Uh oh!
There was an error while loading. Please reload this page.
test_runner: support coverage with isolation:'none' via run() API - #63079
Conversation
nodejs-github-bot
commented
May 2, 2026
Review requested:
|
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@## main #63079 +/- ##
==========================================
+ Coverage 89.66% 89.74% +0.08%
==========================================
Files 713 713 Lines 224076 224250 +174 Branches 42308 42407 +99 ==========================================
+ Hits 200912 201263 +351 + Misses 14996 14815 -181 - Partials 8168 8172 +4
🚀 New features to boost your workflow:
|
Uh oh!
There was an error while loading. Please reload this page.
9853b21 to
c91f5f5CompareAdd a `startCoverage` method on the `profiler` internal binding so that V8 precise coverage can be enabled after bootstrap. The method is idempotent against the existing bootstrap path (which creates a V8CoverageConnection when NODE_V8_COVERAGE or --experimental-test-coverage is set) and a no-op when the inspector is unavailable, e.g. in the parent process of `--test --test-isolation=process` where workers handle coverage and Environment::should_create_inspector() returns false. Refs: nodejs#60023 Signed-off-by: sangwook <rewq5991@gmail.com>
run({ coverage: true, isolation: 'none' }) previously returned an
empty file list because V8 precise coverage is only started at
bootstrap when NODE_V8_COVERAGE or --experimental-test-coverage is
set, neither of which the API path requires. Call the new
profiler.startCoverage() binding from setupCoverage() so the parent
isolate is instrumented when the run() API is the entry point.
Fixes: nodejs#60023
Signed-off-by: sangwook <rewq5991@gmail.com>The CLI path defaults coverageExcludeGlobs to [kDefaultPattern] when --experimental-test-coverage is set, dropping test files from the coverage report. The run() API skipped this default, so callers got test files mixed into their coverage data. Apply the same default when run() is invoked with coverage: true and no explicit coverageExcludeGlobs, so both entry points behave consistently. Update the existing run() coverage tests that depended on the absent default to opt out via coverageExcludeGlobs: '!test/**'. Refs: nodejs#60023 Signed-off-by: sangwook <rewq5991@gmail.com>
Verify that:
- run({ coverage: true, isolation: 'none' }) reports src files,
- default test-file exclusion drops *.test.mjs in both isolation
modes,
- the path is idempotent when --experimental-test-coverage is set
on the same process.
Refs: nodejs#60023
Signed-off-by: sangwook <rewq5991@gmail.com>c91f5f5 to
2851a03Compare
This comment was marked as outdated.
This comment was marked as outdated.
This comment was marked as outdated.
This comment was marked as outdated.
nodejs-github-bot
commented
May 17, 2026
nodejs-github-bot
commented
May 23, 2026
Commit Queue failed- Loading data for nodejs/node/pull/63079 ✔ Done loading data for nodejs/node/pull/63079 ----------------------------------- PR info ------------------------------------ Title test_runner: support coverage with isolation:'none' via run() API (#63079) Author sangwook <rewq5991@gmail.com> (@Han5991) Branch Han5991:fix/test-runner-coverage-isolation-none -> nodejs:main Labels c++, semver-minor, lib / src, needs-ci Commits 5 - inspector: expose precise coverage start to JS runtime - test_runner: enable coverage on run() with isolation: 'none' - test_runner: apply default test-file exclusion via run() API - test: add coverage tests for run() with isolation: 'none' - test: use fixture for isolation=none coverage runner script Committers 1 - sangwook <rewq5991@gmail.com> PR-URL: https://github.com/nodejs/node/pull/63079 Refs: https://github.com/nodejs/node/issues/60023 Reviewed-By: Chemi Atlow <chemi@atlow.co.il> Reviewed-By: Pietro Marchini <pietro.marchini94@gmail.com> Reviewed-By: Aviv Keller <me@aviv.sh> ------------------------------ Generated metadata ------------------------------ PR-URL: https://github.com/nodejs/node/pull/63079 Refs: https://github.com/nodejs/node/issues/60023 Reviewed-By: Chemi Atlow <chemi@atlow.co.il> Reviewed-By: Pietro Marchini <pietro.marchini94@gmail.com> Reviewed-By: Aviv Keller <me@aviv.sh> -------------------------------------------------------------------------------- ℹ This PR was created on Sat, 02 May 2026 06:49:36 GMT ✔ Approvals: 3 ✔ - Chemi Atlow (@atlowChemi): https://github.com/nodejs/node/pull/63079#pullrequestreview-4278650896 ✔ - Pietro Marchini (@pmarchini): https://github.com/nodejs/node/pull/63079#pullrequestreview-4217842569 ✔ - Aviv Keller (@avivkeller): https://github.com/nodejs/node/pull/63079#pullrequestreview-4231403222 ✔ Last GitHub CI successful ℹ Last Full PR CI on 2026-05-17T23:55:40Z: https://ci.nodejs.org/job/node-test-pull-request/73516/ - Querying data for job/node-test-pull-request/73516/ ✔ Build data downloaded ✔ Last Jenkins CI successful -------------------------------------------------------------------------------- ✔ No git cherry-pick in progress ✔ No git am in progress ✔ No git rebase in progress -------------------------------------------------------------------------------- - Bringing origin/main up to date... From https://github.com/nodejs/node * branch main -> FETCH_HEAD ✔ origin/main is now up-to-date - Downloading patch for 63079 From https://github.com/nodejs/node * branch refs/pull/63079/merge -> FETCH_HEAD ✔ Fetched commits as 8d3245e551eb..2851a032b53a -------------------------------------------------------------------------------- [main f5b791804a] inspector: expose precise coverage start to JS runtime Author: sangwook <rewq5991@gmail.com> Date: Sat May 2 15:45:11 2026 +0900 1 file changed, 26 insertions(+) [main b8f1d34ecb] test_runner: enable coverage on run() with isolation: 'none' Author: sangwook <rewq5991@gmail.com> Date: Sat May 2 15:45:16 2026 +0900 1 file changed, 2 insertions(+) Auto-merging lib/internal/test_runner/runner.js [main 2d05602984] test_runner: apply default test-file exclusion via run() API Author: sangwook <rewq5991@gmail.com> Date: Sat May 2 15:45:24 2026 +0900 2 files changed, 11 insertions(+), 1 deletion(-) [main b6a95ad624] test: add coverage tests for run() with isolation: 'none' Author: sangwook <rewq5991@gmail.com> Date: Sat May 2 15:45:35 2026 +0900 3 files changed, 114 insertions(+) create mode 100644 test/fixtures/test-runner/coverage-isolation-none/src/foo.mjs create mode 100644 test/fixtures/test-runner/coverage-isolation-none/tests/foo.test.mjs create mode 100644 test/parallel/test-runner-coverage-isolation-none-api.mjs [main 9d4de8f8c1] test: use fixture for isolation=none coverage runner script Author: sangwook <rewq5991@gmail.com> Date: Wed May 6 06:26:00 2026 +0900 2 files changed, 20 insertions(+), 23 deletions(-) create mode 100644 test/fixtures/test-runner/coverage-isolation-none/runner.mjs ✔ Patches applied There are 5 commits in the PR. Attempting autorebase. (node:396) [DEP0190] DeprecationWarning: Passing args to a child process with shell option true can lead to security vulnerabilities, as the arguments are not escaped, only concatenated. (Use `node --trace-deprecation ...` to show where the warning was created) Rebasing (2/10)
Refs: #60023 |
nodejs-github-bot
commented
May 23, 2026
Landed in c9dbb86 |
