Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

meta: expand memory leak DoS criteria to all DoS#62505

Merged
nodejs-github-bot merged 1 commit into
nodejs:mainnodejs/node:mainfrom
joyeecheung:dosjoyeecheung/node:dosCopy head branch name to clipboard
Apr 1, 2026
Merged

meta: expand memory leak DoS criteria to all DoS#62505
nodejs-github-bot merged 1 commit into
nodejs:mainnodejs/node:mainfrom
joyeecheung:dosjoyeecheung/node:dosCopy head branch name to clipboard

Conversation

@joyeecheung

Copy link
Copy Markdown
Member

We have dedicated requirements about memory leaks when triaging DoS. These applies in generall to all types of DoS, and many recent reports about DoS attack vectors fail to meet them, resulting in a lot of extra back-and-forth in triaging. Clarify in the threat model by expanding these requirements to all DoS.

Drive-by: clarify criteria of documented JavaScript behavior is that they are included in ECMA262. Also use "Node.js application developer" instead of "user" the refer to the party being vulnerable to avoid confusion.

We have dedicated requirements about memory leaks when triaging
DoS. These applies in generall to all types of DoS, and many recent
reports about DoS attack vectors fail to meet them, resulting in
a lot of extra back-and-forth in triaging. Clarify in the threat
model by expanding these requirements to all DoS.

Drive-by: clarify criteria of documented JavaScript behavior is
that they are included in ECMA262. Also use "Node.js application
developer" instead of "user" the refer to the party being
vulnerable to avoid confusion.
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/tsc

@nodejs-github-bot nodejs-github-bot added the doc Issues and PRs related to the documentations. label Mar 30, 2026
@aduh95 aduh95 added author ready PRs that have at least one approval, no pending requests for changes, and a CI started. commit-queue Add this label to land a pull request using GitHub Actions. labels Mar 30, 2026
Comment thread SECURITY.md

@mcollina mcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@nodejs-github-bot nodejs-github-bot removed the commit-queue Add this label to land a pull request using GitHub Actions. label Apr 1, 2026
@nodejs-github-bot nodejs-github-bot merged commit 12c2736 into nodejs:main Apr 1, 2026
28 checks passed
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Landed in 12c2736

karan-lrn pushed a commit to karan-lrn/node that referenced this pull request Apr 2, 2026
We have dedicated requirements about memory leaks when triaging
DoS. These applies in generall to all types of DoS, and many recent
reports about DoS attack vectors fail to meet them, resulting in
a lot of extra back-and-forth in triaging. Clarify in the threat
model by expanding these requirements to all DoS.

Drive-by: clarify criteria of documented JavaScript behavior is
that they are included in ECMA262. Also use "Node.js application
developer" instead of "user" the refer to the party being
vulnerable to avoid confusion.

PR-URL: nodejs#62505
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Beth Griggs <bethanyngriggs@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
aduh95 pushed a commit that referenced this pull request May 5, 2026
We have dedicated requirements about memory leaks when triaging
DoS. These applies in generall to all types of DoS, and many recent
reports about DoS attack vectors fail to meet them, resulting in
a lot of extra back-and-forth in triaging. Clarify in the threat
model by expanding these requirements to all DoS.

Drive-by: clarify criteria of documented JavaScript behavior is
that they are included in ECMA262. Also use "Node.js application
developer" instead of "user" the refer to the party being
vulnerable to avoid confusion.

PR-URL: #62505
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Beth Griggs <bethanyngriggs@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
aduh95 pushed a commit that referenced this pull request May 7, 2026
We have dedicated requirements about memory leaks when triaging
DoS. These applies in generall to all types of DoS, and many recent
reports about DoS attack vectors fail to meet them, resulting in
a lot of extra back-and-forth in triaging. Clarify in the threat
model by expanding these requirements to all DoS.

Drive-by: clarify criteria of documented JavaScript behavior is
that they are included in ECMA262. Also use "Node.js application
developer" instead of "user" the refer to the party being
vulnerable to avoid confusion.

PR-URL: #62505
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Beth Griggs <bethanyngriggs@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author ready PRs that have at least one approval, no pending requests for changes, and a CI started. doc Issues and PRs related to the documentations.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants

Morty Proxy This is a proxified and sanitized view of the page, visit original site.