Skip to content

chore: upgrade Node.js to 22.22.0 (CVE-2025-59466)#3446

Merged
capJavert merged 2 commits intomainfrom
chore-nodejs-upgrade-CVE-2025-59466
Jan 15, 2026
Merged

chore: upgrade Node.js to 22.22.0 (CVE-2025-59466)#3446
capJavert merged 2 commits intomainfrom
chore-nodejs-upgrade-CVE-2025-59466

Conversation

@capJavert
Copy link
Copy Markdown
Contributor

Update Node.js version from 22.16 to 22.22.0 to mitigate CVE-2025-59466 affecting async_hooks / AsyncLocalStorage.

Updated files:

  • .nvmrc
  • package.json (volta)
  • Dockerfile
  • Dockerfile.dev
  • .circleci/config.yml
  • .infra/.nvmrc
  • .infra/package.json (volta)
  • AGENTS.md (version + upgrade checklist)

Update Node.js version from 22.16 to 22.22.0 to mitigate CVE-2025-59466
affecting async_hooks / AsyncLocalStorage.

Updated files:
- .nvmrc
- package.json (volta)
- Dockerfile
- Dockerfile.dev
- .circleci/config.yml
- .infra/.nvmrc
- .infra/package.json (volta)
- AGENTS.md (version + upgrade checklist)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@capJavert capJavert self-assigned this Jan 15, 2026
@capJavert capJavert requested a review from a team as a code owner January 15, 2026 10:23
@pulumi
Copy link
Copy Markdown

pulumi Bot commented Jan 15, 2026

🍹 The Update (preview) for dailydotdev/api/prod (at bb544cb) was successful.

Resource Changes

    Name                                                   Type                           Operation
~   vpc-native-check-analytics-report-cron                 kubernetes:batch/v1:CronJob    update
~   vpc-native-post-analytics-clickhouse-cron              kubernetes:batch/v1:CronJob    update
~   vpc-native-private-deployment                          kubernetes:apps/v1:Deployment  update
~   vpc-native-post-analytics-history-day-clickhouse-cron  kubernetes:batch/v1:CronJob    update
~   vpc-native-update-source-public-threshold-cron         kubernetes:batch/v1:CronJob    update
~   vpc-native-personalized-digest-deployment              kubernetes:apps/v1:Deployment  update
~   vpc-native-update-tags-str-cron                        kubernetes:batch/v1:CronJob    update
~   vpc-native-calculate-top-readers-cron                  kubernetes:batch/v1:CronJob    update
~   vpc-native-clean-stale-user-transactions-cron          kubernetes:batch/v1:CronJob    update
~   vpc-native-hourly-notification-cron                    kubernetes:batch/v1:CronJob    update
~   vpc-native-validate-active-users-cron                  kubernetes:batch/v1:CronJob    update
~   vpc-native-temporal-deployment                         kubernetes:apps/v1:Deployment  update
~   vpc-native-clean-zombie-users-cron                     kubernetes:batch/v1:CronJob    update
-   vpc-native-api-db-migration-ae096247                   kubernetes:batch/v1:Job        delete
~   vpc-native-update-current-streak-cron                  kubernetes:batch/v1:CronJob    update
~   vpc-native-update-highlighted-views-cron               kubernetes:batch/v1:CronJob    update
~   vpc-native-sync-subscription-with-cio-cron             kubernetes:batch/v1:CronJob    update
~   vpc-native-generate-search-invites-cron                kubernetes:batch/v1:CronJob    update
~   vpc-native-personalized-digest-cron                    kubernetes:batch/v1:CronJob    update
~   vpc-native-bg-deployment                               kubernetes:apps/v1:Deployment  update
~   vpc-native-ws-deployment                               kubernetes:apps/v1:Deployment  update
-   vpc-native-api-clickhouse-migration-ae096247           kubernetes:batch/v1:Job        delete
~   vpc-native-clean-zombie-images-cron                    kubernetes:batch/v1:CronJob    update
~   vpc-native-generic-referral-reminder-cron              kubernetes:batch/v1:CronJob    update
~   vpc-native-update-tag-recommendations-cron             kubernetes:batch/v1:CronJob    update
~   vpc-native-clean-zombie-opportunities-cron             kubernetes:batch/v1:CronJob    update
~   vpc-native-deployment                                  kubernetes:apps/v1:Deployment  update
~   vpc-native-update-source-tag-view-cron                 kubernetes:batch/v1:CronJob    update
~   vpc-native-daily-digest-cron                           kubernetes:batch/v1:CronJob    update
~   vpc-native-clean-gifted-plus-cron                      kubernetes:batch/v1:CronJob    update
~   vpc-native-user-profile-updated-sync-cron              kubernetes:batch/v1:CronJob    update
~   vpc-native-update-views-cron                           kubernetes:batch/v1:CronJob    update
+   vpc-native-api-db-migration-32452083                   kubernetes:batch/v1:Job        create
~   vpc-native-update-trending-cron                        kubernetes:batch/v1:CronJob    update
~   vpc-native-clean-zombie-user-companies-cron            kubernetes:batch/v1:CronJob    update
+   vpc-native-api-clickhouse-migration-32452083           kubernetes:batch/v1:Job        create

@capJavert capJavert merged commit 7c23509 into main Jan 15, 2026
10 checks passed
@capJavert capJavert deleted the chore-nodejs-upgrade-CVE-2025-59466 branch January 15, 2026 11:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant