Skip to content

doc: downgrade macOS x64 to Tier 2 - #63055

Merged
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
aduh95:x86_64-darwin-eol
May 6, 2026
Merged

doc: downgrade macOS x64 to Tier 2#63055
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
aduh95:x86_64-darwin-eol

Conversation

@aduh95

Copy link
Copy Markdown
Contributor

With Apple announcing the upcoming end of Rosetta, we might not be able to provide x64 compatible binaries during the lifetime of Node.js 27 (macOS 27 EOL are not known IIUC, but we should expect it to be supported until 2029, Node.js 27 EOL would be in April 2030). I think Tier 2 is what best applies, but happy to change it to Experimental.

node/BUILDING.md

Lines 82 to 85 in 66054cc

***Tier 2**: These platforms represent smaller segments of the Node.js user
base. The Node.js Build Working Group maintains infrastructure for full test
coverage. Test failures on tier 2 platforms will block releases.
Infrastructure issues may delay the release of binaries for these platforms.

Refs: https://developer.apple.com/documentation/apple-silicon/about-the-rosetta-translation-environment/

Signed-off-by: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95aduh95 added the semver-major PRs that contain breaking changes and should be released in the next major version. label Apr 30, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/build
  • @nodejs/tsc

@nodejs-github-botnodejs-github-bot added build Issues and PRs related to build files or the CI. doc Issues and PRs related to the documentations. labels Apr 30, 2026
@ShogunPanda

Copy link
Copy Markdown
Contributor

May I ask why don't directly downgrade to Experimental so we don't have to do it twice?

sxa
sxa approved these changes Apr 30, 2026

@sxasxa left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

May I ask why don't directly downgrade to Experimental so we don't have to do it twice?

My personal opinion is that this should be no lower than tier 2 for now and therefore continues to be a platform that blocks releases if it doesn't work. At present we have the infrastructure capacity to leave it as tier 2 until such time as we cannot reasonably support testing on it, or V8 drops support for it.

@Renegade334

Copy link
Copy Markdown
Member

With Apple announcing the upcoming end of Rosetta, we might not be able to provide x64 compatible binaries during the lifetime of Node.js 27

To be clear with the semver-major timing then, the intention is to drop to Tier 2 from v27.x, with the implicit proviso under the Tier 2 contract that if macOS support gets pulled during that release cycle, we stop producing release binaries?

@richardlau

Copy link
Copy Markdown
Member

With Apple announcing the upcoming end of Rosetta, we might not be able to provide x64 compatible binaries during the lifetime of Node.js 27 (macOS 27 EOL are not known IIUC, but we should expect it to be supported until 2029, Node.js 27 EOL would be in April 2030). I think Tier 2 is what best applies, but happy to change it to Experimental.

node/BUILDING.md

Lines 82 to 85 in 66054cc

***Tier 2**: These platforms represent smaller segments of the Node.js user
base. The Node.js Build Working Group maintains infrastructure for full test
coverage. Test failures on tier 2 platforms will block releases.
Infrastructure issues may delay the release of binaries for these platforms.

Refs: https://developer.apple.com/documentation/apple-silicon/about-the-rosetta-translation-environment/

FWIW Rosetta 2 is due to be in macOS 27 (but not after) but the Apple developer article also states that macOS 26 is the last one with support for x64. I've opend a Build WG issue to discuss the more general quesions, but with Apple a lot of this is "our best guess" because they do not announce End-of-Life dates for macOS, nodejs/build#4317

Also I don't think we currently break the download stats down in a way that lets us work out the number of downloads of macOS x64 builds vs macOS arm64 builds -- we split by OS and we split by architecture but not combinations of the two. And for the pkg we don't know whether people are downloading those for use on arm64 or x64.

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, but I think this should be experimental and dropped from the release pipeline in 27, if not in 26.

Reasoning: 3 years is a long time, and I'm unsure we can guarantee hardware availability that long.

@sxa

sxa commented May 1, 2026

Copy link
Copy Markdown
Member

Also I don't think we currently break the download stats down in a way that lets us work out the number of downloads of macOS x64 builds vs macOS arm64 builds -- we split by OS and we split by architecture but not combinations of the two.

That's unfortunate - is there any way we can start to get them that way going forward since that trend will definitely be useful as we head towards 27.

And for the pkg we don't know whether people are downloading those for use on arm64 or x64.

