$ the-wire · showcase
Node 26.10.0 lands with crypto.parsePKCS12()
By RepoJournal · Filed · About Node.js · Composed from the cited sources · methodology
Node 26.10.0 ships today while the runtime's webstreams, VFS, and test runner work continues underneath, none of it requiring action from you yet.
2026-09-22, Version 26.10.0 (Current), @aduh95 nodejs/node
The Current release adds crypto.parsePKCS12(), a SEMVER-MINOR API for parsing PKCS#12 bundles without hand-rolling DER and ASN.1 handling. It also brings Guilherme Araújo on as a collaborator; the same release is written up in a new nodejs.org blog post.
vfs: support recursive readdir in ZipProvider nodejs/node
ZipProvider used to throw ERR_METHOD_NOT_IMPLEMENTED on readdir() with { recursive: true }; it now scans entry names the same way a flat listing does, returning every member below the directory plus any directory those paths pass through, with names relative to the listed directory. Zip-backed fs code that previously caught the error to walk archives itself can drop that workaround.
test_runner: do not reuse a worker ID held by a running file nodejs/node
WorkerIdPool handed out IDs round-robin without releasing them, so a file that started later could be given an ID still held by a live process, defeating context.workerId. IDs are now held only while the owning file runs, so per-worker databases, ports, and directories stop colliding under --test-concurrency.
stream: trim per-pipe and per-tee costs in webstreams nodejs/node
Matteo Collina's round 18 of the webstreams performance work targets the fixed cost of wiring up a pipe or tee, plus an internal read request rebuilt through the runtime on every pipe, tee, and BYOB tee read. Pull cycles no longer run for sources with no pull() method, and two async wrappers came off the tee and BYOB read paths.
fix: reword add-on unloading paragraph (#142) nodejs/learn
Ben Noordhuis corrected the add-on unloading chapter: main-thread add-ons are never unloaded, and worker-thread add-on loading is deterministic rather than GC-driven. Also on the docs front, nodejs/learn swapped the origin's https:// prefix to fix its production build.