Skip to content

fs: support caller-supplied readFile() buffers - #63634

Merged
nodejs-github-bot merged 4 commits into
nodejs:mainfrom
mcollina:fs-readfile-buffer-option
Jun 13, 2026
Merged

fs: support caller-supplied readFile() buffers#63634
nodejs-github-bot merged 4 commits into
nodejs:mainfrom
mcollina:fs-readfile-buffer-option

Conversation

@mcollina

Copy link
Copy Markdown
Member

Fixes: #63600

@nodejs-github-botnodejs-github-bot added fs Issues and PRs related to the fs subsystem / file system. needs-ci PRs that need a full CI run. labels May 29, 2026
@mcollina
mcollina requested review from LiviaMedeiros, MattiasBuelens and ronag and removed request for MattiasBuelensMay 29, 2026 08:22
@mcollina
mcollina marked this pull request as ready for review May 29, 2026 08:24
@mcollina
mcollinaforce-pushed the fs-readfile-buffer-option branch from 50d050d to e04e121CompareMay 29, 2026 08:24
@mcollina
mcollinaforce-pushed the fs-readfile-buffer-option branch from e04e121 to 2f1e60fCompareMay 29, 2026 08:26

@ShogunPandaShogunPanda left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

Comment threaddoc/api/fs.md Outdated
Comment on lines +708 to +710
* `buffer` {Buffer|TypedArray|DataView} A buffer to read into.
* `getBuffer` {Function} A synchronous function called with the file size and
returning the buffer to read into.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we not consolidate these two? Plenty of places across the API surface have options with "either a thing or a thing-like function" types.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed. It should be quite cheap to check typeof options.buffer === 'function' at the start.

@@ -1033,6 +1035,66 @@ const validateStringAfterArrayBufferView = hideStackFrames((buffer, name) => {
}
});

const validateReadFileBufferOptions = hideStackFrames((options) => {

@Renegade334Renegade334May 29, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would personally advocate for this to throw if both buffer and encoding are provided – directly contradictory patterns should fail validation.

@codecov

codecovBot commented May 29, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 96.32353% with 10 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.35%. Comparing base (8d0a3b8) to head (e8edd28).
⚠️ Report is 89 commits behind head on main.

Files with missing linesPatch %Lines
lib/internal/fs/promises.js93.10%4 Missing ⚠️
lib/fs.js95.89%3 Missing ⚠️
lib/internal/fs/read/context.js95.94%3 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #63634 +/- ##
==========================================
+ Coverage 90.29% 90.35% +0.06% 
==========================================
Files 730 732 +2 Lines 234782 236689 +1907 Branches 43953 44582 +629 ==========================================
+ Hits 211993 213862 +1869 - Misses 14501 14561 +60 + Partials 8288 8266 -22 
Files with missing linesCoverage Δ
lib/internal/fs/utils.js98.53% <100.00%> (+0.09%)⬆️
lib/fs.js98.36% <95.89%> (+0.16%)⬆️
lib/internal/fs/read/context.js94.92% <95.94%> (+0.35%)⬆️
lib/internal/fs/promises.js92.94% <93.10%> (+0.12%)⬆️

... and 65 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

PR-URL: nodejs#63634
Signed-off-by: Matteo Collina <matteo.collina@gmail.com>
@mcollina
mcollinaforce-pushed the fs-readfile-buffer-option branch from 2f1e60f to e8edd28CompareMay 30, 2026 11:01
Comment threadlib/internal/fs/utils.js Outdated
Comment threadlib/internal/fs/utils.js Outdated
Comment threaddoc/api/fs.md Outdated
@mcollinamcollina added semver-minor PRs that contain new features and should be released in the next minor version. request-ci Add this label to start a Jenkins CI on a PR. labels Jun 1, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Jun 1, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

- Remove getBuffer deprecation check from validateReadFileBufferOptions
(getBuffer was never released, dead code)
- Simplify buffer validation using isArrayBufferView check
- Consolidate buffer option description in docs:
'synchronous function called with the file size and returning
the buffer to read into' -> 'function called with the file size
that returns the buffer'
- Add examples for pre-allocated buffer and function variants
Co-authored-by: LiviaMedeiros <livia@example.com>
Co-authored-by: Renegade334 <renegade334@example.com>
Co-authored-by: MattiasBuelens <mattias@example.com>
Co-authored-by: jasnell <jasnell@example.com>
PR-URL: nodejs#63634
Signed-off-by: Matteo Collina <hello@matteocollina.com>
The getBuffer validation was removed from validateReadFileBufferOptions
since getBuffer was never released. Remove the test cases that expected
ERR_INVALID_ARG_VALUE for getBuffer.
PR-URL: nodejs#63634
Signed-off-by: matteo <matteo@example.com>
PR-URL: nodejs#63634
Signed-off-by: matteo <matteo@example.com>
@mcollina

