, it classified 12 as exploitable and six as unreachable or false positives.

### Source excerpt

Chainguard Labs explores FuzzSlice, a novel fuzzing technique, to improve vulnerability remediation by distinguishing exploitable CVEs from false positives.

## Node.js 20.16.0 (LTS)

DevFeed: [Node.js 20.16.0 (LTS)](<https://devfeed.tech/articles/node-js-20-16-0-lts-2715.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/release/v20.16.0>)

Published: 2024-07-24T12:29:52Z

Content type: release

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [tracing](<https://devfeed.tech/topics/tracing.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>)

Tags: [chrome](<https://devfeed.tech/tags/chrome.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [cross-platform](<https://devfeed.tech/tags/cross-platform.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [lts](<https://devfeed.tech/tags/lts.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [servers](<https://devfeed.tech/tags/servers.md>), [tracing](<https://devfeed.tech/tags/tracing.md>), [wasi](<https://devfeed.tech/tags/wasi.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

Node.js 20.16.0 is an LTS release that adds a way to conditionally load built-in modules from a globally available function. It also updates OpenSSL-related behavior, improves profiling behavior with Chrome DevTools, and includes documentation, networking, WASI, test runner, utility, buffer, benchmarking, and build changes.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Latest CVE patch report: Securing software supply chains

DevFeed: [Latest CVE patch report: Securing software supply chains](<https://devfeed.tech/articles/latest-cve-patch-report-securing-software-supply-chains-13140.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/latest-cve-patch-report-securing-software-supply-chains>)

Published: 2024-06-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2024-4603](<https://devfeed.tech/tags/cve-2024-4603.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard's latest CVE patch report describes how its remediation team patches vulnerabilities in Chainguard Images and Wolfi Packages, aiming to provide accurate scanner results and reduce false positives. It also examines CVE-2024-4603 in OpenSSL, which can cause denial-of-service attacks when untrusted, excessively large DSA parameters are checked.

### Source excerpt

Dive into our latest CVE patch report and see how Chainguard proactively mitigates vulnerabilities to enhance software supply chain security.

## Node.js 18.19.1 (LTS)

DevFeed: [Node.js 18.19.1 (LTS)](<https://devfeed.tech/articles/node-js-18-19-1-lts-2670.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/release/v18.19.1>)

Published: 2024-02-14T17:35:50Z

Content type: release

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [linux](<https://devfeed.tech/tags/linux.md>), [lts](<https://devfeed.tech/tags/lts.md>), [macos](<https://devfeed.tech/tags/macos.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [npm](<https://devfeed.tech/tags/npm.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Node.js 18.19.1 is an LTS security release addressing multiple vulnerabilities, including code injection and privilege escalation, HTTP request processing issues, timing attacks, and denial-of-service risks. It also updates dependencies such as undici, npm, OpenSSL, and root certificates, and improves release notarization and signing processes.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Blog: Falco Weekly 46 - 2023

DevFeed: [Blog: Falco Weekly 46 - 2023](<https://devfeed.tech/articles/blog-falco-weekly-46-2023-32509.md>)

Original publisher: [Read original article](<https://falco.org/blog/falco-w-46-2023-weekly-recap/>)

Published: 2023-11-17T00:00:00Z

Content type: article

Language: en

Sources: [Falco - Falco](<https://devfeed.tech/sources/falco-falco.md>), [Falco - The Falco blog](<https://devfeed.tech/sources/falco-the-falco-blog.md>)

Topics: [Falco](<https://devfeed.tech/topics/falco.md>), [Development](<https://devfeed.tech/topics/development.md>), [ci](<https://devfeed.tech/topics/ci.md>), [CMake](<https://devfeed.tech/topics/cmake.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [osx](<https://devfeed.tech/topics/osx.md>), [win32](<https://devfeed.tech/topics/win32.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [changes](<https://devfeed.tech/tags/changes.md>), [ci](<https://devfeed.tech/tags/ci.md>), [cmake](<https://devfeed.tech/tags/cmake.md>), [falco](<https://devfeed.tech/tags/falco.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [osx](<https://devfeed.tech/tags/osx.md>), [weekly](<https://devfeed.tech/tags/weekly.md>), [win32](<https://devfeed.tech/tags/win32.md>)

### AI overview

Falco Weekly 46 reviews development changes across Falco-related repositories, including library cleanups, fixes, new features, experimental ppc64le support, an OpenSSL upgrade, CI support for win32 and osx, and Kubernetes metadata work involving gRPC.

### Source excerpt

This is the first of a series of weekly blog post whose aim is to give a quick overview about the development of Falco and its related projects. What happened in Falco this week? Let's go through the major changes that happened in various repositories under the falcosecurity organization. Libs Lots of cleanups happened in the libs repo; the most outstanding ones being: udig engine removal (https://github.com/falcosecurity/libs/pull/1485) dropped legacy metadata clients for k8s and mesos (https://github.com/falcosecurity/libs/pull/1478) cleaned up proc callback handling code (https://github.com/falcosecurity/libs/pull/1471) Please, note that the removal of the legacy k8s client is part of a bigger effort to entirely rewrite it as a plugin, with a more future proof architecture and language. See the tracking issue: https://github.com/falcosecurity/libs/issues/987. All of these cleanups account for ~26k loc removed!! :rocket: Moreover, some fixes landed: removed some more Undefined Behavior warnings from integer copies (https://github.com/falcosecurity/libs/pull/1481) solved win32 linking issues with zlib (https://github.com/falcosecurity/libs/pull/1484) prevent libbpf stats from being collected with no bpf stats (https://github.com/falcosecurity/libs/pull/1487) Finally, some new features were merged: libraries will now be properly installed under CMAKE_INSTALL_LIBDIR (https://github.com/falcosecurity/libs/pull/1101) added ppc64le experimental support for modern bpf driver (https://github.com/falcosecurity/libs/pull/1475) upgraded openssl to 3.1.4 (https://github.com/falcosecurity/libs/pull/1488) Also, we now have a target release date and a tracking issue for libs 0.14 and next driver release: https://github.com/falcosecurity/libs/issues/1482. Falco Now Falco builds and runs on win32 and osx too! https://github.com/falcosecurity/falco/pull/2889 While Falco won't ship for these platforms, we will now have proper CI for them. Following the huge round of cleanups in libs

## OpenSSL Recent Security Patches

DevFeed: [OpenSSL Recent Security Patches](<https://devfeed.tech/articles/openssl-recent-security-patches-2907.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/vulnerability/openssl-fixes-in-regular-releases-oct2023>)

Published: 2023-10-26T17:00:15Z

Content type: news

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [node](<https://devfeed.tech/tags/node.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Node.js reports that Windows is affected by the low-severity CVE-2023-4807 vulnerability from the OpenSSL security advisories. The fix will be released through regular Node.js releases. Users invoking affected OpenSSL functions through native addons can link against a patched OpenSSL version until then.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

[Next page](<https://devfeed.tech/tags/openssl.md?cursor=WyIyMDIzLTEwLTI2VDE3OjAwOjE1KzAwOjAwIiwgImRhYjkwYTM4LWVlZDUtNGIwZi04MWY0LTMyNDhiMmU0ZDkxYiJd>)