Add a `startCoverage` method on the `profiler` internal binding so that V8 precise coverage can be enabled after bootstrap. The method is idempotent against the existing bootstrap path (which creates a V8CoverageConnection when NODE_V8_COVERAGE or --experimental-test-coverage is set) and a no-op when the inspector is unavailable, e.g. in the parent process of `--test --test-isolation=process` where workers handle coverage and Environment::should_create_inspector() returns false. Refs: #60023 Signed-off-by: sangwook <rewq5991@gmail.com> PR-URL: #63079 Reviewed-By: Chemi Atlow <chemi@atlow.co.il> Reviewed-By: Pietro Marchini <pietro.marchini94@gmail.com> Reviewed-By: Aviv Keller <me@aviv.sh>
Notable changes: buffer: * (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 http: * (SEMVER-MINOR) add httpValidation option to configure header value validation (RajeshKumar11) #61597 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079 lib,permission: * (SEMVER-MINOR) add permission.drop (Rafael Gonzaga) #62672 PR-URL: #63664
Notable changes: buffer: * (SEMVER-MINOR) increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) #63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 doc: * downgrade macOS x64 support to Tier 2 (Antoine du Hamel) #63055 http: * (SEMVER-MINOR) add `httpValidation` option to configure header value validation (RajeshKumar11) #61597 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079 lib,permission: * (SEMVER-MINOR) add `permission.drop` (Rafael Gonzaga) #62672 PR-URL: #63664
Notable changes: buffer: * (SEMVER-MINOR) increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) #63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 doc: * downgrade macOS x64 support to Tier 2 (Antoine du Hamel) #63055 http: * (SEMVER-MINOR) add `httpValidation` option to configure header value validation (RajeshKumar11) #61597 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079 lib,permission: * (SEMVER-MINOR) add `permission.drop` (Rafael Gonzaga) #62672 PR-URL: #63664
Notable changes: buffer: * (SEMVER-MINOR) increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) #63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 doc: * downgrade macOS x64 support to Tier 2 (Antoine du Hamel) #63055 http: * (SEMVER-MINOR) add `httpValidation` option to configure header value validation (RajeshKumar11) #61597 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079 lib,permission: * (SEMVER-MINOR) add `permission.drop` (Rafael Gonzaga) #62672 PR-URL: #63664
Add a `startCoverage` method on the `profiler` internal binding so that V8 precise coverage can be enabled after bootstrap. The method is idempotent against the existing bootstrap path (which creates a V8CoverageConnection when NODE_V8_COVERAGE or --experimental-test-coverage is set) and a no-op when the inspector is unavailable, e.g. in the parent process of `--test --test-isolation=process` where workers handle coverage and Environment::should_create_inspector() returns false. Refs: nodejs#60023 Signed-off-by: sangwook <rewq5991@gmail.com> PR-URL: nodejs#63079 Reviewed-By: Chemi Atlow <chemi@atlow.co.il> Reviewed-By: Pietro Marchini <pietro.marchini94@gmail.com> Reviewed-By: Aviv Keller <me@aviv.sh>
Add a `startCoverage` method on the `profiler` internal binding so that V8 precise coverage can be enabled after bootstrap. The method is idempotent against the existing bootstrap path (which creates a V8CoverageConnection when NODE_V8_COVERAGE or --experimental-test-coverage is set) and a no-op when the inspector is unavailable, e.g. in the parent process of `--test --test-isolation=process` where workers handle coverage and Environment::should_create_inspector() returns false. Refs: #60023 Signed-off-by: sangwook <rewq5991@gmail.com> PR-URL: #63079 Reviewed-By: Chemi Atlow <chemi@atlow.co.il> Reviewed-By: Pietro Marchini <pietro.marchini94@gmail.com> Reviewed-By: Aviv Keller <me@aviv.sh>
Notable changes: buffer: * (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 http: * (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079 PR-URL: #64001
Notable changes: * crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 * (SEMVER-MINOR) buffer: increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597 * (SEMVER-MINOR) crypto: align key argument names in docs and error messages (Filip Skokan) #62527 * (SEMVER-MINOR) crypto: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) #62527 * (SEMVER-MINOR) crypto: unify asymmetric key import through KeyObjectHandle::Init (Filip Skokan) #62499 * (SEMVER-MINOR) crypto: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) #62183 * (SEMVER-MINOR) http: add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155 * (SEMVER-MINOR) inspector: expose precise coverage start to JS runtime (sangwook) #63079 * (SEMVER-MINOR) lib: cleanup stateless diffiehellman key handling (Filip Skokan) #62645 PR-URL: #64062
Notable changes: buffer: * (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 * (SEMVER-MINOR) align key argument names in docs and error messages (Filip Skokan) #62527 * (SEMVER-MINOR) accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) #62527 * (SEMVER-MINOR) add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) #62183 http: * http: avoid stream listeners on idle agent sockets (Matteo Collina) #64004 * (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079 stream: * stream: Revert noop pause/resume on destroyed streams" (Stewart X Addison) #63834 PR-URL: #64062
Notable changes: buffer: * (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) nodejs#63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) nodejs#63527 * (SEMVER-MINOR) align key argument names in docs and error messages (Filip Skokan) nodejs#62527 * (SEMVER-MINOR) accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) nodejs#62527 * (SEMVER-MINOR) add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) nodejs#62183 http: * http: avoid stream listeners on idle agent sockets (Matteo Collina) nodejs#64004 * (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) nodejs#63155 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) nodejs#63079 stream: * stream: Revert noop pause/resume on destroyed streams" (Stewart X Addison) nodejs#63834 PR-URL: nodejs#64062
Notable changes: buffer: * (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 * (SEMVER-MINOR) align key argument names in docs and error messages (Filip Skokan) #62527 * (SEMVER-MINOR) accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) #62527 * (SEMVER-MINOR) add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) #62183 http: * http: avoid stream listeners on idle agent sockets (Matteo Collina) #64004 * (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079 stream: * stream: Revert noop pause/resume on destroyed streams" (Stewart X Addison) #63834 PR-URL: #64062