True ... Unless we have any analytics on the web site relating to how many people change this drop down (which currently defaults to x64 - perhaps something we could switch) before selecting the package.

image

@richardlau

Copy link
Copy Markdown
Member

Also I don't think we currently break the download stats down in a way that lets us work out the number of downloads of macOS x64 builds vs macOS arm64 builds -- we split by OS and we split by architecture but not combinations of the two.

That's unfortunate - is there any way we can start to get them that way going forward since that trend will definitely be useful as we head towards 27.

If you're able to decipher the metrics stuff in the Build WG repo the scrubbing of personal identifiable information and summarizing is all in there.

And for the pkg we don't know whether people are downloading those for use on arm64 or x64.

True ... Unless we have any analytics on the web site relating to how many people change this drop down (which currently defaults to x64 - perhaps something we could switch) before selecting the package.

I don't know if we have web analytics -- that'd be something to ask @nodejs/web-infra.

@aduh95

Copy link
Copy Markdown
ContributorAuthor

Worth noting that Homebrew announced no x86 support was to be expected from them as of September 2027: https://docs.brew.sh/Support-Tiers#future-macos-support
I think we rely on Homebrew to manage some of the dependencies, so we might get stuck with an outdated build chain if we don't find an alternative (even for Node.js 24, EOL is scheduled for April 2028). Maybe we should downgrade to Tier 2 for Node.js 26 already?

@MattIPv4

MattIPv4 commented May 1, 2026

Copy link
Copy Markdown
Member

I'm not sure if we have any analytics for the site dropdowns, but even if we did, I'm not convinced that'd be a great representation of actual usage given how many folks rely on version manager tooling.

However, we can look at traffic data in Cloudflare to get a sense of usage of the actual downloads:

darwin-arm64 has 5.71m requests in the last 30 days
image

darwin-x64 has 1.48m requests in the last 30 days
image

@Renegade334

Renegade334 commented May 1, 2026

Copy link
Copy Markdown
Member

Maybe we should downgrade to Tier 2 for Node.js 26 already?

Aye, this was what I was hoping to clarify. I realise it's a somewhat short-notice decision to make, but I think that waiting another year to downgrade with the new release cycle is too late to be signalling to users that we're downgrading support. We have the opportunity now to make it clear that v26.x does not come with LTS availability guarantees for macOS x64, which should hopefully be a strong signal to the ecosystem to start their sunset planning.

@ryanaslett

Copy link
Copy Markdown

darwin-x64 has 1.48m requests in the last 30 days image

Worth noting that about 40% of that traffic is coming from MIcrosoft's ASN, so there is a sizeable amount of usage that is likely intel mac images on github actions (example: actions/runner-images#13637)

@mcollina

Copy link
Copy Markdown
Member

We might even have a lot of usage, but we can't guarantee hardware for the next 3-4 years, we should cut it now before having to do it mid-cicle.

@Renegade334

Copy link
Copy Markdown
Member

@nodejs/tsc the consensus appears to be drifting towards needing to downgrade this for v26.x, if this has blessing? Even if the PR doesn't land immediately, this could be added to the notable changes in the 26.0.0 release announcement for tomorrow, and then followed up with a standalone blog post.

@aduh95aduh95 added the tsc-agenda Issues and PRs to discuss during the meetings of the TSC. label May 4, 2026
@aduh95aduh95 added the commit-queue Add this label to land a pull request using GitHub Actions. label May 6, 2026
@nodejs-github-botnodejs-github-bot removed the commit-queue Add this label to land a pull request using GitHub Actions. label May 6, 2026
@nodejs-github-bot
nodejs-github-bot merged commit c52fad3 into nodejs:mainMay 6, 2026
37 of 38 checks passed
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Landed in c52fad3

@aduh95
aduh95 deleted the x86_64-darwin-eol branch May 6, 2026 16:23
@aduh95aduh95 added notable-change PRs with changes that should be highlighted in changelogs. dont-land-on-v22.x PRs that should not land on the v22.x-staging branch and should not be released in v22.x. dont-land-on-v24.x PRs that should not land on the v24.x-staging branch and should not be released in v24.x. dont-land-on-v25.x backport-open-v26.x Indicate that the PR has an open backport and removed semver-major PRs that contain breaking changes and should be released in the next major version. tsc-agenda Issues and PRs to discuss during the meetings of the TSC. labels May 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

The notable-changePRs with changes that should be highlighted in changelogs. label has been added by @aduh95.

