Node.js is moving to one major release per year starting with Node 27! 🚀
✅ Simpler: Every release becomes LTS.
✅ Predictable: Version numbers now align with the year.
✅ New: A 6-month Alpha channel for early testing.
Read why we’re evolving: bit.ly/4rnosLg
Announcing the @nodejs LTS Upgrade and Modernization Program! 🟢 🚀
We're helping enterprises move safely off end-of-life Node.js versions to reduce security risks. We are also excited to kick things off with our first partner, @NodeSource.
Modern Node.js is safer Node.js. Check out the details on the OpenJS blog:
bit.ly/3NkjelD#NodeJS#OpenSource#JavaScript#OpenJS
Are you currently hiring for a role that includes using Node.js? Reply with a link to the opening and any relevant context.
If you're not, we'd appreciate a repost for visibility 💚
We have made our HackerOne policies even more strict. Now, if you don't have any Signal, you shouldn't be able to report through HackerOne. We advise you to contact any of the Security Release Stewards via OpenJS Slack.
nodejs.org/en/blog/announcem…
GitHub is funding open source security work across dozens of projects, including OpenJS projects like @nodejs and @webpack.
Strong ecosystems are built through sustained investment in the software supply chain, and we appreciate @github's continued support of open source maintainers. 🫶
Who knows how to secure open source better than the maintainers themselves? 🛡️
In Session 3 of the GitHub Secure Open Source Fund, 67 more projects improved their defenses.
From securing the AI stack to strengthening the global supply chain, find out how these maintainers are making security improvements that benefit the entire ecosystem. 👇
github.blog/open-source/main…
Are you currently hiring for a role that includes using Node.js? Reply with a link to the opening and any relevant context.
If you're not, we'd appreciate a repost for visibility 💚
AI is stress-testing open source security.
More reports. Same maintainers. Rising risk.
If your company relies on OSS projects, it’s time to step up. openjsf.org/blog/ai-is-stres…
Big year for security at OpenJS 👀
With support from Alpha Omega, we leveled up security across Node.js and the OpenJS ecosystem in 2025. Faster vulnerability response, automated releases, a new OpenJS CNA, stronger disclosure practices, and hands on support for over 10 projects.
Read the full 2025 security recap 👇
hubs.la/Q040lXwL0
Big news 👀 The OpenJS Foundation is bringing a dedicated summit to RenderATL 2026. 🔥
Created by and for the JavaScript and Node.js community. Expect technical talks, real world lessons, and practical takeaways.
Check out the details + register for the conference: hubs.la/Q040sX130
⚠️ The Node.js Project now requires a HackerOne Signal score of 1.0 or higher to submit vulnerability reports. This will help our team streamline reports and support effective security reviews.
nodejs.org/en/blog/announcem…