Copy link
Copy Markdown
MemberAuthor

@ShogunPandaShogunPanda left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@mcollinamcollina added the commit-queue Add this label to land a pull request using GitHub Actions. label Jun 13, 2026
@nodejs-github-botnodejs-github-bot added commit-queue-failed An error occurred while landing this pull request using GitHub Actions. and removed commit-queue Add this label to land a pull request using GitHub Actions. labels Jun 13, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator
Commit Queue failed
- Loading data for nodejs/node/pull/63634
✔ Done loading data for nodejs/node/pull/63634
----------------------------------- PR info ------------------------------------
Title fs: support caller-supplied readFile() buffers (#63634)
Author Matteo Collina <matteo.collina@gmail.com> (@mcollina)
Branch mcollina:fs-readfile-buffer-option -> nodejs:main
Labels fs, semver-minor, needs-ci
Commits 4
- fs: support caller-supplied readFile() buffers
- fs: address PR review comments
- test: remove getBuffer tests
- doc: add Buffer import to examples to satisfy lint
Committers 1
- Matteo Collina <hello@matteocollina.com>
PR-URL: https://github.com/nodejs/node/pull/63634
Fixes: https://github.com/nodejs/node/issues/63600
Reviewed-By: Paolo Insogna <paolo@cowtech.it>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: LiviaMedeiros <livia@cirno.name>
------------------------------ Generated metadata ------------------------------
PR-URL: https://github.com/nodejs/node/pull/63634
Fixes: https://github.com/nodejs/node/issues/63600
Reviewed-By: Paolo Insogna <paolo@cowtech.it>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: LiviaMedeiros <livia@cirno.name>
--------------------------------------------------------------------------------
ℹ This PR was created on Fri, 29 May 2026 08:22:28 GMT
✔ Approvals: 3
✔ - Paolo Insogna (@ShogunPanda) (TSC): https://github.com/nodejs/node/pull/63634#pullrequestreview-4478094154
✔ - James M Snell (@jasnell) (TSC): https://github.com/nodejs/node/pull/63634#pullrequestreview-4398614605
✔ - LiviaMedeiros (@LiviaMedeiros): https://github.com/nodejs/node/pull/63634#pullrequestreview-4478938701
✔ Last GitHub CI successful
ℹ Last Full PR CI on 2026-06-12T05:53:54Z: https://ci.nodejs.org/job/node-test-pull-request/74067/
- Querying data for job/node-test-pull-request/74067/
✔ Build data downloaded
✔ Last Jenkins CI successful
--------------------------------------------------------------------------------
✔ No git cherry-pick in progress
✔ No git am in progress
✔ No git rebase in progress
--------------------------------------------------------------------------------
- Bringing origin/main up to date...
From https://github.com/nodejs/node
* branch main -> FETCH_HEAD
✔ origin/main is now up-to-date
- Downloading patch for 63634
From https://github.com/nodejs/node
* branch refs/pull/63634/merge -> FETCH_HEAD
✔ Fetched commits as 4383f67279f2..e6c1949c90e7
--------------------------------------------------------------------------------
Auto-merging lib/fs.js
Auto-merging lib/internal/fs/promises.js
Auto-merging lib/internal/fs/utils.js
[main aabbda3359] fs: support caller-supplied readFile() buffers
Author: Matteo Collina <hello@matteocollina.com>
Date: Fri May 29 10:20:46 2026 +0200
7 files changed, 635 insertions(+), 18 deletions(-)
create mode 100644 test/parallel/test-fs-promises-readfile-buffer-option.js
create mode 100644 test/parallel/test-fs-readfile-buffer-option.js
Auto-merging lib/internal/fs/utils.js
[main a395990cbd] fs: address PR review comments
Author: Matteo Collina <hello@matteocollina.com>
Date: Wed Jun 10 13:14:54 2026 +0000
2 files changed, 88 insertions(+), 22 deletions(-)
[main 5386f6d85d] test: remove getBuffer tests
Author: Matteo Collina <hello@matteocollina.com>
Date: Wed Jun 10 13:42:35 2026 +0000
2 files changed, 12 deletions(-)
[main 928677a24f] doc: add Buffer import to examples to satisfy lint
Author: Matteo Collina <hello@matteocollina.com>
Date: Wed Jun 10 16:15:07 2026 +0000
1 file changed, 6 insertions(+)
✔ Patches applied
There are 4 commits in the PR. Attempting autorebase.
(node:478) [DEP0190] DeprecationWarning: Passing args to a child process with shell option true can lead to security vulnerabilities, as the arguments are not escaped, only concatenated.
(Use `node --trace-deprecation ...` to show where the warning was created)
Rebasing (2/8)
Executing: git node land --amend --yes
--------------------------------- New Message ----------------------------------
fs: support caller-supplied readFile() buffers

Signed-off-by: Matteo Collina <matteo.collina@gmail.com>
PR-URL: #63634
Fixes: #63600
Reviewed-By: Paolo Insogna <paolo@cowtech.it>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: LiviaMedeiros <livia@cirno.name>

[detached HEAD 6051ce1c89] fs: support caller-supplied readFile() buffers
Author: Matteo Collina <hello@matteocollina.com>
Date: Fri May 29 10:20:46 2026 +0200
7 files changed, 635 insertions(+), 18 deletions(-)
create mode 100644 test/parallel/test-fs-promises-readfile-buffer-option.js
create mode 100644 test/parallel/test-fs-readfile-buffer-option.js
Rebasing (3/8)
Rebasing (4/8)
Executing: git node land --amend --yes
--------------------------------- New Message ----------------------------------
fs: address PR review comments

