143 wires and counting

$ follow Node.js

Keep up with Node.js in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-08-12
stories 28

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

NODE CORE TIGHTENS CRYPTO IN FIPS MODE, FIXES SQLITE STATEMENT LEAKS

By RepoJournal · Filed · About Node.js · Composed from the cited sources · methodology

WebCrypto's experimental XOF digests are now disabled when FIPS mode is enabled, closing a cryptographic gap, while a critical SQLite fix plugs statement lifetime management bugs that could leak resources.

The crypto team shipped a breaking change for FIPS deployments [1], disabling hand-rolled XOF digests and rejecting cSHAKE and KMAC parameters that bypass OpenSSL's FIPS provider constraints. This hardens compliance but requires applications relying on experimental crypto features to audit their code. Simultaneously, core landed a SQLite patch that replaces raw pointer management with RAII-style statement tracking [2], fixing two critical bugs: a leaked statement on `StatementSync::Create()` failure that inserted null pointers into the statements list, and tag store statements that were never tracked at all, leaving them open after `db.close()`. The test runner got a precision fix [3] that prevented tag filters from accidentally filtering out test file wrappers under process isolation, which meant no child processes ever spawned. On process infrastructure, the commit queue got a cleanup [4] removing legacy skip logic, and release tooling gained alpha prerelease tag support [5] to formalize pre-release workflows. Dependency bumps across the meeting agenda repo address a js-yaml security fix for quadratic complexity in omap duplicate key detection [6] and a brace-expansion patch [7].

Action items

References

  1. [1] crypto: disable non-FIPS WebCrypto paths in FIPS mode ↗ nodejs/node
  2. [2] sqlite: manage sqlite3_stmt lifetime with RAII ↗ nodejs/node
  3. [3] test_runner: do not tag-filter test file wrappers ↗ nodejs/node
  4. [4] tools: remove skip logic in `commit-queue.sh` ↗ nodejs/node
  5. [5] meta: add support for alpha prerelease tag ↗ nodejs/node
  6. [6] chore(deps-dev): bump js-yaml from 4.3.0 to 4.3.1 ↗ nodejs/node-meeting-agenda
  7. [7] chore(deps-dev): bump brace-expansion from 1.1.11 to 1.1.18 ↗ nodejs/node-meeting-agenda

Quick answers

What shipped in Node.js on August 12, 2026?
WebCrypto's experimental XOF digests are now disabled when FIPS mode is enabled, closing a cryptographic gap, while a critical SQLite fix plugs statement lifetime management bugs that could leak resources. In total, 14 commits and 14 pull requests landed.
Who contributed to Node.js on August 12, 2026?
6 developers shipped this update, including dependabot, Antoine du Hamel, araujogui, panva, Chemi Atlow, and Node.js GitHub Bot.
What were the notable Node.js updates?
crypto: disable non-FIPS WebCrypto paths in FIPS mode, sqlite: manage sqlite3_stmt lifetime with RAII, and test_runner: do not tag-filter test file wrappers.