Please suggest a text for the release notes if you'd like to include a more detailed summary, then proceed to update the PR description with the text or a link to the notable change suggested text comment. Otherwise, the commit will be placed in the Other Notable Changes section.

aduh95 added a commit that referenced this pull request May 30, 2026
Signed-off-by: Antoine du Hamel <duhamelantoine1995@gmail.com>
PR-URL: #63055
Backport-PR-URL: #63153
Refs: https://developer.apple.com/documentation/apple-silicon/about-the-rosetta-translation-environment/
Refs: nodejs/build#4317
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Michaël Zasso <targos@protonmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
Reviewed-By: Stewart X Addison <sxa@redhat.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Reviewed-By: Chengzhong Wu <legendecas@gmail.com>
aduh95 added a commit that referenced this pull request May 30, 2026
Notable changes:
buffer:
* (SEMVER-MINOR) increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) #63597
crypto:
* update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527
doc:
* downgrade macOS x64 support to Tier 2 (Antoine du Hamel) #63055
http:
* (SEMVER-MINOR) add `httpValidation` option to configure header value validation (RajeshKumar11) #61597
inspector:
* (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079
lib,permission:
* (SEMVER-MINOR) add `permission.drop` (Rafael Gonzaga) #62672
PR-URL: #63664
aduh95 added a commit that referenced this pull request May 31, 2026
Notable changes:
buffer:
* (SEMVER-MINOR) increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) #63597
crypto:
* update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527
doc:
* downgrade macOS x64 support to Tier 2 (Antoine du Hamel) #63055
http:
* (SEMVER-MINOR) add `httpValidation` option to configure header value validation (RajeshKumar11) #61597
inspector:
* (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079
lib,permission:
* (SEMVER-MINOR) add `permission.drop` (Rafael Gonzaga) #62672
PR-URL: #63664
aduh95 added a commit that referenced this pull request Jun 1, 2026
Notable changes:
buffer:
* (SEMVER-MINOR) increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) #63597
crypto:
* update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527
doc:
* downgrade macOS x64 support to Tier 2 (Antoine du Hamel) #63055
http:
* (SEMVER-MINOR) add `httpValidation` option to configure header value validation (RajeshKumar11) #61597
inspector:
* (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079
lib,permission:
* (SEMVER-MINOR) add `permission.drop` (Rafael Gonzaga) #62672
PR-URL: #63664
gonzalezanjel162-a11y

This comment was marked as spam.

jamesnavinhill added a commit to studio-jami/intercal that referenced this pull request Jun 5, 2026
…ve API
Add `services/pipeline` (`intercal_pipeline`): the single orchestration
entrypoint that chains the per-service jobs in stage order — ingest →
normalize → extract (mentions+claims) → embed (chunks+claims) → resolve
entities → link claim entities → derive relationships → write fact versions
— and returns a `PipelineRunHealth` summary (per-stage counters, error
counts, run id, timing, succeeded|partial|failed status). Portable CLI:
`intercal-pipeline run --source-id <uuid>` / `run-all`
(`python -m intercal_pipeline <cmd>`) — the same command GitHub Actions
scheduled workflows and Cloud Run Jobs invoke; cadence stays with the
external scheduler (decision 0002). Later-plan synthesis (compute_freshness,
synthesize_digest → Plan 03; dispatch_subscriptions → Plan 04) are explicit
NotImplementedError stubs, not invoked by run_pipeline.
Audit of the prior uncommitted WIP (why earlier attempts failed + fixes):
- Env, not code: `intercal_pipeline` (and every service) is only importable
under `uv sync --all-packages`; prior runs failed at test *collection*, so
the real bugs were never reached. Added the missing `py.typed` marker
(matching the other five packages) so pyright resolves first-party imports
— no global pyproject weakening needed.
- Health counters read wrong keys (`persisted`/`embedded` vs real
`claims_persisted`/`chunks_embedded`/`claims_embedded`) → always-0 on real
data; the fakes masked it. Fixed reads; pinned real keys in fixtures.
- Resolve/link processed ONE batch per call; the orchestrator called them
once, leaving most of ~880 mentions unresolved → the next run resolved the
leftovers into NEW entities (re-run grew the count). Fixed by draining each
stage until no pending mentions (resolve) / no progress (link), with a cap.
- LLM non-determinism: re-extracting an already-processed doc yields a
different mention set → new entities. Orchestrator now skips extraction for
docs that already have mentions (`--extract-force` overrides).
- Relationship gate: added `contributed`/`contributor`/`committed`/`submitted`
to the `person_authored_artifact` predicate vocabulary (semantic match to
the seeded type, not a fabrication).
Verification:
- 373 service tests pass (27 W8 + 2 new resolve regression assertions);
`pnpm py:lint` + `pnpm py:typecheck` clean (0 errors).
- Applied pending production migrations (0023, 0024) + source seeds.
- Live Phase B heartbeat on the PRODUCTION Neon branch via
scripts/dev/verify_w8_pipeline.py (real GitHub-releases ingest, fastembed,
Gemini 2.5-flash): 155 resolved entities, 260 review candidates, 6
relationships, 155 fact versions. Idempotent re-run: all counts stable
(zero duplicate canonical records). PASS.
- Real data reaches the live API (lntercal.vercel.app, prod Neon):
GET /api/v1/entity?name_or_id=Antoine du Hamel returns the entity, its
person_authored_artifact relationship to nodejs/node#63055 (with provenance)
and 5 evidence-linked claims; GET /api/v1/evidence?query=Stabilized returns
the real rust-lang/rust v1.96.0 release-notes document with citation.
Plan 02 is now fully complete (all 8 workstreams + claim-entity linking,
live-verified). Flagged the dated plan for retirement to docs/_legacy/roadmaps/.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
jylenhof pushed a commit to jylenhof/mise-update-tool that referenced this pull request Aug 4, 2026
Automated mise tool upgrades from local config.
Updated tools:
- `action-validator`
- `actionlint`
- `aube`
- `editorconfig-checker`
- `ghalint`
- `node`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`
Command: `mise upgrade --bump --local action-validator actionlint aube editorconfig-checker ghalint node pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`
<details>
<summary>Version changelog (node)</summary>
| Tool | Requested | Installed |
|------|-----------|-----------|
| `node` | `24` → `26` | `24.18.1` → `26.5.1` |
</details>
<details>
<summary>Release notes (1 tools)</summary>
<details>
<summary>node: `24.18.1` → `26.5.1` (nodejs/node)</summary>
### v25.8.2
This is a security release.
