Sign in

Rafael Gonzaga | Node.js

@rafaelgss.dev
793 followers 57 following 100 posts

Node.js Technical Steering Committee member

PostsRepliesMedia
Reposted by Rafael Gonzaga | Node.js
Nico Kaiser @nico.kaiser.me · 11h
📸 #NodeConfEU @rafaelgss.dev & @aduh95.bsky.social: The New Node.js Release Model: Why Node 27 Changes Everything
0134
Rafael Gonzaga | Node.js @rafaelgss.dev · 29/09/2026
Hi!
252
Rafael Gonzaga | Node.js @rafaelgss.dev · 05/05/2026
Node.js v26.0.0 is out 💚 Temporal API enabled by default, V8 14.6, Undici 8, and key deprecations as we keep modernizing the platform. Check it out nodejs.org/en/blog/rele...
nodejs.org
Node.js — Node.js 26.0.0 (Current)
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
112735
Rafael Gonzaga | Node.js @rafaelgss.dev · 02/04/2026
Unfortunately, security reports are no longer eligible for bounties due to the IBB program being paused
052
Rafael Gonzaga | Node.js @rafaelgss.dev · 19/02/2026
We have made our HackerOne policies even more strict. Now, if you don't have any Signal, you shouldn't be able to report through HackerOne. We advise you to contact any of the Security Release Stewards via OpenJS Slack. nodejs.org/en/blog/anno...
nodejs.org
Node.js — New HackerOne Signal Requirement for Vulnerability Reports
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
081
Rafael Gonzaga | Node.js @rafaelgss.dev · 30/01/2026
My first talk of 2026 can now be shared! I will join NodeCongress to present The State of Node.js Security nodecongress.com#person-rafae...
nodecongress.com
Node Congress
Want to master Fullstack: JS Backend, DevOps, Architecture? Join Node Congress on March 26-27, Online! Learn from industry professionals and community members, exchange ideas, interact, and collaborat...
040
Rafael Gonzaga | Node.js @rafaelgss.dev · 29/01/2026
🚨 Node.js assessment of the recent OpenSSL Security Release TL;DR: We'll update OpenSSL versions through a regular release process. nodejs.org/en/blog/vuln...
nodejs.org
Node.js — OpenSSL Security Advisory Assessment, January 2026
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
062
Rafael Gonzaga | Node.js @rafaelgss.dev · 22/01/2026
We have increased the barrier to submit reports through HackerOne due to the amount of low-quality submissions we have received recently. Please, see: nodejs.org/en/blog/anno...
nodejs.org
Node.js — New HackerOne Signal Requirement for Vulnerability Reports
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
071
Reposted by Rafael Gonzaga | Node.js
Joyee Cheung @joyeecheung.bsky.social · 19/01/2026
This release contains a bunch of PRs I recently submitted to mark features I contributed to as stable/release candidate. Here is a thread about them 🧵:
2548
Rafael Gonzaga | Node.js @rafaelgss.dev · 19/01/2026
Node.js v25.4.0 is out! 💚 • require(esm) now stable and a new CLI flag: --require-module • http setGlobalProxyFromEnv() added • Multiple APIs promoted to stable (heapsnapshot, build snapshot, v8.queryObjects) • Root CAs updated to NSS 3.117 More in: nodejs.org/en/blog/rele...
nodejs.org
1387
Rafael Gonzaga | Node.js @rafaelgss.dev · 08/01/2026
🚨Our team has decided to postpone the release to Tuesday, January 13th, 2026. This additional time will allow us to properly test all backports and re-run CITGM to ensure the highest quality for our users.
nodejs.org
Node.js — Thursday, January 8, 2026 Security Releases
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
1185
Rafael Gonzaga | Node.js @rafaelgss.dev · 08/01/2026
Node.s sec release We are doing our best. We are ensuring test passes on all platforms and all active release lines (v20, v22, v24 and v25) - and they aren't currently. Unfortunately, we don't have an ETA for that, and it's likely that this security release will be postponed one more time. Sorry.
084
Reposted by Rafael Gonzaga | Node.js
OpenJS Foundation @openjsf.org · 05/01/2026
Oh hi. 👋 We're back with the latest Security Snapshot that covers how to publish to npm safely and with ease. ✨ @rafaelgss.dev breaks down why local publishing with 2FA gives you the safest setup right now.
085
Rafael Gonzaga | Node.js @rafaelgss.dev · 17/12/2025
New release of bench-node v0.14.0! Two important features were released: github.com/RafaelGSS/be...
github.com
Release v0.14.0 · RafaelGSS/bench-node
0.14.0 (2025-12-17) Features add dce detection plugin (#131) (2e2a6be) add t-test mode for statistical significance testing (#133) (53e20aa) Narrow the bar display by another couple of characters ...
120
Rafael Gonzaga | Node.js @rafaelgss.dev · 15/12/2025
Right on time! Lovely @openjsf.org
180
Reposted by Rafael Gonzaga | Node.js
OpenJS Foundation @openjsf.org · 25/11/2025
Want to dive in further? Check out Rafael’s release of @nodejs.org 25: twitch.tv/videos/25925...
twitch.tv
Releasing Node.js v25.0.0! - rafaelgss on Twitch
rafaelgss went live on Twitch. Catch up on their Software and Game Development VOD now.
042
Reposted by Rafael Gonzaga | Node.js
OpenJS Foundation @openjsf.org · 25/11/2025
SEMVER MAJORS ARE BORING 🚨 Major releases mostly bring breaking changes, not shiny new features. The fun stuff? That’s hiding in the minors. @rafaelgss.dev talks about why you should follow the minor releases in our latest JavaScript Security Snapshot.
1112
Rafael Gonzaga | Node.js @rafaelgss.dev · 22/11/2025
I should get back to this platform. I’ve scrolled it for like 5 minutes and I found many interesting topics that I don’t see in one week of X.
4240
Reposted by Rafael Gonzaga | Node.js
James Snell @jasnell.me · 20/11/2025
ok so... I'm writing a book. It's called JavaScript In Depth (www.manning.com/books/javasc...) ... the first four chapters are available by Manning. This has been a difficult project and will continue to be so. The reason is that it isn't a How To book that focuses only on how to use the langauge
manning.com
JavaScript in Depth - James M. Snell
Explore the inner workings of the world’s most popular programming language and enjoy the power and control that comes only from deep knowledge! In JavaScript in Depth, JavaScript and Node legend Jame...
3305
Reposted by Rafael Gonzaga | Node.js
OpenJS Foundation @openjsf.org · 20/11/2025
Before automated workflows, releasing @nodejs.org meant 20 manual steps. Now it’s one command. 👀 @ulisesgascon.com and @rafaelgss.dev share how the Node.js build team went from a rack of Raspberry Pis in someone’s garage to full release automation. 👉Build Team on GitHub: github.com/nodejs/build
0186
Rafael Gonzaga | Node.js @rafaelgss.dev · 14/11/2025
Live now!
010
Reposted by Rafael Gonzaga | Node.js
Wes @notwes.bsky.social · 14/11/2025
It was great working with you on this! As much as I dislike that we had to do this work, I think it is important that we did it so there is a thorough and accurate resource about the current state of things.
021
Reposted by Rafael Gonzaga | Node.js
OpenJS Foundation @openjsf.org · 14/11/2025
With npm supply chain attacks on the rise, secure publishing practices are becoming a pressing concern for anyone maintaining npm packages. ⚠️ We've released updated guidance to help maintainers reduce exposure, strengthen release processes, and protect the ecosystem: openjsf.org/blog/publish...
openjsf.org
Publishing More Securely on npm: Guidance from the OpenJS Security Collaboration Space | OpenJS Foundation
The OpenJS Security Collaboration Space has been working closely with GitHub’s npm team to understand how new security features affect projects and maintainers, especially as threats and tools keep ev...
12912
Rafael Gonzaga | Node.js @rafaelgss.dev · 14/11/2025
Thanks for your hard work on this @notwes.bsky.social
140
Reposted by Rafael Gonzaga | Node.js
OpenJS Foundation @openjsf.org · 13/11/2025
Too many @nodejs.org users are running old versions 😬 The team is exploring changes to the release schedule to fix that. @rafaelgss.dev shares all the details in our latest JavaScript Security Snapshot. Be a part of the conversation on releases: github.com/nodejs/lts-s...
0165
Reposted by Rafael Gonzaga | Node.js
OpenJS Foundation @openjsf.org · 11/11/2025
Ever wonder why @nodejs.org drops new versions like clockwork? Here’s the scoop. ⏱️ @rafaelgss.dev shares all the details about the Node.js release schedule in our new series, JavaScript Security Snapshot.