  • Remove getBuffer deprecation check from validateReadFileBufferOptions
    (getBuffer was never released, dead code)
  • Simplify buffer validation using isArrayBufferView check
  • Consolidate buffer option description in docs:
    'synchronous function called with the file size and returning
    the buffer to read into' -> 'function called with the file size
    that returns the buffer'
  • Add examples for pre-allocated buffer and function variants

Co-authored-by: LiviaMedeiros <livia@example.com>
Co-authored-by: Renegade334 <renegade334@example.com>
Co-authored-by: MattiasBuelens <mattias@example.com>
Co-authored-by: jasnell <jasnell@example.com>

Signed-off-by: Matteo Collina <hello@matteocollina.com>
PR-URL: #63634
Fixes: #63600
Reviewed-By: Paolo Insogna <paolo@cowtech.it>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: LiviaMedeiros <livia@cirno.name>

[detached HEAD 089d6f919c] fs: address PR review comments
Author: Matteo Collina <hello@matteocollina.com>
Date: Wed Jun 10 13:14:54 2026 +0000
2 files changed, 88 insertions(+), 22 deletions(-)
Rebasing (5/8)
Rebasing (6/8)
Executing: git node land --amend --yes
--------------------------------- New Message ----------------------------------
test: remove getBuffer tests

The getBuffer validation was removed from validateReadFileBufferOptions
since getBuffer was never released. Remove the test cases that expected
ERR_INVALID_ARG_VALUE for getBuffer.

Signed-off-by: matteo <matteo@example.com>
PR-URL: #63634
Fixes: #63600
Reviewed-By: Paolo Insogna <paolo@cowtech.it>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: LiviaMedeiros <livia@cirno.name>

[detached HEAD 59227a2aeb] test: remove getBuffer tests
Author: Matteo Collina <hello@matteocollina.com>
Date: Wed Jun 10 13:42:35 2026 +0000
2 files changed, 12 deletions(-)
Rebasing (7/8)
Rebasing (8/8)
Executing: git node land --amend --yes
--------------------------------- New Message ----------------------------------
doc: add Buffer import to examples to satisfy lint

Signed-off-by: matteo <matteo@example.com>
PR-URL: #63634
Fixes: #63600
Reviewed-By: Paolo Insogna <paolo@cowtech.it>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: LiviaMedeiros <livia@cirno.name>

[detached HEAD 93ce6710f2] doc: add Buffer import to examples to satisfy lint
Author: Matteo Collina <hello@matteocollina.com>
Date: Wed Jun 10 16:15:07 2026 +0000
1 file changed, 6 insertions(+)
Successfully rebased and updated refs/heads/main.

ℹ Add commit-queue-squash label to land the PR as one commit, or commit-queue-rebase to land as separate commits.

https://github.com/nodejs/node/actions/runs/27462268368

@LiviaMedeirosLiviaMedeiros added commit-queue Add this label to land a pull request using GitHub Actions. commit-queue-squash Add this label to instruct the Commit Queue to squash all the PR commits into the first one. and removed commit-queue-failed An error occurred while landing this pull request using GitHub Actions. labels Jun 13, 2026
@nodejs-github-botnodejs-github-bot removed the commit-queue Add this label to land a pull request using GitHub Actions. label Jun 13, 2026
@nodejs-github-bot
nodejs-github-bot merged commit de67c5c into nodejs:mainJun 13, 2026
81 of 82 checks passed
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Landed in de67c5c

