crypto: update root-certificates to 3.123.1 - #63527
Merged
Merged
Conversation
This is the certdata.txt[0] from NSS 3.123.1. This is the version of NSS that shipped in Firefox 151.0.1 on 2026-05-21. Certificates removed: - QuoVadis Root CA 2 - QuoVadis Root CA 3 - DigiCert Assured ID Root CA - DigiCert Global Root CA - DigiCert High Assurance EV Root CA - SwissSign Gold CA - G2 - SecureTrust CA - Secure Global CA - COMODO Certification Authority - Certigna - certSIGN ROOT CA - Izenpe.com - AffirmTrust Commercial - AffirmTrust Networking - AffirmTrust Premium - AffirmTrust Premium ECC - TeliaSonera Root CA v1 - Entrust Root Certification Authority - G2 - Entrust Root Certification Authority - EC1 - Trustwave Global Certification Authority - Trustwave Global ECC P256 Certification Authority - Trustwave Global ECC P384 Certification Authority - GLOBALTRUST 2020 - GTS Root R2 - FIRMAPROFESIONAL CA ROOT-A WEB [0] https://raw.githubusercontent.com/nss-dev/nss/refs/tags/NSS_3_123_1_RTM/lib/ckfw/builtins/certdata.txt
Contributor
|
The
notable-change
Please suggest a text for the release notes if you'd like to include a more detailed summary, then proceed to update the PR description with the text or a link to the notable change suggested text comment. Otherwise, the commit will be placed in the Other Notable Changes section. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #63527 +/- ##
==========================================
- Coverage 90.33% 90.31% -0.02%
==========================================
Files 730 730
Lines 234205 234205
Branches 43927 43918 -9
==========================================
- Hits 211559 211526 -33
- Misses 14370 14414 +44
+ Partials 8276 8265 -11 🚀 New features to boost your workflow:
|
lpinca
approved these changes
May 24, 2026
gurgunday
approved these changes
May 24, 2026
Collaborator
Author
Collaborator
Author
Collaborator
Author
Contributor
|
Landed in 8bb63ed |
aduh95
pushed a commit
that referenced
this pull request
May 27, 2026
This is the [`certdata.txt`][0] from NSS 3.123.1. This is the version of NSS that shipped in Firefox 151.0.1 on 2026-05-21 Certificates removed: - QuoVadis Root CA 2 - QuoVadis Root CA 3 - DigiCert Assured ID Root CA - DigiCert Global Root CA - DigiCert High Assurance EV Root CA - SwissSign Gold CA - G2 - SecureTrust CA - Secure Global CA - COMODO Certification Authority - Certigna - certSIGN ROOT CA - Izenpe.com - AffirmTrust Commercial - AffirmTrust Networking - AffirmTrust Premium - AffirmTrust Premium ECC - TeliaSonera Root CA v1 - Entrust Root Certification Authority - G2 - Entrust Root Certification Authority - EC1 - Trustwave Global Certification Authority - Trustwave Global ECC P256 Certification Authority - Trustwave Global ECC P384 Certification Authority - GLOBALTRUST 2020 - GTS Root R2 - FIRMAPROFESIONAL CA ROOT-A WEB [0]: https://raw.githubusercontent.com/nss-dev/nss/refs/tags/NSS_3_123_1_RTM/lib/ckfw/builtins/certdata.txt PR-URL: #63527 Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Gürgün Dayıoğlu <hey@gurgun.day>
nodejs-github-bot
added a commit
that referenced
this pull request
May 30, 2026
Notable changes: buffer: * (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 http: * (SEMVER-MINOR) add httpValidation option to configure header value validation (RajeshKumar11) #61597 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079 lib,permission: * (SEMVER-MINOR) add permission.drop (Rafael Gonzaga) #62672 PR-URL: #63664
aduh95
added a commit
that referenced
this pull request
May 30, 2026
Notable changes: buffer: * (SEMVER-MINOR) increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) #63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 doc: * downgrade macOS x64 support to Tier 2 (Antoine du Hamel) #63055 http: * (SEMVER-MINOR) add `httpValidation` option to configure header value validation (RajeshKumar11) #61597 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079 lib,permission: * (SEMVER-MINOR) add `permission.drop` (Rafael Gonzaga) #62672 PR-URL: #63664
aduh95
added a commit
that referenced
this pull request
May 31, 2026
Notable changes: buffer: * (SEMVER-MINOR) increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) #63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 doc: * downgrade macOS x64 support to Tier 2 (Antoine du Hamel) #63055 http: * (SEMVER-MINOR) add `httpValidation` option to configure header value validation (RajeshKumar11) #61597 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079 lib,permission: * (SEMVER-MINOR) add `permission.drop` (Rafael Gonzaga) #62672 PR-URL: #63664
aduh95
added a commit
that referenced
this pull request
Jun 1, 2026
Notable changes: buffer: * (SEMVER-MINOR) increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) #63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 doc: * downgrade macOS x64 support to Tier 2 (Antoine du Hamel) #63055 http: * (SEMVER-MINOR) add `httpValidation` option to configure header value validation (RajeshKumar11) #61597 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079 lib,permission: * (SEMVER-MINOR) add `permission.drop` (Rafael Gonzaga) #62672 PR-URL: #63664
sxa
pushed a commit
to sxa/node
that referenced
this pull request
Jun 18, 2026
This is the [`certdata.txt`][0] from NSS 3.123.1. This is the version of NSS that shipped in Firefox 151.0.1 on 2026-05-21 Certificates removed: - QuoVadis Root CA 2 - QuoVadis Root CA 3 - DigiCert Assured ID Root CA - DigiCert Global Root CA - DigiCert High Assurance EV Root CA - SwissSign Gold CA - G2 - SecureTrust CA - Secure Global CA - COMODO Certification Authority - Certigna - certSIGN ROOT CA - Izenpe.com - AffirmTrust Commercial - AffirmTrust Networking - AffirmTrust Premium - AffirmTrust Premium ECC - TeliaSonera Root CA v1 - Entrust Root Certification Authority - G2 - Entrust Root Certification Authority - EC1 - Trustwave Global Certification Authority - Trustwave Global ECC P256 Certification Authority - Trustwave Global ECC P384 Certification Authority - GLOBALTRUST 2020 - GTS Root R2 - FIRMAPROFESIONAL CA ROOT-A WEB [0]: https://raw.githubusercontent.com/nss-dev/nss/refs/tags/NSS_3_123_1_RTM/lib/ckfw/builtins/certdata.txt PR-URL: nodejs#63527 Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Gürgün Dayıoğlu <hey@gurgun.day>
