$ cat nodejs/week/2026-09-28.log
the week in review · Sep 28 – Oct 4, 2026
node-gyp 13.1.0 patches tar CVE, raises CMake floor
By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology
Tar below 7.5.7 carries a hardlink path traversal, and gyp-next now demands CMake 3.10 for native builds.
v13.1.0 nodejs/node-gyp
The release bumps gyp-next to v0.22.3 and pulls in the patched tar, so native addon builds get both the CMake fix and the CVE fix in one update. Projects pinned to the 13.x line need this version to stay clear of CVE-2026-24842.
chore(deps): upgrade tar to 7.5.7 to address CVE-2026-24842 (#3375) nodejs/node-gyp
The bundled tar moves to 7.5.7 for GHSA-34x7-hfp2-rc4v, a hardlink path traversal where the security check for hardlink entries and hardlink creation resolve paths with different semantics. A crafted archive can escape the extraction root; anything that untars untrusted input should be on tar 7.5.7 or later.
fix!(cmake): require CMake 3.10 and quote custom command comments (#361) nodejs/gyp-next
The generated cmake_minimum_required(VERSION 2.8.8) is a hard error on CMake 4.0+, which dropped compatibility with anything older than 3.5. Addons building through node-gyp on newer CMake either pass CMAKE_POLICY_VERSION_MINIMUM or move to gyp-next 0.22.3.
buffer: add isLatin1 nodejs/node
Buffer.isLatin1 does the byte-string check natively instead of through a regex, and the benchmark in the pull request puts it at 232M ops/s on short one-byte input against 122M for the regex and 55M for a loop. Any hot path that currently regex-tests strings before encoding can swap it out.
child_process: build the default env block in one native pass nodejs/node
spawn(), spawnSync(), and everything layered on them get roughly 20 to 24 percent faster when options.env is omitted, the common case, because the child environment block is now built in one native pass instead of one process.env proxy hop per variable. No API change, just a cheaper default path.
worker: discard queued messages on termination nodejs/node
terminate() now closes the outside port and removes its message forwarding listeners synchronously, so messages already queued can no longer dispatch after termination. The current event is allowed to finish rather than being cut off mid-flight.
report: skip unresponsive workers on process timeout nodejs/node
When --process-timeout expired, --report-on-process-timeout asked every Worker for a subreport and waited without a time limit; a worker blocked in a synchronous native call never answered and the watchdog force-exited before the report was written. Unresponsive workers are now skipped so the report lands.
crypto: fix raw key export error for wrong key type nodejs/node
Exporting a key in raw, raw-public, or raw-seed format with a mismatched key type (an ECDSA private key as raw, an ML-KEM public key as raw-seed) threw the generic NotSupportedError instead of InvalidAccessError. Code that branches on error name to detect wrong-type exports will see different behavior.
$ ls nodejs/week/ # the briefings behind this review
Keep up with Node.js in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.
fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.
Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.