aduh95 pushed a commit that referenced this pull request Jun 18, 2026
Signed-off-by: Matteo Collina <matteo.collina@gmail.com>
PR-URL: #63634Fixes: #63600
Reviewed-By: Paolo Insogna <paolo@cowtech.it>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: LiviaMedeiros <livia@cirno.name>
nodejs-github-bot added a commit that referenced this pull request Jun 22, 2026
Notable changes:
build, doc:
* generate node.1 with doc-kit (Aviv Keller) #62044
deps:
* (SEMVER-MINOR) update OpenSSL build config to support compression (Tim Perry) #62217
doc:
* (SEMVER-MINOR) update `blockList` stability status to release candidate (alphaleadership) #63050
fs:
* (SEMVER-MINOR) support caller-supplied readFile() buffers (Matteo Collina) #63634
http:
* (SEMVER-MINOR) close pre-request sockets in closeIdleConnections (semimikoh) #63470
loader:
* (SEMVER-MINOR) implement package maps (Maël Nison) #62239
net:
* (SEMVER-MINOR) support TCP_KEEPINTVL and TCP_KEEPCNT in setKeepAlive (Guy Bedford) #63825
tls:
* (SEMVER-MINOR) add certificateCompression option (Tim Perry) #62217
vfs:
* (SEMVER-MINOR) dispatch fs/promises to mounted VFS instances (Matteo Collina) #63537
* (SEMVER-MINOR) add minimal node:vfs subsystem (Matteo Collina) #63115
PR-URL: #64058
aduh95 added a commit that referenced this pull request Jun 23, 2026
Notable changes:
deps:
* (SEMVER-MINOR) update OpenSSL build config to support compression (Tim Perry) #62217
doc:
* (SEMVER-MINOR) update `blockList` stability status to release candidate (alphaleadership) #63050
fs:
* (SEMVER-MINOR) support caller-supplied `readFile()` buffers (Matteo Collina) #63634
http:
* (SEMVER-MINOR) close pre-request sockets in `closeIdleConnections` (semimikoh) #63470
loader:
* (SEMVER-MINOR) implement package maps (Maël Nison) #62239
net:
* (SEMVER-MINOR) support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` (Guy Bedford) #63825
tls:
* (SEMVER-MINOR) add `certificateCompression` option (Tim Perry) #62217
vfs:
* (SEMVER-MINOR) dispatch `node:fs/promises` to mounted VFS instances (Matteo Collina) #63537
* (SEMVER-MINOR) add minimal `node:vfs` subsystem (Matteo Collina) #63115
PR-URL: #64058
aduh95 added a commit that referenced this pull request Jun 24, 2026
Notable changes:
deps:
* (SEMVER-MINOR) update OpenSSL build config to support compression (Tim Perry) #62217
doc:
* (SEMVER-MINOR) update `blockList` stability status to release candidate (alphaleadership) #63050
fs:
* (SEMVER-MINOR) support caller-supplied `readFile()` buffers (Matteo Collina) #63634
http:
* (SEMVER-MINOR) close pre-request sockets in `closeIdleConnections` (semimikoh) #63470
loader:
* (SEMVER-MINOR) implement package maps (Maël Nison) #62239
net:
* (SEMVER-MINOR) support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` (Guy Bedford) #63825
tls:
* (SEMVER-MINOR) add `certificateCompression` option (Tim Perry) #62217
vfs:
* (SEMVER-MINOR) dispatch `node:fs/promises` to mounted VFS instances (Matteo Collina) #63537
* (SEMVER-MINOR) add minimal `node:vfs` subsystem (Matteo Collina) #63115
PR-URL: #64058
aduh95 pushed a commit that referenced this pull request Jun 25, 2026
Signed-off-by: Matteo Collina <matteo.collina@gmail.com>
PR-URL: #63634Fixes: #63600
Reviewed-By: Paolo Insogna <paolo@cowtech.it>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: LiviaMedeiros <livia@cirno.name>
aduh95 added a commit that referenced this pull request Jul 21, 2026
Notable changes:
buffer:
* (SEMVER-MINOR) implement `blob.textStream()` (Matthew Aitken) #64036
deps:
* (SEMVER-MINOR) update OpenSSL build config to support compression (Tim Perry) #62217
doc:
* (SEMVER-MINOR) update `blockList` stability status to release candidate (alphaleadership) #63050
* mark `stream.compose` stable (Matteo Collina) #62562
esm:
* (SEMVER-MINOR) add `--experimental-import-text` flag (Efe) #62300
fs:
* (SEMVER-MINOR) support caller-supplied `readFile()` buffers (Matteo Collina) #63634
http:
* (SEMVER-MINOR) add `httpValidation` option to configure header value validation (RajeshKumar11) #61597
net:
* (SEMVER-MINOR) support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in setKeepAlive (Guy Bedford) #63825
perf_hooks:
* (SEMVER-MINOR) sample delay per event loop iteration (Pablo Erhard) #62935
src:
* (SEMVER-MINOR) allow empty `--experimental-config-file` (Marco Ippolito) #61610
stream:
* (SEMVER-MINOR) expose `ReadableStreamTee` (Matteo Collina) #64195
tls:
* (SEMVER-MINOR) report negotiated TLS groups (Filip Skokan) #64119
* (SEMVER-MINOR) add `certificateCompression` option (Tim Perry) #62217
PR-URL: #64654
aduh95 pushed a commit that referenced this pull request Jul 30, 2026
Signed-off-by: Matteo Collina <matteo.collina@gmail.com>
PR-URL: #63634Fixes: #63600
Reviewed-By: Paolo Insogna <paolo@cowtech.it>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: LiviaMedeiros <livia@cirno.name>
aduh95 added a commit that referenced this pull request Jul 30, 2026
Notable changes:
buffer:
