143 wires and counting

$ follow Node.js

Keep up with Node.js in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-09-22
stories 40

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

undici 8.11.0 lands HTTP/2 length checks and WebSocket fixes

By RepoJournal · Filed · About Node.js · Composed from the cited sources · methodology

undici validated the tail of its HTTP/2 and WebSocket paths while Node core closed a recursive child-spawning bug in watch mode.

fix(h2): validate response content-length nodejs/undici

by mcollina

The HTTP/2 client now checks a response's Content-Length against the DATA bytes it actually receives, so truncated and oversized bodies fail with the existing response length mismatch error instead of arriving wrong. HEAD and 304 semantics are preserved, and fetch regression tests cover mismatches plus session reuse.

fix(websocket): reset the compressed flag when a message completes nodejs/undici

by askalf

ByteParser never cleared #info.compressed after delivering a permessage-deflate message, so the continuation-frame guard in lib/web/websocket/receiver.js was skipped after any compressed message and a stray continuation frame was decompressed and delivered. Resetting the flag on message completion closes that path.

watch: strip watch flags from NODE_OPTIONS in child process nodejs/node

by marcopiraccini

NODE_OPTIONS containing --watch made the watch parent spawn a child that inherited the same NODE_OPTIONS, entering watch mode itself and spawning another child in an infinite chain. The parent now strips --watch, --watch-path, --watch-preserve-output, and --watch-kill-signal from the child environment.

fix(h2): keep queued requests alive when the last stream closes nodejs/undici

by kjsik11

closeStreamSession unrefs the session when the last stream closes even while requests are still queued, leaving no handle to keep the event loop alive; this follows the earlier fix to resumeH2 for peers advertising SETTINGS_MAX_CONCURRENT_STREAMS = 0. If you queue HTTP/2 requests through undici, stalled sessions are the thing to watch.

v8.11.0 nodejs/undici

by github-actions[bot]

The 8.11.0 release collects the HTTP/2, decompress, cookie, and upgrade-diagnostics work above into a tagged version, with a repeated content-encoding header now joined and a cookie named __proto__ kept by getCookies. The long tail was routine: a jest dev bump to 30.5.2, a WebCryptoAPI WPT sync, and two test deflakes from panva that fix a 1/256 buffer collision in test-benchmark-crypto and lost...

Quick answers

What shipped in Node.js on September 22, 2026?
undici validated the tail of its HTTP/2 and WebSocket paths while Node core closed a recursive child-spawning bug in watch mode. In total, 18 commits, 21 pull requests, and 1 releases landed.
Who contributed to Node.js on September 22, 2026?
9 developers shipped this update, including mcollina, askalf, dependabot, github-actions[bot], kjsik11, marcopiraccini, TrevorBurnham, and nodejs-github-bot, and 1 more.
What were the notable Node.js updates?
fix(h2): validate response content-length, fix(websocket): reset the compressed flag when a message completes, and watch: strip watch flags from NODE_OPTIONS in child process.