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [node](https://github.com/nodejs/node) | stage | minor | `24.16.0-trixie` → `24.18.0-trixie` | --- ### Release Notes <details> <summary>nodejs/node (node)</summary> ### [`v24.18.0`](https://github.com/nodejs/node/releases/tag/v24.18.0): 2026-06-23, Version 24.18.0 'Krypton' (LTS), @​richardlau prepared by @​sxa [Compare Source](nodejs/node@v24.17.0...v24.18.0) ##### Notable Changes - \[[`e07e7a31e1`](nodejs/node@e07e7a31e1)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#​63527](nodejs/node#63527) - \[[`44c8ebcbd6`](nodejs/node@44c8ebcbd6)] - **http**: avoid stream listeners on idle agent sockets (Matteo Collina) [#​64004](nodejs/node#64004) - \[[`d3ef4122ee`](nodejs/node@d3ef4122ee)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#​63597](nodejs/node#63597) - \[[`bb2857b85a`](nodejs/node@bb2857b85a)] - **(SEMVER-MINOR)** **crypto**: align key argument names in docs and error messages (Filip Skokan) [#​62527](nodejs/node#62527) - \[[`b9d5e87880`](nodejs/node@b9d5e87880)] - **(SEMVER-MINOR)** **crypto**: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) [#​62527](nodejs/node#62527) - \[[`ccd756d61e`](nodejs/node@ccd756d61e)] - **(SEMVER-MINOR)** **crypto**: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) [#​62183](nodejs/node#62183) - \[[`4c9251fc09`](nodejs/node@4c9251fc09)] - **(SEMVER-MINOR)** **http**: add writeInformation to send arbitrary 1xx status codes (Tim Perry) [#​63155](nodejs/node#63155) - \[[`8c989ec4a3`](nodejs/node@8c989ec4a3)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#​63079](nodejs/node#63079) - \[[`3f54c8ba32`](nodejs/node@3f54c8ba32)] - ***Revert*** "**stream**: noop pause/resume on destroyed streams" (Stewart X Addison) [#​63834](nodejs/node#63834) ##### Commits - \[[`d3ef4122ee`](nodejs/node@d3ef4122ee)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#​63597](nodejs/node#63597) - \[[`9ff36e40f0`](nodejs/node@9ff36e40f0)] - **build**: add --enable-all-experimentals build flag (Paolo Insogna) [#​62755](nodejs/node#62755) - \[[`7c22ee23aa`](nodejs/node@7c22ee23aa)] - **build**: def `NODE_USE_NODE_CODE_CACHE` only used in node\_mksnapshot (Chengzhong Wu) [#​63588](nodejs/node#63588) - \[[`2551abdb4a`](nodejs/node@2551abdb4a)] - **build,win**: enable x64 PGO (Stefan Stojanovic) [#​62761](nodejs/node#62761) - \[[`e8a55ce9b1`](nodejs/node@e8a55ce9b1)] - **crypto**: strengthen argument CHECKs in TurboSHAKE (Tobias Nießen) [#​62763](nodejs/node#62763) - \[[`ae61cd68f3`](nodejs/node@ae61cd68f3)] - **crypto**: harden WebCrypto against prototype pollution (Filip Skokan) [#​63363](nodejs/node#63363) - \[[`3d05a1d396`](nodejs/node@3d05a1d396)] - **crypto**: pass CryptoKey handles to KDF jobs (Filip Skokan) [#​63363](nodejs/node#63363) - \[[`f9d10a3f6b`](nodejs/node@f9d10a3f6b)] - **crypto**: remove async from WebCrypto methods (Filip Skokan) [#​63363](nodejs/node#63363) - \[[`e431d93e9e`](nodejs/node@e431d93e9e)] - **crypto**: add WebCrypto CryptoJob mode (Filip Skokan) [#​63363](nodejs/node#63363) - \[[`56e2505e48`](nodejs/node@56e2505e48)] - **crypto**: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) [#​63255](nodejs/node#63255) - \[[`3bac77f2a8`](nodejs/node@3bac77f2a8)] - **crypto**: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) [#​63255](nodejs/node#63255) - \[[`1bff901b09`](nodejs/node@1bff901b09)] - **crypto**: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) [#​63255](nodejs/node#63255) - \[[`4433fca3df`](nodejs/node@4433fca3df)] - **crypto**: harden CryptoKey algorithm slots (Filip Skokan) [#​63111](nodejs/node#63111) - \[[`b5cf01217a`](nodejs/node@b5cf01217a)] - **crypto**: harden KeyObject internal slots (Filip Skokan) [#​63111](nodejs/node#63111) - \[[`ce84aef37d`](nodejs/node@ce84aef37d)] - **crypto**: add guards and adjust tests for BoringSSL (Filip Skokan) [#​62883](nodejs/node#62883) - \[[`26781689b0`](nodejs/node@26781689b0)] - **crypto**: reject duplicate ML-KEM JWK key\_ops (Filip Skokan) [#​62905](nodejs/node#62905) - \[[`aeea8f4970`](nodejs/node@aeea8f4970)] - **crypto**: add JWK support for ML-KEM and SLH-DSA key types (Filip Skokan) [#​62706](nodejs/node#62706) - \[[`407cf91656`](nodejs/node@407cf91656)] - **crypto**: guard against size\_t overflow on experimental 32-bit arch (Filip Skokan) [#​62626](nodejs/node#62626) - \[[`bb2857b85a`](nodejs/node@bb2857b85a)] - **(SEMVER-MINOR)** **crypto**: align key argument names in docs and error messages (Filip Skokan) [#​62527](nodejs/node#62527) - \[[`b9d5e87880`](nodejs/node@b9d5e87880)] - **(SEMVER-MINOR)** **crypto**: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) [#​62527](nodejs/node#62527) - \[[`b46d52b283`](nodejs/node@b46d52b283)] - **crypto**: unify asymmetric key import through KeyObjectHandle::Init (Filip Skokan) [#​62499](nodejs/node#62499) - \[[`ccd756d61e`](nodejs/node@ccd756d61e)] - **(SEMVER-MINOR)** **crypto**: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) [#​62183](nodejs/node#62183) - \[[`e07e7a31e1`](nodejs/node@e07e7a31e1)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#​63527](nodejs/node#63527) - \[[`61826df455`](nodejs/node@61826df455)] - **crypto**: coerce -0 keylen to +0 in pbkdf2 and scrypt (Jordan Harband) [#​63531](nodejs/node#63531) - \[[`16d2fd3c07`](nodejs/node@16d2fd3c07)] - **crypto**: align verifyOneShot accepted types (Anshika Jain) [#​63280](nodejs/node#63280) - \[[`3b8330deda`](nodejs/node@3b8330deda)] - **crypto**: improve system certificate enumeration logic on macOS (Robo) [#​62576](nodejs/node#62576) - \[[`141de35399`](nodejs/node@141de35399)] - **debugger**: add --help to `node inspect` and improve docs (Joyee Cheung) [#​63201](nodejs/node#63201) - \[[`b76bfcd4fa`](nodejs/node@b76bfcd4fa)] - **deps**: upgrade npm to 11.16.0 (npm team) [#​63602](nodejs/node#63602) - \[[`4ec142314c`](nodejs/node@4ec142314c)] - **deps**: SQLite: cherry-pick [`b869ed6`](nodejs/node@b869ed6) (Junsu Han) [#​63525](nodejs/node#63525) - \[[`19e8ce1c36`](nodejs/node@19e8ce1c36)] - **deps**: upgrade npm to 11.15.0 (npm team) [#​63463](nodejs/node#63463) - \[[`8a264260e2`](nodejs/node@8a264260e2)] - **deps**: update sqlite to 3.53.1 (Node.js GitHub Bot) [#​63217](nodejs/node#63217) - \[[`50c8ff3f94`](nodejs/node@50c8ff3f94)] - **deps**: update simdjson to 4.6.4 (Node.js GitHub Bot) [#​62811](nodejs/node#62811) - \[[`6e56f01c4b`](nodejs/node@6e56f01c4b)] - **deps**: V8: cherry-pick [`435a2cd`](nodejs/node@435a2cdf664c) (Matthias Liedtke) [#​63136](nodejs/node#63136) - \[[`3ba813b242`](nodejs/node@3ba813b242)] - **deps**: cherry-pick [libuv/libuv@`a43e543`](libuv/libuv@a43e543) (Ali Hassan) [#​63222](nodejs/node#63222) - \[[`2390e3a5ac`](nodejs/node@2390e3a5ac)] - **doc**: remove duplicated sentences in large-pull-requests.md (Joyee Cheung) [#​63650](nodejs/node#63650) - \[[`52a1c18374`](nodejs/node@52a1c18374)] - **doc**: update `git node land` instructions for security releases (Antoine du Hamel) [#​63586](nodejs/node#63586) - \[[`3e6b4da037`](nodejs/node@3e6b4da037)] - **doc**: drop --experimental from --permission (Rafael Gonzaga) [#​63583](nodejs/node#63583) - \[[`84d05163b9`](nodejs/node@84d05163b9)] - **doc**: explicitly ask for reproducible in JS (Rafael Gonzaga) [#​63479](nodejs/node#63479) - \[[`7da2a4450e`](nodejs/node@7da2a4450e)] - **doc**: fix URL postMessage example in worker\_threads (Kit Dallege) [#​62203](nodejs/node#62203) - \[[`3d79bd8b29`](nodejs/node@3d79bd8b29)] - **doc**: clarify `filter` option of `sqlite.database.applyChangeset` (Antoine du Hamel) [#​63515](nodejs/node#63515) - \[[`4f4174aace`](nodejs/node@4f4174aace)] - **doc**: fix double spaces in ERR\_TLS\_INVALID\_PROTOCOL\_METHOD (Daijiro Wachi) [#​63511](nodejs/node#63511) - \[[`388323ca4b`](nodejs/node@388323ca4b)] - **doc**: fix double space in modules.md (Daijiro Wachi) [#​63512](nodejs/node#63512) - \[[`5258ccc058`](nodejs/node@5258ccc058)] - **doc**: fix "options" to "option" in tls.createServer (Daijiro Wachi) [#​63453](nodejs/node#63453) - \[[`43e83e6507`](nodejs/node@43e83e6507)] - **doc**: fix typo in deprecations (Daijiro Wachi) [#​63434](nodejs/node#63434) - \[[`f05a61d54c`](nodejs/node@f05a61d54c)] - **doc**: remove unsupported template type from v8.md (René) [#​63410](nodejs/node#63410) - \[[`c39d5fc820`](nodejs/node@c39d5fc820)] - **doc**: fix article usage before vowel-sound acronyms (joao-oliveira-softtor) [#​62696](nodejs/node#62696) - \[[`398261f911`](nodejs/node@398261f911)] - **doc**: remove the bi-monthly contributor spotlight section (Claudio Wunder) [#​62734](nodejs/node#62734) - \[[`fd9e14c405`](nodejs/node@fd9e14c405)] - **doc**: update http2's `push` and `trailers` events with `rawHeaders` param (YuSheng Chen) [#​63259](nodejs/node#63259) - \[[`b943ce6933`](nodejs/node@b943ce6933)] - **doc**: remove inactive members from Triagers list (Antoine du Hamel) [#​63329](nodejs/node#63329) - \[[`4b9cdfc022`](nodejs/node@4b9cdfc022)] - **doc**: reference correct function in Module docs (Robin Malfait) [#​63247](nodejs/node#63247) - \[[`bed84b6df2`](nodejs/node@bed84b6df2)] - **doc**: replace Visual Studio 2022 Evergreen version reference with 17.14 (Mike McCready) [#​63211](nodejs/node#63211) - \[[`32ea70569b`](nodejs/node@32ea70569b)] - **doc**: recommend explicitly Tier 1 or 2 for production applications (Mike McCready) [#​63187](nodejs/node#63187) - \[[`4627bcfd82`](nodejs/node@4627bcfd82)] - **doc**: run license-builder (github-actions\[bot]) [#​63232](nodejs/node#63232) - \[[`28eba71845`](nodejs/node@28eba71845)] - **doc**: add large pull requests contributing guide (Matteo Collina) [#​62829](nodejs/node#62829) - \[[`2648efd438`](nodejs/node@2648efd438)] - **doc**: remove unnecessary `<!