* (SEMVER-MINOR) implement `blob.textStream()` (Matthew Aitken) #64036
deps:
* (SEMVER-MINOR) update OpenSSL build config to support compression (Tim Perry) #62217
doc:
* (SEMVER-MINOR) update `blockList` stability status to release candidate (alphaleadership) #63050
* mark `stream.compose` stable (Matteo Collina) #62562
esm:
* (SEMVER-MINOR) add `--experimental-import-text` flag (Efe) #62300
fs:
* (SEMVER-MINOR) support caller-supplied `readFile()` buffers (Matteo Collina) #63634
http:
* (SEMVER-MINOR) add `httpValidation` option to configure header value validation (RajeshKumar11) #61597
net:
* (SEMVER-MINOR) support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` (Guy Bedford) #63825
perf_hooks:
* (SEMVER-MINOR) sample delay per event loop iteration (Pablo Erhard) #62935
src:
* (SEMVER-MINOR) allow empty `--experimental-config-file` (Marco Ippolito) #61610
stream:
* (SEMVER-MINOR) expose `ReadableStreamTee` (Matteo Collina) #64195
tls:
* (SEMVER-MINOR) report negotiated TLS groups (Filip Skokan) #64119
* (SEMVER-MINOR) add `certificateCompression` option (Tim Perry) #62217
PR-URL: #64654
aduh95 added a commit that referenced this pull request Aug 3, 2026
Notable changes:
buffer:
* (SEMVER-MINOR) implement `blob.textStream()` (Matthew Aitken) #64036
deps:
* (SEMVER-MINOR) update OpenSSL build config to support compression (Tim Perry) #62217
doc:
* (SEMVER-MINOR) update `blockList` stability status to release candidate (alphaleadership) #63050
* mark `stream.compose` stable (Matteo Collina) #62562
esm:
* (SEMVER-MINOR) add `--experimental-import-text` flag (Efe) #62300
fs:
* (SEMVER-MINOR) support caller-supplied `readFile()` buffers (Matteo Collina) #63634
http:
* (SEMVER-MINOR) add `httpValidation` option to configure header value validation (RajeshKumar11) #61597
net:
* (SEMVER-MINOR) support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` (Guy Bedford) #63825
perf_hooks:
* (SEMVER-MINOR) sample delay per event loop iteration (Pablo Erhard) #62935
src:
* (SEMVER-MINOR) allow empty `--experimental-config-file` (Marco Ippolito) #61610
stream:
* (SEMVER-MINOR) expose `ReadableStreamTee` (Matteo Collina) #64195
tls:
* (SEMVER-MINOR) report negotiated TLS groups (Filip Skokan) #64119
* (SEMVER-MINOR) add `certificateCompression` option (Tim Perry) #62217
PR-URL: #64654
jylenhof pushed a commit to jylenhof/mise-update-tool that referenced this pull request Aug 4, 2026
Automated mise tool upgrades from local config.
Updated tools:
- `action-validator`
- `actionlint`
- `aube`
- `editorconfig-checker`
- `ghalint`
- `node`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`
Command: `mise upgrade --bump --local action-validator actionlint aube editorconfig-checker ghalint node pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`
<details>
<summary>Version changelog (node)</summary>
| Tool | Requested | Installed |
|------|-----------|-----------|
| `node` | `24` → `26` | `24.18.1` → `26.5.1` |
</details>
<details>
<summary>Release notes (1 tools)</summary>
<details>
<summary>node: `24.18.1` → `26.5.1` (nodejs/node)</summary>
### v25.8.2
This is a security release.
### Notable Changes
* (CVE-2026-21637) wrap `SNICallback` invocation in `try`/`catch` (Matteo Collina) - High
* (CVE-2026-21710) use null prototype for `headersDistinct`/`trailersDistinct` (Matteo Collina) - High
* (CVE-2026-21711) include permission check to `pipe_wrap.cc` (RafaelGSS) - Medium
* (CVE-2026-21712) handle url crash on different url formats (RafaelGSS) - Medium
* (CVE-2026-21713) use timing-safe comparison in Web Cryptography HMAC and KMAC (Filip Skokan) - Medium
* (CVE-2026-21714) handle `NGHTTP2_ERR_FLOW_CONTROL` error code (RafaelGSS) - Medium
* (CVE-2026-21717) test array index hash collision (Joyee Cheung) - Medium
* (CVE-2026-21715) add permission check to `realpath.native` (RafaelGSS) - Low
* (CVE-2026-21716) include permission check on `lib/fs/promises` (RafaelGSS) - Low
### Commits
* \[[`2086b7477b`](nodejs/node@2086b7477b)] - **(CVE-2026-21717)** **build,test**: test array index hash collision (Joyee Cheung) [nodejs-private/node-private#834](https://github.com/nodejs-private/node-private/pull/834)
* \[[`0f9332a40a`](nodejs/node@0f9332a40a)] - **(CVE-2026-21713)** **crypto**: use timing-safe comparison in Web Cryptography HMAC and KMAC (Filip Skokan) [nodejs-private/node-private#822](https://github.com/nodejs-private/node-private/pull/822)
* \[[`2b6937ddb2`](nodejs/node@2b6937ddb2)] - **deps**: update undici to 7.24.4 (Node.js GitHub Bot) [#62271](nodejs/node#62271)
* \[[`bfb8ad5787`](nodejs/node@bfb8ad5787)] - **deps**: update undici to 7.24.3 (Node.js GitHub Bot) [#62233](nodejs/node#62233)
* \[[`be6384727f`](nodejs/node@be6384727f)] - **deps**: upgrade npm to 11.11.1 (npm team) [#62216](nodejs/node#62216)
* \[[`2feea5bb97`](nodejs/node@2feea5bb97)] - **deps**: V8: override… (truncated)
### v25.9.0
### Notable Changes
#### Test runner module mocking improvements
`MockModuleOptions.defaultExport` and `MockModuleOptions.namedExports` have been
