<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Node.JS 16.X now out of maintenance window in Reporting Service &amp; Alerting</title>
    <link>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2133731#M1808</link>
    <description>&lt;P&gt;HI Dale, I was told that &lt;SPAN&gt;&lt;SPAN class="ui-provider bfp bfq bfr bfs bft bfu bfv bfw bfx bfy bfz bga bgb bgc bgd bge bgf bgg bgh bgi bgj bgk bgl bgm bgn bgo bgp bgq bgr bgs bgt bgu bgv bgw bgx"&gt;we support a NodeJS version where the vulnerabilities are fixed, i e 16.18.1. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Nov 2023 12:24:42 GMT</pubDate>
    <dc:creator>Alan_Slaughter</dc:creator>
    <dc:date>2023-11-01T12:24:42Z</dc:date>
    <item>
      <title>Node.JS 16.X now out of maintenance window</title>
      <link>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2132988#M1805</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Is there any plan to move Alerting to a supported version of node.js? The requirements of Alerting point to 16.18.0 which was released over a year ago now, even the current latest version of 16.X (16.20.2 at time of writing) is from August (from what i can glean from node's website 16.X as a whole is now out of maintenance so presumably no longer recieving security updates.&lt;/P&gt;
&lt;P&gt;Last time our infrastructure guys updated node to a later version it completely broke alerting but could revert to 16.18.1 and that worked, are we ok to move to 16.20.2 or preferably to a supported version? Bit confused as to why a migration didn't happen with the latest July release just before 16.X went out of support (unless I'm reading node's website incorrectly)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Dale&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 15:57:23 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2132988#M1805</guid>
      <dc:creator>dwqlik82</dc:creator>
      <dc:date>2025-01-29T15:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Node.JS 16.X now out of maintenance window</title>
      <link>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2133711#M1806</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;SPAN&gt;&lt;SPAN class="ui-provider bfp bfq bfr bfs bft bfu bfv bfw bfx bfy bfz bga bgb bgc bgd bge bgf bgg bgh bgi bgj bgk bgl bgm bgn bgo bgp bgq bgr bgs bgt bgu bgv bgw bgx"&gt; July 2023 supports 16.18.1.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 11:35:58 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2133711#M1806</guid>
      <dc:creator>Alan_Slaughter</dc:creator>
      <dc:date>2023-11-01T11:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: Node.JS 16.X now out of maintenance window</title>
      <link>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2133721#M1807</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;the issue is there have been quite a few CVE's released since 16.18.1 (from Node's archive it looks like 4th Nov 22) and 16.X as a whole is now out of even maintenance support (unless i'm reading node's website incorrectly).&amp;nbsp; The latest version of 16 is 16.20.2 (released 8th August)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://nodejs.org/en/about/previous-releases" target="_blank"&gt;Previous Releases | Node.js (nodejs.org)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am assuming that no fixes will be released for 16 as its out of its maintenance window?&amp;nbsp; I know from previous experience that just going to a newer major version broke the previous version of alerting, does alerting support 16.20.2 at least as that will fix some vulnerabilities at least:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://nodejs.org/en/blog/release/v16.20.2" target="_blank"&gt;Node v16.20.2 (LTS) | Node.js (nodejs.org)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;ta&lt;/P&gt;
&lt;P&gt;Dale&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 12:01:22 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2133721#M1807</guid>
      <dc:creator>dwqlik82</dc:creator>
      <dc:date>2023-11-01T12:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Node.JS 16.X now out of maintenance window</title>
      <link>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2133731#M1808</link>
      <description>&lt;P&gt;HI Dale, I was told that &lt;SPAN&gt;&lt;SPAN class="ui-provider bfp bfq bfr bfs bft bfu bfv bfw bfx bfy bfz bga bgb bgc bgd bge bgf bgg bgh bgi bgj bgk bgl bgm bgn bgo bgp bgq bgr bgs bgt bgu bgv bgw bgx"&gt;we support a NodeJS version where the vulnerabilities are fixed, i e 16.18.1. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 12:24:42 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2133731#M1808</guid>
      <dc:creator>Alan_Slaughter</dc:creator>
      <dc:date>2023-11-01T12:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: Node.JS 16.X now out of maintenance window</title>
      <link>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2133745#M1809</link>
      <description>&lt;P&gt;but what about vulnerabilities discovered since 16.18.1 was released in November last year?&lt;/P&gt;