-- eslint-` magic comments (Antoine du Hamel) [#​63200](nodejs/node#63200) - \[[`a95fc1f8fc`](nodejs/node@a95fc1f8fc)] - **doc**: clarify SEA platform support excludes darwin-x64 (MJSHANG) [#​63181](nodejs/node#63181) - \[[`aaef29e2e1`](nodejs/node@aaef29e2e1)] - **doc**: update release steps when post-release fails (Rafael Gonzaga) [#​63131](nodejs/node#63131) - \[[`7d81419cf2`](nodejs/node@7d81419cf2)] - **doc**: add Hmac.digest() documentation-only deprecation (DEP0206) (Anshika Jain) [#​63121](nodejs/node#63121) - \[[`ececd80d81`](nodejs/node@ececd80d81)] - **doc**: document the latest-vX.x schema (Marco Ippolito) [#​63033](nodejs/node#63033) - \[[`27c1c1d842`](nodejs/node@27c1c1d842)] - **doc**: remove list of versions in `BUILDING.md` (Antoine du Hamel) [#​63113](nodejs/node#63113) - \[[`e369886a65`](nodejs/node@e369886a65)] - **doc,sqlite**: document entryPoint argument for loadExtension (Edy Silva) [#​63152](nodejs/node#63152) - \[[`e4e5137cbd`](nodejs/node@e4e5137cbd)] - **errors**: handle V8 warnings in DisallowJavascriptExecutionScope (Divyanshu Sharma) [#​63491](nodejs/node#63491) - \[[`6d1f6048d2`](nodejs/node@6d1f6048d2)] - **fs**: make `Date` properties on `Stats` enumerable (LiviaMedeiros) [#​63328](nodejs/node#63328) - \[[`44c8ebcbd6`](nodejs/node@44c8ebcbd6)] - **http**: avoid stream listeners on idle agent sockets (Matteo Collina) [#​64004](nodejs/node#64004) - \[[`4c9251fc09`](nodejs/node@4c9251fc09)] - **(SEMVER-MINOR)** **http**: add writeInformation to send arbitrary 1xx status codes (Tim Perry) [#​63155](nodejs/node#63155) - \[[`39f61fb06c`](nodejs/node@39f61fb06c)] - **http2**: emit session close before stream close (Matteo Collina) [#​63414](nodejs/node#63414) - \[[`8a8f2127d1`](nodejs/node@8a8f2127d1)] - **http2**: validate non-link headers in writeEarlyHints (Matteo Collina) [#​62017](nodejs/node#62017) - \[[`8c989ec4a3`](nodejs/node@8c989ec4a3)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#​63079](nodejs/node#63079) - \[[`c05f38229b`](nodejs/node@c05f38229b)] - **lib**: cleanup stateless diffiehellman key handling (Filip Skokan) [#​62645](nodejs/node#62645) - \[[`1c16b45d35`](nodejs/node@1c16b45d35)] - **lib**: refactor internal webidl converters (Filip Skokan) [#​62979](nodejs/node#62979) - \[[`02f35d6dce`](nodejs/node@02f35d6dce)] - **lib**: define `kEnumerableProperty` atomically (Antoine du Hamel) [#​63609](nodejs/node#63609) - \[[`12c51547ba`](nodejs/node@12c51547ba)] - **lib**: fix typos in esm loader comments (RonGamzu) [#​63465](nodejs/node#63465) - \[[`9b03b84262`](nodejs/node@9b03b84262)] - **lib**: fix typo idenity => identity (Daijiro Wachi) [#​63112](nodejs/node#63112) - \[[`a84e6b0567`](nodejs/node@a84e6b0567)] - **lib**: fixes validator message (Daijiro Wachi) [#​62823](nodejs/node#62823) - \[[`11734166a8`](nodejs/node@11734166a8)] - **lib**: narrow ReadableStreamBYOBRequest.view return type to Uint8Array (RoomWithOutRoof) [#​63017](nodejs/node#63017) - \[[`7cead61d21`](nodejs/node@7cead61d21)] - **meta**: flip mcollina emails in .mailmap (Matteo Collina) [#​63621](nodejs/node#63621) - \[[`a08cfcfd35`](nodejs/node@a08cfcfd35)] - **meta**: label "source maps" PRs (Chengzhong Wu) [#​63591](nodejs/node#63591) - \[[`d56e8d2512`](nodejs/node@d56e8d2512)] - **meta**: add `vfs` subsystem label (René) [#​62331](nodejs/node#62331) - \[[`6201cfe488`](nodejs/node@6201cfe488)] - **meta**: skip scheduled workflows on forks (Jamie Magee) [#​63565](nodejs/node#63565) - \[[`f095e2bd31`](nodejs/node@f095e2bd31)] - **meta**: add additional gitignore entries (James M Snell) [#​63267](nodejs/node#63267) - \[[`1ea52c444c`](nodejs/node@1ea52c444c)] - **meta**: move one or more collaborators to emeritus (Node.js GitHub Bot) [#​63402](nodejs/node#63402) - \[[`b1b2327611`](nodejs/node@b1b2327611)] - **meta**: move one or more collaborators to emeritus (Node.js GitHub Bot) [#​63235](nodejs/node#63235) - \[[`7d88e130a9`](nodejs/node@7d88e130a9)] - **meta**: ignore AI assistants files (Matteo Collina) [#​62612](nodejs/node#62612) - \[[`a53b51df38`](nodejs/node@a53b51df38)] - **module**: load ESM helpers eagerly in the snapshot (Joyee Cheung) [#​63550](nodejs/node#63550) - \[[`69df688fff`](nodejs/node@69df688fff)] - **module**: fix sync hook short-circuit in require() in imported CJS (Joyee Cheung) [#​62920](nodejs/node#62920) - \[[`75d9a4ed47`](nodejs/node@75d9a4ed47)] - **node-api**: support SharedArrayBuffer in napi\_create\_typedarray (Yilong Li) [#​62710](nodejs/node#62710) - \[[`c20aa4c47b`](nodejs/node@c20aa4c47b)] - **quic**: add reusePort option to QuicEndpoint (James M Snell) [#​63267](nodejs/node#63267) - \[[`26a30d8a7f`](nodejs/node@26a30d8a7f)] - **quic**: implement rate limiting for version nego and immediate close (James M Snell) [#​63267](nodejs/node#63267) - \[[`0b534b5770`](nodejs/node@0b534b5770)] - **quic**: fixup linting issue after other changes (James M Snell) [#​63267](nodejs/node#63267) - \[[`4b367cbe09`](nodejs/node@4b367cbe09)] - **quic**: remove unused binding variable in session.cc (James M Snell) [#​63177](nodejs/node#63177) - \[[`2574bef5a6`](nodejs/node@2574bef5a6)] - **repl**: fix dedup comparing normalized line against raw history (Daijiro Wachi) [#​62886](nodejs/node#62886) - \[[`30e71c7e49`](nodejs/node@30e71c7e49)] - **sqlite**: keep source database alive during backup (Matteo Collina) [#​62673](nodejs/node#62673) - \[[`677ca7e76c`](nodejs/node@677ca7e76c)] - **src**: simplify OpenSSL feature gates (Filip Skokan) [#​63255](nodejs/node#63255) - \[[`c863c75c39`](nodejs/node@c863c75c39)] - **src**: add BoringSSL EVP enumeration fallback (Filip Skokan) [#​63206](nodejs/node#63206) - \[[`f6b2466921`](nodejs/node@f6b2466921)] - **src**: decouple KeyObject and CryptoKey and move CryptoKey to src (Filip Skokan) [#​62924](nodejs/node#62924) - \[[`92d4f07dd2`](nodejs/node@92d4f07dd2)] - **src**: remove license headers for new node\_profiling files (Chengzhong Wu) [#​63066](nodejs/node#63066) - \[[`8ac5d771c8`](nodejs/node@8ac5d771c8)] - **src**: split profiling helpers from util (Ilyas Shabi) [#​63008](nodejs/node#63008) - \[[`85d1639495`](nodejs/node@85d1639495)] - **src**: remove TOCTOU race condition when encoding SAB-backed `Buffer`s (Antoine du Hamel) [#​63517](nodejs/node#63517) - \[[`9473c5f05c`](nodejs/node@9473c5f05c)] - **src**: skip duplicate UTF-8 validation in TextDecoder fatal path (Mert Can Altin) [#​63231](nodejs/node#63231) - \[[`f35c91ee68`](nodejs/node@f35c91ee68)] - **src**: improve token return value check (James M