143 wires and counting

$ follow Node.js

Keep up with Node.js in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-09-26
stories 78

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

localStorage hardens on bad files, sqlite classes get new names

By RepoJournal · Filed · About Node.js · Composed from the cited sources · methodology

Node's core desks spent the day tightening failure modes in storage and compression and renaming the SQLite surface before it freezes, while the nightly and release tooling churned quietly behind them.

src: throw on a malformed localStorage file nodejs/node

by Trevor Burnham

A localStorage backing file that already contains tables of the expected names is adopted as-is, and its values can carry any SQLite type, so a wrong-typed value aborted the process on every read. A bad schema_version was the worst case because that assertion sits in Storage::Open(), meaning any access aborted the application outright; the patch throws on the malformed file instead.

sqlite: rename DatabaseSync and StatementSync nodejs/node

by Guilherme Araújo

DatabaseSync and StatementSync become Database and Statement, with the internal DatabaseSyncLimits helper renamed DatabaseLimits. The old names survive as aliases and are documentation-only deprecated under DEP0210 and DEP0211, so existing code keeps running while new code should target the shorter names.

crypto: use backend cSHAKE and KMAC nodejs/node

by Filip Skokan

cSHAKE and KMAC now route through OpenSSL's KMAC provider and cSHAKE implementation, with SHAKE kept only when both cSHAKE parameters are empty; the custom Keccak framing, partial-bit handling, and short-key fallback are gone. Output lengths and KMAC key lengths must now be multiples of 8 bits, and KMAC keys at least 32 bits.

zlib: reject reset while a zstd frame is incomplete nodejs/node

by xia-chao

Calling reset() on a zstd compressor mid-frame dropped the in-progress frame state while bytes already emitted by flush() or a buffer-filling write stayed in the output, producing a stream that could not be decompressed and reported nothing. reset() now throws instead of silently corrupting the output.

module: normalize package map paths nodejs/node

by Dansatch

Package-map URLs ending in a slash, including ".." and "./", were stored in a different form than the one used at lookup time, so valid dependencies failed with ERR_PACKAGE_MAP_EXTERNAL_FILE; reproduced on v26.8.2. Paths are now normalized at map load, with tests covering CommonJS, ESM, parent-directory URLs, trailing slashes, and duplicate paths.

fix: add trailing slash to NIGHTLY_RELEASES_DIR path (#1035) nodejs/release-cloudflare-worker

by Brian Muenzenmeyer

The rest of the day was plumbing: a missing trailing slash on NIGHTLY_RELEASES_DIR in the release Cloudflare worker, refreshed redirect links, the snap nightly at 27.0.0-nightly20260925a3bb551ea7, and the 2026-09-26 reliability report.

Quick answers

What shipped in Node.js on September 26, 2026?
Node's core desks spent the day tightening failure modes in storage and compression and renaming the SQLite surface before it freezes, while the nightly and release tooling churned quietly behind them. In total, 55 commits and 23 pull requests landed.
Who contributed to Node.js on September 26, 2026?
8 developers shipped this update, including Trevor Burnham, Guilherme Araújo, Filip Skokan, xia-chao, Dansatch, GitHub Actions, Brian Muenzenmeyer, and Node.js GitHub Bot.
What were the notable Node.js updates?
src: throw on a malformed localStorage file, sqlite: rename DatabaseSync and StatementSync, and crypto: use backend cSHAKE and KMAC.