diff --git a/types/node/tls.d.ts b/types/node/tls.d.ts index 0050a7b025..368ea8eb0b 100644 --- a/types/node/tls.d.ts +++ b/types/node/tls.d.ts @@ -334,7 +334,7 @@ declare module "tls" { cleartext: TLSSocket; } - type SecureVersion = 'TLSv1.2' | 'TLSv1.1' | 'TLSv1'; + type SecureVersion = 'TLSv1.3' | 'TLSv1.2' | 'TLSv1.1' | 'TLSv1'; interface SecureContextOptions { pfx?: string | Buffer | Array; @@ -353,18 +353,22 @@ declare module "tls" { sessionIdContext?: string; /** * Optionally set the maximum TLS version to allow. One - * of `TLSv1.2'`, `'TLSv1.1'`, or `'TLSv1'`. Cannot be specified along with the - * `secureProtocol` option, use one or the other. **Default:** `'TLSv1.2'`. + * of `'TLSv1.3'`, `'TLSv1.2'`, `'TLSv1.1'`, or `'TLSv1'`. Cannot be specified along with the + * `secureProtocol` option, use one or the other. + * **Default:** `'TLSv1.3'`, unless changed using CLI options. Using + * `--tls-max-v1.2` sets the default to `'TLSv1.2'`. Using `--tls-max-v1.3` sets the default to + * `'TLSv1.3'`. If multiple of the options are provided, the highest maximum is used. */ maxVersion?: SecureVersion; /** * Optionally set the minimum TLS version to allow. One - * of `TLSv1.2'`, `'TLSv1.1'`, or `'TLSv1'`. Cannot be specified along with the + * of `'TLSv1.3'`, `'TLSv1.2'`, `'TLSv1.1'`, or `'TLSv1'`. Cannot be specified along with the * `secureProtocol` option, use one or the other. It is not recommended to use * less than TLSv1.2, but it may be required for interoperability. * **Default:** `'TLSv1.2'`, unless changed using CLI options. Using - * `--tls-v1.0` changes the default to `'TLSv1'`. Using `--tls-v1.1` changes - * the default to `'TLSv1.1'`. + * `--tls-v1.0` sets the default to `'TLSv1'`. Using `--tls-v1.1` sets the default to + * `'TLSv1.1'`. Using `--tls-min-v1.3` sets the default to + * 'TLSv1.3'. If multiple of the options are provided, the lowest minimum is used. */ minVersion?: SecureVersion; }