Uh oh!
There was an error while loading. Please reload this page.
http: add writeInformation to send arbitrary 1xx status codes - #63155
Merged
Conversation
nodejs-github-bot
commented
May 6, 2026
Collaborator
Review requested:
|
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@## main #63155 +/- ##
==========================================
- Coverage 90.03% 90.02% -0.02%
==========================================
Files 713 713 Lines 224510 224565 +55 Branches 42438 42462 +24 ==========================================
+ Hits 202148 202161 +13 - Misses 14163 14222 +59 + Partials 8199 8182 -17
🚀 New features to boost your workflow:
|
metcoder95
approved these changes
May 7, 2026
metcoder95
left a comment
Member
There was a problem hiding this comment.
Don't have approval power, but lgtm; nice addition
Signed-off-by: Tim Perry <pimterry@gmail.com>
pimterryforce-pushed
the
h1-additional-headers
branch
from
May 7, 2026 08:20
d6b58d7 to
af03c6bComparepimterry
commented
May 7, 2026
MemberAuthor
Rebased to hopefully fix the build now that the QUIC coverage issue is sorted. |
nodejs-github-bot
commented
May 15, 2026
Collaborator
jasnell
approved these changes
May 15, 2026
nodejs-github-bot
commented
May 15, 2026
Collaborator
Ethan-Arrowood
approved these changes
May 15, 2026
Uh oh!
There was an error while loading. Please reload this page.
nodejs-github-bot
commented
May 15, 2026
Collaborator
Landed in 03f27fe |
aduh95 pushed a commit
that referenced
this pull request
May 19, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com> PR-URL: #63155 Reviewed-By: Matteo Collina <matteo.collina@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com> Reviewed-By: Ethan Arrowood <ethan@arrowood.dev>
aduh95 pushed a commit
that referenced
this pull request
May 19, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com> PR-URL: #63155 Reviewed-By: Matteo Collina <matteo.collina@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com> Reviewed-By: Ethan Arrowood <ethan@arrowood.dev>
aduh95 pushed a commit
that referenced
this pull request
May 23, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com> PR-URL: #63155 Reviewed-By: Matteo Collina <matteo.collina@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com> Reviewed-By: Ethan Arrowood <ethan@arrowood.dev>
aduh95 pushed a commit
that referenced
this pull request
Jun 18, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com> PR-URL: #63155 Reviewed-By: Matteo Collina <matteo.collina@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com> Reviewed-By: Ethan Arrowood <ethan@arrowood.dev>
nodejs-github-bot added a commit
that referenced
this pull request
Jun 19, 2026
Notable changes: buffer: * (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 http: * (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079 PR-URL: #64001
sxa added a commit
that referenced
this pull request
Jun 22, 2026
Notable changes: * crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 * (SEMVER-MINOR) buffer: increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597 * (SEMVER-MINOR) crypto: align key argument names in docs and error messages (Filip Skokan) #62527 * (SEMVER-MINOR) crypto: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) #62527 * (SEMVER-MINOR) crypto: unify asymmetric key import through KeyObjectHandle::Init (Filip Skokan) #62499 * (SEMVER-MINOR) crypto: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) #62183 * (SEMVER-MINOR) http: add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155 * (SEMVER-MINOR) inspector: expose precise coverage start to JS runtime (sangwook) #63079 * (SEMVER-MINOR) lib: cleanup stateless diffiehellman key handling (Filip Skokan) #62645 PR-URL: #64062
sxa added a commit
that referenced
this pull request
Jun 22, 2026
Notable changes: buffer: * (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 * (SEMVER-MINOR) align key argument names in docs and error messages (Filip Skokan) #62527 * (SEMVER-MINOR) accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) #62527 * (SEMVER-MINOR) add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) #62183 http: * http: avoid stream listeners on idle agent sockets (Matteo Collina) #64004 * (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079 stream: * stream: Revert noop pause/resume on destroyed streams" (Stewart X Addison) #63834 PR-URL: #64062
sxa added a commit
to sxa/node
that referenced
this pull request
Jun 23, 2026
Notable changes: buffer: * (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) nodejs#63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) nodejs#63527 * (SEMVER-MINOR) align key argument names in docs and error messages (Filip Skokan) nodejs#62527 * (SEMVER-MINOR) accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) nodejs#62527 * (SEMVER-MINOR) add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) nodejs#62183 http: * http: avoid stream listeners on idle agent sockets (Matteo Collina) nodejs#64004 * (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) nodejs#63155 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) nodejs#63079 stream: * stream: Revert noop pause/resume on destroyed streams" (Stewart X Addison) nodejs#63834 PR-URL: nodejs#64062
richardlau pushed a commit
that referenced
this pull request
Jun 23, 2026
Notable changes: buffer: * (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 * (SEMVER-MINOR) align key argument names in docs and error messages (Filip Skokan) #62527 * (SEMVER-MINOR) accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) #62527 * (SEMVER-MINOR) add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) #62183 http: * http: avoid stream listeners on idle agent sockets (Matteo Collina) #64004 * (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079 stream: * stream: Revert noop pause/resume on destroyed streams" (Stewart X Addison) #63834 PR-URL: #64062
mwalbeck pushed a commit
to mwalbeck/docker-cyberchef
that referenced
this pull request
