1. Mar 11, 2016
  2. Mar 09, 2016
  3. Mar 08, 2016
    • Rod Vagg's avatar
      2016-03-08 Version 0.12.12 (LTS) Release · 3f8ff60f
      Rod Vagg authored
      Notable changes:
      
      * openssl: Fully remove SSLv2 support, the `--enable-ssl2` command
        line argument will now produce an error. The DROWN Attack
        (https://drownattack.com/) creates a vulnerability where SSLv2 is
        enabled by a server, even if a client connection is not using SSLv2.
        The SSLv2 protocol is widely considered unacceptably broken and
        should not be supported. More information is available at
        https://www.openssl.org/news/vulnerabilities.html#2016-0800
      
      Note that the upgrade to OpenSSL 1.0.1s in Node.js v0.12.11 removed
      internal SSLv2 support. The change in this release was originally
      intended for v0.12.11. The `--enable-ssl2` command line argument now
      produces an error rather than being a no-op.
      3f8ff60f
  4. Mar 04, 2016
  5. Mar 03, 2016
  6. Mar 02, 2016
  7. Feb 24, 2016
  8. Feb 12, 2016
  9. Feb 10, 2016
  10. Dec 04, 2015
  11. Dec 03, 2015
  12. Nov 25, 2015