sxa
pushed a commit
that referenced
this pull request
Jun 18, 2026
This is the [`certdata.txt`][0] from NSS 3.123.1. This is the version of NSS that shipped in Firefox 151.0.1 on 2026-05-21 Certificates removed: - QuoVadis Root CA 2 - QuoVadis Root CA 3 - DigiCert Assured ID Root CA - DigiCert Global Root CA - DigiCert High Assurance EV Root CA - SwissSign Gold CA - G2 - SecureTrust CA - Secure Global CA - COMODO Certification Authority - Certigna - certSIGN ROOT CA - Izenpe.com - AffirmTrust Commercial - AffirmTrust Networking - AffirmTrust Premium - AffirmTrust Premium ECC - TeliaSonera Root CA v1 - Entrust Root Certification Authority - G2 - Entrust Root Certification Authority - EC1 - Trustwave Global Certification Authority - Trustwave Global ECC P256 Certification Authority - Trustwave Global ECC P384 Certification Authority - GLOBALTRUST 2020 - GTS Root R2 - FIRMAPROFESIONAL CA ROOT-A WEB [0]: https://raw.githubusercontent.com/nss-dev/nss/refs/tags/NSS_3_123_1_RTM/lib/ckfw/builtins/certdata.txt PR-URL: #63527 Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Gürgün Dayıoğlu <hey@gurgun.day>
sxa
added a commit
that referenced
this pull request
Jun 22, 2026
Notable changes: * crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 * (SEMVER-MINOR) buffer: increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597 * (SEMVER-MINOR) crypto: align key argument names in docs and error messages (Filip Skokan) #62527 * (SEMVER-MINOR) crypto: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) #62527 * (SEMVER-MINOR) crypto: unify asymmetric key import through KeyObjectHandle::Init (Filip Skokan) #62499 * (SEMVER-MINOR) crypto: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) #62183 * (SEMVER-MINOR) http: add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155 * (SEMVER-MINOR) inspector: expose precise coverage start to JS runtime (sangwook) #63079 * (SEMVER-MINOR) lib: cleanup stateless diffiehellman key handling (Filip Skokan) #62645 PR-URL: #64062
sxa
added a commit
that referenced
this pull request
Jun 22, 2026
Notable changes: buffer: * (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 * (SEMVER-MINOR) align key argument names in docs and error messages (Filip Skokan) #62527 * (SEMVER-MINOR) accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) #62527 * (SEMVER-MINOR) add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) #62183 http: * http: avoid stream listeners on idle agent sockets (Matteo Collina) #64004 * (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079 stream: * stream: Revert noop pause/resume on destroyed streams" (Stewart X Addison) #63834 PR-URL: #64062
sxa
added a commit
to sxa/node
that referenced
this pull request
Jun 23, 2026
Notable changes: buffer: * (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) nodejs#63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) nodejs#63527 * (SEMVER-MINOR) align key argument names in docs and error messages (Filip Skokan) nodejs#62527 * (SEMVER-MINOR) accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) nodejs#62527 * (SEMVER-MINOR) add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) nodejs#62183 http: * http: avoid stream listeners on idle agent sockets (Matteo Collina) nodejs#64004 * (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) nodejs#63155 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) nodejs#63079 stream: * stream: Revert noop pause/resume on destroyed streams" (Stewart X Addison) nodejs#63834 PR-URL: nodejs#64062
richardlau
pushed a commit
that referenced
this pull request
Jun 23, 2026
Notable changes: buffer: * (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 * (SEMVER-MINOR) align key argument names in docs and error messages (Filip Skokan) #62527 * (SEMVER-MINOR) accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) #62527 * (SEMVER-MINOR) add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) #62183 http: * http: avoid stream listeners on idle agent sockets (Matteo Collina) #64004 * (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155 inspector: * (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079 stream: * stream: Revert noop pause/resume on destroyed streams" (Stewart X Addison) #63834 PR-URL: #64062
mwalbeck
pushed a commit
to mwalbeck/docker-cyberchef
that referenced
this pull request
Jul 11, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [node](https://github.com/nodejs/node) | stage | minor | `24.16.0-trixie` → `24.18.0-trixie` | --- ### Release Notes <details> <summary>nodejs/node (node)</summary> ### [`v24.18.0`](https://github.com/nodejs/node/releases/tag/v24.18.0): 2026-06-23, Version 24.18.0 'Krypton' (LTS), @​richardlau prepared by @​sxa [Compare Source](nodejs/node@v24.17.0...v24.18.0) ##### Notable Changes - \[[`e07e7a31e1`](nodejs/node@e07e7a31e1)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#​63527](nodejs/node#63527) - \[[`44c8ebcbd6`](nodejs/node@44c8ebcbd6)] - **http**: avoid stream listeners on idle agent sockets (Matteo Collina) [#​64004](nodejs/node#64004) - \[[`d3ef4122ee`](nodejs/node@d3ef4122ee)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#​63597](nodejs/node#63597) - \[[`bb2857b85a`](nodejs/node@bb2857b85a)] - **(SEMVER-MINOR)** **crypto**: align key argument names in docs and error messages (Filip Skokan) [#​62527](nodejs/node#62527) - \[[`b9d5e87880`](nodejs/node@b9d5e87880)] - **(SEMVER-MINOR)** **crypto**: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) [#​62527](nodejs/node#62527) - \[[`ccd756d61e`](nodejs/node@ccd756d61e)] - **(SEMVER-MINOR)** **crypto**: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) [#​62183](nodejs/node#62183) - \[[`4c9251fc09`](nodejs/node@4c9251fc09)] - **(SEMVER-MINOR)** **http**: add writeInformation to send arbitrary 1xx status codes (Tim Perry) [#​63155](nodejs/node#63155) - \[[`8c989ec4a3`](nodejs/node@8c989ec4a3)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#​63079](nodejs/node#63079) - \[[`3f54c8ba32`](nodejs/node@3f54c8ba32)] - ***Revert*** "**stream**: noop pause/resume on destroyed streams" (Stewart X Addison) [#​63834](nodejs/node#63834) ##### Commits - \[[`d3ef4122ee`](nodejs/node@d3ef4122ee)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#​63597](nodejs/node#63597) - \[[`9ff36e40f0`](nodejs/node@9ff36e40f0)] - **build**: add --enable-all-experimentals build flag (Paolo Insogna) [#​62755](nodejs/node#62755) - \[[`7c22ee23aa`](nodejs/node@7c22ee23aa)] - **build**: def `NODE_USE_NODE_CODE_CACHE` only used in node\_mksnapshot (Chengzhong Wu) [#​63588](nodejs/node#63588) - \[[`2551abdb4a`](nodejs/node@2551abdb4a)] - **build,win**: enable x64 PGO (Stefan Stojanovic) [#​62761](nodejs/node#62761) - \[[`e8a55ce9b1`](nodejs/node@e8a55ce9b1)] - **crypto**: strengthen argument CHECKs in TurboSHAKE (Tobias Nießen) [#​62763](nodejs/node#62763) - \[[`ae61cd68f3`](nodejs/node@ae61cd68f3)] - **crypto**: harden WebCrypto against prototype pollution (Filip Skokan) [#​63363](nodejs/node#63363) - \[[`3d05a1d396`](nodejs/node@3d05a1d396)] - **crypto**: pass CryptoKey handles to KDF jobs (Filip Skokan) [#​63363](nodejs/node#63363) - \[[`f9d10a3f6b`](nodejs/node@f9d10a3f6b)] - **crypto**: remove async from WebCrypto methods (Filip Skokan) [#​63363](nodejs/node#63363) - \[[`e431d93e9e`](nodejs/node@e431d93e9e)] - **crypto**: add WebCrypto CryptoJob mode (Filip Skokan) [#​63363](nodejs/node#63363) - \[[`56e2505e48`](nodejs/node@56e2505e48)] - **crypto**: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) [#​63255](nodejs/node#63255) - \[[`3bac77f2a8`](nodejs/node@3bac77f2a8)] - **crypto**: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) [#​63255](nodejs/node#63255) - \[[`1bff901b09`](nodejs/node@1bff901b09)] - **crypto**: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) [#​63255](nodejs/node#63255) - \[[`4433fca3df`](nodejs/node@4433fca3df)] - **crypto**: harden CryptoKey algorithm slots (Filip Skokan) [#​63111](nodejs/node#63111) - \[[`b5cf01217a`](nodejs/node@b5cf01217a)] - **crypto**: harden KeyObject internal slots (Filip Skokan) [#​63111](nodejs/node#63111) - \[[`ce84aef37d`](nodejs/node@ce84aef37d)] - **crypto**: add guards and adjust tests for BoringSSL (Filip Skokan) [#​62883](nodejs/node#62883) - \[[`26781689b0`](nodejs/node@26781689b0)] - **crypto**: reject duplicate ML-KEM JWK key\_ops (Filip Skokan) [#​62905](nodejs/node#62905) - \[[`aeea8f4970`](nodejs/node@aeea8f4970)] - **crypto**: add JWK support for ML-KEM and SLH-DSA key types (Filip Skokan) [#​62706](nodejs/node#62706) - \[[`407cf91656`](nodejs/node@407cf91656)] - **crypto**: guard against size\_t overflow on experimental 32-bit arch (Filip Skokan) [#​62626](nodejs/node#62626) - \[[`bb2857b85a`](nodejs/node@bb2857b85a)] - **(SEMVER-MINOR)** **crypto**: align key argument names in docs and error messages (Filip Skokan) [#​62527](nodejs/node#62527) - \[[`b9d5e87880`](nodejs/node@b9d5e87880)] - **(SEMVER-MINOR)** **crypto**: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) [#​62527](nodejs/node#62527) - \[[`b46d52b283`](nodejs/node@b46d52b283)] - **crypto**: unify asymmetric key import through KeyObjectHandle::Init (Filip Skokan) [#​62499](nodejs/node#62499) - \[[`ccd756d61e`](nodejs/node@ccd756d61e)] - **(SEMVER-MINOR)** **crypto**: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) [#​62183](nodejs/node#62183) - \[[`e07e7a31e1`](nodejs/node@e07e7a31e1)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#​63527](nodejs/node#63527) - \[[`61826df455`](nodejs/node@61826df455)] - **crypto**: coerce -0 keylen to +0 in pbkdf2 and scrypt (Jordan Harband) [#​63531](nodejs/node#63531) - \[[`16d2fd3c07`](nodejs/node@16d2fd3c07)] - **crypto**: align verifyOneShot accepted types (Anshika Jain) [#​63280](nodejs/node#63280) - \[[`3b8330deda`](nodejs/node@3b8330deda)] - **crypto**: improve system certificate enumeration logic on macOS (Robo) [#​62576](nodejs/node#62576) - \[[`141de35399`](nodejs/node@141de35399)] - **debugger**: add --help to `node inspect` and improve docs (Joyee Cheung) [#​63201](nodejs/node#63201) - \[[`b76bfcd4fa`](nodejs/node@b76bfcd4fa)] - **deps**: upgrade npm to 11.16.0 (npm team) [#​63602](nodejs/node#63602) - \[[`4ec142314c`](nodejs/node@4ec142314c)] - **deps**: SQLite: cherry-pick [`b869ed6`](nodejs/node@b869ed6) (Junsu Han) [#​63525](nodejs/node#63525) - \[[`19e8ce1c36`](nodejs/node@19e8ce1c36)] - **deps**: upgrade npm to 11.15.0 (npm team) [#​63463](nodejs/node#63463) - \[[`8a264260e2`](nodejs/node@8a264260e2)] - **deps**: update sqlite to 3.53.1 (Node.js GitHub Bot) [#​63217](nodejs/node#63217) - \[[`50c8ff3f94`](nodejs/node@50c8ff3f94)] - **deps**: update simdjson to 4.6.4 (Node.js GitHub Bot) [#​62811](nodejs/node#62811) - \[[`6e56f01c4b`](nodejs/node@6e56f01c4b)] - **deps**: V8: cherry-pick [`435a2cd`](nodejs/node@435a2cdf664c) (Matthias Liedtke) [#​63136](nodejs/node#63136) - \[[`3ba813b242`](nodejs/node@3ba813b242)] - **deps**: cherry-pick [libuv/libuv@`a43e543`](libuv/libuv@a43e543) (Ali Hassan) [#​63222](nodejs/node#63222) - \[[`2390e3a5ac`](nodejs/node@2390e3a5ac)] - **doc**: remove duplicated sentences in large-pull-requests.md (Joyee Cheung) [#​63650](nodejs/node#63650) - \[[`52a1c18374`](nodejs/node@52a1c18374)] - **doc**: update `git node land` instructions for security releases (Antoine du Hamel) [#​63586](nodejs/node#63586) - \[[`3e6b4da037`](nodejs/node@3e6b4da037)] - **doc**: drop --experimental from --permission (Rafael Gonzaga) [#​63583](nodejs/node#63583) - \[[`84d05163b9`](nodejs/node@84d05163b9)] - **doc**: explicitly ask for reproducible in JS (Rafael Gonzaga) [#​63479](nodejs/node#63479) - \[[`7da2a4450e`](nodejs/node@7da2a4450e)] - **doc**: fix URL postMessage example in worker\_threads (Kit Dallege) [#​62203](nodejs/node#62203) - \[[`3d79bd8b29`](nodejs/node@3d79bd8b29)] - **doc**: clarify `filter` option of `sqlite.database.applyChangeset` (Antoine du Hamel) [#​63515](nodejs/node#63515) - \[[`4f4174aace`](nodejs/node@4f4174aace)] - **doc**: fix double spaces in ERR\_TLS\_INVALID\_PROTOCOL\_METHOD (Daijiro