$ the-wire · showcase
WebCrypto raw key export throws InvalidAccessError, node-gyp pins patched tar
By RepoJournal · Filed · About Node.js · Composed from the cited sources · methodology
Node's WebCrypto export path now matches the spec's error contract, node-gyp's declared tar floor finally reflects the hardlink path traversal fix, and worker termination stops leaking queued messages.
crypto: fix raw key export error for wrong key type nodejs/node
Exporting a key as 'raw', 'raw-public', or 'raw-seed' when the key type does not match (an ECDSA private key as 'raw', an ML-KEM public key as 'raw-seed') used to fall through to a generic NotSupportedError; the Web Crypto and modern-algos export steps require InvalidAccessError there. The fix mirrors exportKeySpki() and exportKeyPkcs8(): select the exporter per algorithm first, then check the ...
chore(deps): upgrade tar to 7.5.7 to address CVE-2026-24842 (#3375) nodejs/node-gyp
tar below 7.5.7 is affected by GHSA-34x7-hfp2-rc4v, a hardlink path traversal where the security check and the hardlink creation resolve paths with different semantics, so a crafted archive can escape the extraction directory. A fresh install already resolved to a patched tar, but the declared range was still ^7.5.4, and the floor is what audit tooling and lockfile-pinned consumers report.
worker: discard queued messages on termination nodejs/node
Terminating a worker now closes the outside port and removes its message forwarding listeners synchronously, so messages already queued no longer dispatch when terminate() runs inside a listener. The current event is allowed to finish while subsequent messages, including those drained when the backing thread exits, are discarded.
deps: update lief to 1.0.0 nodejs/node
Node's vendored binary-parsing dependency jumped from the 0.x line to a 1.0.0 release, landed through the automated update path. Anyone building Node against system-provided libraries rather than the bundled copy should check the corresponding API surface.
feat: update gyp-next to v0.22.3 nodejs/node-gyp
The Node.js GitHub Bot bumped node-gyp's gyp-next dependency to v0.22.3. The reliability desk's only activity was the routine 2026-09-30 report.
Action items