143 wires and counting

$ follow Node.js

Keep up with Node.js in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-09-27
stories 48

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

Node adds --allow-env permission, brotli reset fix

By RepoJournal · Filed · About Node.js · Composed from the cited sources · methodology

Node.js landed a semver-major permission flag that scrubs environment variables at startup, alongside a zlib fix that restores brotli dictionaries and params after a stream reset.

src,lib: add --allow-env permission nodejs/node

by James M Snell

With --permission enabled, every environment variable not matched by --allow-env is removed at startup; the flag accepts names, prefix patterns like PREFIX_*, or *, repeatable or comma-separated. Node's own variables (NODE_OPTIONS, NODE_EXTRA_CA_CERTS, PATH, HOME) are never scrubbed, but NODE_ENV is not on that safe list, so it disappears unless you allow it explicitly. James M Snell flagged th...

zlib: preserve brotli params and dictionary on reset nodejs/node

by Xia Chao

ResetStream was calling Init() with no arguments, dropping the stored dictionary and never replaying SetParams, so a reset brotli stream lost its configuration. Node now remembers every successful parameter and replays both dictionary and params on reset, fixing the regression tracked in issue 66156.

querystring: speed up default parse and unescape nodejs/node

by anonrig

The default querystring.parse and unescape path skips the %XX walk when the input contains no % and uses a dedicated '&'/'=' scanner instead of building separator code arrays and running the multi-character state machine. Custom separators, maxKeys, decodeURIComponent, and a replaced querystring.unescape still go through the existing parser. The author notes the change was implemented with assi...

worker: strip types in Web Worker module entries nodejs/node

by osztenkurden

Experimental Web Worker module entries do not strip TypeScript annotations, so a .ts entry file throws a SyntaxError even while a JavaScript-compatible entry importing typed files works. The proposal strips types from file-backed .ts, .mts, and .cts module-worker entries before evaluation while preserving existing fetching and worker-type semantics.

worker: remove messageerror listeners on exit nodejs/node

by Dayun

Worker threads now remove their messageerror listeners on exit. The reliability desk also posted its report for 2026-09-27.

Quick answers

What shipped in Node.js on September 27, 2026?
Node.js landed a semver-major permission flag that scrubs environment variables at startup, alongside a zlib fix that restores brotli dictionaries and params after a stream reset. In total, 28 commits and 20 pull requests landed.
Who contributed to Node.js on September 27, 2026?
6 developers shipped this update, including James M Snell, anonrig, Xia Chao, Dayun, osztenkurden, and Node.js GitHub Bot.
What were the notable Node.js updates?
src,lib: add --allow-env permission, zlib: preserve brotli params and dictionary on reset, and querystring: speed up default parse and unescape.