Wachi) [#​63511](nodejs/node#63511) - \[[`388323ca4b`](nodejs/node@388323ca4b)] - **doc**: fix double space in modules.md (Daijiro Wachi) [#​63512](nodejs/node#63512) - \[[`5258ccc058`](nodejs/node@5258ccc058)] - **doc**: fix "options" to "option" in tls.createServer (Daijiro Wachi) [#​63453](nodejs/node#63453) - \[[`43e83e6507`](nodejs/node@43e83e6507)] - **doc**: fix typo in deprecations (Daijiro Wachi) [#​63434](nodejs/node#63434) - \[[`f05a61d54c`](nodejs/node@f05a61d54c)] - **doc**: remove unsupported template type from v8.md (René) [#​63410](nodejs/node#63410) - \[[`c39d5fc820`](nodejs/node@c39d5fc820)] - **doc**: fix article usage before vowel-sound acronyms (joao-oliveira-softtor) [#​62696](nodejs/node#62696) - \[[`398261f911`](nodejs/node@398261f911)] - **doc**: remove the bi-monthly contributor spotlight section (Claudio Wunder) [#​62734](nodejs/node#62734) - \[[`fd9e14c405`](nodejs/node@fd9e14c405)] - **doc**: update http2's `push` and `trailers` events with `rawHeaders` param (YuSheng Chen) [#​63259](nodejs/node#63259) - \[[`b943ce6933`](nodejs/node@b943ce6933)] - **doc**: remove inactive members from Triagers list (Antoine du Hamel) [#​63329](nodejs/node#63329) - \[[`4b9cdfc022`](nodejs/node@4b9cdfc022)] - **doc**: reference correct function in Module docs (Robin Malfait) [#​63247](nodejs/node#63247) - \[[`bed84b6df2`](nodejs/node@bed84b6df2)] - **doc**: replace Visual Studio 2022 Evergreen version reference with 17.14 (Mike McCready) [#​63211](nodejs/node#63211) - \[[`32ea70569b`](nodejs/node@32ea70569b)] - **doc**: recommend explicitly Tier 1 or 2 for production applications (Mike McCready) [#​63187](nodejs/node#63187) - \[[`4627bcfd82`](nodejs/node@4627bcfd82)] - **doc**: run license-builder (github-actions\[bot]) [#​63232](nodejs/node#63232) - \[[`28eba71845`](nodejs/node@28eba71845)] - **doc**: add large pull requests contributing guide (Matteo Collina) [#​62829](nodejs/node#62829) - \[[`2648efd438`](nodejs/node@2648efd438)] - **doc**: remove unnecessary `<!-- eslint-` magic comments (Antoine du Hamel) [#​63200](nodejs/node#63200) - \[[`a95fc1f8fc`](nodejs/node@a95fc1f8fc)] - **doc**: clarify SEA platform support excludes darwin-x64 (MJSHANG) [#​63181](nodejs/node#63181) - \[[`aaef29e2e1`](nodejs/node@aaef29e2e1)] - **doc**: update release steps when post-release fails (Rafael Gonzaga) [#​63131](nodejs/node#63131) - \[[`7d81419cf2`](nodejs/node@7d81419cf2)] - **doc**: add Hmac.digest() documentation-only deprecation (DEP0206) (Anshika Jain) [#​63121](nodejs/node#63121) - \[[`ececd80d81`](nodejs/node@ececd80d81)] - **doc**: document the latest-vX.x schema (Marco Ippolito) [#​63033](nodejs/node#63033) - \[[`27c1c1d842`](nodejs/node@27c1c1d842)] - **doc**: remove list of versions in `BUILDING.md` (Antoine du Hamel) [#​63113](nodejs/node#63113) - \[[`e369886a65`](nodejs/node@e369886a65)] - **doc,sqlite**: document entryPoint argument for loadExtension (Edy Silva) [#​63152](nodejs/node#63152) - \[[`e4e5137cbd`](nodejs/node@e4e5137cbd)] - **errors**: handle V8 warnings in DisallowJavascriptExecutionScope (Divyanshu Sharma) [#​63491](nodejs/node#63491) - \[[`6d1f6048d2`](nodejs/node@6d1f6048d2)] - **fs**: make `Date` properties on `Stats` enumerable (LiviaMedeiros) [#​63328](nodejs/node#63328) - \[[`44c8ebcbd6`](nodejs/node@44c8ebcbd6)] - **http**: avoid stream listeners on idle agent sockets (Matteo Collina) [#​64004](nodejs/node#64004) - \[[`4c9251fc09`](nodejs/node@4c9251fc09)] - **(SEMVER-MINOR)** **http**: add writeInformation to send arbitrary 1xx status codes (Tim Perry) [#​63155](nodejs/node#63155) - \[[`39f61fb06c`](nodejs/node@39f61fb06c)] - **http2**: emit session close before stream close (Matteo Collina) [#​63414](nodejs/node#63414) - \[[`8a8f2127d1`](nodejs/node@8a8f2127d1)] - **http2**: validate non-link headers in writeEarlyHints (Matteo Collina) [#​62017](nodejs/node#62017) - \[[`8c989ec4a3`](nodejs/node@8c989ec4a3)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#​63079](nodejs/node#63079) - \[[`c05f38229b`](nodejs/node@c05f38229b)] - **lib**: cleanup stateless diffiehellman key handling (Filip Skokan) [#​62645](nodejs/node#62645) - \[[`1c16b45d35`](nodejs/node@1c16b45d35)] - **lib**: refactor internal webidl converters (Filip Skokan) [#​62979](nodejs/node#62979) - \[[`02f35d6dce`](nodejs/node@02f35d6dce)] - **lib**: define `kEnumerableProperty` atomically (Antoine du Hamel) [#​63609](nodejs/node#63609) - \[[`12c51547ba`](nodejs/node@12c51547ba)] - **lib**: fix typos in esm loader comments (RonGamzu) [#​63465](nodejs/node#63465) - \[[`9b03b84262`](nodejs/node@9b03b84262)] - **lib**: fix typo idenity => identity (Daijiro Wachi) [#​63112](nodejs/node#63112) - \[[`a84e6b0567`](nodejs/node@a84e6b0567)] - **lib**: fixes validator message (Daijiro Wachi) [#​62823](nodejs/node#62823) - \[[`11734166a8`](nodejs/node@11734166a8)] - **lib**: narrow ReadableStreamBYOBRequest.view return type to Uint8Array (RoomWithOutRoof) [#​63017](nodejs/node#63017) - \[[`7cead61d21`](nodejs/node@7cead61d21)] - **meta**: flip mcollina emails in .mailmap (Matteo Collina) [#​63621](nodejs/node#63621) - \[[`a08cfcfd35`](nodejs/node@a08cfcfd35)] - **meta**: label "source maps" PRs (Chengzhong Wu) [#​63591](nodejs/node#63591) - \[[`d56e8d2512`](nodejs/node@d56e8d2512)] - **meta**: add `vfs` subsystem label (René) [#​62331](nodejs/node#62331) - \[[`6201cfe488`](nodejs/node@6201cfe488)] - **meta**: skip scheduled workflows on forks (Jamie Magee) [#​63565](nodejs/node#63565) - \[[`f095e2bd31`](nodejs/node@f095e2bd31)] - **meta**: add additional gitignore entries (James M Snell) [#​63267](nodejs/node#63267) - \[[`1ea52c444c`](nodejs/node@1ea52c444c)] - **meta**: move one or more collaborators to emeritus (Node.js GitHub Bot) [#​63402](nodejs/node#63402) - \[[`b1b2327611`](nodejs/node@b1b2327611)] - **meta**: move one or more collaborators to emeritus (Node.js GitHub Bot) [#​63235](nodejs/node#63235) - \[[`7d88e130a9`](nodejs/node@7d88e130a9)] - **meta**: ignore AI assistants files (Matteo Collina) [#​62612](nodejs/node#62612) - \[[`a53b51df38`](nodejs/node@a53b51df38)] - **module**: load ESM helpers eagerly