### Notable Changes
* (CVE-2026-21637) wrap `SNICallback` invocation in `try`/`catch` (Matteo Collina) - High
* (CVE-2026-21710) use null prototype for `headersDistinct`/`trailersDistinct` (Matteo Collina) - High
* (CVE-2026-21711) include permission check to `pipe_wrap.cc` (RafaelGSS) - Medium
* (CVE-2026-21712) handle url crash on different url formats (RafaelGSS) - Medium
* (CVE-2026-21713) use timing-safe comparison in Web Cryptography HMAC and KMAC (Filip Skokan) - Medium
* (CVE-2026-21714) handle `NGHTTP2_ERR_FLOW_CONTROL` error code (RafaelGSS) - Medium
* (CVE-2026-21717) test array index hash collision (Joyee Cheung) - Medium
* (CVE-2026-21715) add permission check to `realpath.native` (RafaelGSS) - Low
* (CVE-2026-21716) include permission check on `lib/fs/promises` (RafaelGSS) - Low
### Commits
* \[[`2086b7477b`](nodejs/node@2086b7477b)] - **(CVE-2026-21717)** **build,test**: test array index hash collision (Joyee Cheung) [nodejs-private/node-private#834](https://github.com/nodejs-private/node-private/pull/834)
* \[[`0f9332a40a`](nodejs/node@0f9332a40a)] - **(CVE-2026-21713)** **crypto**: use timing-safe comparison in Web Cryptography HMAC and KMAC (Filip Skokan) [nodejs-private/node-private#822](https://github.com/nodejs-private/node-private/pull/822)
* \[[`2b6937ddb2`](nodejs/node@2b6937ddb2)] - **deps**: update undici to 7.24.4 (Node.js GitHub Bot) [#62271](nodejs/node#62271)
* \[[`bfb8ad5787`](nodejs/node@bfb8ad5787)] - **deps**: update undici to 7.24.3 (Node.js GitHub Bot) [#62233](nodejs/node#62233)
* \[[`be6384727f`](nodejs/node@be6384727f)] - **deps**: upgrade npm to 11.11.1 (npm team) [#62216](nodejs/node#62216)
* \[[`2feea5bb97`](nodejs/node@2feea5bb97)] - **deps**: V8: override… (truncated)
### v25.9.0
### Notable Changes
#### Test runner module mocking improvements
`MockModuleOptions.defaultExport` and `MockModuleOptions.namedExports` have been
consolidated into a single option `MockModuleOptions.exports` to align with user
expectations and other test runners.
A `default` property on `MockModuleOptions.exports` represents the default
export, and own enumerable properties are treated as named exports.
An automated migration is available to update user code:
<https://github.com/nodejs/userland-migrations/tree/main/recipes/mock-module-exports>
```bash
npx codemod @​nodejs/mock-module-exports
```
Contributed by sangwook in [#61727](nodejs/node#61727).
#### Other notable changes
* \[[`312476cb84`](nodejs/node@312476cb84)] - **(SEMVER-MINOR)** **async\_hooks**: add using scopes to `AsyncLocalStorage` (Stephen Belanger) [#61674](nodejs/node#61674)
* \[[`62d2cd473b`](nodejs/node@62d2cd473b)] - **(SEMVER-MINOR)** **cli**: add `--max-heap-size` option (tannal) [#58708](nodejs/node#58708)
* \[[`d0ebf0e44b`](nodejs/node@d0ebf0e44b)] - **(SEMVER-MINOR)** **crypto**: add `TurboSHAKE` and `KangarooTwelve` Web Cryptography algorithms (Filip Skokan) [#62183](nodejs/node#62183)
* \[[`f85b9d9fa8`](nodejs/node@f85b9d9fa8)] - **(SEMVER-MINOR)** **repl**: add customizable error handling (Anna Henningsen) [#62188](nodejs/node#62188)
* \[[`67b854d407`](nodejs/node@67b854d407)] - **(SEMVER-MINOR)** **repl**: remove dependency on `node:domain` (Matteo Collina) [#61227](nodejs/node#61227)
* \[[`966b700623`](nodejs/node@966b700623)] - **(SEMVER-MINOR)** **sea**: support code cache for ESM entrypoint in SEA (Joyee Cheung) [#62158](nodejs/node#62158)
*… (truncated)
### v26.0.0
We're excited to announce the release of Node.js 26! Highlights include the Temporal API enabled by default,
updates to the V8 JavaScript engine to 14.6, Undici to 8.0, and several important deprecations and removals
as we continue to modernize the platform.
As a reminder, Node.js 26 will enter long-term support (LTS) in October, but until then, it will be the "Current" release for the next six months.
We encourage you to explore the new features and benefits offered by this latest release and evaluate their potential impact on your applications.
### Notable Changes
#### Temporal API
The Temporal API is now enabled by default in Node.js 26. Temporal is a modern date/time API for JavaScript
that provides a more robust and feature-rich alternative to the legacy `Date` object.
Contributed by Richard Lau in [#61806](nodejs/node#61806).