consolidated into a single option `MockModuleOptions.exports` to align with user
expectations and other test runners.
A `default` property on `MockModuleOptions.exports` represents the default
export, and own enumerable properties are treated as named exports.
An automated migration is available to update user code:
<https://github.com/nodejs/userland-migrations/tree/main/recipes/mock-module-exports>
```bash
npx codemod @​nodejs/mock-module-exports
```
Contributed by sangwook in [#61727](nodejs/node#61727).
#### Other notable changes
* \[[`312476cb84`](nodejs/node@312476cb84)] - **(SEMVER-MINOR)** **async\_hooks**: add using scopes to `AsyncLocalStorage` (Stephen Belanger) [#61674](nodejs/node#61674)
* \[[`62d2cd473b`](nodejs/node@62d2cd473b)] - **(SEMVER-MINOR)** **cli**: add `--max-heap-size` option (tannal) [#58708](nodejs/node#58708)
* \[[`d0ebf0e44b`](nodejs/node@d0ebf0e44b)] - **(SEMVER-MINOR)** **crypto**: add `TurboSHAKE` and `KangarooTwelve` Web Cryptography algorithms (Filip Skokan) [#62183](nodejs/node#62183)
* \[[`f85b9d9fa8`](nodejs/node@f85b9d9fa8)] - **(SEMVER-MINOR)** **repl**: add customizable error handling (Anna Henningsen) [#62188](nodejs/node#62188)
* \[[`67b854d407`](nodejs/node@67b854d407)] - **(SEMVER-MINOR)** **repl**: remove dependency on `node:domain` (Matteo Collina) [#61227](nodejs/node#61227)
* \[[`966b700623`](nodejs/node@966b700623)] - **(SEMVER-MINOR)** **sea**: support code cache for ESM entrypoint in SEA (Joyee Cheung) [#62158](nodejs/node#62158)
*… (truncated)
### v26.0.0
We're excited to announce the release of Node.js 26! Highlights include the Temporal API enabled by default,
updates to the V8 JavaScript engine to 14.6, Undici to 8.0, and several important deprecations and removals
as we continue to modernize the platform.
As a reminder, Node.js 26 will enter long-term support (LTS) in October, but until then, it will be the "Current" release for the next six months.
We encourage you to explore the new features and benefits offered by this latest release and evaluate their potential impact on your applications.
### Notable Changes
#### Temporal API
The Temporal API is now enabled by default in Node.js 26. Temporal is a modern date/time API for JavaScript
that provides a more robust and feature-rich alternative to the legacy `Date` object.
Contributed by Richard Lau in [#61806](nodejs/node#61806).
#### V8 14.6
The V8 engine is updated to version 14.6.202.33, which is part of Chromium 134.
This version also includes:
* Upsert (<https://github.com/tc39/proposal-upsert>): `[Weak]Map.prototype.getOrInsert()`, `[Weak]Map.prototype.getOrInsertComputed()`
* Iterator sequencing (<https://github.com/tc39/proposal-iterator-sequencing>): `Iterator.concat()`
Contributed by Michaël Zasso in [#61898](nodejs/node#61898).
#### Undici 8
Undici has been updated to version 8.0.2, bringing new features and improvements to Node.js's HTTP client implementation.
#### Deprecations and Removals
* \[[`dff46c07c3`](nodejs/node@dff46c07c3)] - **(SEMVER-MAJOR)** **crypto**: move DEP0182 to End-of-Life (Tobias Nießen) [#61084](nodejs/node#61084)
* \[[`93c25815ee`](nodejs/node@93c25815ee)] - **(SEMVER-MAJOR)** **http**: move writeHeader to end-of-life (Sebastian Beltran) [#60635](nodejs/node#60635)
`http.Server.prototype.writeHeader()` is now fully removed. Use `http.Server.prototype.write… (truncated)
### v26.1.0
### Notable Changes
#### Experimental `node:ffi` module
Node.js now includes an experimental `node:ffi` module for loading dynamic
libraries and calling native symbols from JavaScript.
The API is gated behind the `--experimental-ffi` flag and, when the Permission
Model is enabled, requires `--allow-ffi`.
This API is inherently unsafe. Invalid pointers, incorrect signatures, or accessing memory
after it has been freed can crash the process or corrupt memory.
Contributed by Paolo Insogna in [#62072](nodejs/node#62072).
#### Other Notable Changes
* \[[`34a6454fe3`](nodejs/node@34a6454fe3)] - **(SEMVER-MINOR)** **buffer**: add `end` parameter (Robert Nagy) [#62390](nodejs/node#62390)
* \[[`073e84d7fe`](nodejs/node@073e84d7fe)] - **(SEMVER-MINOR)** **crypto**: accept key data in `crypto.diffieHellman()` and cleanup DH jobs (Filip Skokan) [#62527](nodejs/node#62527)
* \[[`5b9cb10a5f`](nodejs/node@5b9cb10a5f)] - **(SEMVER-MINOR)** **crypto**: implement `randomUUIDv7()` (nabeel378) [#62553](nodejs/node#62553)
* \[[`98f9becd16`](nodejs/node@98f9becd16)] - **(SEMVER-MINOR)** **debugger**: add edit-free runtime expression probes to `node inspect` (Joyee Cheung) [#62713](nodejs/node#62713)
* \[[`06defaa2ea`](nodejs/node@06defaa2ea)] - **(SEMVER-MINOR)** **fs**: add `signal` option to `fs.stat()` (Mert Can Altin) [#57775](nodejs/node#57775)
* \[[`db66a963bf`](nodejs/node@db66a963bf)] - **(SEMVER-MINOR)** **fs**: expose `frsize` field in `statfs` (Jinho Jang) [#62277](nodejs/node#62277)
