nodejs 4.4.6 has been uploaded to carbon. This doesn't fix all the security issues originally announced (that's why this is not 4.5.0 yet), but still CVE-2016-1669. I have built fixed packages and uploaded them to carbon. The following services using nodejs4/jessie need to be migrated:
aqsrestbaseetherpad- ruthenium (testreduce/parsoid)
maps (tilerator/kartoterian)scbmobileapps TESTED, OKgraphoid TESTED, OKmathoid TESTED, OKcxserver TESTED, OKcitoid TESTED, OKchangeprop TESTED, OK