in the snapshot (Joyee Cheung) [#​63550](nodejs/node#63550) - \[[`69df688fff`](nodejs/node@69df688fff)] - **module**: fix sync hook short-circuit in require() in imported CJS (Joyee Cheung) [#​62920](nodejs/node#62920) - \[[`75d9a4ed47`](nodejs/node@75d9a4ed47)] - **node-api**: support SharedArrayBuffer in napi\_create\_typedarray (Yilong Li) [#​62710](nodejs/node#62710) - \[[`c20aa4c47b`](nodejs/node@c20aa4c47b)] - **quic**: add reusePort option to QuicEndpoint (James M Snell) [#​63267](nodejs/node#63267) - \[[`26a30d8a7f`](nodejs/node@26a30d8a7f)] - **quic**: implement rate limiting for version nego and immediate close (James M Snell) [#​63267](nodejs/node#63267) - \[[`0b534b5770`](nodejs/node@0b534b5770)] - **quic**: fixup linting issue after other changes (James M Snell) [#​63267](nodejs/node#63267) - \[[`4b367cbe09`](nodejs/node@4b367cbe09)] - **quic**: remove unused binding variable in session.cc (James M Snell) [#​63177](nodejs/node#63177) - \[[`2574bef5a6`](nodejs/node@2574bef5a6)] - **repl**: fix dedup comparing normalized line against raw history (Daijiro Wachi) [#​62886](nodejs/node#62886) - \[[`30e71c7e49`](nodejs/node@30e71c7e49)] - **sqlite**: keep source database alive during backup (Matteo Collina) [#​62673](nodejs/node#62673) - \[[`677ca7e76c`](nodejs/node@677ca7e76c)] - **src**: simplify OpenSSL feature gates (Filip Skokan) [#​63255](nodejs/node#63255) - \[[`c863c75c39`](nodejs/node@c863c75c39)] - **src**: add BoringSSL EVP enumeration fallback (Filip Skokan) [#​63206](nodejs/node#63206) - \[[`f6b2466921`](nodejs/node@f6b2466921)] - **src**: decouple KeyObject and CryptoKey and move CryptoKey to src (Filip Skokan) [#​62924](nodejs/node#62924) - \[[`92d4f07dd2`](nodejs/node@92d4f07dd2)] - **src**: remove license headers for new node\_profiling files (Chengzhong Wu) [#​63066](nodejs/node#63066) - \[[`8ac5d771c8`](nodejs/node@8ac5d771c8)] - **src**: split profiling helpers from util (Ilyas Shabi) [#​63008](nodejs/node#63008) - \[[`85d1639495`](nodejs/node@85d1639495)] - **src**: remove TOCTOU race condition when encoding SAB-backed `Buffer`s (Antoine du Hamel) [#​63517](nodejs/node#63517) - \[[`9473c5f05c`](nodejs/node@9473c5f05c)] - **src**: skip duplicate UTF-8 validation in TextDecoder fatal path (Mert Can Altin) [#​63231](nodejs/node#63231) - \[[`f35c91ee68`](nodejs/node@f35c91ee68)] - **src**: improve token return value check (James M Snell) [#​63483](nodejs/node#63483) - \[[`26f677c1c5`](nodejs/node@26f677c1c5)] - **src**: expose `node::RegisterContext` to make a node managed context (Chengzhong Wu) [#​62322](nodejs/node#62322) - \[[`275cf909b6`](nodejs/node@275cf909b6)] - **src,sqlite**: only pass `xFilter` when user provided a callback (Antoine du Hamel) [#​63516](nodejs/node#63516) - \[[`287e02303f`](nodejs/node@287e02303f)] - **src,sqlite**: remove dead code (Edy Silva) [#​63204](nodejs/node#63204) - \[[`58fa2ee189`](nodejs/node@58fa2ee189)] - **stream**: switch to internal `sleep` binding (Antoine du Hamel) [#​63611](nodejs/node#63611) - \[[`f954ab3f1a`](nodejs/node@f954ab3f1a)] - **stream**: use data listener for compose forwarding (Trivikram Kamat) [#​63593](nodejs/node#63593) - \[[`dc57173003`](nodejs/node@dc57173003)] - **stream**: fix Writable.toWeb() hang on synchronous drain (sangwook) [#​61197](nodejs/node#61197) - \[[`3f54c8ba32`](nodejs/node@3f54c8ba32)] - ***Revert*** "**stream**: noop pause/resume on destroyed streams" (Stewart X Addison) [#​63834](nodejs/node#63834) - \[[`cee279c5d6`](nodejs/node@cee279c5d6)] - **stream**: remove unnecessary check (Antoine du Hamel) [#​63030](nodejs/node#63030) - \[[`61b20f60a3`](nodejs/node@61b20f60a3)] - **test**: update tls/crypto behaviour expectations when using BoringSSL (Filip Skokan) [#​63161](nodejs/node#63161) - \[[`a835363808`](nodejs/node@a835363808)] - **test**: update WPT for WebCryptoAPI to [`97bbc72`](nodejs/node@97bbc7247a) (Node.js GitHub Bot) [#​63417](nodejs/node#63417) - \[[`a00297480b`](nodejs/node@a00297480b)] - **test**: update WPT resources, interfaces and WebCryptoAPI (Node.js GitHub Bot) [#​62389](nodejs/node#62389) - \[[`5a95a2b055`](nodejs/node@5a95a2b055)] - **test**: shorten path in net pipe connect errors (Matteo Collina) [#​63405](nodejs/node#63405) - \[[`5e8ff22d8f`](nodejs/node@5e8ff22d8f)] - **test**: remove test-node-output-v8-warning (Joyee Cheung) [#​63469](nodejs/node#63469) - \[[`ee15380950`](nodejs/node@ee15380950)] - **test**: update test426-fixtures to [`9b9e225`](nodejs/node@9b9e225) (Node.js GitHub Bot) [#​63373](nodejs/node#63373) - \[[`9e063d9bea`](nodejs/node@9e063d9bea)] - **test**: update WPT for url to [`e4a4672`](nodejs/node@e4a4672e9e) (Node.js GitHub Bot) [#​63372](nodejs/node#63372) - \[[`503bee4b43`](nodejs/node@503bee4b43)] - **test**: deflake async-hooks statwatcher test (Trivikram Kamat) [#​63396](nodejs/node#63396) - \[[`cccc7c32d8`](nodejs/node@cccc7c32d8)] - **test**: avoid test\_runner watch restart in spec snapshot (Trivikram Kamat) [#​63392](nodejs/node#63392) - \[[`c89489258c`](nodejs/node@c89489258c)] - **test**: reduce watch mode restart flakiness (Trivikram Kamat) [#​63390](nodejs/node#63390) - \[[`e4d5e2578e`](nodejs/node@e4d5e2578e)] - **test**: isolate rerun-failures state file under tmpdir (Chemi Atlow) [#​63449](nodejs/node#63449) - \[[`362644a9ba`](nodejs/node@362644a9ba)] - **test**: wait for ok before initial break after restart (Yuya Inoue) [#​62807](nodejs/node#62807) - \[[`c4058d0e05`](nodejs/node@c4058d0e05)] - **test**: disable Maglev in near-heap-limit worker test (Trivikram Kamat) [#​63398](nodejs/node#63398) - \[[`214da630a7`](nodejs/node@214da630a7)] - **test**: deflake connection refused proxy tests (Trivikram Kamat) [#​63395](nodejs/node#63395) - \[[`1d61a29876`](nodejs/node@1d61a29876)] - **test**: avoid repeated writes in watch helper (Trivikram Kamat) [#​63386](nodejs/node#63386) - \[[`2004e25387`](nodejs/node@2004e25387)] - **test**: deflake watch mode worker test (Trivikram Kamat) [#​63384](nodejs/node#63384) - \[[`d691cccfc1`](nodejs/node@d691cccfc1)] - **test**: relax test-memory-usage arrayBuffers check (inoway46) [#​63244](nodejs/node#63244) - \[[`0ff6bf853c`](nodejs/node@0ff6bf853c)] - **test**: reduce flakiness of `different-registry-per-thread` (Antoine du Hamel) [#​63244](nodejs/node#63244) - \[[`d9f4e8e503`](nodejs/node@d9f4e8e503)] - **test**: fix flaky test-watch-mode-inspect timeout (Matteo Collina) [#​63361](nodejs/node#63361) - \[[`6d7cd50328`](nodejs/node@6d7cd50328)] - **test**: relax min assertion in test-performance-eventloopdelay (Marco) [#​63100](nodejs/node#63100) - \[[`9dafe1d2d8`](nodejs/node@9dafe1d2d8)] - **test**: avoid flaky restart sync in debugger exceptions test (Yuya Inoue) [#​62055](nodejs/node#62055) - \[[`989b2de973`](nodejs/node@989b2de973)] - **test**: avoid initial-break wait in restart-message (inoway46) [#​62060](nodejs/node#62060) - \[[`a072a25ee7`](nodejs/node@a072a25ee7)] - **test**: move FFI tests to `NATIVE_SUITES` (Antoine du Hamel) [#​63165](nodejs/node#63165) - \[[`64efbfd878`](nodejs/node@64efbfd878)] - **test**: use ERM to destroy sqlite database handles after tests (René) [#​63076](nodejs/node#63076) - \[[`7dee66cd94`](nodejs/node@7dee66cd94)] - **test\_runner**: dont buffer unordered events in process isolation mode (Moshe Atlow) [#​63432](nodejs/node#63432) - \[[`d257eec1e3`](nodejs/node@d257eec1e3)] - **test\_runner**: fix --test-rerun-failures swallowing failures on retry (Chemi Atlow) [#​63431](nodejs/node#63431) - \[[`288c320e2f`](nodejs/node@288c320e2f)] - **test\_runner**: show replayed-from-attempt hint in spec reporter (Moshe Atlow) [#​63429](nodejs/node#63429) - \[[`904bdf5bb4`](nodejs/node@904bdf5bb4)] - **test\_runner**: preserve run duration when using test-rerun (Moshe Atlow) [#​63429](nodejs/node#63429) - \[[`df183d7bfa`](nodejs/node@df183d7bfa)] - **test\_runner**: avoid hanging on incomplete v8 frames (Ali Hassan) [#​62704](nodejs/node#62704) - \[[`ec86c69726`](nodejs/node@ec86c69726)] - **test\_runner**: fix diagnostics channel context tracking (Moshe Atlow) [#​63283](nodejs/node#63283) - \[[`94e5f63b83`](nodejs/node@94e5f63b83)] - **tls**: add unsupported renegotiation error (Filip Skokan) [#​63161](nodejs/node#63161) - \[[`06d308fb61`](nodejs/node@06d308fb61)] - **tools**: prevent lib code from reading KeyObject and CryptoKey accessors (Filip Skokan) [#​63111](nodejs/node#63111) - \[[`2e4a0d0c91`](nodejs/node@2e4a0d0c91)] - **tools**: bump brace-expansion from 5.0.5 to 5.0.6 in /tools/eslint (dependabot\[bot]) [#​63415](nodejs/node#63415) - \[[`4c9666b366`](nodejs/node@4c9666b366)] - **tools**: skip commit-lint on backport pull requests (Marco) [#​63378](nodejs/node#63378) - \[[`67d0c490a8`](nodejs/node@67d0c490a8)] - **tools**: fix skip of `test-internet` on forks (Antoine du Hamel) [#​63492](nodejs/node#63492) - \[[`02f73c7cac`](nodejs/node@02f73c7cac)] - **tools**: bump the eslint group in /tools/eslint with 4 updates (dependabot\[bot]) [#​63075](nodejs/node#63075) - \[[`5d016d3241`](nodejs/node@5d016d3241)] - **tools**: update gyp-next to 0.22.2 (Node.js GitHub Bot) [#​63374](nodejs/node#63374) - \[[`55af0f0edb`](nodejs/node@55af0f0edb)] - **tools**: fix test426 updater (Antoine du Hamel) [#​63271](nodejs/node#63271) - \[[`d8475e167a`](nodejs/node@d8475e167a)] - **tools**: use different branch for tool updates on staging branches (Antoine du Hamel) [#​63110](nodejs/node#63110) - \[[`c605df9e50`](nodejs/node@c605df9e50)] - **util**: remove unused functions (Antoine du Hamel) [#​63612](nodejs/node#63612) - \[[`fe4540ebdb`](nodejs/node@fe4540ebdb)] - **util**: create hex style cache and fast path (Guilherme Araújo) [#​62999](nodejs/node#62999) ### [`v24.17.0`](https://github.com/nodejs/node/releases/tag/v24.17.0): 2026-06-18, Version 24.17.0 'Krypton' (LTS), @​aduh95 [Compare Source](nodejs/node@v24.16.0...v24.17.0) This is a security release. ##### Notable Changes - (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High - (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High - (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium - (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium - (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium - (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium - (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium - (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 – Medium - (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low - (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low - (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low ##### Commits - \[[`9e4dfc7bba`](nodejs/node@9e4dfc7bba)] - **(CVE-2026-48933)** **crypto**: guard WebCrypto cipher output length (Filip Skokan) [nodejs-private/node-private#878](https://github.com/nodejs-private/node-private/pull/878) - \[[`cb2aed980c`](nodejs/node@cb2aed980c)] - **deps**: update llhttp to 9.4.2 (Antoine du Hamel) [nodejs-private/node-private#890](https://github.com/nodejs-private/node-private/pull/890) - \[[`a8a0d12875`](nodejs/node@a8a0d12875)] - **(CVE-2026-48937)** **deps**: fix integration issues with the latest nghttp2 (Tim Perry) [#​62891](nodejs/node#62891) - \[[`66e6203c1c`](nodejs/node@66e6203c1c)] - **(SEMVER-MAJOR)** **deps**: update nghttp2 to 1.69.0 (Node.js GitHub Bot) [#​62891](nodejs/node#62891) - \[[`dd627ced27`](nodejs/node@dd627ced27)] - **deps**: update archs files for openssl-3.5.7 (Node.js GitHub Bot) [#​63820](nodejs/node#63820) - \[[`684bae568f`](nodejs/node@684bae568f)] - **deps**: upgrade openssl sources to openssl-3.5.7 (Node.js GitHub Bot) [#​63820](nodejs/node#63820) - \[[`3a631e7f83`](nodejs/node@3a631e7f83)] - **deps**: fix aix implicit declaration in OpenSSL (Abdirahim Musse) [#​62656](nodejs/node#62656) - \[[`cf44df3996`](nodejs/node@cf44df3996)] - **deps**: update undici to 7.28.0 (Node.js GitHub Bot) [#​63703](nodejs/node#63703) - \[[`138c70294b`](nodejs/node@138c70294b)] - **(CVE-2026-48930)** **dns,net**: reject hostnames with embedded NUL bytes (Matteo Collina) [nodejs-private/node-private#868](https://github.com/nodejs-private/node-private/pull/868) - \[[`be7e719c3f`](nodejs/node@be7e719c3f)] - **(CVE-2026-48931)** **http**: fix response queue poisoning in http.Agent (Matteo Collina) [nodejs-private/node-private#846](https://github.com/nodejs-private/node-private/pull/846) - \[[`cc7c11b4d1`](nodejs/node@cc7c11b4d1)] - **(CVE-2026-48619)** **http2**: cap originSet size to prevent unbounded memory growth (Matteo Collina) [nodejs-private/node-private#855](https://github.com/nodejs-private/node-private/pull/855) - \[[`9224427b92`](nodejs/node@9224427b92)] - **(CVE-2026-48615)** **lib,test**: redact proxy credentials in tunnel errors (Matteo Collina) [nodejs-private/node-private#867](https://github.com/nodejs-private/node-private/pull/867) - \[[`cf85d54839`](nodejs/node@cf85d54839)] - **(CVE-2026-48935)** **permission**: disable FileHandle utimes with permission model (RafaelGSS) [nodejs-private/node-private#873](https://github.com/nodejs-private/node-private/pull/873) - \[[`a1bbc24f96`](nodejs/node@a1bbc24f96)] - **(CVE-2026-48617)** **permission**: handle process.chdir on writereport (RafaelGSS) [nodejs-private/node-private#870](https://github.com/nodejs-private/node-private/pull/870) - \[[`e3723ff2d6`](nodejs/node@e3723ff2d6)] - **test**: add session reuse host verification regressions (Matteo Collina) [nodejs-private/node-private#854](https://github.com/nodejs-private/node-private/pull/854) - \[[`a77af4867b`](nodejs/node@a77af4867b)] - **(CVE-2026-48934)** **tls**: bind reusable sessions to authenticated host (Matteo Collina) [nodejs-private/node-private#854](https://github.com/nodejs-private/node-private/pull/854) - \[[`31beb4f707`](nodejs/node@31beb4f707)] - **(CVE-2026-48928)** **tls**: fix case-sensitive SNI context matching (Matteo Collina) [nodejs-private/node-private#857](https://github.com/nodejs-private/node-private/pull/857) - \[[`8e75c73f91`](nodejs/node@8e75c73f91)] - **(CVE-2026-48618)** **tls**: normalize hostname for server identity checks (Matteo Collina) [nodejs-private/node-private#869](https://github.com/nodejs-private/node-private/pull/869) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzAuMTkiLCJ1cGRhdGVkSW5WZXIiOiI0My4xNzAuMTkiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=--> Reviewed-on: https://git.walbeck.it/mwalbeck/docker-cyberchef/pulls/488
juanarbol
pushed a commit
to juanarbol/node
that referenced
this pull request
Jul 16, 2026
This is the [`certdata.txt`][0] from NSS 3.123.1. This is the version of NSS that shipped in Firefox 151.0.1 on 2026-05-21 Certificates removed: - QuoVadis Root CA 2 - QuoVadis Root CA 3 - DigiCert Assured ID Root CA - DigiCert Global Root CA - DigiCert High Assurance EV Root CA - SwissSign Gold CA - G2 - SecureTrust CA - Secure Global CA - COMODO Certification Authority - Certigna - certSIGN ROOT CA - Izenpe.com - AffirmTrust Commercial - AffirmTrust Networking - AffirmTrust Premium - AffirmTrust Premium ECC - TeliaSonera Root CA v1 - Entrust Root Certification Authority - G2 - Entrust Root Certification Authority - EC1 - Trustwave Global Certification Authority - Trustwave Global ECC P256 Certification Authority - Trustwave Global ECC P384 Certification Authority - GLOBALTRUST 2020 - GTS Root R2 - FIRMAPROFESIONAL CA ROOT-A WEB [0]: https://raw.githubusercontent.com/nss-dev/nss/refs/tags/NSS_3_123_1_RTM/lib/ckfw/builtins/certdata.txt PR-URL: nodejs#63527 Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Gürgün Dayıoğlu <hey@gurgun.day>
juanarbol
added a commit
that referenced
this pull request
Jul 16, 2026
Notable changes: async_hooks: * (SEMVER-MINOR) add trackPromises option to createHook() (Joyee Cheung) #61415 buffer: * (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597 cli: * (SEMVER-MINOR) add --max-heap-size option (tannal) #58708 console: * (SEMVER-MINOR) allow per-stream `inspectOptions` option (Anna Henningsen) #60082 crypto: * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527 debugger: * (SEMVER-MINOR) add edit-free runtime expression probes to `node inspect` (Joyee Cheung) #62713 fs: * (SEMVER-MINOR) add signal option to fs.stat() (Mert Can Altin) #57775 * (SEMVER-MINOR) expose frsize field in statfs (Jinho Jang) #62277 * (SEMVER-MINOR) add `throwIfNoEntry` option for fs.stat and fs.promises.stat (Juan José) #61178 * (SEMVER-MINOR) add ignore option to fs.watch (Matteo Collina) #61433 http: * (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155 * (SEMVER-MINOR) add req.signal to IncomingMessage (Akshat) #62541 lib: * (SEMVER-MINOR) remove util.getCallSite (Rafael Gonzaga) #59980 net: * (SEMVER-MINOR) add `setTOS` and `getTOS` to `Socket` (Amol Yadav) #61503 node-api: * (SEMVER-MINOR) support SharedArrayBuffer in napi_create_dataview (Kevin Eady) #60473 * (SEMVER-MINOR) add napi_create_object_with_properties (Miguel Marcondes Filho) #59953 perf_hooks: * (SEMVER-MINOR) move non-standard performance properties to perf_hooks (Chengzhong Wu) #60370 sqlite: * (SEMVER-MINOR) add sqlite prepare options args (Guilherme Araújo) #61311 * (SEMVER-MINOR) create authorization api (Guilherme Araújo) #59928 src: * (CVE-2026-21712) handle url crash on different url formats (RafaelGSS) nodejs-private/node-private#816 src,permission: * (SEMVER-MINOR) add --allow-inspector ability (Rafael Gonzaga) #59711 stream: * (SEMVER-MINOR) add bytes() method to stream/consumers (wantaek) #60426 * (SEMVER-MINOR) do not pass `readable.compose()` output via `Readable.from()` (René) #60907 test_runner: * (SEMVER-MINOR) align mock timeout api (sangwook) #62820 PR-URL: TODO
Closed
juanarbol
pushed a commit
that referenced
this pull request
Jul 17, 2026
This is the [`certdata.txt`][0] from NSS 3.123.1. This is the version of NSS that shipped in Firefox 151.0.1 on 2026-05-21 Certificates removed: - QuoVadis Root CA 2 - QuoVadis Root CA 3 - DigiCert Assured ID Root CA - DigiCert Global Root CA - DigiCert High Assurance EV Root CA - SwissSign Gold CA - G2 - SecureTrust CA - Secure Global CA - COMODO Certification Authority - Certigna - certSIGN ROOT CA - Izenpe.com - AffirmTrust Commercial - AffirmTrust Networking - AffirmTrust Premium - AffirmTrust Premium ECC - TeliaSonera Root CA v1 - Entrust Root Certification Authority - G2 - Entrust Root Certification Authority - EC1 - Trustwave Global Certification Authority - Trustwave Global ECC P256 Certification Authority - Trustwave Global ECC P384 Certification Authority - GLOBALTRUST 2020 - GTS Root R2 - FIRMAPROFESIONAL CA ROOT-A WEB [0]: https://raw.githubusercontent.com/nss-dev/nss/refs/tags/NSS_3_123_1_RTM/lib/ckfw/builtins/certdata.txt PR-URL: #63527 Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Gürgün Dayıoğlu <hey@gurgun.day>
