Reposted by Rafael Gonzaga | Node.jsNico Kaiser @nico.kaiser.me · 11h📸 #NodeConfEU @rafaelgss.dev & @aduh95.bsky.social: The New Node.js Release Model: Why Node 27 Changes Everything 0134
Rafael Gonzaga | Node.js @rafaelgss.dev · 05/05/2026Node.js v26.0.0 is out 💚 Temporal API enabled by default, V8 14.6, Undici 8, and key deprecations as we keep modernizing the platform. Check it out nodejs.org/en/blog/rele...nodejs.orgNode.js — Node.js 26.0.0 (Current)Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts. 112735
Rafael Gonzaga | Node.js @rafaelgss.dev · 02/04/2026Unfortunately, security reports are no longer eligible for bounties due to the IBB program being paused 052
Rafael Gonzaga | Node.js @rafaelgss.dev · 19/02/2026We have made our HackerOne policies even more strict. Now, if you don't have any Signal, you shouldn't be able to report through HackerOne. We advise you to contact any of the Security Release Stewards via OpenJS Slack. nodejs.org/en/blog/anno...nodejs.orgNode.js — New HackerOne Signal Requirement for Vulnerability ReportsNode.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts. 081
Rafael Gonzaga | Node.js @rafaelgss.dev · 30/01/2026My first talk of 2026 can now be shared! I will join NodeCongress to present The State of Node.js Security nodecongress.com#person-rafae...nodecongress.comNode CongressWant to master Fullstack: JS Backend, DevOps, Architecture? Join Node Congress on March 26-27, Online! Learn from industry professionals and community members, exchange ideas, interact, and collaborat... 040
Rafael Gonzaga | Node.js @rafaelgss.dev · 29/01/2026🚨 Node.js assessment of the recent OpenSSL Security Release TL;DR: We'll update OpenSSL versions through a regular release process. nodejs.org/en/blog/vuln...nodejs.orgNode.js — OpenSSL Security Advisory Assessment, January 2026Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts. 062
Rafael Gonzaga | Node.js @rafaelgss.dev · 22/01/2026We have increased the barrier to submit reports through HackerOne due to the amount of low-quality submissions we have received recently. Please, see: nodejs.org/en/blog/anno...nodejs.orgNode.js — New HackerOne Signal Requirement for Vulnerability ReportsNode.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts. 071
Reposted by Rafael Gonzaga | Node.jsJoyee Cheung @joyeecheung.bsky.social · 19/01/2026This release contains a bunch of PRs I recently submitted to mark features I contributed to as stable/release candidate. Here is a thread about them 🧵: 2548
Rafael Gonzaga | Node.js @rafaelgss.dev · 19/01/2026Node.js v25.4.0 is out! 💚 • require(esm) now stable and a new CLI flag: --require-module • http setGlobalProxyFromEnv() added • Multiple APIs promoted to stable (heapsnapshot, build snapshot, v8.queryObjects) • Root CAs updated to NSS 3.117 More in: nodejs.org/en/blog/rele...nodejs.org 1387
Rafael Gonzaga | Node.js @rafaelgss.dev · 08/01/2026🚨Our team has decided to postpone the release to Tuesday, January 13th, 2026. This additional time will allow us to properly test all backports and re-run CITGM to ensure the highest quality for our users.nodejs.orgNode.js — Thursday, January 8, 2026 Security ReleasesNode.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts. 1185
Rafael Gonzaga | Node.js @rafaelgss.dev · 08/01/2026Node.s sec release We are doing our best. We are ensuring test passes on all platforms and all active release lines (v20, v22, v24 and v25) - and they aren't currently. Unfortunately, we don't have an ETA for that, and it's likely that this security release will be postponed one more time. Sorry. 084
Reposted by Rafael Gonzaga | Node.jsOpenJS Foundation @openjsf.org · 05/01/2026Oh hi. 👋 We're back with the latest Security Snapshot that covers how to publish to npm safely and with ease. ✨ @rafaelgss.dev breaks down why local publishing with 2FA gives you the safest setup right now. 085