#### V8 14.6
The V8 engine is updated to version 14.6.202.33, which is part of Chromium 134.
This version also includes:
* Upsert (<https://github.com/tc39/proposal-upsert>): `[Weak]Map.prototype.getOrInsert()`, `[Weak]Map.prototype.getOrInsertComputed()`
* Iterator sequencing (<https://github.com/tc39/proposal-iterator-sequencing>): `Iterator.concat()`
Contributed by Michaël Zasso in [#61898](nodejs/node#61898).
#### Undici 8
Undici has been updated to version 8.0.2, bringing new features and improvements to Node.js's HTTP client implementation.
#### Deprecations and Removals
* \[[`dff46c07c3`](nodejs/node@dff46c07c3)] - **(SEMVER-MAJOR)** **crypto**: move DEP0182 to End-of-Life (Tobias Nießen) [#61084](nodejs/node#61084)
* \[[`93c25815ee`](nodejs/node@93c25815ee)] - **(SEMVER-MAJOR)** **http**: move writeHeader to end-of-life (Sebastian Beltran) [#60635](nodejs/node#60635)
`http.Server.prototype.writeHeader()` is now fully removed. Use `http.Server.prototype.write… (truncated)
### v26.1.0
### Notable Changes
#### Experimental `node:ffi` module
Node.js now includes an experimental `node:ffi` module for loading dynamic
libraries and calling native symbols from JavaScript.
The API is gated behind the `--experimental-ffi` flag and, when the Permission
Model is enabled, requires `--allow-ffi`.
This API is inherently unsafe. Invalid pointers, incorrect signatures, or accessing memory
after it has been freed can crash the process or corrupt memory.
Contributed by Paolo Insogna in [#62072](nodejs/node#62072).
#### Other Notable Changes
* \[[`34a6454fe3`](nodejs/node@34a6454fe3)] - **(SEMVER-MINOR)** **buffer**: add `end` parameter (Robert Nagy) [#62390](nodejs/node#62390)
* \[[`073e84d7fe`](nodejs/node@073e84d7fe)] - **(SEMVER-MINOR)** **crypto**: accept key data in `crypto.diffieHellman()` and cleanup DH jobs (Filip Skokan) [#62527](nodejs/node#62527)
* \[[`5b9cb10a5f`](nodejs/node@5b9cb10a5f)] - **(SEMVER-MINOR)** **crypto**: implement `randomUUIDv7()` (nabeel378) [#62553](nodejs/node#62553)
* \[[`98f9becd16`](nodejs/node@98f9becd16)] - **(SEMVER-MINOR)** **debugger**: add edit-free runtime expression probes to `node inspect` (Joyee Cheung) [#62713](nodejs/node#62713)
* \[[`06defaa2ea`](nodejs/node@06defaa2ea)] - **(SEMVER-MINOR)** **fs**: add `signal` option to `fs.stat()` (Mert Can Altin) [#57775](nodejs/node#57775)
* \[[`db66a963bf`](nodejs/node@db66a963bf)] - **(SEMVER-MINOR)** **fs**: expose `frsize` field in `statfs` (Jinho Jang) [#62277](nodejs/node#62277)
* \[[`87adb3472b`](nodejs/node@87adb3472b)] - **(SEMVER-MINOR)** **http**: harden `ClientRequest` options merge (Matteo Collina) [#6… (truncated)
### v26.2.0
### Notable Changes
* \[[`189d43a193`](nodejs/node@189d43a193)] - **doc**: mark `stream.compose` stable (Matteo Collina) [#62562](nodejs/node#62562)
* \[[`f858c6140e`](nodejs/node@f858c6140e)] - **(SEMVER-MINOR)** **fs**: add `Temporal.Instant` support to `Stats` and `BigIntStats` (Livia Medeiros) [#60789](nodejs/node#60789)
* \[[`0cbb3895df`](nodejs/node@0cbb3895df)] - **(SEMVER-MINOR)** **http**: add `writeInformation` to send arbitrary 1xx status codes (Tim Perry) [#63155](nodejs/node#63155)
### Commits
* \[[`9a394bab84`](nodejs/node@9a394bab84)] - **benchmark**: respect stream/iter broadcast backpressure (Trivikram Kamat) [#63314](nodejs/node#63314)
* \[[`ad98b4620b`](nodejs/node@ad98b4620b)] - **crypto**: align verifyOneShot accepted types (Anshika Jain) [#63280](nodejs/node#63280)
* \[[`ba0736a847`](nodejs/node@ba0736a847)] - **crypto**: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255)
* \[[`5573a6a4a8`](nodejs/node@5573a6a4a8)] - **crypto**: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255)
* \[[`7dc563b8d6`](nodejs/node@7dc563b8d6)] - **crypto**: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255)
* \[[`b55e2b1f4d`](nodejs/node@b55e2b1f4d)] - **crypto**: improve system certificate enumeration logic on macOS (Robo) [#62576](nodejs/node#62576)
* \[[`fd509a755a`](nodejs/node@fd509a755a)] - **crypto**: harden CryptoKey algorithm slots… (truncated)
### v26.3.0
### Notable Changes
#### Potential changes to macOS Universal Binary availability
With Apple and its ecosystem progressively dropping support for Intel-based
