143 wires and counting

$ follow Node.js

Keep up with Node.js in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-10-03
stories 29

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

Legacy AsyncLocalStorage removed, FFI permission checks dropped

By RepoJournal · Filed · About Node.js · Composed from the cited sources · methodology

Node's async context machinery loses its async_hooks fallback, the FFI permission model gets one inconsistent gap closed, and the V8 serialization header stops being pinned in tests.

async_hooks: remove legacy AsyncLocalStorage implementation nodejs/node

by Matteo Collina

The async_hooks-based AsyncLocalStorage fallback and the --no-async-context-frame flag are gone; AsyncContextFrame is now the sole implementation. This is a breaking change for anyone still passing --no-async-context-frame or relying on async_hooks to back AsyncLocalStorage.

ffi: remove permission checks from dlclose and dlsym nodejs/node

by Trivikram Kamat

After process.permission.drop('ffi'), ffi.dlclose(lib) threw ERR_ACCESS_DENIED while the equivalent lib.close() succeeded, because only the ffi.* wrappers ran checkFFIPermission(). The checks are removed so dlclose and dlsym defer to the handle, whose permission is already validated when the DynamicLibrary is constructed.

test: do not hardcode V8 serialization header nodejs/node

by Joyee Cheung

V8's serialization header changes when V8 is updated, so the test no longer hardcodes it. The effect is that a V8 bump should now surface only in test/parallel/test-v8-serdes.js instead of breaking unrelated tests.

module: centralize builtin exposure policies nodejs/node

by sjungwon03

Builtin exposure rules were split between realm.js and per-option setup functions in pre_execution.js; they now live in one table that pre-execution applies after option initialization. The policy deliberately stays in the JavaScript loader rather than being derived from native option registration, since a single native option can expose multiple builtins.

test: mark worker init failure flaky on SmartOS nodejs/node

by Filip Skokan

The worker init failure test on SmartOS is marked flaky, tracking a descriptor-dependent V8 entropy failure until the libuv update in #66282 removes the dependency on opening /dev/urandom. Elsewhere, doc-kit wired oxfmt import sorting, a sitemap URL fix, and api.deps.dev as an allowed endpoint in its workflow.

Quick answers

What shipped in Node.js on October 3, 2026?
Node's async context machinery loses its async_hooks fallback, the FFI permission model gets one inconsistent gap closed, and the V8 serialization header stops being pinned in tests. In total, 16 commits and 13 pull requests landed.
Who contributed to Node.js on October 3, 2026?
9 developers shipped this update, including Joyee Cheung, Trivikram Kamat, Filip Skokan, Matteo Collina, sjungwon03, TheAlexLichter, Brian Muenzenmeyer, and Aviv Keller, and 1 more.
What were the notable Node.js updates?
async_hooks: remove legacy AsyncLocalStorage implementation, ffi: remove permission checks from dlclose and dlsym, and test: do not hardcode V8 serialization header.