โจ Keep up to date with @nodejs.org by watching the #Nodejs #Release Working Group's last meeting on YouTube!
www.youtube.com/watch?v=ulMh...
@rwklau.bsky.social
Software Engineer at IBM. Node.js Build Infrastructure, Releaser & Technical Steering Committee.
โจ Keep up to date with @nodejs.org by watching the #Nodejs #Release Working Group's last meeting on YouTube!
www.youtube.com/watch?v=ulMh...
I just published the January report for open source software packages for Linux on #IBMZ and #LinuxONE ๐ง
The team tested nearly two dozen projects, including doxygen, Elastic Logstash, and PHP ๐ฅณ
Full report: community.ibm.com/community/us... #mainframe
Node.js patch release day! Full changelog and download links at nodejs.org/en/blog/rele... and nodejs.org/en/blog/rele...
10.02.2026 14:20 โ ๐ 19 ๐ 5 ๐ฌ 0 ๐ 0Want to make an impact? Join the OpenJS Foundation. Fund the projects you rely on. Contribute engineer time where it matters.
09.02.2026 17:30 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0It took a while, but the State of JS 2025 survey results are now live! 2025.stateofjs.com/en-US
Thanks to @danielroe.dev for contributing the conclusion.
We released version 1.2 of our GitHub Actions service for IBM Z and Power ๐ including improvements to Python support, so you can now use the IBM fork (until it's accepted upstream) of python-versions to specify versions: community.ibm.com/community/us...
02.02.2026 21:28 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0I think I figured out what's going on. Here is another blog post about tinkering with Node.js Core on ARM64 Windows (and tips about reducing the wait time on Windows) joyeecheung.github.io/blog/2026/01...
31.01.2026 10:24 โ ๐ 8 ๐ 1 ๐ฌ 0 ๐ 0nvm.sh users: please upgrade to github.com/nvm-sh/nvm/r... if you're using `wget` on your system, to fix a medium vulnerability (github.com/nvm-sh/nvm/s...).
29.01.2026 23:07 โ ๐ 6 ๐ 4 ๐ฌ 1 ๐ 0๐จ Node.js assessment of the recent OpenSSL Security Release
TL;DR: We'll update OpenSSL versions through a regular release process.
nodejs.org/en/blog/vuln...
I love how the answer to the title of this article is "they don't"
"Why Costco Still Relies On IBM Computers From The '80s"
www.bgr.com/2079471/why-...
The new Power 11 servers are so shiny โจ I was able to meet my first one at IBM TechXchange 2025 back in October.
(I work on IBM Z, not Power)
โ ๏ธ The Node.js Project now requires a HackerOne Signal score of 1.0 or higher to submit vulnerability reports. This will help our team streamline reports and support effective security reviews.
nodejs.org/en/blog/anno...
How did we do at the end of 2025 as far as testing our current collection of open source software packages for Linux on #IBMZ and #LinuxONE?
It was a strong finish! The team worked on over two dozen packages, including cAdvisor, PostgreSQL, and SPIRE.
Full report: community.ibm.com/community/us...
State of WebAssembly (Wasm) - recap events of 2025 and preview what 2026 can bring.
platform.uno/blog/the-sta...
This release contains a bunch of PRs I recently submitted to mark features I contributed to as stable/release candidate. Here is a thread about them ๐งต:
19.01.2026 18:42 โ ๐ 53 ๐ 8 ๐ฌ 2 ๐ 1Node.js v25.4.0 is out! ๐
โข require(esm) now stable and a new CLI flag: --require-module
โข http setGlobalProxyFromEnv() added
โข Multiple APIs promoted to stable (heapsnapshot, build snapshot, v8.queryObjects)
โข Root CAs updated to NSS 3.117
More in: nodejs.org/en/blog/rele...
Today the Temporal proposal has entered the stable stream shipping Chrome 144. This opens the gates for attaining Stage 4 at TC39.
That means tonight I will be purchasing a supply of champagne in preparation.
Itโs been a long journey and so very worthwhile!
Today, we published a security release for @nodejs.org that fixes a critical bug affecting virtually every production Node.js app.
If you use React Server Components, Next.js, or ANY APM tool (Datadog, New Relic, OpenTelemetry), your app could be vulnerable to DoS attacks.
๐
We appreciate your patience and understanding as we work to deliver a secure and reliable release.
Updates are now available for the 25.x, 24.x, 22.x, 20.x Node.js release lines to address:
- 3 high severity issues
- 4 medium severity issues
- 1 low severity issue
nodejs.org/en/blog/vuln...
๐จOur team has decided to postpone the release to Tuesday, January 13th, 2026. This additional time will allow us to properly test all backports and re-run CITGM to ensure the highest quality for our users.
08.01.2026 21:50 โ ๐ 17 ๐ 5 ๐ฌ 1 ๐ 0The Node.js package configuration guide is now live! ๐
Whether you're creating your first package or migrating to ESM, this guide walks you through it with examples.
https://nodejs.github.io/package-examples
npm is planning to implement staged publishing, adding a review step before packages go live.
It follows a year of supply chain attacks & a rocky shift away from classic tokens over the past month that left many maintainers struggling.
socket.dev/blog/npm-to-... #NodeJS cc: @campuscodi.risky.biz
When the reproducibility of a serialized object breaks and
1. It doesnโt show up in debug builds
2. There is no obvious pattern in how the bits change
Then that might be an uninitialised padding
(Spent a couple of hours trying to fix this againโฆafter I forgot how I fixed something similar before)
Here we are, the last report of the year from the #Linux on #IBMZ and #LinuxONE porting team and beyond ๐
The list for November has nearly three dozen projects tested, including Apache Cassandra, fluentd, and neo4j + GnuCOBOL on our GitHub Actions for s390x ๐งโ๐ป
community.ibm.com/community/us...
โ ๏ธ Node.js security release has been postponed โ ๏ธ
We have decided to delay the security release further to January 7th 2026 to ensure the team has enough time to prepare the releases and avoid distruptions during the holiday season.
nodejs.org/en/blog/vuln...
Unfortunately my experience of December has been people stop turning up to the meetings but do not indicate that they won't/can't attend nor cancel them ๐.
17.12.2025 15:08 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0โ ๏ธ The security release has been postponed to the 18th of December. The team is working on a challenging patch.
15.12.2025 19:55 โ ๐ 19 ๐ 4 ๐ฌ 0 ๐ 0A quote from RFC 6238: "The verifier MUST NOT accept the second attempt of the OTP after the successful validation has been issued for the first OTP, which ensures one-time only use of an OTP."
In the end, it would be best if NPM just blocked TOTP reuse.
TOTP stands for โTime-based One-Time Password,โ after all. The โone-timeโ property is important enough to account for 50% of the acronym. ๐
Even the spec explicitly calls for blocking reuse: datatracker.ietf.org/doc/html/rfc... 6/6
Devonte' Hawkins and I published a blog post all about the giant IBM Telum II that was professionally designed, you can read the full post here: community.ibm.com/community/us...
But at the end there's a surprise: the instructions and parts list for building your own little dual-chip module! Enjoy!
npm has revoked classic tokens for publishing, pushing maintainers toward OIDC trusted publishing or granular tokens. But @openjsf.org warns trusted publishing still has risky gaps for critical projects. What maintainers should do next:
socket.dev/blog/npm-rev... #NodeJS #JavaScript