Jul 11, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [node](https://github.com/nodejs/node) | stage | minor | `24.16.0-trixie` → `24.18.0-trixie` | --- ### Release Notes <details> <summary>nodejs/node (node)</summary> ### [`v24.18.0`](https://github.com/nodejs/node/releases/tag/v24.18.0): 2026-06-23, Version 24.18.0 'Krypton' (LTS), @​richardlau prepared by @​sxa [Compare Source](nodejs/node@v24.17.0...v24.18.0) ##### Notable Changes - \[[`e07e7a31e1`](nodejs/node@e07e7a31e1)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#​63527](nodejs/node#63527) - \[[`44c8ebcbd6`](nodejs/node@44c8ebcbd6)] - **http**: avoid stream listeners on idle agent sockets (Matteo Collina) [#​64004](nodejs/node#64004) - \[[`d3ef4122ee`](nodejs/node@d3ef4122ee)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#​63597](nodejs/node#63597) - \[[`bb2857b85a`](nodejs/node@bb2857b85a)] - **(SEMVER-MINOR)** **crypto**: align key argument names in docs and error messages (Filip Skokan) [#​62527](nodejs/node#62527) - \[[`b9d5e87880`](nodejs/node@b9d5e87880)] - **(SEMVER-MINOR)** **crypto**: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) [#​62527](nodejs/node#62527) - \[[`ccd756d61e`](nodejs/node@ccd756d61e)] - **(SEMVER-MINOR)** **crypto**: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) [#​62183](nodejs/node#62183) - \[[`4c9251fc09`](nodejs/node@4c9251fc09)] - **(SEMVER-MINOR)** **http**: add writeInformation to send arbitrary 1xx status codes (Tim Perry) [#​63155](nodejs/node#63155) - \[[`8c989ec4a3`](nodejs/node@8c989ec4a3)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#​63079](nodejs/node#63079) - \[[`3f54c8ba32`](nodejs/node@3f54c8ba32)] - ***Revert*** "**stream**: noop pause/resume on destroyed streams" (Stewart X Addison) [#​63834](nodejs/node#63834) ##### Commits - \[[`d3ef4122ee`](nodejs/node@d3ef4122ee)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#​63597](nodejs/node#63597) - \[[`9ff36e40f0`](nodejs/node@9ff36e40f0)] - **build**: add --enable-all-experimentals build flag (Paolo Insogna) [#​62755](nodejs/node#62755) - \[[`7c22ee23aa`](nodejs/node@7c22ee23aa)] - **build**: def `NODE_USE_NODE_CODE_CACHE` only used in node\_mksnapshot (Chengzhong Wu) [#​63588](nodejs/node#63588) - \[[`2551abdb4a`](nodejs/node@2551abdb4a)] - **build,win**: enable x64 PGO (Stefan Stojanovic) [#​62761](nodejs/node#62761) - \[[`e8a55ce9b1`](nodejs/node@e8a55ce9b1)] - **crypto**: strengthen argument CHECKs in TurboSHAKE (Tobias Nießen) [#​62763](nodejs/node#62763) - \[[`ae61cd68f3`](nodejs/node@ae61cd68f3)] - **crypto**: harden WebCrypto against prototype pollution (Filip Skokan) [#​63363](nodejs/node#63363) - \[[`3d05a1d396`](nodejs/node@3d05a1d396)] - **crypto**: pass CryptoKey handles to KDF jobs (Filip Skokan) [#​63363](nodejs/node#63363) - \[[`f9d10a3f6b`](nodejs/node@f9d10a3f6b)] - **crypto**: remove async from WebCrypto methods (Filip Skokan) [#​63363](nodejs/node#63363) - \[[`e431d93e9e`](nodejs/node@e431d93e9e)] - **crypto**: add WebCrypto CryptoJob mode (Filip Skokan) [#​63363](nodejs/node#63363) - \[[`56e2505e48`](nodejs/node@56e2505e48)] - **crypto**: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) [#​63255](nodejs/node#63255) - \[[`3bac77f2a8`](nodejs/node@3bac77f2a8)] - **crypto**: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) [#​63255](nodejs/node#63255) - \[[`1bff901b09`](nodejs/node@1bff901b09)] - **crypto**: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) [#​63255](nodejs/node#63255) - \[[`4433fca3df`](nodejs/node@4433fca3df)] - **crypto**: harden CryptoKey algorithm slots (Filip Skokan) [#​63111](nodejs/node#63111) - \[[`b5cf01217a`](nodejs/node@b5cf01217a)] - **crypto**: harden KeyObject internal slots (Filip Skokan) [#​63111](nodejs/node#63111) - \[[`ce84aef37d`](nodejs/node@ce84aef37d)] - **crypto**: add guards and adjust tests for BoringSSL (Filip Skokan) [#​62883](nodejs/node#62883) - \[[`26781689b0`](nodejs/node@26781689b0)] - **crypto**: reject duplicate ML-KEM JWK key\_ops (Filip Skokan) [#​62905](nodejs/node#62905) - \[[`aeea8f4970`](nodejs/node@aeea8f4970)] - **crypto**: add JWK support for ML-KEM and SLH-DSA key types (Filip Skokan) [#​62706](nodejs/node#62706) - \[[`407cf91656`](nodejs/node@407cf91656)] - **crypto**: guard against size\_t overflow on experimental 32-bit arch (Filip Skokan) [#​62626](nodejs/node#62626) - \[[`bb2857b85a`](nodejs/node@bb2857b85a)] - **(SEMVER-MINOR)** **crypto**: align key argument names in docs and error messages (Filip Skokan) [#​62527](nodejs/node#62527) - \[[`b9d5e87880`](nodejs/node@b9d5e87880)] - **(SEMVER-MINOR)** **crypto**: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) [#​62527](nodejs/node#62527) - \[[`b46d52b283`](nodejs/node@b46d52b283)] - **crypto**: unify asymmetric key import through KeyObjectHandle::Init (Filip Skokan) [#​62499](nodejs/node#62499) - \[[`ccd756d61e`](nodejs/node@ccd756d61e)] - **(SEMVER-MINOR)** **crypto**: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) [#​62183](nodejs/node#62183) - \[[`e07e7a31e1`](nodejs/node@e07e7a31e1)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#​63527](nodejs/node#63527) - \[[`61826df455`](nodejs/node@61826df455)] - **crypto**: coerce -0 keylen to +0 in pbkdf2 and scrypt (Jordan Harband) [#​63531](nodejs/node#63531) - \[[`16d2fd3c07`](nodejs/node@16d2fd3c07)] - **crypto**: align verifyOneShot accepted types (Anshika Jain) [#​63280](nodejs/node#63280) - \[[`3b8330deda`](nodejs/node@3b8330deda)] - **crypto**: improve system certificate enumeration logic on macOS (Robo) [#​62576](nodejs/node#62576) - \[[`141de35399`](nodejs/node@141de35399)] - **debugger**: add --help to `node inspect` and improve docs (Joyee Cheung) [#​63201](nodejs/node#63201) - \[[`b76bfcd4fa`](nodejs/node@b76bfcd4fa)] - **deps**: upgrade npm to 11.16.0 (npm team) [#​63602](nodejs/node#63602) - \[[`4ec142314c`](nodejs/node@4ec142314c)] - **deps**: SQLite: cherry-pick [`b869ed6`](nodejs/node@b869ed6) (Junsu Han) [#​63525](nodejs/node#63525) - \[[`19e8ce1c36`](nodejs/node@19e8ce1c36)] - **deps**: upgrade npm to 11.15.0 (npm team) [#​63463](nodejs/node#63463) - \[[`8a264260e2`](nodejs/node@8a264260e2)] - **deps**: update sqlite to 3.53.1 (Node.js GitHub Bot) [#​63217](nodejs/node#63217) - \[[`50c8ff3f94`](nodejs/node@50c8ff3f94)] - **deps**: update simdjson to 4.6.4 (Node.js GitHub Bot) [#​62811](nodejs/node#62811) - \[[`6e56f01c4b`](nodejs/node@6e56f01c4b)] - **deps**: V8: cherry-pick [`435a2cd`](nodejs/node@435a2cdf664c) (Matthias Liedtke) [#​63136](nodejs/node#63136) - \[[`3ba813b242`](nodejs/node@3ba813b242)] - **deps**: cherry-pick [libuv/libuv@`a43e543`](libuv/libuv@a43e543) (Ali Hassan) [#​63222](nodejs/node#63222) - \[[`2390e3a5ac`](nodejs/node@2390e3a5ac)] - **doc**: remove duplicated sentences in large-pull-requests.md (Joyee Cheung) [#​63650](nodejs/node#63650) - \[[`52a1c18374`](nodejs/node@52a1c18374)] - **doc**: update `git node land` instructions for security releases (Antoine du Hamel) [#​63586](nodejs/node#63586) - \[[`3e6b4da037`](nodejs/node@3e6b4da037)] - **doc**: drop --experimental from --permission (Rafael Gonzaga) [#​63583](nodejs/node#63583) - \[[`84d05163b9`](nodejs/node@84d05163b9)] - **doc**: explicitly ask for reproducible in JS (Rafael Gonzaga) [#​63479](nodejs/node#63479) - \[[`7da2a4450e`](nodejs/node@7da2a4450e)] - **doc**: fix URL postMessage example in worker\_threads (Kit Dallege) [#​62203](nodejs/node#62203) - \[[`3d79bd8b29`](nodejs/node@3d79bd8b29)] - **doc**: clarify `filter` option of `sqlite.database.applyChangeset` (Antoine du Hamel) [#​63515](nodejs/node#63515) - \[[`4f4174aace`](nodejs/node@4f4174aace)] - **doc**: fix double spaces in ERR\_TLS\_INVALID\_PROTOCOL\_METHOD (Daijiro Wachi) [#​63511](nodejs/node#63511) - \[[`388323ca4b`](nodejs/node@388323ca4b)] - **doc**: fix double space in modules.md (Daijiro