$ the-wire · showcase
Node adds --allow-env permission, brotli reset fix
By RepoJournal · Filed · About Node.js · Composed from the cited sources · methodology
Node.js landed a semver-major permission flag that scrubs environment variables at startup, alongside a zlib fix that restores brotli dictionaries and params after a stream reset.
src,lib: add --allow-env permission nodejs/node
With --permission enabled, every environment variable not matched by --allow-env is removed at startup; the flag accepts names, prefix patterns like PREFIX_*, or *, repeatable or comma-separated. Node's own variables (NODE_OPTIONS, NODE_EXTRA_CA_CERTS, PATH, HOME) are never scrubbed, but NODE_ENV is not on that safe list, so it disappears unless you allow it explicitly. James M Snell flagged th...
zlib: preserve brotli params and dictionary on reset nodejs/node
ResetStream was calling Init() with no arguments, dropping the stored dictionary and never replaying SetParams, so a reset brotli stream lost its configuration. Node now remembers every successful parameter and replays both dictionary and params on reset, fixing the regression tracked in issue 66156.
querystring: speed up default parse and unescape nodejs/node
The default querystring.parse and unescape path skips the %XX walk when the input contains no % and uses a dedicated '&'/'=' scanner instead of building separator code arrays and running the multi-character state machine. Custom separators, maxKeys, decodeURIComponent, and a replaced querystring.unescape still go through the existing parser. The author notes the change was implemented with assi...
worker: strip types in Web Worker module entries nodejs/node
Experimental Web Worker module entries do not strip TypeScript annotations, so a .ts entry file throws a SyntaxError even while a JavaScript-compatible entry importing typed files works. The proposal strips types from file-backed .ts, .mts, and .cts module-worker entries before evaluation while preserving existing fetching and worker-type semantics.
worker: remove messageerror listeners on exit nodejs/node
Worker threads now remove their messageerror listeners on exit. The reliability desk also posted its report for 2026-09-27.
Action items