Snell) [#​63483](nodejs/node#63483) - \[[`26f677c1c5`](nodejs/node@26f677c1c5)] - **src**: expose `node::RegisterContext` to make a node managed context (Chengzhong Wu) [#​62322](nodejs/node#62322) - \[[`275cf909b6`](nodejs/node@275cf909b6)] - **src,sqlite**: only pass `xFilter` when user provided a callback (Antoine du Hamel) [#​63516](nodejs/node#63516) - \[[`287e02303f`](nodejs/node@287e02303f)] - **src,sqlite**: remove dead code (Edy Silva) [#​63204](nodejs/node#63204) - \[[`58fa2ee189`](nodejs/node@58fa2ee189)] - **stream**: switch to internal `sleep` binding (Antoine du Hamel) [#​63611](nodejs/node#63611) - \[[`f954ab3f1a`](nodejs/node@f954ab3f1a)] - **stream**: use data listener for compose forwarding (Trivikram Kamat) [#​63593](nodejs/node#63593) - \[[`dc57173003`](nodejs/node@dc57173003)] - **stream**: fix Writable.toWeb() hang on synchronous drain (sangwook) [#​61197](nodejs/node#61197) - \[[`3f54c8ba32`](nodejs/node@3f54c8ba32)] - ***Revert*** "**stream**: noop pause/resume on destroyed streams" (Stewart X Addison) [#​63834](nodejs/node#63834) - \[[`cee279c5d6`](nodejs/node@cee279c5d6)] - **stream**: remove unnecessary check (Antoine du Hamel) [#​63030](nodejs/node#63030) - \[[`61b20f60a3`](nodejs/node@61b20f60a3)] - **test**: update tls/crypto behaviour expectations when using BoringSSL (Filip Skokan) [#​63161](nodejs/node#63161) - \[[`a835363808`](nodejs/node@a835363808)] - **test**: update WPT for WebCryptoAPI to [`97bbc72`](nodejs/node@97bbc7247a) (Node.js GitHub Bot) [#​63417](nodejs/node#63417) - \[[`a00297480b`](nodejs/node@a00297480b)] - **test**: update WPT resources, interfaces and WebCryptoAPI (Node.js GitHub Bot) [#​62389](nodejs/node#62389) - \[[`5a95a2b055`](nodejs/node@5a95a2b055)] - **test**: shorten path in net pipe connect errors (Matteo Collina) [#​63405](nodejs/node#63405) - \[[`5e8ff22d8f`](nodejs/node@5e8ff22d8f)] - **test**: remove test-node-output-v8-warning (Joyee Cheung) [#​63469](nodejs/node#63469) - \[[`ee15380950`](nodejs/node@ee15380950)] - **test**: update test426-fixtures to [`9b9e225`](nodejs/node@9b9e225) (Node.js GitHub Bot) [#​63373](nodejs/node#63373) - \[[`9e063d9bea`](nodejs/node@9e063d9bea)] - **test**: update WPT for url to [`e4a4672`](nodejs/node@e4a4672e9e) (Node.js GitHub Bot) [#​63372](nodejs/node#63372) - \[[`503bee4b43`](nodejs/node@503bee4b43)] - **test**: deflake async-hooks statwatcher test (Trivikram Kamat) [#​63396](nodejs/node#63396) - \[[`cccc7c32d8`](nodejs/node@cccc7c32d8)] - **test**: avoid test\_runner watch restart in spec snapshot (Trivikram Kamat) [#​63392](nodejs/node#63392) - \[[`c89489258c`](nodejs/node@c89489258c)] - **test**: reduce watch mode restart flakiness (Trivikram Kamat) [#​63390](nodejs/node#63390) - \[[`e4d5e2578e`](nodejs/node@e4d5e2578e)] - **test**: isolate rerun-failures state file under tmpdir (Chemi Atlow) [#​63449](nodejs/node#63449) - \[[`362644a9ba`](nodejs/node@362644a9ba)] - **test**: wait for ok before initial break after restart (Yuya Inoue) [#​62807](nodejs/node#62807) - \[[`c4058d0e05`](nodejs/node@c4058d0e05)] - **test**: disable Maglev in near-heap-limit worker test (Trivikram Kamat) [#​63398](nodejs/node#63398) - \[[`214da630a7`](nodejs/node@214da630a7)] - **test**: deflake connection refused proxy tests (Trivikram Kamat) [#​63395](nodejs/node#63395) - \[[`1d61a29876`](nodejs/node@1d61a29876)] - **test**: avoid repeated writes in watch helper (Trivikram Kamat) [#​63386](nodejs/node#63386) - \[[`2004e25387`](nodejs/node@2004e25387)] - **test**: deflake watch mode worker test (Trivikram Kamat) [#​63384](nodejs/node#63384) - \[[`d691cccfc1`](nodejs/node@d691cccfc1)] - **test**: relax test-memory-usage arrayBuffers check (inoway46) [#​63244](nodejs/node#63244) - \[[`0ff6bf853c`](nodejs/node@0ff6bf853c)] - **test**: reduce flakiness of `different-registry-per-thread` (Antoine du Hamel) [#​63244](nodejs/node#63244) - \[[`d9f4e8e503`](nodejs/node@d9f4e8e503)] - **test**: fix flaky test-watch-mode-inspect timeout (Matteo Collina) [#​63361](nodejs/node#63361) - \[[`6d7cd50328`](nodejs/node@6d7cd50328)] - **test**: relax min assertion in test-performance-eventloopdelay (Marco) [#​63100](nodejs/node#63100) - \[[`9dafe1d2d8`](nodejs/node@9dafe1d2d8)] - **test**: avoid flaky restart sync in debugger exceptions test (Yuya Inoue) [#​62055](nodejs/node#62055) - \[[`989b2de973`](nodejs/node@989b2de973)] - **test**: avoid initial-break wait in restart-message (inoway46) [#​62060](nodejs/node#62060) - \[[`a072a25ee7`](nodejs/node@a072a25ee7)] - **test**: move FFI tests to `NATIVE_SUITES` (Antoine du Hamel) [#​63165](nodejs/node#63165) - \[[`64efbfd878`](nodejs/node@64efbfd878)] - **test**: use ERM to destroy sqlite database handles after tests (René) [#​63076](nodejs/node#63076) - \[[`7dee66cd94`](nodejs/node@7dee66cd94)] - **test\_runner**: dont buffer unordered events in process isolation mode (Moshe Atlow) [#​63432](nodejs/node#63432) - \[[`d257eec1e3`](nodejs/node@d257eec1e3)] - **test\_runner**: fix --test-rerun-failures swallowing failures on retry (Chemi Atlow) [#​63431](nodejs/node#63431) - \[[`288c320e2f`](nodejs/node@288c320e2f)] - **test\_runner**: show replayed-from-attempt hint in spec reporter (Moshe Atlow) [#​63429](nodejs/node#63429) - \[[`904bdf5bb4`](nodejs/node@904bdf5bb4)] - **test\_runner**: preserve run duration when using test-rerun (Moshe Atlow) [#​63429](nodejs/node#63429) - \[[`df183d7bfa`](nodejs/node@df183d7bfa)] - **test\_runner**: avoid hanging on incomplete v8 frames (Ali Hassan) [#​62704](nodejs/node#62704) - \[[`ec86c69726`](nodejs/node@ec86c69726)] - **test\_runner**: fix diagnostics channel context tracking (Moshe Atlow) [#​63283](nodejs/node#63283) - \[[`94e5f63b83`](nodejs/node@94e5f63b83)] - **tls**: add unsupported renegotiation error (Filip Skokan) [#​63161](nodejs/node#63161) - \[[`06d308fb61`](nodejs/node@06d308fb61)] - **tools**: prevent lib code from reading KeyObject and CryptoKey accessors (Filip Skokan) [#​63111](nodejs/node#63111) - \[[`2e4a0d0c91`](nodejs/node@2e4a0d0c91)] - **tools**: bump brace-expansion from 5.0.5 to 5.0.6 in /tools/eslint (dependabot\[bot]) [#​63415](nodejs/node#63415) - \[[`4c9666b366`](nodejs/node@4c9666b366)] - **tools**: skip commit-lint on backport pull requests (Marco) [#​63378](nodejs/node#63378) - \[[`67d0c490a8`](nodejs/node@67d0c490a8)] - **tools**: fix skip of `test-internet` on forks (Antoine du Hamel) [#​63492](nodejs/node#63492) - \[[`02f73c7cac`](nodejs/node@02f73c7cac)] - **tools**: bump the eslint group in /tools/eslint with 4 updates (dependabot\[bot]) [#​63075](nodejs/node#63075) - \[[`5d016d3241`](nodejs/node@5d016d3241)] - **tools**: update gyp-next to 0.22.2 (Node.js GitHub Bot) [#​63374](nodejs/node#63374) - \[[`55af0f0edb`](nodejs/node@55af0f0edb)] - **tools**: fix test426 updater (Antoine du Hamel) [#​63271](nodejs/node#63271) - \[[`d8475e167a`](nodejs/node@d8475e167a)] - **tools**: use different branch for tool updates on staging branches (Antoine du Hamel) [#​63110](nodejs/node#63110) - \[[`c605df9e50`](nodejs/node@c605df9e50)] - **util**: remove unused functions (Antoine du Hamel) [#​63612](nodejs/node#63612) - \[[`fe4540ebdb`](nodejs/node@fe4540ebdb)] - **util**: create hex style cache and fast path (Guilherme Araújo) [#​62999](nodejs/node#62999) ### [`v24.17.0`](https://github.com/nodejs/node/releases/tag/v24.17.0): 2026-06-18, Version 24.17.0 'Krypton' (LTS), @​aduh95 [Compare Source](nodejs/node@v24.16.0...v24.17.0) This is a security release. ##### Notable Changes - (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High - (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High - (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium - (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium - (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium - (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium - (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium - (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 – Medium - (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low - (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low - (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low ##### Commits - \[[`9e4dfc7bba`](nodejs/node@9e4dfc7bba)] - **(CVE-2026-48933)** **crypto**: guard WebCrypto cipher output length (Filip Skokan) [nodejs-private/node-private#878](https://github.com/nodejs-private/node-private/pull/878) - \[[`cb2aed980c`](nodejs/node@cb2aed980c)] - **deps**: update llhttp to 9.4.2 (Antoine du Hamel) [nodejs-private/node-private#890](https://github.com/nodejs-private/node-private/pull/890) - \[[`a8a0d12875`](nodejs/node@a8a0d12875)] - **(CVE-2026-48937)** **deps**: fix integration issues with the latest nghttp2 (Tim Perry) [#​62891](nodejs/node#62891) - \[[`66e6203c1c`](nodejs/node@66e6203c1c)] - **(SEMVER-MAJOR)** **deps**: update nghttp2 to 1.69.0 (Node.js GitHub Bot) [#​62891](nodejs/node#62891) - \[[`dd627ced27`](nodejs/node@dd627ced27)] - **deps**: update archs files for openssl-3.5.7 (Node.js GitHub Bot) [#​63820](nodejs/node#63820) - \[[`684bae568f`](nodejs/node@684bae568f)] - **deps**: upgrade openssl sources to openssl-3.5.7 (Node.js GitHub Bot) [#​63820](nodejs/node#63820) - \[[`3a631e7f83`](nodejs/node@3a631e7f83)] - **deps**: fix aix implicit declaration in OpenSSL (Abdirahim Musse) [#​62656](nodejs/node#62656) - \[[`cf44df3996`](nodejs/node@cf44df3996)] - **deps**: update undici to 7.28.0 (Node.js GitHub Bot) [#​63703](nodejs/node#63703) - \[[`138c70294b`](nodejs/node@138c70294b)] - **(CVE-2026-48930)** **dns,net**: reject hostnames with embedded NUL bytes (Matteo Collina) [nodejs-private/node-private#868](https://github.com/nodejs-private/node-private/pull/868) - \[[`be7e719c3f`](nodejs/node@be7e719c3f)] - **(CVE-2026-48931)** **http**: fix response queue poisoning in http.Agent (Matteo Collina) [nodejs-private/node-private#846](https://github.com/nodejs-private/node-private/pull/846) - \[[`cc7c11b4d1`](nodejs/node@cc7c11b4d1)] - **(CVE-2026-48619)** **http2**: cap originSet size to prevent unbounded memory growth (Matteo Collina) [nodejs-private/node-private#855](https://github.com/nodejs-private/node-private/pull/855) - \[[`9224427b92`](nodejs/node@9224427b92)] - **(CVE-2026-48615)** **lib,test**: redact proxy credentials in tunnel errors (Matteo Collina) [nodejs-private/node-private#867](https://github.com/nodejs-private/node-private/pull/867) - \[[`cf85d54839`](nodejs/node@cf85d54839)] - **(CVE-2026-48935)** **permission**: disable FileHandle utimes with permission model (RafaelGSS) [nodejs-private/node-private#873](https://github.com/nodejs-private/node-private/pull/873) - \[[`a1bbc24f96`](nodejs/node@a1bbc24f96)] - **(CVE-2026-48617)** **permission**: handle process.chdir on writereport (RafaelGSS) [nodejs-private/node-private#870](https://github.com/nodejs-private/node-private/pull/870) - \[[`e3723ff2d6`](nodejs/node@e3723ff2d6)] - **test**: add session reuse host verification regressions (Matteo Collina) [nodejs-private/node-private#854](https://github.com/nodejs-private/node-private/pull/854) - \[[`a77af4867b`](nodejs/node@a77af4867b)] - **(CVE-2026-48934)** **tls**: bind reusable sessions to authenticated host (Matteo Collina) [nodejs-private/node-private#854](https://github.com/nodejs-private/node-private/pull/854) - \[[`31beb4f707`](nodejs/node@31beb4f707)] - **(CVE-2026-48928)** **tls**: fix case-sensitive SNI context matching (Matteo Collina) [nodejs-private/node-private#857](https://github.com/nodejs-private/node-private/pull/857) - \[[`8e75c73f91`](nodejs/node@8e75c73f91)] - **(CVE-2026-48618)** **tls**: normalize hostname for server identity checks (Matteo Collina) [nodejs-private/node-private#869](https://github.com/nodejs-private/node-private/pull/869) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzAuMTkiLCJ1cGRhdGVkSW5WZXIiOiI0My4xNzAuMTkiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=--> Reviewed-on: https://git.walbeck.it/mwalbeck/docker-cyberchef/pulls/488
Automated mise tool upgrades from local config. Updated tools: - `action-validator` - `actionlint` - `aube` - `editorconfig-checker` - `ghalint` - `node` - `pinact` - `pipx:gh-action-pulse` - `prek` - `rumdl` - `shellcheck` - `shfmt` - `tombi` - `uv` - `yamlfmt` - `yamllint` - `zizmor` Command: `mise upgrade --bump --local action-validator actionlint aube editorconfig-checker ghalint node pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor` <details> <summary>Version changelog (node)</summary> | Tool | Requested | Installed | |------|-----------|-----------| | `node` | `24` → `26` | `24.18.1` → `26.5.1` | </details> <details> <summary>Release notes (1 tools)</summary> <details> <summary>node: `24.18.1` → `26.5.1` (nodejs/node)</summary> ### v25.8.2 This is a security release. ### Notable Changes * (CVE-2026-21637) wrap `SNICallback` invocation in `try`/`catch` (Matteo Collina) - High * (CVE-2026-21710) use null prototype for `headersDistinct`/`trailersDistinct` (Matteo Collina) - High * (CVE-2026-21711) include permission check to `pipe_wrap.cc` (RafaelGSS) - Medium * (CVE-2026-21712) handle url crash on different url formats (RafaelGSS) - Medium * (CVE-2026-21713) use timing-safe comparison in Web Cryptography HMAC and KMAC (Filip Skokan) - Medium * (CVE-2026-21714) handle `NGHTTP2_ERR_FLOW_CONTROL` error code (RafaelGSS) - Medium * (CVE-2026-21717) test array index hash collision (Joyee Cheung) - Medium * (CVE-2026-21715) add permission check to `realpath.native` (RafaelGSS) - Low * (CVE-2026-21716) include permission check on `lib/fs/promises` (RafaelGSS) - Low ### Commits * \[[`2086b7477b`](nodejs/node@2086b7477b)] - **(CVE-2026-21717)** **build,test**: test array index hash collision (Joyee Cheung) [nodejs-private/node-private#834](https://github.com/nodejs-private/node-private/pull/834) * \[[`0f9332a40a`](nodejs/node@0f9332a40a)] - **(CVE-2026-21713)** **crypto**: use timing-safe comparison in Web Cryptography HMAC and KMAC (Filip Skokan) [nodejs-private/node-private#822](https://github.com/nodejs-private/node-private/pull/822) * \[[`2b6937ddb2`](nodejs/node@2b6937ddb2)] - **deps**: update undici to 7.24.4 (Node.js GitHub Bot) [#62271](nodejs/node#62271) * \[[`bfb8ad5787`](nodejs/node@bfb8ad5787)] - **deps**: update undici to 7.24.3 (Node.js GitHub Bot) [#62233](nodejs/node#62233) * \[[`be6384727f`](nodejs/node@be6384727f)] - **deps**: upgrade npm to 11.11.1 (npm team) [#62216](nodejs/node#62216) * \[[`2feea5bb97`](nodejs/node@2feea5bb97)] - **deps**: V8: override… (truncated) ### v25.9.0 ### Notable Changes #### Test runner module mocking improvements `MockModuleOptions.defaultExport` and `MockModuleOptions.namedExports` have been consolidated into a single option `MockModuleOptions.exports` to align with user expectations and other test runners. A `default` property on `MockModuleOptions.exports` represents the default export, and own enumerable properties are treated as named exports. An automated migration is available to update user code: <https://github.com/nodejs/userland-migrations/tree/main/recipes/mock-module-exports> ```bash npx codemod @nodejs/mock-module-exports ``` Contributed by sangwook in [#61727](nodejs/node#61727). #### Other notable