Wachi) [#​63512](nodejs/node#63512) - \[[`5258ccc058`](nodejs/node@5258ccc058)] - **doc**: fix "options" to "option" in tls.createServer (Daijiro Wachi) [#​63453](nodejs/node#63453) - \[[`43e83e6507`](nodejs/node@43e83e6507)] - **doc**: fix typo in deprecations (Daijiro Wachi) [#​63434](nodejs/node#63434) - \[[`f05a61d54c`](nodejs/node@f05a61d54c)] - **doc**: remove unsupported template type from v8.md (René) [#​63410](nodejs/node#63410) - \[[`c39d5fc820`](nodejs/node@c39d5fc820)] - **doc**: fix article usage before vowel-sound acronyms (joao-oliveira-softtor) [#​62696](nodejs/node#62696) - \[[`398261f911`](nodejs/node@398261f911)] - **doc**: remove the bi-monthly contributor spotlight section (Claudio Wunder) [#​62734](nodejs/node#62734) - \[[`fd9e14c405`](nodejs/node@fd9e14c405)] - **doc**: update http2's `push` and `trailers` events with `rawHeaders` param (YuSheng Chen) [#​63259](nodejs/node#63259) - \[[`b943ce6933`](nodejs/node@b943ce6933)] - **doc**: remove inactive members from Triagers list (Antoine du Hamel) [#​63329](nodejs/node#63329) - \[[`4b9cdfc022`](nodejs/node@4b9cdfc022)] - **doc**: reference correct function in Module docs (Robin Malfait) [#​63247](nodejs/node#63247) - \[[`bed84b6df2`](nodejs/node@bed84b6df2)] - **doc**: replace Visual Studio 2022 Evergreen version reference with 17.14 (Mike McCready) [#​63211](nodejs/node#63211) - \[[`32ea70569b`](nodejs/node@32ea70569b)] - **doc**: recommend explicitly Tier 1 or 2 for production applications (Mike McCready) [#​63187](nodejs/node#63187) - \[[`4627bcfd82`](nodejs/node@4627bcfd82)] - **doc**: run license-builder (github-actions\[bot]) [#​63232](nodejs/node#63232) - \[[`28eba71845`](nodejs/node@28eba71845)] - **doc**: add large pull requests contributing guide (Matteo Collina) [#​62829](nodejs/node#62829) - \[[`2648efd438`](nodejs/node@2648efd438)] - **doc**: remove unnecessary `<!-- eslint-` magic comments (Antoine du Hamel) [#​63200](nodejs/node#63200) - \[[`a95fc1f8fc`](nodejs/node@a95fc1f8fc)] - **doc**: clarify SEA platform support excludes darwin-x64 (MJSHANG) [#​63181](nodejs/node#63181) - \[[`aaef29e2e1`](nodejs/node@aaef29e2e1)] - **doc**: update release steps when post-release fails (Rafael Gonzaga) [#​63131](nodejs/node#63131) - \[[`7d81419cf2`](nodejs/node@7d81419cf2)] - **doc**: add Hmac.digest() documentation-only deprecation (DEP0206) (Anshika Jain) [#​63121](nodejs/node#63121) - \[[`ececd80d81`](nodejs/node@ececd80d81)] - **doc**: document the latest-vX.x schema (Marco Ippolito) [#​63033](nodejs/node#63033) - \[[`27c1c1d842`](nodejs/node@27c1c1d842)] - **doc**: remove list of versions in `BUILDING.md` (Antoine du Hamel) [#​63113](nodejs/node#63113) - \[[`e369886a65`](nodejs/node@e369886a65)] - **doc,sqlite**: document entryPoint argument for loadExtension (Edy Silva) [#​63152](nodejs/node#63152) - \[[`e4e5137cbd`](nodejs/node@e4e5137cbd)] - **errors**: handle V8 warnings in DisallowJavascriptExecutionScope (Divyanshu Sharma) [#​63491](nodejs/node#63491) - \[[`6d1f6048d2`](nodejs/node@6d1f6048d2)] - **fs**: make `Date` properties on `Stats` enumerable (LiviaMedeiros) [#​63328](nodejs/node#63328) - \[[`44c8ebcbd6`](nodejs/node@44c8ebcbd6)] - **http**: avoid stream listeners on idle agent sockets (Matteo Collina) [#​64004](nodejs/node#64004) - \[[`4c9251fc09`](nodejs/node@4c9251fc09)] - **(SEMVER-MINOR)** **http**: add writeInformation to send arbitrary 1xx status codes (Tim Perry) [#​63155](nodejs/node#63155) - \[[`39f61fb06c`](nodejs/node@39f61fb06c)] - **http2**: emit session close before stream close (Matteo Collina) [#​63414](nodejs/node#63414) - \[[`8a8f2127d1`](nodejs/node@8a8f2127d1)] - **http2**: validate non-link headers in writeEarlyHints (Matteo Collina) [#​62017](nodejs/node#62017) - \[[`8c989ec4a3`](nodejs/node@8c989ec4a3)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#​63079](nodejs/node#63079) - \[[`c05f38229b`](nodejs/node@c05f38229b)] - **lib**: cleanup stateless diffiehellman key handling (Filip Skokan) [#​62645](nodejs/node#62645) - \[[`1c16b45d35`](nodejs/node@1c16b45d35)] - **lib**: refactor internal webidl converters (Filip Skokan) [#​62979](nodejs/node#62979) - \[[`02f35d6dce`](nodejs/node@02f35d6dce)] - **lib**: define `kEnumerableProperty` atomically (Antoine du Hamel) [#​63609](nodejs/node#63609) - \[[`12c51547ba`](nodejs/node@12c51547ba)] - **lib**: fix typos in esm loader comments (RonGamzu) [#​63465](nodejs/node#63465) - \[[`9b03b84262`](nodejs/node@9b03b84262)] - **lib**: fix typo idenity => identity (Daijiro Wachi) [#​63112](nodejs/node#63112) - \[[`a84e6b0567`](nodejs/node@a84e6b0567)] - **lib**: fixes validator message (Daijiro Wachi) [#​62823](nodejs/node#62823) - \[[`11734166a8`](nodejs/node@11734166a8)] - **lib**: narrow ReadableStreamBYOBRequest.view return type to Uint8Array (RoomWithOutRoof) [#​63017](nodejs/node#63017) - \[[`7cead61d21`](nodejs/node@7cead61d21)] - **meta**: flip mcollina emails in .mailmap (Matteo Collina) [#​63621](nodejs/node#63621) - \[[`a08cfcfd35`](nodejs/node@a08cfcfd35)] - **meta**: label "source maps" PRs (Chengzhong Wu) [#​63591](nodejs/node#63591) - \[[`d56e8d2512`](nodejs/node@d56e8d2512)] - **meta**: add `vfs` subsystem label (René) [#​62331](nodejs/node#62331) - \[[`6201cfe488`](nodejs/node@6201cfe488)] - **meta**: skip scheduled workflows on forks (Jamie Magee) [#​63565](nodejs/node#63565) - \[[`f095e2bd31`](nodejs/node@f095e2bd31)] - **meta**: add additional gitignore entries (James M Snell) [#​63267](nodejs/node#63267) - \[[`1ea52c444c`](nodejs/node@1ea52c444c)] - **meta**: move one or more collaborators to emeritus (Node.js GitHub Bot) [#​63402](nodejs/node#63402) - \[[`b1b2327611`](nodejs/node@b1b2327611)] - **meta**: move one or more collaborators to emeritus (Node.js GitHub Bot) [#​63235](nodejs/node#63235) - \[[`7d88e130a9`](nodejs/node@7d88e130a9)] - **meta**: ignore AI assistants files (Matteo Collina) [#​62612](nodejs/node#62612) - \[[`a53b51df38`](nodejs/node@a53b51df38)] - **module**: load ESM helpers eagerly in the snapshot (Joyee Cheung) [#​63550](nodejs/node#63550) - \[[`69df688fff`](nodejs/node@69df688fff)] - **module**: fix sync hook short-circuit in require() in imported CJS (Joyee Cheung) [#​62920](nodejs/node#62920) - \[[`75d9a4ed47`](nodejs/node@75d9a4ed47)] - **node-api**: support SharedArrayBuffer in napi\_create\_typedarray (Yilong Li) [#​62710](nodejs/node#62710) - \[[`c20aa4c47b`](nodejs/node@c20aa4c47b)] - **quic**: add reusePort option to QuicEndpoint (James M Snell) [#​63267](nodejs/node#63267) - \[[`26a30d8a7f`](nodejs/node@26a30d8a7f)] - **quic**: implement rate limiting for version nego and immediate close (James M Snell) [#​63267](nodejs/node#63267) - \[[`0b534b5770`](nodejs/node@0b534b5770)] - **quic**: fixup linting issue after other changes (James M Snell) [#​63267](nodejs/node#63267) - \[[`4b367cbe09`](nodejs/node@4b367cbe09)] - **quic**: remove unused binding variable in session.cc (James