architectures, it has become apparent that the Node.js project may not be able
to maintain the universal binaries we currently distribute for the full lifetime
of Node.js 26. This change serves to communicate that risk. At present, our
intention remains to continue shipping universal binaries supporting both Apple
Silicon and Intel-based Macs for as long as practical.
Contributed by Antoine du Hamel in [#63055](nodejs/node#63055).
#### Other notable changes
* \[[`a2a4b33dd8`](nodejs/node@a2a4b33dd8)] - **(SEMVER-MINOR)** **buffer**: increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) [#63597](nodejs/node#63597)
* \[[`051a2152f7`](nodejs/node@051a2152f7)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#63527](nodejs/node#63527)
* \[[`49462eca37`](nodejs/node@49462eca37)] - **(SEMVER-MINOR)** **http**: add `httpValidation` option to configure header value validation (RajeshKumar11) [#61597](nodejs/node#61597)
* \[[`97b7ab19bd`](nodejs/node@97b7ab19bd)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#63079](nodejs/node#63079)
* \[[`cfb80a2103`](nodejs/node@cfb80a2103)] - **(SEMVER-MINOR)** **lib,permission**: add `permission.drop` (Rafael Gonzaga) [#62672](nodejs/node#62672)
### Commits
* \[[`a2a4b33dd8`](nodejs/node@a2a4b33dd8)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#63597](nodejs/node#63597)
* \[[`0eff3e23b9`](https://github.com/nodejs/n… (truncated)
### v26.3.1
This is a security release.
### Notable Changes
* (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High
* (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High
* (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium
* (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium
* (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium
* (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium
* (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium
* (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low
* (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low
* (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low
* (CVE-2026-48936) permission: guard pipe open and chmod with net scope (RafaelGSS) – Low
### Commits
* \[[`98fbc89211`](nodejs/node@98fbc89211)] - **(CVE-2026-48933)** **crypto**: guard WebCrypto cipher output length (Filip Skokan) [nodejs-private/node-private#878](https://github.com/nodejs-private/node-private/pull/878)
* \[[`110840f2c7`](nodejs/node@110840f2c7)] - **deps**: update llhttp to 9.4.2 (Antoine du Hamel) [nodejs-private/node-private#890](https://github.com/nodejs-private/node-private/pull/890)
* \[[`8d36d522b2`](nodejs/node@8d36d522b2)] - **deps**: update undici to 8.5.0 (Node.js GitHub Bot) [#63903](nodejs/node#63903)
* \[[`2e6d03993a`](nodejs/node@2e6d03993a)] - **deps**: update undici to 8.4.0 (Node.js GitHub Bot) [#63779](nodejs/node#63779)
* \[[`5a17d5b07a`](nodejs/node@5a17d5b07a)] - **deps… (truncated)
### v26.4.0
### Notable Changes
* \[[`cde0daabcc`](nodejs/node@cde0daabcc)] - **(SEMVER-MINOR)** **doc**: update `blockList` stability status to release candidate (alphaleadership) [#63050](nodejs/node#63050)
* \[[`b78f5a7537`](nodejs/node@b78f5a7537)] - **(SEMVER-MINOR)** **fs**: support caller-supplied `readFile()` buffers (Matteo Collina) [#63634](nodejs/node#63634)
* \[[`417aacbc36`](nodejs/node@417aacbc36)] - **(SEMVER-MINOR)** **http**: close pre-request sockets in `closeIdleConnections` (semimikoh) [#63470](nodejs/node#63470)
* \[[`fbb108be7d`](nodejs/node@fbb108be7d)] - **(SEMVER-MINOR)** **loader**: implement package maps (Maël Nison) [#62239](nodejs/node#62239)
* \[[`45494d5a8a`](nodejs/node@45494d5a8a)] - **(SEMVER-MINOR)** **net**: support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` (Guy Bedford) [#63825](nodejs/node#63825)
* \[[`ee29465e77`](nodejs/node@ee29465e77)] - **(SEMVER-MINOR)** **tls**: add certificateCompression option (Tim Perry) [#62217](nodejs/node#62217)
* \[[`b17817eb2b`](nodejs/node@b17817eb2b)] - **(SEMVER-MINOR)** **vfs**: dispatch `node:fs/promises` to mounted VFS instances (Matteo Collina) [#63537](nodejs/node#63537)
* \[[`7bc93a6ac5`](nodejs/node@7bc93a6ac5)] - **(SEMVER-MINOR)** **vfs**: add minimal `node:vfs` subsystem (Matteo Collina) [#63115](nodejs/node#63115)