changes * \[[`312476cb84`](nodejs/node@312476cb84)] - **(SEMVER-MINOR)** **async\_hooks**: add using scopes to `AsyncLocalStorage` (Stephen Belanger) [#61674](nodejs/node#61674) * \[[`62d2cd473b`](nodejs/node@62d2cd473b)] - **(SEMVER-MINOR)** **cli**: add `--max-heap-size` option (tannal) [#58708](nodejs/node#58708) * \[[`d0ebf0e44b`](nodejs/node@d0ebf0e44b)] - **(SEMVER-MINOR)** **crypto**: add `TurboSHAKE` and `KangarooTwelve` Web Cryptography algorithms (Filip Skokan) [#62183](nodejs/node#62183) * \[[`f85b9d9fa8`](nodejs/node@f85b9d9fa8)] - **(SEMVER-MINOR)** **repl**: add customizable error handling (Anna Henningsen) [#62188](nodejs/node#62188) * \[[`67b854d407`](nodejs/node@67b854d407)] - **(SEMVER-MINOR)** **repl**: remove dependency on `node:domain` (Matteo Collina) [#61227](nodejs/node#61227) * \[[`966b700623`](nodejs/node@966b700623)] - **(SEMVER-MINOR)** **sea**: support code cache for ESM entrypoint in SEA (Joyee Cheung) [#62158](nodejs/node#62158) *… (truncated) ### v26.0.0 We're excited to announce the release of Node.js 26! Highlights include the Temporal API enabled by default, updates to the V8 JavaScript engine to 14.6, Undici to 8.0, and several important deprecations and removals as we continue to modernize the platform. As a reminder, Node.js 26 will enter long-term support (LTS) in October, but until then, it will be the "Current" release for the next six months. We encourage you to explore the new features and benefits offered by this latest release and evaluate their potential impact on your applications. ### Notable Changes #### Temporal API The Temporal API is now enabled by default in Node.js 26. Temporal is a modern date/time API for JavaScript that provides a more robust and feature-rich alternative to the legacy `Date` object. Contributed by Richard Lau in [#61806](nodejs/node#61806). #### V8 14.6 The V8 engine is updated to version 14.6.202.33, which is part of Chromium 134. This version also includes: * Upsert (<https://github.com/tc39/proposal-upsert>): `[Weak]Map.prototype.getOrInsert()`, `[Weak]Map.prototype.getOrInsertComputed()` * Iterator sequencing (<https://github.com/tc39/proposal-iterator-sequencing>): `Iterator.concat()` Contributed by Michaël Zasso in [#61898](nodejs/node#61898). #### Undici 8 Undici has been updated to version 8.0.2, bringing new features and improvements to Node.js's HTTP client implementation. #### Deprecations and Removals * \[[`dff46c07c3`](nodejs/node@dff46c07c3)] - **(SEMVER-MAJOR)** **crypto**: move DEP0182 to End-of-Life (Tobias Nießen) [#61084](nodejs/node#61084) * \[[`93c25815ee`](nodejs/node@93c25815ee)] - **(SEMVER-MAJOR)** **http**: move writeHeader to end-of-life (Sebastian Beltran) [#60635](nodejs/node#60635) `http.Server.prototype.writeHeader()` is now fully removed. Use `http.Server.prototype.write… (truncated) ### v26.1.0 ### Notable Changes #### Experimental `node:ffi` module Node.js now includes an experimental `node:ffi` module for loading dynamic libraries and calling native symbols from JavaScript. The API is gated behind the `--experimental-ffi` flag and, when the Permission Model is enabled, requires `--allow-ffi`. This API is inherently unsafe. Invalid pointers, incorrect signatures, or accessing memory after it has been freed can crash the process or corrupt memory. Contributed by Paolo Insogna in [#62072](nodejs/node#62072). #### Other Notable Changes * \[[`34a6454fe3`](nodejs/node@34a6454fe3)] - **(SEMVER-MINOR)** **buffer**: add `end` parameter (Robert Nagy) [#62390](nodejs/node#62390) * \[[`073e84d7fe`](nodejs/node@073e84d7fe)] - **(SEMVER-MINOR)** **crypto**: accept key data in `crypto.diffieHellman()` and cleanup DH jobs (Filip Skokan) [#62527](nodejs/node#62527) * \[[`5b9cb10a5f`](nodejs/node@5b9cb10a5f)] - **(SEMVER-MINOR)** **crypto**: implement `randomUUIDv7()` (nabeel378) [#62553](nodejs/node#62553) * \[[`98f9becd16`](nodejs/node@98f9becd16)] - **(SEMVER-MINOR)** **debugger**: add edit-free runtime expression probes to `node inspect` (Joyee Cheung) [#62713](nodejs/node#62713) * \[[`06defaa2ea`](nodejs/node@06defaa2ea)] - **(SEMVER-MINOR)** **fs**: add `signal` option to `fs.stat()` (Mert Can Altin) [#57775](nodejs/node#57775) * \[[`db66a963bf`](nodejs/node@db66a963bf)] - **(SEMVER-MINOR)** **fs**: expose `frsize` field in `statfs` (Jinho Jang) [#62277](nodejs/node#62277) * \[[`87adb3472b`](nodejs/node@87adb3472b)] - **(SEMVER-MINOR)** **http**: harden `ClientRequest` options merge (Matteo Collina) [#6… (truncated) ### v26.2.0 ### Notable Changes * \[[`189d43a193`](nodejs/node@189d43a193)] - **doc**: mark `stream.compose` stable (Matteo Collina) [#62562](nodejs/node#62562) * \[[`f858c6140e`](nodejs/node@f858c6140e)] - **(SEMVER-MINOR)** **fs**: add `Temporal.Instant` support to `Stats` and `BigIntStats` (Livia Medeiros) [#60789](nodejs/node#60789) * \[[`0cbb3895df`](nodejs/node@0cbb3895df)] - **(SEMVER-MINOR)** **http**: add `writeInformation` to send arbitrary 1xx status codes (Tim Perry) [#63155](nodejs/node#63155) ### Commits * \[[`9a394bab84`](nodejs/node@9a394bab84)] - **benchmark**: respect stream/iter broadcast backpressure (Trivikram Kamat) [#63314](nodejs/node#63314) * \[[`ad98b4620b`](nodejs/node@ad98b4620b)] - **crypto**: align verifyOneShot accepted types (Anshika Jain) [#63280](nodejs/node#63280) * \[[`ba0736a847`](nodejs/node@ba0736a847)] - **crypto**: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255) * \[[`5573a6a4a8`](nodejs/node@5573a6a4a8)] - **crypto**: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255) * \[[`7dc563b8d6`](nodejs/node@7dc563b8d6)] - **crypto**: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255) * \[[`b55e2b1f4d`](nodejs/node@b55e2b1f4d)] - **crypto**: improve system certificate enumeration logic on macOS (Robo) [#62576](nodejs/node#62576) * \[[`fd509a755a`](nodejs/node@fd509a755a)] - **crypto**: harden CryptoKey algorithm slots… (truncated) ### v26.3.0 ### Notable Changes #### Potential changes to macOS Universal Binary availability With Apple and its ecosystem progressively dropping support for Intel-based architectures, it has become apparent that the Node.js project may not be able to maintain the universal binaries we currently distribute for the full lifetime of Node.js 26. This change serves to communicate that risk. At present, our intention remains to continue shipping universal binaries supporting both Apple Silicon and Intel-based Macs for as long as practical. Contributed by Antoine du Hamel in [#63055](nodejs/node#63055). #### Other notable changes * \[[`a2a4b33dd8`](nodejs/node@a2a4b33dd8)] - **(SEMVER-MINOR)** **buffer**: increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) [#63597](nodejs/node#63597) * \[[`051a2152f7`](nodejs/node@051a2152f7)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#63527](nodejs/node#63527) * \[[`49462eca37`](nodejs/node@49462eca37)] - **(SEMVER-MINOR)** **http**: add `httpValidation` option to configure header value validation (RajeshKumar11) [#61597](nodejs/node#61597) * \[[`97b7ab19bd`](nodejs/node@97b7ab19bd)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#63079](nodejs/node#63079) * \[[`cfb80a2103`](nodejs/node@cfb80a2103)] - **(SEMVER-MINOR)** **lib,permission**: add `permission.drop` (Rafael Gonzaga) [#62672](nodejs/node#62672) ### Commits * \[[`a2a4b33dd8`](nodejs/node@a2a4b33dd8)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#63597](nodejs/node#63597) * \[[`0eff3e23b9`](https://github.com/nodejs/n… (truncated) ### v26.3.1 This is a security release. ### Notable Changes * (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High * (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High * (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium * (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium * (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium * (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium * (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium * (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low * (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low * (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low * (CVE-2026-48936) permission: guard pipe open and chmod with net scope (RafaelGSS) – Low ### Commits * \[[`98fbc89211`](nodejs/node@98fbc89211)] - **(CVE-2026-48933)** **crypto**: guard WebCrypto cipher output length (Filip Skokan) [nodejs-private/node-private#878](https://github.com/nodejs-private/node-private/pull/878) * \[[`110840f2c7`](nodejs/node@110840f2c7)] - **deps**: update llhttp to 9.4.2 (Antoine du Hamel) [nodejs-private/node-private#890](https://github.com/nodejs-private/node-private/pull/890) * \[[`8d36d522b2`](nodejs/node@8d36d522b2)] - **deps**: update undici to 8.5.0 (Node.js GitHub Bot) [#63903](nodejs/node#63903) * \[[`2e6d03993a`](nodejs/node@2e6d03993a)] - **deps**: update undici to 8.4.0 (Node.js GitHub Bot) [#63779](nodejs/node#63779) * \[[`5a17d5b07a`](nodejs/node@5a17d5b07a)] - **deps… (truncated) ### v26.4.0 ### Notable Changes * \[[`cde0daabcc`](nodejs/node@cde0daabcc)] - **(SEMVER-MINOR)** **doc**: update `blockList` stability status to release candidate (alphaleadership) [#63050](nodejs/node#63050) * \[[`b78f5a7537`](nodejs/node@b78f5a7537)] - **(SEMVER-MINOR)** **fs**: support caller-supplied `readFile()` buffers (Matteo Collina) [#63634](nodejs/node#63634) * \[[`417aacbc36`](nodejs/node@417aacbc36)] - **(SEMVER-MINOR)** **http**: close pre-request sockets in `closeIdleConnections` (semimikoh) [#63470](nodejs/node#63470) * \[[`fbb108be7d`](nodejs/node@fbb108be7d)] - **(SEMVER-MINOR)** **loader**: implement package maps (Maël Nison) [#62239](nodejs/node#62239) * \[[`45494d5a8a`](nodejs/node@45494d5a8a)] - **(SEMVER-MINOR)** **net**: support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` (Guy Bedford) [#63825](nodejs/node#63825) * \[[`ee29465e77`](nodejs/node@ee29465e77)] - **(SEMVER-MINOR)** **tls**: add certificateCompression option (Tim Perry) [#62217](nodejs/node#62217) * \[[`b17817eb2b`](nodejs/node@b17817eb2b)] - **(SEMVER-MINOR)** **vfs**: dispatch `node:fs/promises` to mounted VFS instances (Matteo Collina) [#63537](nodejs/node#63537) * \[[`7bc93a6ac5`](nodejs/node@7bc93a6ac5)] - **(SEMVER-MINOR)** **vfs**: add minimal `node:vfs` subsystem (Matteo Collina) [#63115](nodejs/node#63115) ### Commits * \[[`c7eb83b46a`](nodejs/node@c7eb83b46a)] - **benchmark**: add child\_process async path baselines (Yagiz Nizipli) [#63929](nodejs/node#63929) * \[[`066fff17a5`](https://github.com/nodejs/node/commit/066f… (truncated) ### v26.5.0 ### Notable Changes #### New release key Welcome to our newest releaser, [Stewart X Addison](https://github.com/sxa). Future Node.js releases may be signed with his [release key](https://github.com/nodejs/node/blob/main/README.md#release-keys), `655F3B5C1FB3FA8D1A0CA6BDE4A7D232B936D2FD`. #### Other notable changes * \[[`55f48446c7`](nodejs/node@55f48446c7)] - **(SEMVER-MINOR)** **buffer**: implement blob.textStream() (Matthew Aitken) [#64036](nodejs/node#64036) * \[[`b373202efc`](nodejs/node@b373202efc)] - **(SEMVER-MINOR)** **esm**: add `--experimental-import-text` flag (Efe) [#62300](nodejs/node#62300) * \[[`39e0c14455`](nodejs/node@39e0c14455)] - **(SEMVER-MINOR)** **perf\_hooks**: sample delay per event loop iteration (Pablo Erhard) [#62935](nodejs/node#62935) * \[[`999a83c937`](nodejs/node@999a83c937)] - **(SEMVER-MINOR)** **stream**: expose ReadableStreamTee (Matteo Collina) [#64195](nodejs/node#64195) * \[[`4e0236dc3d`](nodejs/node@4e0236dc3d)] - **(SEMVER-MINOR)** **tls**: report negotiated TLS groups (Filip Skokan) [#64119](nodejs/node#64119) ### Commits * \[[`87648c0a6c`](nodejs/node@87648c0a6c)] - **benchmark**: trim down the argon2 sets (Filip Skokan) [#64218](nodejs/node#64218) * \[[`a483bfd3f0`](nodejs/node@a483bfd3f0)] - **buffer**: remove unreachable overflow check in atob (haramjeong) [#60161](nodejs/node#60161) * \[[`6d14279688`](nodejs/node@6d14279688)] - **buffer**: add fast api for isUtf8 and isAscii (Gürgün Dayıoğlu) [#64169](nodejs/node#64169) * \[[`55f48446c7`](nodejs/node@55f48446c7)] -… (truncated) ### v26.5.1 This is a security release. ### Notable Changes * (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High * (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High * (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium * (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium * (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium * (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium * (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium * (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low * (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low * (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low * deps: update llhttp to 9.4.3 (Paolo Insogna) * deps: update undici to 8.9.0 (Node.js GitHub Bot) ### Commits * \[[`af0bf96877`](nodejs/node@af0bf96877)] - **deps**: update llhttp to 9.4.3 (Paolo Insogna) [nodejs-private/node-private#935](https://github.com/nodejs-private/node-private/pull/935) * \[[`0354678355`](nodejs/node@0354678355)] - **deps**: update undici to 8.9.0 (Node.js GitHub Bot) [#64712](nodejs/node#64712) * \[[`dbeeaeec13`](nodejs/node@dbeeaeec13)] - **(CVE-2026-58042)** **dns**: handle large resolveAny address replies (RafaelGSS) [nodejs-private/node-private#929](https://github.com/nodejs-private/node-private/pull/929) * \[[`064d339f56`](nodejs/node@064d339f56)] - **(CVE-2026-58044)** **http**: reject requests exceeding max header count (Matteo Collina) [nodejs-private/node-private#922](https://github.com/nodejs-private/node-private/pull/922) * \[[`23b94c843a`](https://github.… (truncated) _Omitted 12 older releases._ </details> </details> Modified files: - `.mise.toml`
Summary
Fixes#60023.
run({ coverage: true, isolation: 'none' })returned an empty file list because V8 precise coverage is only enabled at bootstrap whenNODE_V8_COVERAGEor--experimental-test-coverageis set, neither of which the API path requires. The reporter also surfaced a related inconsistency: withisolation: 'process', test files (e.g.foo.test.mjs) appeared in the coverage report via the API path, while the CLI path excluded them by default.This PR fixes both halves:
run()is the entry point. A newprofiler.startCoverage()internal binding enables V8 precise coverage atrun()time. It is idempotent against the existing bootstrap path and a no-op when the inspector is unavailable (the parent of--test --test-isolation=process, where workers handle coverage themselves).coverage: trueis passed torun()withoutcoverageExcludeGlobs,[kDefaultPattern]is applied — matchingparseCommandLine's behavior. Two existing run() coverage tests that depended on the absent default are updated to opt out viacoverageExcludeGlobs: '!test/**'.Test plan
test/parallel/test-runner-coverage-isolation-none-api.mjspasses — covers isolation=none reports src files, default exclusion drops*.test.mjsin both isolation modes, and idempotency under--experimental-test-coverage.parallel/test-runner-*tests pass.tools/test.pysuite passes; unrelated FFI fixture-build setup and watch-mode flakiness verified independent of this change.Refs: #60023