M Snell) [#​63177](nodejs/node#63177) - \[[`2574bef5a6`](nodejs/node@2574bef5a6)] - **repl**: fix dedup comparing normalized line against raw history (Daijiro Wachi) [#​62886](nodejs/node#62886) - \[[`30e71c7e49`](nodejs/node@30e71c7e49)] - **sqlite**: keep source database alive during backup (Matteo Collina) [#​62673](nodejs/node#62673) - \[[`677ca7e76c`](nodejs/node@677ca7e76c)] - **src**: simplify OpenSSL feature gates (Filip Skokan) [#​63255](nodejs/node#63255) - \[[`c863c75c39`](nodejs/node@c863c75c39)] - **src**: add BoringSSL EVP enumeration fallback (Filip Skokan) [#​63206](nodejs/node#63206) - \[[`f6b2466921`](nodejs/node@f6b2466921)] - **src**: decouple KeyObject and CryptoKey and move CryptoKey to src (Filip Skokan) [#​62924](nodejs/node#62924) - \[[`92d4f07dd2`](nodejs/node@92d4f07dd2)] - **src**: remove license headers for new node\_profiling files (Chengzhong Wu) [#​63066](nodejs/node#63066) - \[[`8ac5d771c8`](nodejs/node@8ac5d771c8)] - **src**: split profiling helpers from util (Ilyas Shabi) [#​63008](nodejs/node#63008) - \[[`85d1639495`](nodejs/node@85d1639495)] - **src**: remove TOCTOU race condition when encoding SAB-backed `Buffer`s (Antoine du Hamel) [#​63517](nodejs/node#63517) - \[[`9473c5f05c`](nodejs/node@9473c5f05c)] - **src**: skip duplicate UTF-8 validation in TextDecoder fatal path (Mert Can Altin) [#​63231](nodejs/node#63231) - \[[`f35c91ee68`](nodejs/node@f35c91ee68)] - **src**: improve token return value check (James M Snell) [#​63483](nodejs/node#63483) - \[[`26f677c1c5`](nodejs/node@26f677c1c5)] - **src**: expose `node::RegisterContext` to make a node managed context (Chengzhong Wu) [#​62322](nodejs/node#62322) - \[[`275cf909b6`](nodejs/node@275cf909b6)] - **src,sqlite**: only pass `xFilter` when user provided a callback (Antoine du Hamel) [#​63516](nodejs/node#63516) - \[[`287e02303f`](nodejs/node@287e02303f)] - **src,sqlite**: remove dead code (Edy Silva) [#​63204](nodejs/node#63204) - \[[`58fa2ee189`](nodejs/node@58fa2ee189)] - **stream**: switch to internal `sleep` binding (Antoine du Hamel) [#​63611](nodejs/node#63611) - \[[`f954ab3f1a`](nodejs/node@f954ab3f1a)] - **stream**: use data listener for compose forwarding (Trivikram Kamat) [#​63593](nodejs/node#63593) - \[[`dc57173003`](nodejs/node@dc57173003)] - **stream**: fix Writable.toWeb() hang on synchronous drain (sangwook) [#​61197](nodejs/node#61197) - \[[`3f54c8ba32`](nodejs/node@3f54c8ba32)] - ***Revert*** "**stream**: noop pause/resume on destroyed streams" (Stewart X Addison) [#​63834](nodejs/node#63834) - \[[`cee279c5d6`](nodejs/node@cee279c5d6)] - **stream**: remove unnecessary check (Antoine du Hamel) [#​63030](nodejs/node#63030) - \[[`61b20f60a3`](nodejs/node@61b20f60a3)] - **test**: update tls/crypto behaviour expectations when using BoringSSL (Filip Skokan) [#​63161](nodejs/node#63161) - \[[`a835363808`](nodejs/node@a835363808)] - **test**: update WPT for WebCryptoAPI to [`97bbc72`](nodejs/node@97bbc7247a) (Node.js GitHub Bot) [#​63417](nodejs/node#63417) - \[[`a00297480b`](nodejs/node@a00297480b)] - **test**: update WPT resources, interfaces and WebCryptoAPI (Node.js GitHub Bot) [#​62389](nodejs/node#62389) - \[[`5a95a2b055`](nodejs/node@5a95a2b055)] - **test**: shorten path in net pipe connect errors (Matteo Collina) [#​63405](nodejs/node#63405) - \[[`5e8ff22d8f`](nodejs/node@5e8ff22d8f)] - **test**: remove test-node-output-v8-warning (Joyee Cheung) [#​63469](nodejs/node#63469) - \[[`ee15380950`](nodejs/node@ee15380950)] - **test**: update test426-fixtures to [`9b9e225`](nodejs/node@9b9e225) (Node.js GitHub Bot) [#​63373](nodejs/node#63373) - \[[`9e063d9bea`](nodejs/node@9e063d9bea)] - **test**: update WPT for url to [`e4a4672`](nodejs/node@e4a4672e9e) (Node.js GitHub Bot) [#​63372](nodejs/node#63372) - \[[`503bee4b43`](nodejs/node@503bee4b43)] - **test**: deflake async-hooks statwatcher test (Trivikram Kamat) [#​63396](nodejs/node#63396) - \[[`cccc7c32d8`](nodejs/node@cccc7c32d8)] - **test**: avoid test\_runner watch restart in spec snapshot (Trivikram Kamat) [#​63392](nodejs/node#63392) - \[[`c89489258c`](nodejs/node@c89489258c)] - **test**: reduce watch mode restart flakiness (Trivikram Kamat) [#​63390](nodejs/node#63390) - \[[`e4d5e2578e`](nodejs/node@e4d5e2578e)] - **test**: isolate rerun-failures state file under tmpdir (Chemi Atlow) [#​63449](nodejs/node#63449) - \[[`362644a9ba`](nodejs/node@362644a9ba)] - **test**: wait for ok before initial break after restart (Yuya Inoue) [#​62807](nodejs/node#62807) - \[[`c4058d0e05`](nodejs/node@c4058d0e05)] - **test**: disable Maglev in near-heap-limit worker test (Trivikram Kamat) [#​63398](nodejs/node#63398) - \[[`214da630a7`](nodejs/node@214da630a7)] - **test**: deflake connection refused proxy tests (Trivikram Kamat) [#​63395](nodejs/node#63395) - \[[`1d61a29876`](nodejs/node@1d61a29876)] - **test**: avoid repeated writes in watch helper (Trivikram Kamat) [#​63386](nodejs/node#63386) - \[[`2004e25387`](nodejs/node@2004e25387)] - **test**: deflake watch mode worker test (Trivikram Kamat) [#​63384](nodejs/node#63384) - \[[`d691cccfc1`](nodejs/node@d691cccfc1)] - **test**: relax test-memory-usage arrayBuffers check (inoway46) [#​63244](nodejs/node#63244) - \[[`0ff6bf853c`](nodejs/node@0ff6bf853c)] - **test**: reduce flakiness of `different-registry-per-thread` (Antoine du Hamel) [#​63244](nodejs/node#63244) - \[[`d9f4e8e503`](nodejs/node@d9f4e8e503)] - **test**: fix flaky test-watch-mode-inspect timeout (Matteo Collina) [#​63361](nodejs/node#63361) - \[[`6d7cd50328`](nodejs/node@6d7cd50328)] - **test**: relax min assertion in test-performance-eventloopdelay (Marco) [#​63100](nodejs/node#63100) - \[[`9dafe1d2d8`](nodejs/node@9dafe1d2d8)] - **test**: avoid flaky restart sync in debugger exceptions test (Yuya Inoue) [#​62055](nodejs/node#62055) - \[[`989b2de973`](nodejs/node@989b2de973)] - **test**: avoid initial-break wait in restart-message (inoway46) [#​62060](nodejs/node#62060) - \[[`a072a25ee7`](nodejs/node@a072a25ee7)] - **test**: move FFI tests to `NATIVE_SUITES` (Antoine du Hamel) [#​63165](nodejs/node#63165) - \[[`64efbfd878`](nodejs/node@64efbfd878)] - **test**: use ERM to destroy sqlite database handles after tests (René) [#​63076](nodejs/node#63076) - \[[`7dee66cd94`](nodejs/node@7dee66cd94)] - **test\_runner**: dont buffer unordered events in process isolation mode (Moshe Atlow) [#​63432](nodejs/node#63432) - \[[`d257eec1e3`](nodejs/node@d257eec1e3)] - **test\_runner**: fix --test-rerun-failures swallowing failures on retry (Chemi Atlow) [#​63431](nodejs/node#63431) - \[[`288c320e2f`](nodejs/node@288c320e2f)] - **test\_runner**: show replayed-from-attempt hint in spec reporter (Moshe Atlow) [#​63429](nodejs/node#63429) - \[[`904bdf5bb4`](nodejs/node@904bdf5bb4)] - **test\_runner**: preserve run duration when using test-rerun (Moshe Atlow) [#​63429](nodejs/node#63429) - \[[`df183d7bfa`](nodejs/node@df183d7bfa)] - **test\_runner**: avoid hanging on incomplete v8 frames (Ali Hassan) [#​62704](nodejs/node#62704) - \[[`ec86c69726`](nodejs/node@ec86c69726)] - **test\_runner**: fix diagnostics channel context tracking (Moshe Atlow) [#​63283](nodejs/node#63283) - \[[`94e5f63b83`](nodejs/node@94e5f63b83)] - **tls**: add unsupported renegotiation error (Filip Skokan) [#​63161](nodejs/node#63161) - \[[`06d308fb61`](nodejs/node@06d308fb61)] - **tools**: prevent lib code from reading KeyObject and CryptoKey accessors (Filip Skokan) [#​63111](nodejs/node#63111) - \[[`2e4a0d0c91`](nodejs/node@2e4a0d0c91)] - **tools**: bump brace-expansion from 5.0.5 to 5.0.6 in /tools/eslint (dependabot\[bot]) [#​63415](nodejs/node#63415) - \[[`4c9666b366`](nodejs/node@4c9666b366)] - **tools**: skip commit-lint on backport pull requests (Marco) [#​63378](nodejs/node#63378) - \[[`67d0c490a8`](nodejs/node@67d0c490a8)] - **tools**: fix skip of `test-internet` on forks (Antoine du Hamel) [#​63492](nodejs/node#63492) - \[[`02f73c7cac`](nodejs/node@02f73c7cac)] - **tools**: bump the eslint group in /tools/eslint with 4 updates (dependabot\[bot]) [#​63075](nodejs/node#63075) - \[[`5d016d3241`](nodejs/node@5d016d3241)] - **tools**: update gyp-next to 0.22.2 (Node.js GitHub Bot) [#​63374](nodejs/node#63374) - \[[`55af0f0edb`](nodejs/node@55af0f0edb)] - **tools**: fix test426 updater (Antoine du Hamel) [#​63271](nodejs/node#63271) - \[[`d8475e167a`](nodejs/node@d8475e167a)] - **tools**: use different branch for tool updates on staging branches (Antoine du Hamel) [#​63110](nodejs/node#63110) - \[[`c605df9e50`](nodejs/node@c605df9e50)] - **util**: remove unused functions (Antoine du Hamel) [#​63612](nodejs/node#63612) - \[[`fe4540ebdb`](nodejs/node@fe4540ebdb)] - **util**: create hex style cache and fast path (Guilherme Araújo) [#​62999](nodejs/node#62999) ### [`v24.17.0`](https://github.com/nodejs/node/releases/tag/v24.17.0): 2026-06-18, Version 24.17.0 'Krypton' (LTS), @​aduh95 [Compare Source](nodejs/node@v24.16.0...v24.17.0) This is a security release. ##### Notable Changes - (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High - (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High - (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium - (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium - (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium - (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium - (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium - (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 – Medium - (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low - (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low - (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low ##### Commits - \[[`9e4dfc7bba`](nodejs/node@9e4dfc7bba)] - **(CVE-2026-48933)** **crypto**: guard WebCrypto cipher output length (Filip Skokan) [nodejs-private/node-private#878](https://github.com/nodejs-private/node-private/pull/878) - \[[`cb2aed980c`](nodejs/node@cb2aed980c)] - **deps**: update llhttp to 9.4.2 (Antoine du Hamel) [nodejs-private/node-private#890](https://github.com/nodejs-private/node-private/pull/890) - \[[`a8a0d12875`](nodejs/node@a8a0d12875)] - **(CVE-2026-48937)** **deps**: fix integration issues with the latest nghttp2 (Tim Perry) [#​62891](nodejs/node#62891) - \[[`66e6203c1c`](nodejs/node@66e6203c1c)] - **(SEMVER-MAJOR)** **deps**: update nghttp2 to 1.69.0 (Node.js GitHub Bot) [#​62891](nodejs/node#62891) - \[[`dd627ced27`](nodejs/node@dd627ced27)] - **deps**: update archs files for openssl-3.5.7 (Node.js GitHub Bot) [#​63820](nodejs/node#63820) - \[[`684bae568f`](nodejs/node@684bae568f)] - **deps**: upgrade openssl sources to openssl-3.5.7 (Node.js GitHub Bot) [#​63820](nodejs/node#63820) - \[[`3a631e7f83`](nodejs/node@3a631e7f83)] - **deps**: fix aix implicit declaration in OpenSSL (Abdirahim Musse) [#​62656](nodejs/node#62656) - \[[`cf44df3996`](nodejs/node@cf44df3996)] - **deps**: update undici to 7.28.0 (Node.js GitHub Bot) [#​63703](nodejs/node#63703) - \[[`138c70294b`](nodejs/node@138c70294b)] - **(CVE-2026-48930)** **dns,net**: reject hostnames with embedded NUL bytes (Matteo Collina) [nodejs-private/node-private#868](https://github.com/nodejs-private/node-private/pull/868) - \[[`be7e719c3f`](nodejs/node@be7e719c3f)] - **(CVE-2026-48931)** **http**: fix response queue poisoning in http.Agent (Matteo Collina) [nodejs-private/node-private#846](https://github.com/nodejs-private/node-private/pull/846) - \[[`cc7c11b4d1`](nodejs/node@cc7c11b4d1)] - **(CVE-2026-48619)** **http2**: cap originSet size to prevent unbounded memory growth (Matteo Collina) [nodejs-private/node-private#855](https://github.com/nodejs-private/node-private/pull/855) - \[[`9224427b92`](nodejs/node@9224427b92)] - **(CVE-2026-48615)** **lib,test**: redact proxy credentials in tunnel errors (Matteo Collina) [nodejs-private/node-private#867](https://github.com/nodejs-private/node-private/pull/867) - \[[`cf85d54839`](nodejs/node@cf85d54839)] - **(CVE-2026-48935)** **permission**: disable FileHandle utimes with permission model (RafaelGSS) [nodejs-private/node-private#873](https://github.com/nodejs-private/node-private/pull/873) - \[[`a1bbc24f96`](nodejs/node@a1bbc24f96)] - **(CVE-2026-48617)** **permission**: handle process.chdir on writereport (RafaelGSS) [nodejs-private/node-private#870](https://github.com/nodejs-private/node-private/pull/870) - \[[`e3723ff2d6`](nodejs/node@e3723ff2d6)] - **test**: add session reuse host verification regressions (Matteo Collina) [nodejs-private/node-private#854](https://github.com/nodejs-private/node-private/pull/854) - \[[`a77af4867b`](nodejs/node@a77af4867b)] - **(CVE-2026-48934)** **tls**: bind reusable sessions to authenticated host (Matteo Collina) [nodejs-private/node-private#854](https://github.com/nodejs-private/node-private/pull/854) - \[[`31beb4f707`](nodejs/node@31beb4f707)] - **(CVE-2026-48928)** **tls**: fix case-sensitive SNI context matching (Matteo Collina) [nodejs-private/node-private#857](https://github.com/nodejs-private/node-private/pull/857) - \[[`8e75c73f91`](nodejs/node@8e75c73f91)] - **(CVE-2026-48618)** **tls**: normalize hostname for server identity checks (Matteo Collina) [nodejs-private/node-private#869](https://github.com/nodejs-private/node-private/pull/869) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzAuMTkiLCJ1cGRhdGVkSW5WZXIiOiI0My4xNzAuMTkiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=--> Reviewed-on: https://git.walbeck.it/mwalbeck/docker-cyberchef/pulls/488
juanarbol pushed a commit
to juanarbol/node
that referenced
this pull request
Jul 16, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com> PR-URL: nodejs#63155 Reviewed-By: Matteo Collina <matteo.collina@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com> Reviewed-By: Ethan Arrowood <ethan@arrowood.dev>
juanarbol added a commit
that referenced
