Node.js retweeted
Finding vulnerabilities is only part of open source security. Maintainers still need resources to triage, patch, and ship secure releases.
The new OpenJS Security Stewardship Program will fund researchers and maintainers, starting with Node.js.
hubs.la/Q04ykc4R0
Node.js 24.20.0 and Node.js 26.8.1 are out now. 💚
- nodejs.org/en/blog/release/v…
- nodejs.org/en/blog/release/v…
Are you a Node.js user? We want your feedback.
Tell us all about how you're using Node.js in our annual user survey. Your response helps shape our future priorities!
linuxfoundation.surveymonkey…
Node.js Interactive 2026 brought together the developers and maintainers shaping the future of Node.js. ⚡️
The event covered practical work happening across the project, including built in TypeScript support, node:test, QUIC and HTTP/3, documentation tooling, integration testing, and AI assisted development.
The conversations also highlighted an important part of building Node.js: strong testing, security, documentation, and maintainer support remain essential as the ecosystem evolves.
Read the full Node.js Interactive 2026 recap 👇
bit.ly/4gix0zB
Huge thanks to @aviv_keller for the recap.
📣 New Node.js release 📣
Node.js 26.7.0 is out with Perfetto tracing support, STORE loaders for private keys, and `module.register()` hooks are now disposable, plus many patches.
Full changelog and download links: nodejs.org/en/blog/release/v…
Node.js 26.6.0 and 24.19.0 are out 💚
- nodejs.org/blog/release/v24.…
- nodejs.org/blog/release/v26.…
⚠️ Node.js Security Update: Updates are now available for the 26.x, 24.x, 22.x release lines.
Details: nodejs.org/en/blog/vulnerabi…
⚠️ The Node.js project will release new versions of the 26.x, 24.x, 22.x releases lines on or shortly after, Monday, July 27, 2026.
Details: nodejs.org/en/blog/vulnerabi…
The Node.js Interactive speaker lineup at RenderATL is here.
This is the program we've been building — technical talks from the people actively working on Node.js core, its ecosystem, and the tools developers ship with every day.
What's on the schedule:
→ QUIC and HTTP/3 landing in Node.js core
→ Built-in TypeScript, node:test, node:sqlite, and the Permission System in Node 26
→ Event loop diagnostics under real production load
→ MCP and spec-driven development for Node.js backends
→ The npm supply chain economy after Shai-Hulud and Axios
→ doc-kit replacing 14 years of documentation infrastructure
→ Integration testing patterns for complex Node.js systems
→ Platform engineering fundamentals for the AI era
→ SemVer build metadata as an extension point for package management
→ JavaScript governance, WinterCG, and cross-runtime interoperability
→ Open sourcing production systems sustainably
Every talk connects back to what Node.js developers are building, maintaining, and protecting right now.
Full speaker list: openjsf.org/blog/node-intera…
Join us in Atlanta: renderatl.com/node
New to open source, or wondering how to get your first Node.js contribution landed and released?
Check out our new first-time contributors guide, with practical tips and answers to FAQs about working with our volunteer-driven model. Welcome aboard! 🤝
github.com/nodejs/node/blob/…
Node.js 26.4.0 is out with a new `node:vfs` built-in module (behind `--experimental-vfs` flag).
It also adds support for package maps, and many bug fixes, including a fix for a regression shipped with last week security release.
Full changelog and download links: nodejs.org/en/blog/release/v…
⚠️ Updates are now available for the 26.x, 24.x, 22.x Node.js release lines for the following issues.
More information here: nodejs.org/en/blog/vulnerabi…
⚠️ Security release pre-alert: The Node.js project will release new versions of the 26.x, 24.x, 22.x
releases lines on or shortly after, Wednesday, June 17, 2026 in order to address one or more security issues, the highest severity is HIGH.
Details: nodejs.org/en/blog/vulnerabi…
Guess who's back? 👀
Node.js Interactive returns at RenderATL 2026.
Join maintainers, contributors, and developers for two days of talks on Node.js performance, security, AI tooling, infrastructure, and the real world challenges of running JavaScript at scale.
See you in Atlanta. Details: openjsf.org/blog/nodejs-inte…
Are you currently hiring for a role that includes using Node.js? Reply with a link to the opening and any relevant context.
If you're not, we'd appreciate a repost for visibility 💚
Node.js 26.3.0 is out with a bunch of various fixes, and a new `process.permission.drop()` API (shoutout to @_rafaelgss)
Full changelog and download links: nodejs.org/en/blog/release/v…
Another day, another Node.js release 😎
Node.js 24.16.0 is out! A few test runner features, `randomUUIDv7`, plus many more bug fixes and small improvements.
Full changelog and download links: nodejs.org/en/blog/release/v…
Node.js 26.2.0 is out! ✨
`stream.compose` is now stable, `node:fs` integrates with the new `Temporal` API, and a fair load of bug fixes.
Full changelog and download: nodejs.org/en/blog/release/v…
Do you use Node.js on Alpine Linux? While the Node.js project publishes Alpine containers to dockerhub it is currently an "experimental" platform and does not have the same guarantees as other platforms.
We are looking for volunteers to help us bring Alpine to "Tier 2" where it would be built and released through the normal CI process.
If you can help, let us know: bit.ly/4v03NiW
⚠️ Node.js 20 is officially End-of-Life.
Staying on an unsupported version introduces significant security risks, but we know migration takes time. Join members of the Node.js Technical Steering Committee Matteo Collina and Marco Ippolito as we discuss how to navigate this transition safely.
We’ll cover:
✅ The logic behind the new release cadence leading to Node 27.
✅ How the project is defending against the surge of AI-generated CVE reports.
✅ Support options for those unable to migrate off Node 20 immediately.
Don’t leave your production environment to chance. Hear directly from the maintainers.
📅 May 27 | 11:00 AM EST
👉 Register for the live session: bit.ly/4tzcAqE