2256
Rafael Gonzaga | Node.js @rafaelgss.dev · 30/10/2025
Done
051
Reposted by Rafael Gonzaga | Node.js
Jordan Harband @jordan.har.band · 17/10/2025
i’m starting to get that “this word is weird now” feeling from hearing so many sentences like “releasers releasing releases” at the @nodejs.org collab summit
071
Reposted by Rafael Gonzaga | Node.js
Ruy Adorno @ruyadorno.com · 17/10/2025
Starting the day at the Node.js Collab Summit #nodejs #javascript
picture of a group exercise collab summit sign in the hallway
1202
Reposted by Rafael Gonzaga | Node.js
OpenJS Foundation @openjsf.org · 16/10/2025
Introducing 🥁🥁🥁 our JavaScriptLandia award recipients for this year! Beyond building new features, our recipients guide others, maintain essential systems, document the hard parts, and strengthen the community every step of the way. 💙 Read more about our honorees here: hubs.la/Q03NQvx10
0176
Reposted by Rafael Gonzaga | Node.js
naugtur @naugtur.pl · 15/10/2025
I'm excited about net in permissions!
0134
Rafael Gonzaga | Node.js @rafaelgss.dev · 15/10/2025
Node.js 25 is here! We have upgraded V8 to 14.1, bringing major JSON.stringify performance improvements and JIT pipeline optimizations. This release introduces the permission model --allow-net, Web Storage is enabled by default, and more! nodejs.org/en/blog/rele...
nodejs.org
Node.js
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
09523
Reposted by Rafael Gonzaga | Node.js
Node.js @nodejs.org · 13/10/2025
Node.js v24.10.0 is out. * Per-stream inspectOptions support in console * Removal of util.getCallSite (in favour of util.getCallSites) * Upgraded OpenSSL to 3.5.4 and npm to 11.6.1 * Various src and benchmark optimizations nodejs.org/en/blog/release/v24.10.0
nodejs.org
Node.js
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
0417
Reposted by Rafael Gonzaga | Node.js
Ulises Gascón @ulisesgascon.com · 22/09/2025
Welcome @rafaelgss.dev to the @openjsf.org #CNA team! 👏 👏 👏 github.com/openjs-found...
github.com
Nominate @rafaelgss as CNA Coordinator by UlisesGascon · Pull Request #297 · openjs-foundation/security-collab-space
@RafaelGSS has made outstanding contributions to the open source security ecosystem, particularly through his leadership in the Node.js project and related tooling. He brings deep expertise in vuln...
153
Reposted by Rafael Gonzaga | Node.js
Wes @notwes.bsky.social · 17/09/2025
Lots of GREAT progress and discussion on our @expressjs.bsky.social Performance Working Group. Thanks everyone who is participating as I think this is the second most (security comes first) impactful thing we could be working on. For anyone interested in helping out: github.com/expressjs/pe...
github.com
GitHub - expressjs/perf-wg: Performance Working Group
Performance Working Group. Contribute to expressjs/perf-wg development by creating an account on GitHub.
0112
Reposted by Rafael Gonzaga | Node.js
jonchurch @jonchurch.com · 17/09/2025
Our goal is to provide guidance and tooling for perf based decisions to the maintainers under our umbrella. Aligning our philosophy for how/what we monitor and how to interpret the results lets us be consistent across our 50+ packages. Ive been learning a lot so far, and big ty to @rafaelgss.dev
022
Rafael Gonzaga | Node.js @rafaelgss.dev · 15/08/2025
Node.js v24.6.0 is out💚 Highlights: * Use your system’s trusted certificates with NODE_USE_SYSTEM_CA=1 * crypto: ML-DSA (KeyObject/sign/verify) * http: server.keepAliveTimeoutBuffer * zlib: Zstd dictionary support * fs: Utf8Stream (from SonicBoom) Changelog: nodejs.org/en/blog/rele...
nodejs.org
Node.js — Node.js v24.6.0 (Current)
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
1255
Rafael Gonzaga | Node.js @rafaelgss.dev · 25/07/2025
I'm live doing Node.js Core benchmark work! www.twitch.tv/rafaelgss
twitch.tv
RafaelGSS - Twitch
Node.js Core Mentoring
040
Rafael Gonzaga | Node.js @rafaelgss.dev · 23/07/2025
I've been working on something interesting (at least for me) github.com/nodejs/node/...
github.com
benchmark: add calibrate-n script by RafaelGSS · Pull Request #59186 · nodejs/node
benchmark: add calibrate-n script This script should help identify the best N when creating/updating benchmarks It's not new that our benchmark suite takes a huge amount to conclude. I have e...