this pull request
Jul 16, 2026
Notable changes: async_hooks: * (SEMVER-MINOR) add trackPromises option to createHook() (Joyee Cheung) #61415 buffer: * (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597 cli: * (SEMVER-MINOR) add --max-heap-size option (tannal) #58708 console: * (SEMVER-MINOR) allow per-stream `inspectOptions` option (Anna Henningsen) #60082 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 debugger: * (SEMVER-MINOR) add edit-free runtime expression probes to `node inspect` (Joyee Cheung) #62713 fs: * (SEMVER-MINOR) add signal option to fs.stat() (Mert Can Altin) #57775 * (SEMVER-MINOR) expose frsize field in statfs (Jinho Jang) #62277 * (SEMVER-MINOR) add `throwIfNoEntry` option for fs.stat and fs.promises.stat (Juan José) #61178 * (SEMVER-MINOR) add ignore option to fs.watch (Matteo Collina) #61433 http: * (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155 * (SEMVER-MINOR) add req.signal to IncomingMessage (Akshat) #62541 lib: * (SEMVER-MINOR) remove util.getCallSite (Rafael Gonzaga) #59980 net: * (SEMVER-MINOR) add `setTOS` and `getTOS` to `Socket` (Amol Yadav) #61503 node-api: * (SEMVER-MINOR) support SharedArrayBuffer in napi_create_dataview (Kevin Eady) #60473 * (SEMVER-MINOR) add napi_create_object_with_properties (Miguel Marcondes Filho) #59953 perf_hooks: * (SEMVER-MINOR) move non-standard performance properties to perf_hooks (Chengzhong Wu) #60370 sqlite: * (SEMVER-MINOR) add sqlite prepare options args (Guilherme Araújo) #61311 * (SEMVER-MINOR) create authorization api (Guilherme Araújo) #59928 src: * (CVE-2026-21712) handle url crash on different url formats (RafaelGSS) nodejs-private/node-private#816 src,permission: * (SEMVER-MINOR) add --allow-inspector ability (Rafael Gonzaga) #59711 stream: * (SEMVER-MINOR) add bytes() method to stream/consumers (wantaek) #60426 * (SEMVER-MINOR) do not pass `readable.compose()` output via `Readable.from()` (René) #60907 test_runner: * (SEMVER-MINOR) align mock timeout api (sangwook) #62820 PR-URL: TODO
Closed
This was referenced Jul 27, 2026
jylenhof pushed a commit
to jylenhof/mise-update-tool
that referenced
this pull request
Aug 4, 2026
Automated mise tool upgrades from local config. Updated tools: - `action-validator` - `actionlint` - `aube` - `editorconfig-checker` - `ghalint` - `node` - `pinact` - `pipx:gh-action-pulse` - `prek` - `rumdl` - `shellcheck` - `shfmt` - `tombi` - `uv` - `yamlfmt` - `yamllint` - `zizmor` Command: `mise upgrade --bump --local action-validator actionlint aube editorconfig-checker ghalint node pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor` <details> <summary>Version changelog (node)</summary> | Tool | Requested | Installed | |------|-----------|-----------| | `node` | `24` → `26` | `24.18.1` → `26.5.1` | </details> <details> <summary>Release notes (1 tools)</summary> <details> <summary>node: `24.18.1` → `26.5.1` (nodejs/node)</summary> ### v25.8.2 This is a security release. ### Notable Changes * (CVE-2026-21637) wrap `SNICallback` invocation in `try`/`catch` (Matteo Collina) - High * (CVE-2026-21710) use null prototype for `headersDistinct`/`trailersDistinct` (Matteo Collina) - High * (CVE-2026-21711) include permission check to `pipe_wrap.cc` (RafaelGSS) - Medium * (CVE-2026-21712) handle url crash on different url formats (RafaelGSS) - Medium * (CVE-2026-21713) use timing-safe comparison in Web Cryptography HMAC and KMAC (Filip Skokan) - Medium * (CVE-2026-21714) handle `NGHTTP2_ERR_FLOW_CONTROL` error code (RafaelGSS) - Medium * (CVE-2026-21717) test array index hash collision (Joyee Cheung) - Medium * (CVE-2026-21715) add permission check to `realpath.native` (RafaelGSS) - Low * (CVE-2026-21716) include permission check on `lib/fs/promises` (RafaelGSS) - Low ### Commits * \[[`2086b7477b`](nodejs/node@2086b7477b)] - **(CVE-2026-21717)** **build,test**: test array index hash collision (Joyee Cheung) [nodejs-private/node-private#834](https://github.com/nodejs-private/node-private/pull/834) * \[[`0f9332a40a`](nodejs/node@0f9332a40a)] - **(CVE-2026-21713)** **crypto**: use timing-safe comparison in Web Cryptography HMAC and KMAC (Filip Skokan) [nodejs-private/node-private#822](https://github.com/nodejs-private/node-private/pull/822) * \[[`2b6937ddb2`](nodejs/node@2b6937ddb2)] - **deps**: update undici to 7.24.4 (Node.js GitHub Bot) [#62271](nodejs/node#62271) * \[[`bfb8ad5787`](nodejs/node@bfb8ad5787)] - **deps**: update undici to 7.24.3 (Node.js GitHub Bot) [#62233](nodejs/node#62233) * \[[`be6384727f`](nodejs/node@be6384727f)] - **deps**: upgrade npm to 11.11.1 (npm team) [#62216](nodejs/node#62216) * \[[`2feea5bb97`](nodejs/node@2feea5bb97)] - **deps**: V8: override… (truncated) ### v25.9.0 ### Notable Changes #### Test runner module mocking improvements `MockModuleOptions.defaultExport` and `MockModuleOptions.namedExports` have been consolidated into a single option `MockModuleOptions.exports` to align with user expectations and other test runners. A `default` property on `MockModuleOptions.exports` represents the default export, and own enumerable properties are treated as named exports. An automated migration is available to update user code: <https://github.com/nodejs/userland-migrations/tree/main/recipes/mock-module-exports> ```bash npx codemod @nodejs/mock-module-exports ``` Contributed by sangwook in [#61727](nodejs/node#61727). #### Other notable changes * \[[`312476cb84`](nodejs/node@312476cb84)] - **(SEMVER-MINOR)** **async\_hooks**: add using scopes to `AsyncLocalStorage` (Stephen Belanger) [#61674](nodejs/node#61674) * \[[`62d2cd473b`](nodejs/node@62d2cd473b)] - **(SEMVER-MINOR)** **cli**: add `--max-heap-size` option (tannal) [#58708](nodejs/node#58708) * \[[`d0ebf0e44b`](nodejs/node@d0ebf0e44b)] - **(SEMVER-MINOR)** **crypto**: add `TurboSHAKE` and `KangarooTwelve` Web Cryptography algorithms (Filip Skokan) [#62183](nodejs/node#62183) * \[[`f85b9d9fa8`](nodejs/node@f85b9d9fa8)] - **(SEMVER-MINOR)** **repl**: add customizable error handling (Anna Henningsen) [#62188](nodejs/node#62188) * \[[`67b854d407`](nodejs/node@67b854d407)] - **(SEMVER-MINOR)** **repl**: remove dependency on `node:domain` (Matteo Collina) [#61227](nodejs/node#61227) * \[[`966b700623`](nodejs/node@966b700623)] - **(SEMVER-MINOR)** **sea**: support code cache for ESM entrypoint in SEA (Joyee Cheung) [#62158](nodejs/node#62158) *… (truncated) ### v26.0.0 We're excited to announce the release of Node.js 26! Highlights include the Temporal API enabled by default, updates to the V8 JavaScript engine to 14.6, Undici to 8.0, and several important deprecations and removals as we continue to modernize the platform. As a reminder, Node.js 26 will enter long-term support (LTS) in October, but until then, it will be the "Current" release for the next six months. We encourage you to explore the new features and benefits offered by this latest release and evaluate their