Rafael Gonzaga | Node.js @rafaelgss.dev · 17/12/2025New release of bench-node v0.14.0! Two important features were released: github.com/RafaelGSS/be...github.comRelease v0.14.0 · RafaelGSS/bench-node0.14.0 (2025-12-17) Features add dce detection plugin (#131) (2e2a6be) add t-test mode for statistical significance testing (#133) (53e20aa) Narrow the bar display by another couple of characters ... 120
Reposted by Rafael Gonzaga | Node.jsOpenJS Foundation @openjsf.org · 25/11/2025Want to dive in further? Check out Rafael’s release of @nodejs.org 25: twitch.tv/videos/25925...twitch.tvReleasing Node.js v25.0.0! - rafaelgss on Twitchrafaelgss went live on Twitch. Catch up on their Software and Game Development VOD now. 042
Reposted by Rafael Gonzaga | Node.jsOpenJS Foundation @openjsf.org · 25/11/2025SEMVER MAJORS ARE BORING 🚨 Major releases mostly bring breaking changes, not shiny new features. The fun stuff? That’s hiding in the minors. @rafaelgss.dev talks about why you should follow the minor releases in our latest JavaScript Security Snapshot. 1112
Rafael Gonzaga | Node.js @rafaelgss.dev · 22/11/2025I should get back to this platform. I’ve scrolled it for like 5 minutes and I found many interesting topics that I don’t see in one week of X. 4240
Reposted by Rafael Gonzaga | Node.jsJames Snell @jasnell.me · 20/11/2025ok so... I'm writing a book. It's called JavaScript In Depth (www.manning.com/books/javasc...) ... the first four chapters are available by Manning. This has been a difficult project and will continue to be so. The reason is that it isn't a How To book that focuses only on how to use the langaugemanning.comJavaScript in Depth - James M. SnellExplore the inner workings of the world’s most popular programming language and enjoy the power and control that comes only from deep knowledge! In JavaScript in Depth, JavaScript and Node legend Jame... 3305
Reposted by Rafael Gonzaga | Node.jsOpenJS Foundation @openjsf.org · 20/11/2025Before automated workflows, releasing @nodejs.org meant 20 manual steps. Now it’s one command. 👀 @ulisesgascon.com and @rafaelgss.dev share how the Node.js build team went from a rack of Raspberry Pis in someone’s garage to full release automation. 👉Build Team on GitHub: github.com/nodejs/build 0186
Reposted by Rafael Gonzaga | Node.jsWes @notwes.bsky.social · 14/11/2025It was great working with you on this! As much as I dislike that we had to do this work, I think it is important that we did it so there is a thorough and accurate resource about the current state of things. 021
Reposted by Rafael Gonzaga | Node.jsOpenJS Foundation @openjsf.org · 14/11/2025With npm supply chain attacks on the rise, secure publishing practices are becoming a pressing concern for anyone maintaining npm packages. ⚠️ We've released updated guidance to help maintainers reduce exposure, strengthen release processes, and protect the ecosystem: openjsf.org/blog/publish...openjsf.orgPublishing More Securely on npm: Guidance from the OpenJS Security Collaboration Space | OpenJS FoundationThe OpenJS Security Collaboration Space has been working closely with GitHub’s npm team to understand how new security features affect projects and maintainers, especially as threats and tools keep ev... 12912
Rafael Gonzaga | Node.js @rafaelgss.dev · 14/11/2025Thanks for your hard work on this @notwes.bsky.social 140
Reposted by Rafael Gonzaga | Node.jsOpenJS Foundation @openjsf.org · 13/11/2025Too many @nodejs.org users are running old versions 😬 The team is exploring changes to the release schedule to fix that. @rafaelgss.dev shares all the details in our latest JavaScript Security Snapshot. Be a part of the conversation on releases: github.com/nodejs/lts-s... 0165
