Node.js v25.4.0 is out! 💚
• require(esm) now stable and a new CLI flag: --require-module
• Module compile cache now stable
• http.setGlobalProxyFromEnv() added
• Multiple APIs promoted to stable (heapsnapshot, build snapshot, v8.queryObjects)
• Root CAs updated to NSS 3.117
• Several semver-minor improvements across events, module, stream, process, util
See: nodejs.org/en/blog/release/v…
Today, @nodejs published a security release for Node.js that fixes a critical bug affecting virtually every production Node.js app.
If you use React Server Components, Next.js, or ANY APM tool (Datadog, New Relic, OpenTelemetry), your app could be vulnerable to DoS attacks.
👇
We appreciate your patience and understanding as we work to deliver a secure and reliable release.
Updates are now available for the 25.x, 24.x, 22.x, 20.x Node.js release lines to address:
- 3 high severity issues
- 4 medium severity issues
- 1 low severity issue
nodejs.org/en/blog/vulnerabi…
🚨Our team has decided to postpone the release to Tuesday, January 13th, 2026. This additional time will allow us to properly test all backports and re-run CITGM to ensure the highest quality for our users.
Additionally, releasing on Tuesday rather than Friday helps ensure that security updates are available during regular business hours across all time zones, particularly for our users in the Asia-Pacific region.
nodejs.org/en/blog/vulnerabi…
The Node.js package configuration guide is now live! 🎉
Whether you're creating your first package or migrating to ESM, this guide walks you through it with examples.
nodejs.github.io/package-exa…
The guide is still in progress, but currently covers JavaScript packages without a build step.
More to come. Feedback, issues, and PRs are welcome!
github.com/nodejs/package-ex…
It's a new year 🎉 Are you currently hiring for a role that includes using Node.js? Reply with a link to the opening and any relevant context.
If you're not, we'd appreciate a repost for visibility 💚
Oh hi. 👋 We're back with the latest Security Snapshot that covers how to publish to npm safely and with ease. ✨
@_rafaelgss breaks down why local publishing with 2FA gives you the safest setup right now.
Hey @nodejs community!
We’re looking for your feedback on our beta documentation layout!
👉 nodejs-api-docs-tooling.verc…
Share your thoughts by replying to this post, or open an issue:
👉 github.com/nodejs/doc-kit/is…
The docs are built for you, so your input truly makes a difference 🙌
⚠️Node.js security release has been postponed ⚠️
We have decided to delay the security release further to January 7th 2026 to ensure the team has enough time to prepare the releases and avoid distruptions during the holiday season.
nodejs.org/en/blog/vulnerabi…
Thank you @discord for supporting open source! Discord amazingly donated boosts and verified status to @nodejs@webpack and @electronjs. Super grateful for the Discord team for supporting us at @openjsf!
How can you ACTUALLY get involved with OpenJS projects??
@kom_256 gives the download in our latest snapshot.
Join Slack, join our community meetings, or watch recordings.
Come say hi. 👋
❗️Node.js Security release pre-alert ❗️
We will release new versions of v20, v22, v24, v25 release lines on or shortly after the 15th of December 2025 in order to address:
* 3 high severity issues.
* 1 low severity issue.
* 1 medium severity issue.
nodejs.org/en/blog/vulnerabi…
Working in an enterprise setup with corporate proxies or custom CAs? Node.js has native support for that.
No external dependency required, just configure and continue 👍
Details: nodejs.org/en/learn/http/ent…
❗️Node.js Security release pre-alert ❗️
We will release new versions of v20, v22, v24, v25 release lines on or shortly after the 15th of December 2025 in order to address:
* 3 high severity issues.
* 1 low severity issue.
* 1 medium severity issue.
nodejs.org/en/blog/vulnerabi…
JavaScript is 30. Still running the web & still our favorite. 💛✨
The OpenJS Foundation is grateful for every contributor who has shaped its path, and we look forward to the continued growth of this community.
Are you currently hiring for a role that includes using Node.js? Reply with a link to the opening and any relevant context.
If you're not, we'd appreciate a repost for visibility 💚
SEMVER MAJORS ARE BORING 🚨
Major releases mostly bring breaking changes, not shiny new features.
The fun stuff? That’s hiding in the minors.
@_rafaelgss talks about why you should follow the minor releases in our latest JavaScript Security Snapshot.
Want to dive in further? Check out Rafael’s release of @nodejs 25: twitch.tv/videos/2592538705