potential impact on your applications. ### Notable Changes #### Temporal API The Temporal API is now enabled by default in Node.js 26. Temporal is a modern date/time API for JavaScript that provides a more robust and feature-rich alternative to the legacy `Date` object. Contributed by Richard Lau in [#61806](nodejs/node#61806). #### V8 14.6 The V8 engine is updated to version 14.6.202.33, which is part of Chromium 134. This version also includes: * Upsert (<https://github.com/tc39/proposal-upsert>): `[Weak]Map.prototype.getOrInsert()`, `[Weak]Map.prototype.getOrInsertComputed()` * Iterator sequencing (<https://github.com/tc39/proposal-iterator-sequencing>): `Iterator.concat()` Contributed by Michaël Zasso in [#61898](nodejs/node#61898). #### Undici 8 Undici has been updated to version 8.0.2, bringing new features and improvements to Node.js's HTTP client implementation. #### Deprecations and Removals * \[[`dff46c07c3`](nodejs/node@dff46c07c3)] - **(SEMVER-MAJOR)** **crypto**: move DEP0182 to End-of-Life (Tobias Nießen) [#61084](nodejs/node#61084) * \[[`93c25815ee`](nodejs/node@93c25815ee)] - **(SEMVER-MAJOR)** **http**: move writeHeader to end-of-life (Sebastian Beltran) [#60635](nodejs/node#60635) `http.Server.prototype.writeHeader()` is now fully removed. Use `http.Server.prototype.write… (truncated) ### v26.1.0 ### Notable Changes #### Experimental `node:ffi` module Node.js now includes an experimental `node:ffi` module for loading dynamic libraries and calling native symbols from JavaScript. The API is gated behind the `--experimental-ffi` flag and, when the Permission Model is enabled, requires `--allow-ffi`. This API is inherently unsafe. Invalid pointers, incorrect signatures, or accessing memory after it has been freed can crash the process or corrupt memory. Contributed by Paolo Insogna in [#62072](nodejs/node#62072). #### Other Notable Changes * \[[`34a6454fe3`](nodejs/node@34a6454fe3)] - **(SEMVER-MINOR)** **buffer**: add `end` parameter (Robert Nagy) [#62390](nodejs/node#62390) * \[[`073e84d7fe`](nodejs/node@073e84d7fe)] - **(SEMVER-MINOR)** **crypto**: accept key data in `crypto.diffieHellman()` and cleanup DH jobs (Filip Skokan) [#62527](nodejs/node#62527) * \[[`5b9cb10a5f`](nodejs/node@5b9cb10a5f)] - **(SEMVER-MINOR)** **crypto**: implement `randomUUIDv7()` (nabeel378) [#62553](nodejs/node#62553) * \[[`98f9becd16`](nodejs/node@98f9becd16)] - **(SEMVER-MINOR)** **debugger**: add edit-free runtime expression probes to `node inspect` (Joyee Cheung) [#62713](nodejs/node#62713) * \[[`06defaa2ea`](nodejs/node@06defaa2ea)] - **(SEMVER-MINOR)** **fs**: add `signal` option to `fs.stat()` (Mert Can Altin) [#57775](nodejs/node#57775) * \[[`db66a963bf`](nodejs/node@db66a963bf)] - **(SEMVER-MINOR)** **fs**: expose `frsize` field in `statfs` (Jinho Jang) [#62277](nodejs/node#62277) * \[[`87adb3472b`](nodejs/node@87adb3472b)] - **(SEMVER-MINOR)** **http**: harden `ClientRequest` options merge (Matteo Collina) [#6… (truncated) ### v26.2.0 ### Notable Changes * \[[`189d43a193`](nodejs/node@189d43a193)] - **doc**: mark `stream.compose` stable (Matteo Collina) [#62562](nodejs/node#62562) * \[[`f858c6140e`](nodejs/node@f858c6140e)] - **(SEMVER-MINOR)** **fs**: add `Temporal.Instant` support to `Stats` and `BigIntStats` (Livia Medeiros) [#60789](nodejs/node#60789) * \[[`0cbb3895df`](nodejs/node@0cbb3895df)] - **(SEMVER-MINOR)** **http**: add `writeInformation` to send arbitrary 1xx status codes (Tim Perry) [#63155](nodejs/node#63155) ### Commits * \[[`9a394bab84`](nodejs/node@9a394bab84)] - **benchmark**: respect stream/iter broadcast backpressure (Trivikram Kamat) [#63314](nodejs/node#63314) * \[[`ad98b4620b`](nodejs/node@ad98b4620b)] - **crypto**: align verifyOneShot accepted types (Anshika Jain) [#63280](nodejs/node#63280) * \[[`ba0736a847`](nodejs/node@ba0736a847)] - **crypto**: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255) * \[[`5573a6a4a8`](nodejs/node@5573a6a4a8)] - **crypto**: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255) * \[[`7dc563b8d6`](nodejs/node@7dc563b8d6)] - **crypto**: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255) * \[[`b55e2b1f4d`](nodejs/node@b55e2b1f4d)] - **crypto**: improve system certificate enumeration logic on macOS (Robo) [#62576](nodejs/node#62576) * \[[`fd509a755a`](nodejs/node@fd509a755a)] - **crypto**: harden CryptoKey algorithm slots… (truncated) ### v26.3.0 ### Notable Changes #### Potential changes to macOS Universal Binary availability With Apple and its ecosystem progressively dropping support for Intel-based architectures, it has become apparent that the Node.js project may not be able to maintain the universal binaries we currently distribute for the full lifetime of Node.js 26. This change serves to communicate that risk. At present, our intention remains to continue shipping universal binaries supporting both Apple Silicon and Intel-based Macs for as long as practical. Contributed by Antoine du Hamel in [#63055](nodejs/node#63055). #### Other notable changes * \[[`a2a4b33dd8`](nodejs/node@a2a4b33dd8)] - **(SEMVER-MINOR)** **buffer**: increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) [#63597](nodejs/node#63597) * \[[`051a2152f7`](nodejs/node@051a2152f7)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#63527](nodejs/node#63527) * \[[`49462eca37`](nodejs/node@49462eca37)] - **(SEMVER-MINOR)** **http**: add `httpValidation` option to configure header value validation (RajeshKumar11) [#61597](nodejs/node#61597) * \[[`97b7ab19bd`](nodejs/node@97b7ab19bd)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#63079](nodejs/node#63079) * \[[`cfb80a2103`](nodejs/node@cfb80a2103)] - **(SEMVER-MINOR)** **lib,permission**: add `permission.drop` (Rafael Gonzaga) [#62672](nodejs/node#62672) ### Commits * \[[`a2a4b33dd8`](nodejs/node@a2a4b33dd8)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#63597](nodejs/node#63597) * \[[`0eff3e23b9`](https://github.com/nodejs/n… (truncated) ### v26.3.1 This is a security release. ### Notable Changes * (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High * (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High * (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium * (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium * (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium * (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium * (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium * (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low * (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low * (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low * (CVE-2026-48936) permission: guard pipe open and chmod with net scope (RafaelGSS) – Low ### Commits * \[[`98fbc89211`](nodejs/node@98fbc89211)] - **(CVE-2026-48933)** **crypto**: guard WebCrypto cipher output length (Filip