Reposted by Rafael Gonzaga | Node.jsOpenJS Foundation @openjsf.org · 11/11/2025Ever wonder why @nodejs.org drops new versions like clockwork? Here’s the scoop. ⏱️ @rafaelgss.dev shares all the details about the Node.js release schedule in our new series, JavaScript Security Snapshot. 2256
Reposted by Rafael Gonzaga | Node.jsJordan Harband @jordan.har.band · 17/10/2025i’m starting to get that “this word is weird now” feeling from hearing so many sentences like “releasers releasing releases” at the @nodejs.org collab summit 071
Reposted by Rafael Gonzaga | Node.jsRuy Adorno @ruyadorno.com · 17/10/2025Starting the day at the Node.js Collab Summit #nodejs #javascript 1202
Reposted by Rafael Gonzaga | Node.jsOpenJS Foundation @openjsf.org · 16/10/2025Introducing 🥁🥁🥁 our JavaScriptLandia award recipients for this year! Beyond building new features, our recipients guide others, maintain essential systems, document the hard parts, and strengthen the community every step of the way. 💙 Read more about our honorees here: hubs.la/Q03NQvx10 0176
Reposted by Rafael Gonzaga | Node.jsnaugtur @naugtur.pl · 15/10/2025I'm excited about net in permissions! 0134
Rafael Gonzaga | Node.js @rafaelgss.dev · 15/10/2025Node.js 25 is here! We have upgraded V8 to 14.1, bringing major JSON.stringify performance improvements and JIT pipeline optimizations. This release introduces the permission model --allow-net, Web Storage is enabled by default, and more! nodejs.org/en/blog/rele...nodejs.orgNode.jsNode.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts. 09523
Reposted by Rafael Gonzaga | Node.jsNode.js @nodejs.org · 13/10/2025Node.js v24.10.0 is out. * Per-stream inspectOptions support in console * Removal of util.getCallSite (in favour of util.getCallSites) * Upgraded OpenSSL to 3.5.4 and npm to 11.6.1 * Various src and benchmark optimizations nodejs.org/en/blog/release/v24.10.0 nodejs.orgNode.jsNode.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts. 0417
Reposted by Rafael Gonzaga | Node.jsUlises Gascón @ulisesgascon.com · 22/09/2025Welcome @rafaelgss.dev to the @openjsf.org #CNA team! 👏 👏 👏 github.com/openjs-found...github.comNominate @rafaelgss as CNA Coordinator by UlisesGascon · Pull Request #297 · openjs-foundation/security-collab-space@RafaelGSS has made outstanding contributions to the open source security ecosystem, particularly through his leadership in the Node.js project and related tooling. He brings deep expertise in vuln... 153
Reposted by Rafael Gonzaga | Node.jsWes @notwes.bsky.social · 17/09/2025Lots of GREAT progress and discussion on our @expressjs.bsky.social Performance Working Group. Thanks everyone who is participating as I think this is the second most (security comes first) impactful thing we could be working on. For anyone interested in helping out: github.com/expressjs/pe...github.comGitHub - expressjs/perf-wg: Performance Working GroupPerformance Working Group. Contribute to expressjs/perf-wg development by creating an account on GitHub. 0112
Reposted by Rafael Gonzaga | Node.jsjonchurch @jonchurch.com · 17/09/2025Our goal is to provide guidance and tooling for perf based decisions to the maintainers under our umbrella. Aligning our philosophy for how/what we monitor and how to interpret the results lets us be consistent across our 50+ packages. Ive been learning a lot so far, and big ty to @rafaelgss.dev 022
Rafael Gonzaga | Node.js @rafaelgss.dev · 15/08/2025Node.js v24.6.0 is out💚 Highlights: * Use your system’s trusted certificates with NODE_USE_SYSTEM_CA=1 * crypto: ML-DSA (KeyObject/sign/verify) * http: server.keepAliveTimeoutBuffer * zlib: Zstd dictionary support * fs: Utf8Stream (from SonicBoom) Changelog: nodejs.org/en/blog/rele...nodejs.orgNode.js — Node.js v24.6.0 (Current)Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts. 1255
Rafael Gonzaga | Node.js @rafaelgss.dev · 25/07/2025I'm live doing Node.js Core benchmark work! www.twitch.tv/rafaelgsstwitch.tvRafaelGSS - TwitchNode.js Core Mentoring 040