* \[[`87adb3472b`](nodejs/node@87adb3472b)] - **(SEMVER-MINOR)** **http**: harden `ClientRequest` options merge (Matteo Collina) [#6… (truncated)
### v26.2.0
### Notable Changes
* \[[`189d43a193`](nodejs/node@189d43a193)] - **doc**: mark `stream.compose` stable (Matteo Collina) [#62562](nodejs/node#62562)
* \[[`f858c6140e`](nodejs/node@f858c6140e)] - **(SEMVER-MINOR)** **fs**: add `Temporal.Instant` support to `Stats` and `BigIntStats` (Livia Medeiros) [#60789](nodejs/node#60789)
* \[[`0cbb3895df`](nodejs/node@0cbb3895df)] - **(SEMVER-MINOR)** **http**: add `writeInformation` to send arbitrary 1xx status codes (Tim Perry) [#63155](nodejs/node#63155)
### Commits
* \[[`9a394bab84`](nodejs/node@9a394bab84)] - **benchmark**: respect stream/iter broadcast backpressure (Trivikram Kamat) [#63314](nodejs/node#63314)
* \[[`ad98b4620b`](nodejs/node@ad98b4620b)] - **crypto**: align verifyOneShot accepted types (Anshika Jain) [#63280](nodejs/node#63280)
* \[[`ba0736a847`](nodejs/node@ba0736a847)] - **crypto**: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255)
* \[[`5573a6a4a8`](nodejs/node@5573a6a4a8)] - **crypto**: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255)
* \[[`7dc563b8d6`](nodejs/node@7dc563b8d6)] - **crypto**: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255)
* \[[`b55e2b1f4d`](nodejs/node@b55e2b1f4d)] - **crypto**: improve system certificate enumeration logic on macOS (Robo) [#62576](nodejs/node#62576)
* \[[`fd509a755a`](nodejs/node@fd509a755a)] - **crypto**: harden CryptoKey algorithm slots… (truncated)
### v26.3.0
### Notable Changes
#### Potential changes to macOS Universal Binary availability
With Apple and its ecosystem progressively dropping support for Intel-based
architectures, it has become apparent that the Node.js project may not be able
to maintain the universal binaries we currently distribute for the full lifetime
of Node.js 26. This change serves to communicate that risk. At present, our
intention remains to continue shipping universal binaries supporting both Apple
Silicon and Intel-based Macs for as long as practical.
Contributed by Antoine du Hamel in [#63055](nodejs/node#63055).
#### Other notable changes
* \[[`a2a4b33dd8`](nodejs/node@a2a4b33dd8)] - **(SEMVER-MINOR)** **buffer**: increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) [#63597](nodejs/node#63597)
* \[[`051a2152f7`](nodejs/node@051a2152f7)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#63527](nodejs/node#63527)
* \[[`49462eca37`](nodejs/node@49462eca37)] - **(SEMVER-MINOR)** **http**: add `httpValidation` option to configure header value validation (RajeshKumar11) [#61597](nodejs/node#61597)
* \[[`97b7ab19bd`](nodejs/node@97b7ab19bd)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#63079](nodejs/node#63079)
* \[[`cfb80a2103`](nodejs/node@cfb80a2103)] - **(SEMVER-MINOR)** **lib,permission**: add `permission.drop` (Rafael Gonzaga) [#62672](nodejs/node#62672)
### Commits
* \[[`a2a4b33dd8`](nodejs/node@a2a4b33dd8)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#63597](nodejs/node#63597)
* \[[`0eff3e23b9`](https://github.com/nodejs/n… (truncated)
### v26.3.1
This is a security release.
### Notable Changes
* (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High
* (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High
* (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium
* (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium
* (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium
* (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium
* (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium
* (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low
* (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low
* (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low
* (CVE-2026-48936) permission: guard pipe open and chmod with net scope (RafaelGSS) – Low
### Commits
* \[[`98fbc89211`](nodejs/node@98fbc89211)] - **(CVE-2026-48933)** **crypto**: guard WebCrypto cipher output length (Filip Skokan) [nodejs-private/node-private#878](https://github.com/nodejs-private/node-private/pull/878)
* \[[`110840f2c7`](nodejs/node@110840f2c7)] - **deps**: update llhttp to 9.4.2 (Antoine du Hamel) [nodejs-private/node-private#890](https://github.com/nodejs-private/node-private/pull/890)
* \[[`8d36d522b2`](nodejs/node@8d36d522b2)] - **deps**: update undici to 8.5.0 (Node.js GitHub Bot) [#63903](nodejs/node#63903)
* \[[`2e6d03993a`](nodejs/node@2e6d03993a)] - **deps**: update undici to 8.4.0 (Node.js GitHub Bot) [#63779](nodejs/node#63779)
* \[[`5a17d5b07a`](nodejs/node@5a17d5b07a)] - **deps… (truncated)
### v26.4.0
### Notable Changes
* \[[`cde0daabcc`](nodejs/node@cde0daabcc)] - **(SEMVER-MINOR)** **doc**: update `blockList` stability status to release candidate (alphaleadership) [#63050](nodejs/node#63050)
* \[[`b78f5a7537`](nodejs/node@b78f5a7537)] - **(SEMVER-MINOR)** **fs**: support caller-supplied `readFile()` buffers (Matteo Collina) [#63634](nodejs/node#63634)