Skokan) [nodejs-private/node-private#878](https://github.com/nodejs-private/node-private/pull/878) * \[[`110840f2c7`](nodejs/node@110840f2c7)] - **deps**: update llhttp to 9.4.2 (Antoine du Hamel) [nodejs-private/node-private#890](https://github.com/nodejs-private/node-private/pull/890) * \[[`8d36d522b2`](nodejs/node@8d36d522b2)] - **deps**: update undici to 8.5.0 (Node.js GitHub Bot) [#63903](nodejs/node#63903) * \[[`2e6d03993a`](nodejs/node@2e6d03993a)] - **deps**: update undici to 8.4.0 (Node.js GitHub Bot) [#63779](nodejs/node#63779) * \[[`5a17d5b07a`](nodejs/node@5a17d5b07a)] - **deps… (truncated) ### v26.4.0 ### Notable Changes * \[[`cde0daabcc`](nodejs/node@cde0daabcc)] - **(SEMVER-MINOR)** **doc**: update `blockList` stability status to release candidate (alphaleadership) [#63050](nodejs/node#63050) * \[[`b78f5a7537`](nodejs/node@b78f5a7537)] - **(SEMVER-MINOR)** **fs**: support caller-supplied `readFile()` buffers (Matteo Collina) [#63634](nodejs/node#63634) * \[[`417aacbc36`](nodejs/node@417aacbc36)] - **(SEMVER-MINOR)** **http**: close pre-request sockets in `closeIdleConnections` (semimikoh) [#63470](nodejs/node#63470) * \[[`fbb108be7d`](nodejs/node@fbb108be7d)] - **(SEMVER-MINOR)** **loader**: implement package maps (Maël Nison) [#62239](nodejs/node#62239) * \[[`45494d5a8a`](nodejs/node@45494d5a8a)] - **(SEMVER-MINOR)** **net**: support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` (Guy Bedford) [#63825](nodejs/node#63825) * \[[`ee29465e77`](nodejs/node@ee29465e77)] - **(SEMVER-MINOR)** **tls**: add certificateCompression option (Tim Perry) [#62217](nodejs/node#62217) * \[[`b17817eb2b`](nodejs/node@b17817eb2b)] - **(SEMVER-MINOR)** **vfs**: dispatch `node:fs/promises` to mounted VFS instances (Matteo Collina) [#63537](nodejs/node#63537) * \[[`7bc93a6ac5`](nodejs/node@7bc93a6ac5)] - **(SEMVER-MINOR)** **vfs**: add minimal `node:vfs` subsystem (Matteo Collina) [#63115](nodejs/node#63115) ### Commits * \[[`c7eb83b46a`](nodejs/node@c7eb83b46a)] - **benchmark**: add child\_process async path baselines (Yagiz Nizipli) [#63929](nodejs/node#63929) * \[[`066fff17a5`](https://github.com/nodejs/node/commit/066f… (truncated) ### v26.5.0 ### Notable Changes #### New release key Welcome to our newest releaser, [Stewart X Addison](https://github.com/sxa). Future Node.js releases may be signed with his [release key](https://github.com/nodejs/node/blob/main/README.md#release-keys), `655F3B5C1FB3FA8D1A0CA6BDE4A7D232B936D2FD`. #### Other notable changes * \[[`55f48446c7`](nodejs/node@55f48446c7)] - **(SEMVER-MINOR)** **buffer**: implement blob.textStream() (Matthew Aitken) [#64036](nodejs/node#64036) * \[[`b373202efc`](nodejs/node@b373202efc)] - **(SEMVER-MINOR)** **esm**: add `--experimental-import-text` flag (Efe) [#62300](nodejs/node#62300) * \[[`39e0c14455`](nodejs/node@39e0c14455)] - **(SEMVER-MINOR)** **perf\_hooks**: sample delay per event loop iteration (Pablo Erhard) [#62935](nodejs/node#62935) * \[[`999a83c937`](nodejs/node@999a83c937)] - **(SEMVER-MINOR)** **stream**: expose ReadableStreamTee (Matteo Collina) [#64195](nodejs/node#64195) * \[[`4e0236dc3d`](nodejs/node@4e0236dc3d)] - **(SEMVER-MINOR)** **tls**: report negotiated TLS groups (Filip Skokan) [#64119](nodejs/node#64119) ### Commits * \[[`87648c0a6c`](nodejs/node@87648c0a6c)] - **benchmark**: trim down the argon2 sets (Filip Skokan) [#64218](nodejs/node#64218) * \[[`a483bfd3f0`](nodejs/node@a483bfd3f0)] - **buffer**: remove unreachable overflow check in atob (haramjeong) [#60161](nodejs/node#60161) * \[[`6d14279688`](nodejs/node@6d14279688)] - **buffer**: add fast api for isUtf8 and isAscii (Gürgün Dayıoğlu) [#64169](nodejs/node#64169) * \[[`55f48446c7`](nodejs/node@55f48446c7)] -… (truncated) ### v26.5.1 This is a security release. ### Notable Changes * (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High * (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High * (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium * (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium * (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium * (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium * (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium * (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low * (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low * (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low * deps: update llhttp to 9.4.3 (Paolo Insogna) * deps: update undici to 8.9.0 (Node.js GitHub Bot) ### Commits * \[[`af0bf96877`](nodejs/node@af0bf96877)] - **deps**: update llhttp to 9.4.3 (Paolo Insogna) [nodejs-private/node-private#935](https://github.com/nodejs-private/node-private/pull/935) * \[[`0354678355`](nodejs/node@0354678355)] - **deps**: update undici to 8.9.0 (Node.js GitHub Bot) [#64712](nodejs/node#64712) * \[[`dbeeaeec13`](nodejs/node@dbeeaeec13)] - **(CVE-2026-58042)** **dns**: handle large resolveAny address replies (RafaelGSS) [nodejs-private/node-private#929](https://github.com/nodejs-private/node-private/pull/929) * \[[`064d339f56`](nodejs/node@064d339f56)] - **(CVE-2026-58044)** **http**: reject requests exceeding max header count (Matteo Collina) [nodejs-private/node-private#922](https://github.com/nodejs-private/node-private/pull/922) * \[[`23b94c843a`](https://github.… (truncated) _Omitted 12 older releases._ </details> </details> Modified files: - `.mise.toml`
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This provides a generic HTTP/1 API for 1xx responses, equivalent to our existing HTTP/2 additionalHeaders API. This supports any 1xx status code, except 101, which I've intentionally excluded - since it changes the protocol entirely, there's no possible way to unilaterally send that without breaking things later in our current API, so you just have to use 'upgrade' in that case.
This fixes various past requests like:
And acts as a nice workaround to solve:
(All 3 closed as stale, not fixed)
I'm also hoping it'll discourage usage of the private
res._writeRawmethod as a workaround for the existing limitations. We even did this in our own tests, see test/parallel/test-http-information-headers.js here.This is useful to support custom 1xx values (perfectly valid AFAICT, if unusual), proxies (who want to pass through data in a standard way, without having to separately handle each case individually as today) and to give us trivial general support for future standardized 1xx values, without needing a whole separate PR to add a new per-status API every time.
The existing methods are refactored to use the generic method under the hood, and HTTP/2 compat uses additionalHeaders.
There's one annoying inconsistency here: the H1 methods throw if we've already sent a final status code, while the H2 methods just no-op. I've kept that as-is and matched this in the new method to avoid a breaking change, but it would probably be best to align on throwing in both cases in a separate major bump.