### Commits
* \[[`c7eb83b46a`](nodejs/node@c7eb83b46a)] - **benchmark**: add child\_process async path baselines (Yagiz Nizipli) [#63929](nodejs/node#63929)
* \[[`066fff17a5`](https://github.com/nodejs/node/commit/066f… (truncated)
### v26.5.0
### Notable Changes
#### New release key
Welcome to our newest releaser, [Stewart X Addison](https://github.com/sxa). Future Node.js releases may be signed with his [release key](https://github.com/nodejs/node/blob/main/README.md#release-keys), `655F3B5C1FB3FA8D1A0CA6BDE4A7D232B936D2FD`.
#### Other notable changes
* \[[`55f48446c7`](nodejs/node@55f48446c7)] - **(SEMVER-MINOR)** **buffer**: implement blob.textStream() (Matthew Aitken) [#64036](nodejs/node#64036)
* \[[`b373202efc`](nodejs/node@b373202efc)] - **(SEMVER-MINOR)** **esm**: add `--experimental-import-text` flag (Efe) [#62300](nodejs/node#62300)
* \[[`39e0c14455`](nodejs/node@39e0c14455)] - **(SEMVER-MINOR)** **perf\_hooks**: sample delay per event loop iteration (Pablo Erhard) [#62935](nodejs/node#62935)
* \[[`999a83c937`](nodejs/node@999a83c937)] - **(SEMVER-MINOR)** **stream**: expose ReadableStreamTee (Matteo Collina) [#64195](nodejs/node#64195)
* \[[`4e0236dc3d`](nodejs/node@4e0236dc3d)] - **(SEMVER-MINOR)** **tls**: report negotiated TLS groups (Filip Skokan) [#64119](nodejs/node#64119)
### Commits
* \[[`87648c0a6c`](nodejs/node@87648c0a6c)] - **benchmark**: trim down the argon2 sets (Filip Skokan) [#64218](nodejs/node#64218)
* \[[`a483bfd3f0`](nodejs/node@a483bfd3f0)] - **buffer**: remove unreachable overflow check in atob (haramjeong) [#60161](nodejs/node#60161)
* \[[`6d14279688`](nodejs/node@6d14279688)] - **buffer**: add fast api for isUtf8 and isAscii (Gürgün Dayıoğlu) [#64169](nodejs/node#64169)
* \[[`55f48446c7`](nodejs/node@55f48446c7)] -… (truncated)
### v26.5.1
This is a security release.
### Notable Changes
* (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
* (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
* (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
* (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
* (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium
* (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
* (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
* (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
* (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
* (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
* deps: update llhttp to 9.4.3 (Paolo Insogna)
* deps: update undici to 8.9.0 (Node.js GitHub Bot)
### Commits
* \[[`af0bf96877`](nodejs/node@af0bf96877)] - **deps**: update llhttp to 9.4.3 (Paolo Insogna) [nodejs-private/node-private#935](https://github.com/nodejs-private/node-private/pull/935)
* \[[`0354678355`](nodejs/node@0354678355)] - **deps**: update undici to 8.9.0 (Node.js GitHub Bot) [#64712](nodejs/node#64712)
* \[[`dbeeaeec13`](nodejs/node@dbeeaeec13)] - **(CVE-2026-58042)** **dns**: handle large resolveAny address replies (RafaelGSS) [nodejs-private/node-private#929](https://github.com/nodejs-private/node-private/pull/929)
* \[[`064d339f56`](nodejs/node@064d339f56)] - **(CVE-2026-58044)** **http**: reject requests exceeding max header count (Matteo Collina) [nodejs-private/node-private#922](https://github.com/nodejs-private/node-private/pull/922)
* \[[`23b94c843a`](https://github.… (truncated)
_Omitted 12 older releases._
</details>
</details>
Modified files:
- `.mise.toml`
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-open-v26.xIndicate that the PR has an open backportbuildIssues and PRs related to build files or the CI.docIssues and PRs related to the documentations.dont-land-on-v22.xPRs that should not land on the v22.x-staging branch and should not be released in v22.x.dont-land-on-v24.xPRs that should not land on the v24.x-staging branch and should not be released in v24.x.notable-changePRs with changes that should be highlighted in changelogs.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

19 participants

@aduh95@nodejs-github-bot@ShogunPanda@Renegade334@richardlau@sxa@MattIPv4@ryanaslett@mcollina@panva@lpinca@anonrig@targos@UlisesGascon@legendecas@RafaelGSS@marco-ippolito@gurgunday@gonzalezanjel162-a11y