143 wires and counting

$ follow Node.js

Keep up with Node.js in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-09-30
stories 38

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

WebCrypto raw key export throws InvalidAccessError, node-gyp pins patched tar

By RepoJournal · Filed · About Node.js · Composed from the cited sources · methodology

Node's WebCrypto export path now matches the spec's error contract, node-gyp's declared tar floor finally reflects the hardlink path traversal fix, and worker termination stops leaking queued messages.

crypto: fix raw key export error for wrong key type nodejs/node

by 한국

Exporting a key as 'raw', 'raw-public', or 'raw-seed' when the key type does not match (an ECDSA private key as 'raw', an ML-KEM public key as 'raw-seed') used to fall through to a generic NotSupportedError; the Web Crypto and modern-algos export steps require InvalidAccessError there. The fix mirrors exportKeySpki() and exportKeyPkcs8(): select the exporter per algorithm first, then check the ...

chore(deps): upgrade tar to 7.5.7 to address CVE-2026-24842 (#3375) nodejs/node-gyp

by Jiawen Geng

tar below 7.5.7 is affected by GHSA-34x7-hfp2-rc4v, a hardlink path traversal where the security check and the hardlink creation resolve paths with different semantics, so a crafted archive can escape the extraction directory. A fresh install already resolved to a patched tar, but the declared range was still ^7.5.4, and the floor is what audit tooling and lockfile-pinned consumers report.

worker: discard queued messages on termination nodejs/node

by Filip Skokan

Terminating a worker now closes the outside port and removes its message forwarding listeners synchronously, so messages already queued no longer dispatch when terminate() runs inside a listener. The current event is allowed to finish while subsequent messages, including those drained when the backing thread exits, are discarded.

deps: update lief to 1.0.0 nodejs/node

by nodejs-github-bot

Node's vendored binary-parsing dependency jumped from the 0.x line to a 1.0.0 release, landed through the automated update path. Anyone building Node against system-provided libraries rather than the bundled copy should check the corresponding API surface.

feat: update gyp-next to v0.22.3 nodejs/node-gyp

by nodejs-github-bot

The Node.js GitHub Bot bumped node-gyp's gyp-next dependency to v0.22.3. The reliability desk's only activity was the routine 2026-09-30 report.

Quick answers

What shipped in Node.js on September 30, 2026?
Node's WebCrypto export path now matches the spec's error contract, node-gyp's declared tar floor finally reflects the hardlink path traversal fix, and worker termination stops leaking queued messages. In total, 25 commits and 13 pull requests landed.
Who contributed to Node.js on September 30, 2026?
6 developers shipped this update, including koreahghg, Filip Skokan, nodejs-github-bot, Antoine du Hamel, Brian Muenzenmeyer, and Jiawen Geng.
What were the notable Node.js updates?
crypto: fix raw key export error for wrong key type, chore(deps): upgrade tar to 7.5.7 to address CVE-2026-24842 (#3375), and worker: discard queued messages on termination.