020
Rafael Gonzaga | Node.js @rafaelgss.dev · 18/07/2025
Hi folks, We will have a Node.js core mentoring live stream today Stay tuned!
031
Rafael Gonzaga | Node.js @rafaelgss.dev · 09/07/2025
Node.js v24.4.0 is out! 💚 What's new? • crypto.hash() supports outputLength (XOF) • fs.mkdtempSync() gets disposable mode • --watch-kill-signal lands • permission.has('addon') is now supported • spawn() propagates permission flags • sqlite adds readBigInts More in: nodejs.org/en/blog/rele...
nodejs.org
0237
Rafael Gonzaga | Node.js @rafaelgss.dev · 30/05/2025
Live on! twitch.tv/rafaelgss
000
Rafael Gonzaga | Node.js @rafaelgss.dev · 28/05/2025
A warm welcome to our newest Node.js TSC member: Filip Skokan! Happy to see you onboard! github.com/nodejs/node/...
github.com
doc: add Filip Skokan to TSC by RafaelGSS · Pull Request #58499 · nodejs/node
Refs: nodejs/TSC#1740 cc: @panva
085
Reposted by Rafael Gonzaga | Node.js
Maksim Sinik @maksim.dev · 16/05/2025
Folks, right now @rafaelgss.dev is doing an awesome livestram on m.twitch.tv/rafaelgss talking about Node.js threads, memory management and perfs. Join us!
m.twitch.tv
RafaelGSS - Twitch
Node.js Core Mentoring
151
Reposted by Rafael Gonzaga | Node.js
Node.js @nodejs.org · 08/05/2025
⚠️ Security release pre-alert: We will release new versions of v20.x, v22.x, v23.x, v24.x release lines on or shortly after May 14, 2025, in order to address: - 1 high severity issue - 1 moderate severity issue - 1 low severity issue Details: nodejs.org/en/blog/vuln...
nodejs.org
Node.js — Wednesday, May 14, 2025 Security Releases
Node.js® is a JavaScript runtime built on Chrome's V8 JavaScript engine.
03310
Rafael Gonzaga | Node.js @rafaelgss.dev · 06/05/2025
I’d love to do something like that but in person… kind of collab summit workshop
120
Rafael Gonzaga | Node.js @rafaelgss.dev · 06/05/2025
Happy to announce @nodejs v24.0.0 💚! This release brings several updates, including the V8 13.6 and npm to version 11. As a reminder, Node.js 24 will enter long-term support (LTS) in October, but until then, it will be the "Current" release Check it nodejs.org/en/blog/rele...
nodejs.org
29421
Rafael Gonzaga | Node.js @rafaelgss.dev · 05/05/2025
A handy way to test Node.js release candidates. I suggest you have something similar in your test suite, so you can act before a semver-major release of Node.js gets out. github.com/fastify/fast...
github.com
ci: add support to test release candidates by RafaelGSS · Pull Request #6103 · fastify/fastify
This is just an idea, but I think it would be interesting to be able to test Node.js release candidates, specially for semver-major versions
020
Rafael Gonzaga | Node.js @rafaelgss.dev · 01/04/2025
RC.2 Node.js v24.0.0 github.com/nodejs/node/...
github.com
2025-04-23, Version 24.0.0 (Current) by RafaelGSS · Pull Request #57609 · nodejs/node
Cut-off date: 2025-03-24 Target release date: 2025-04-23 Roadmap: nodejs/Release#1081 TODO: V8 Update [help wanted] deps: update V8 to 13.4 #57114 Update REPLACEME Update notable changes 2025...
051
Rafael Gonzaga | Node.js @rafaelgss.dev · 07/03/2025
Recent updates on Node.js CVE to EOL lines. TL;DR The Node.js team has decided to update previous vulnerability specific CVEs to cover EOL releases, reflecting their ongoing security risks. See: nodejs.org/en/blog/vuln...
nodejs.org
Node.js — Updates on CVE for End-of-Life Versions
Node.js® is a JavaScript runtime built on Chrome's V8 JavaScript engine.
0225