143 wires and counting

$ follow Node.js

Keep up with Node.js in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-09-28
stories 30

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

Retired undici pool clients, a faster Buffer.isLatin1, and reports that finish on timeout

By RepoJournal · Filed · About Node.js · Composed from the cited sources · methodology

undici stops retired pool clients from stealing queued requests, Node's buffer gains a native Latin1 fast path, and the process-timeout report no longer gets cut off by an unresponsive Worker.

fix(pool): ensure that removed clients don't pick up requests (#5881) nodejs/undici

by James M Snell

jasnell reproduced an audit-test failure where a client removed after a failed connect still picked up queued requests: the pool reported zero connections while the socket stayed open, and pool.destroy() neither aborted the request nor closed the socket. pool-base now adds a kRetireCli marker so removed clients are out of the request path for good.

buffer: add isLatin1 nodejs/node

by jasnell

Buffer.isLatin1 is a native fast check for whether a string is Latin1, benchmarked far ahead of the equivalent regex on long inputs (221M vs 93M ops/sec on long one-byte strings) and flat rather than collapsing on long two-byte input (6.7M vs 913k for regex). Reach for it in input validation and encoding paths that currently pay for a string-wide regex.

report: skip unresponsive workers on process timeout nodejs/node

by trivikr

With --process-timeout and --report-on-process-timeout, the report walked every Worker and waited indefinitely; a Worker stuck in a synchronous native call never answered, so the watchdog force-exited before the report was written, leaving truncated, invalid JSON and a forced-exit message glued onto the "Writing Node.js report to file" line. Reports triggered by --process-timeout now wait only ...

perf_hooks: add options to monitorEventLoopDelay() nodejs/node

by jasnell

monitorEventLoopDelay() accepts options for tuning histogram parameters, so you can trade resolution against memory instead of taking the defaults. The same change corrects a truncation and a documentation bug.

chore: remove debian-slim comment linking libatomic1 with arm (#2635) nodejs/docker-node

by Mike McCready

The debian-slim Dockerfile comment tying libatomic1 to arm is gone: libatomic1 is required for Debian and Node.js 25 and later regardless of architecture. The other desks were housekeeping: CodeQL now skips test files in undici, and node's FFI tests were split so a timeout names the failing callback case.

Quick answers

What shipped in Node.js on September 28, 2026?
undici stops retired pool clients from stealing queued requests, Node's buffer gains a native Latin1 fast path, and the process-timeout report no longer gets cut off by an unresponsive Worker. In total, 15 commits and 15 pull requests landed.
Who contributed to Node.js on September 28, 2026?
6 developers shipped this update, including jasnell, Matteo Collina, Mike McCready, trivikr, panva, and Donghoon Kang.
What were the notable Node.js updates?
fix(pool): ensure that removed clients don't pick up requests (#5881), buffer: add isLatin1, and report: skip unresponsive workers on process timeout.