&lt;P&gt;from Node's own site there have been 3 security releases since then (February, June and August)&amp;nbsp; that would presumably be covered by 16.20.2&amp;nbsp;&amp;nbsp;&lt;A href="https://nodejs.org/en/blog/vulnerability" target="_blank"&gt;Vulnerabilities | Node.js (nodejs.org).&lt;/A&gt;&amp;nbsp; As 16 is no longer supported the vulnerabilities in the October release will presumably never be addressed.&amp;nbsp; Are there any mitigating actions I can share with our security team around this you are aware of (I appreciate you are just acting as go between and am grateful for your response)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ta&lt;/P&gt;
&lt;P&gt;Dale&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 12:43:55 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2133745#M1809</guid>
      <dc:creator>dwqlik82</dc:creator>
      <dc:date>2023-11-01T12:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Node.JS 16.X now out of maintenance window</title>
      <link>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2133769#M1810</link>
      <description>&lt;P&gt;Hi Dale,&amp;nbsp;&lt;SPAN&gt;&lt;SPAN class="ui-provider bfp bfq bfr bfs bft bfu bfv bfw bfx bfy bfz bga bgb bgc bgd bge bgf bgg bgh bgi bgj bgk bgl bgm bgn bgo bgp bgq bgr bgs bgt bgu bgv bgw bgx"&gt;The Node JS library used in the 2023 version will be:&amp;nbsp;18.12.1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 13:58:00 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2133769#M1810</guid>
      <dc:creator>Alan_Slaughter</dc:creator>
      <dc:date>2023-11-01T13:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: Node.JS 16.X now out of maintenance window</title>
      <link>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2133778#M1811</link>
      <description>&lt;P&gt;Thanks for this &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; but doesn't the same issue apply? 18.12.1 was released the same date as 16.18.1 so will potentially have same/similar number of vulns? latest version of&amp;nbsp; the LTS version of 18.X is 18.18.2 and released a few weeks ago.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 14:18:04 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2133778#M1811</guid>
      <dc:creator>dwqlik82</dc:creator>
      <dc:date>2023-11-01T14:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: Node.JS 16.X now out of maintenance window</title>
      <link>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2133809#M1812</link>
      <description>&lt;P&gt;Qlik is on a different NodeJs library with a little more runway - we continually review our product for required library updates&lt;SPAN&gt;&lt;SPAN class="ui-provider bfp bfq bfr bfs bft bfu bfv bfw bfx bfy bfz bga bgb bgc bgd bge bgf bgg bgh bgi bgj bgk bgl bgm bgn bgo bgp bgq bgr bgs bgt bgu bgv bgw bgx"&gt;.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 15:36:46 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2133809#M1812</guid>
      <dc:creator>Alan_Slaughter</dc:creator>
      <dc:date>2023-11-01T15:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: Node.JS 16.X now out of maintenance window</title>
      <link>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2134322#M1813</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/37466"&gt;@dwqlik82&lt;/a&gt;&amp;nbsp; I checked internally and got confirmation that&amp;nbsp;Alerting supports node 18.12.1. You can upgrade node to this version.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 05:39:34 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2134322#M1813</guid>
      <dc:creator>Vicky_Z</dc:creator>
      <dc:date>2023-11-03T05:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: Node.JS 16.X now out of maintenance window</title>
      <link>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2134376#M1814</link>
      <description>&lt;P&gt;Hi Vicky,&lt;/P&gt;
&lt;P&gt;thanks, i believe Alan said the same above, the main issue is 18.12.1 is now a year behind on security updates (same as 16.18.1 - they were released the same day) by my count using Node's security release documentation just CVE's there are 6 Highs,9 Mediums that affect 16.X an 18.X that have been fixed by going to the latest version (plus any other things like openssl fixes etc). I would presume that the latest version of 18.X (18.18.2) would be ok to use but would be nice to get confirmation&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 08:29:30 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2134376#M1814</guid>
      <dc:creator>dwqlik82</dc:creator>
      <dc:date>2023-11-03T08:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: Node.JS 16.X now out of maintenance window</title>
      <link>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2134449#M1815</link>
      <description>&lt;P&gt;HI dwqlik82, it is confirmed by the Alert team that you can safely use 18.12.1.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 11:19:57 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Reporting-Service-Alerting/Node-JS-16-X-now-out-of-maintenance-window/m-p/2134449#M1815</guid>
      <dc:creator>Alan_Slaughter</dc:creator>
      <dc:date>2023-11-03T11:19:57Z</dc:date>
    </item>
  </channel>
</rss>