* \[[`417aacbc36`](nodejs/node@417aacbc36)] - **(SEMVER-MINOR)** **http**: close pre-request sockets in `closeIdleConnections` (semimikoh) [#63470](nodejs/node#63470)
* \[[`fbb108be7d`](nodejs/node@fbb108be7d)] - **(SEMVER-MINOR)** **loader**: implement package maps (Maël Nison) [#62239](nodejs/node#62239)
* \[[`45494d5a8a`](nodejs/node@45494d5a8a)] - **(SEMVER-MINOR)** **net**: support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` (Guy Bedford) [#63825](nodejs/node#63825)
* \[[`ee29465e77`](nodejs/node@ee29465e77)] - **(SEMVER-MINOR)** **tls**: add certificateCompression option (Tim Perry) [#62217](nodejs/node#62217)
* \[[`b17817eb2b`](nodejs/node@b17817eb2b)] - **(SEMVER-MINOR)** **vfs**: dispatch `node:fs/promises` to mounted VFS instances (Matteo Collina) [#63537](nodejs/node#63537)
* \[[`7bc93a6ac5`](nodejs/node@7bc93a6ac5)] - **(SEMVER-MINOR)** **vfs**: add minimal `node:vfs` subsystem (Matteo Collina) [#63115](nodejs/node#63115)
### Commits
* \[[`c7eb83b46a`](nodejs/node@c7eb83b46a)] - **benchmark**: add child\_process async path baselines (Yagiz Nizipli) [#63929](nodejs/node#63929)
* \[[`066fff17a5`](https://github.com/nodejs/node/commit/066f… (truncated)
### v26.5.0
### Notable Changes
#### New release key
Welcome to our newest releaser, [Stewart X Addison](https://github.com/sxa). Future Node.js releases may be signed with his [release key](https://github.com/nodejs/node/blob/main/README.md#release-keys), `655F3B5C1FB3FA8D1A0CA6BDE4A7D232B936D2FD`.
#### Other notable changes
* \[[`55f48446c7`](nodejs/node@55f48446c7)] - **(SEMVER-MINOR)** **buffer**: implement blob.textStream() (Matthew Aitken) [#64036](nodejs/node#64036)
* \[[`b373202efc`](nodejs/node@b373202efc)] - **(SEMVER-MINOR)** **esm**: add `--experimental-import-text` flag (Efe) [#62300](nodejs/node#62300)
* \[[`39e0c14455`](nodejs/node@39e0c14455)] - **(SEMVER-MINOR)** **perf\_hooks**: sample delay per event loop iteration (Pablo Erhard) [#62935](nodejs/node#62935)
* \[[`999a83c937`](nodejs/node@999a83c937)] - **(SEMVER-MINOR)** **stream**: expose ReadableStreamTee (Matteo Collina) [#64195](nodejs/node#64195)
* \[[`4e0236dc3d`](nodejs/node@4e0236dc3d)] - **(SEMVER-MINOR)** **tls**: report negotiated TLS groups (Filip Skokan) [#64119](nodejs/node#64119)
### Commits
* \[[`87648c0a6c`](nodejs/node@87648c0a6c)] - **benchmark**: trim down the argon2 sets (Filip Skokan) [#64218](nodejs/node#64218)
* \[[`a483bfd3f0`](nodejs/node@a483bfd3f0)] - **buffer**: remove unreachable overflow check in atob (haramjeong) [#60161](nodejs/node#60161)
* \[[`6d14279688`](nodejs/node@6d14279688)] - **buffer**: add fast api for isUtf8 and isAscii (Gürgün Dayıoğlu) [#64169](nodejs/node#64169)
* \[[`55f48446c7`](nodejs/node@55f48446c7)] -… (truncated)
### v26.5.1
This is a security release.
### Notable Changes
* (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
* (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
* (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
* (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
* (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium
* (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
* (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
* (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
* (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
* (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
* deps: update llhttp to 9.4.3 (Paolo Insogna)
* deps: update undici to 8.9.0 (Node.js GitHub Bot)
### Commits
* \[[`af0bf96877`](nodejs/node@af0bf96877)] - **deps**: update llhttp to 9.4.3 (Paolo Insogna) [nodejs-private/node-private#935](https://github.com/nodejs-private/node-private/pull/935)
* \[[`0354678355`](nodejs/node@0354678355)] - **deps**: update undici to 8.9.0 (Node.js GitHub Bot) [#64712](nodejs/node#64712)
* \[[`dbeeaeec13`](nodejs/node@dbeeaeec13)] - **(CVE-2026-58042)** **dns**: handle large resolveAny address replies (RafaelGSS) [nodejs-private/node-private#929](https://github.com/nodejs-private/node-private/pull/929)
* \[[`064d339f56`](nodejs/node@064d339f56)] - **(CVE-2026-58044)** **http**: reject requests exceeding max header count (Matteo Collina) [nodejs-private/node-private#922](https://github.com/nodejs-private/node-private/pull/922)
* \[[`23b94c843a`](https://github.… (truncated)
_Omitted 12 older releases._
</details>
</details>
Modified files:
- `.mise.toml`
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

commit-queue-squashAdd this label to instruct the Commit Queue to squash all the PR commits into the first one.fsIssues and PRs related to the fs subsystem / file system.needs-ciPRs that need a full CI run.semver-minorPRs that contain new features and should be released in the next minor version.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fs: caller-supplied buffer for fs.readFile / fs.readFileSync

7 participants

@mcollina@nodejs-github-bot@ShogunPanda@jasnell@MattiasBuelens@Renegade334@LiviaMedeiros