Rafael Gonzaga | Node.js @rafaelgss.dev · 23/07/2025I've been working on something interesting (at least for me) github.com/nodejs/node/...github.combenchmark: add calibrate-n script by RafaelGSS · Pull Request #59186 · nodejs/nodebenchmark: add calibrate-n script This script should help identify the best N when creating/updating benchmarks It's not new that our benchmark suite takes a huge amount to conclude. I have e... 020
Rafael Gonzaga | Node.js @rafaelgss.dev · 18/07/2025Hi folks, We will have a Node.js core mentoring live stream today Stay tuned! 031
Rafael Gonzaga | Node.js @rafaelgss.dev · 09/07/2025Node.js v24.4.0 is out! 💚 What's new? • crypto.hash() supports outputLength (XOF) • fs.mkdtempSync() gets disposable mode • --watch-kill-signal lands • permission.has('addon') is now supported • spawn() propagates permission flags • sqlite adds readBigInts More in: nodejs.org/en/blog/rele...nodejs.org 0237
Rafael Gonzaga | Node.js @rafaelgss.dev · 28/05/2025A warm welcome to our newest Node.js TSC member: Filip Skokan! Happy to see you onboard! github.com/nodejs/node/...github.comdoc: add Filip Skokan to TSC by RafaelGSS · Pull Request #58499 · nodejs/nodeRefs: nodejs/TSC#1740 cc: @panva 085
Reposted by Rafael Gonzaga | Node.jsMaksim Sinik @maksim.dev · 16/05/2025Folks, right now @rafaelgss.dev is doing an awesome livestram on m.twitch.tv/rafaelgss talking about Node.js threads, memory management and perfs. Join us!m.twitch.tvRafaelGSS - TwitchNode.js Core Mentoring 151
Reposted by Rafael Gonzaga | Node.jsNode.js @nodejs.org · 08/05/2025⚠️ Security release pre-alert: We will release new versions of v20.x, v22.x, v23.x, v24.x release lines on or shortly after May 14, 2025, in order to address: - 1 high severity issue - 1 moderate severity issue - 1 low severity issue Details: nodejs.org/en/blog/vuln...nodejs.orgNode.js — Wednesday, May 14, 2025 Security ReleasesNode.js® is a JavaScript runtime built on Chrome's V8 JavaScript engine. 03310
Rafael Gonzaga | Node.js @rafaelgss.dev · 06/05/2025I’d love to do something like that but in person… kind of collab summit workshop 120
Rafael Gonzaga | Node.js @rafaelgss.dev · 06/05/2025Happy to announce @nodejs v24.0.0 💚! This release brings several updates, including the V8 13.6 and npm to version 11. As a reminder, Node.js 24 will enter long-term support (LTS) in October, but until then, it will be the "Current" release Check it nodejs.org/en/blog/rele...nodejs.org 29421
Rafael Gonzaga | Node.js @rafaelgss.dev · 05/05/2025A handy way to test Node.js release candidates. I suggest you have something similar in your test suite, so you can act before a semver-major release of Node.js gets out. github.com/fastify/fast...github.comci: add support to test release candidates by RafaelGSS · Pull Request #6103 · fastify/fastifyThis is just an idea, but I think it would be interesting to be able to test Node.js release candidates, specially for semver-major versions 020
Rafael Gonzaga | Node.js @rafaelgss.dev · 01/04/2025RC.2 Node.js v24.0.0 github.com/nodejs/node/...github.com2025-04-23, Version 24.0.0 (Current) by RafaelGSS · Pull Request #57609 · nodejs/nodeCut-off date: 2025-03-24 Target release date: 2025-04-23 Roadmap: nodejs/Release#1081 TODO: V8 Update [help wanted] deps: update V8 to 13.4 #57114 Update REPLACEME Update notable changes 2025... 051
Rafael Gonzaga | Node.js @rafaelgss.dev · 07/03/2025Recent updates on Node.js CVE to EOL lines. TL;DR The Node.js team has decided to update previous vulnerability specific CVEs to cover EOL releases, reflecting their ongoing security risks. See: nodejs.org/en/blog/vuln...nodejs.orgNode.js — Updates on CVE for End-of-Life VersionsNode.js® is a JavaScript runtime built on Chrome's V8 JavaScript engine. 0225