juanarbol
pushed a commit
that referenced
this pull request
Jul 19, 2026
This is the [`certdata.txt`][0] from NSS 3.123.1. This is the version of NSS that shipped in Firefox 151.0.1 on 2026-05-21 Certificates removed: - QuoVadis Root CA 2 - QuoVadis Root CA 3 - DigiCert Assured ID Root CA - DigiCert Global Root CA - DigiCert High Assurance EV Root CA - SwissSign Gold CA - G2 - SecureTrust CA - Secure Global CA - COMODO Certification Authority - Certigna - certSIGN ROOT CA - Izenpe.com - AffirmTrust Commercial - AffirmTrust Networking - AffirmTrust Premium - AffirmTrust Premium ECC - TeliaSonera Root CA v1 - Entrust Root Certification Authority - G2 - Entrust Root Certification Authority - EC1 - Trustwave Global Certification Authority - Trustwave Global ECC P256 Certification Authority - Trustwave Global ECC P384 Certification Authority - GLOBALTRUST 2020 - GTS Root R2 - FIRMAPROFESIONAL CA ROOT-A WEB [0]: https://raw.githubusercontent.com/nss-dev/nss/refs/tags/NSS_3_123_1_RTM/lib/ckfw/builtins/certdata.txt PR-URL: #63527 Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Gürgün Dayıoğlu <hey@gurgun.day>
marco-ippolito
pushed a commit
that referenced
this pull request
Jul 29, 2026
This is the [`certdata.txt`][0] from NSS 3.123.1. This is the version of NSS that shipped in Firefox 151.0.1 on 2026-05-21 Certificates removed: - QuoVadis Root CA 2 - QuoVadis Root CA 3 - DigiCert Assured ID Root CA - DigiCert Global Root CA - DigiCert High Assurance EV Root CA - SwissSign Gold CA - G2 - SecureTrust CA - Secure Global CA - COMODO Certification Authority - Certigna - certSIGN ROOT CA - Izenpe.com - AffirmTrust Commercial - AffirmTrust Networking - AffirmTrust Premium - AffirmTrust Premium ECC - TeliaSonera Root CA v1 - Entrust Root Certification Authority - G2 - Entrust Root Certification Authority - EC1 - Trustwave Global Certification Authority - Trustwave Global ECC P256 Certification Authority - Trustwave Global ECC P384 Certification Authority - GLOBALTRUST 2020 - GTS Root R2 - FIRMAPROFESIONAL CA ROOT-A WEB [0]: https://raw.githubusercontent.com/nss-dev/nss/refs/tags/NSS_3_123_1_RTM/lib/ckfw/builtins/certdata.txt PR-URL: #63527 Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Gürgün Dayıoğlu <hey@gurgun.day>
jylenhof
pushed a commit
to jylenhof/mise-update-tool
that referenced
this pull request
Aug 4, 2026
Automated mise tool upgrades from local config. Updated tools: - `action-validator` - `actionlint` - `aube` - `editorconfig-checker` - `ghalint` - `node` - `pinact` - `pipx:gh-action-pulse` - `prek` - `rumdl` - `shellcheck` - `shfmt` - `tombi` - `uv` - `yamlfmt` - `yamllint` - `zizmor` Command: `mise upgrade --bump --local action-validator actionlint aube editorconfig-checker ghalint node pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor` <details> <summary>Version changelog (node)</summary> | Tool | Requested | Installed | |------|-----------|-----------| | `node` | `24` → `26` | `24.18.1` → `26.5.1` | </details> <details> <summary>Release notes (1 tools)</summary> <details> <summary>node: `24.18.1` → `26.5.1` (nodejs/node)</summary> ### v25.8.2 This is a security release. ### Notable Changes * (CVE-2026-21637) wrap `SNICallback` invocation in `try`/`catch` (Matteo Collina) - High * (CVE-2026-21710) use null prototype for `headersDistinct`/`trailersDistinct` (Matteo Collina) - High * (CVE-2026-21711) include permission check to `pipe_wrap.cc` (RafaelGSS) - Medium * (CVE-2026-21712) handle url crash on different url formats (RafaelGSS) - Medium * (CVE-2026-21713) use timing-safe comparison in Web Cryptography HMAC and KMAC (Filip Skokan) - Medium * (CVE-2026-21714) handle `NGHTTP2_ERR_FLOW_CONTROL` error code (RafaelGSS) - Medium * (CVE-2026-21717) test array index hash collision (Joyee Cheung) - Medium * (CVE-2026-21715) add permission check to `realpath.native` (RafaelGSS) - Low * (CVE-2026-21716) include permission check on `lib/fs/promises` (RafaelGSS) - Low ### Commits * \[[`2086b7477b`](nodejs/node@2086b7477b)] - **(CVE-2026-21717)** **build,test**: test array index hash collision (Joyee Cheung) [nodejs-private/node-private#834](https://github.com/nodejs-private/node-private/pull/834) * \[[`0f9332a40a`](nodejs/node@0f9332a40a)] - **(CVE-2026-21713)** **crypto**: use timing-safe comparison in Web Cryptography HMAC and KMAC (Filip Skokan) [nodejs-private/node-private#822](https://github.com/nodejs-private/node-private/pull/822) * \[[`2b6937ddb2`](nodejs/node@2b6937ddb2)] - **deps**: update undici to 7.24.4 (Node.js GitHub Bot) [#62271](nodejs/node#62271) * \[[`bfb8ad5787`](nodejs/node@bfb8ad5787)] - **deps**: update undici to 7.24.3 (Node.js GitHub Bot) [#62233](nodejs/node#62233) * \[[`be6384727f`](nodejs/node@be6384727f)] - **deps**: upgrade npm to 11.11.1 (npm team) [#62216](nodejs/node#62216) * \[[`2feea5bb97`](nodejs/node@2feea5bb97)] - **deps**: V8: override… (truncated) ### v25.9.0 ### Notable Changes #### Test runner module mocking improvements `MockModuleOptions.defaultExport` and `MockModuleOptions.namedExports` have been consolidated into a single option `MockModuleOptions.exports` to align with user expectations and other test runners. A `default` property on `MockModuleOptions.exports` represents the default export, and own enumerable properties are treated as named exports. An automated migration is available to update user code: <https://github.com/nodejs/userland-migrations/tree/main/recipes/mock-module-exports> ```bash npx codemod @nodejs/mock-module-exports ``` Contributed by sangwook in [#61727](nodejs/node#61727). #### Other notable changes * \[[`312476cb84`](nodejs/node@312476cb84)] - **(SEMVER-MINOR)** **async\_hooks**: add using scopes to `AsyncLocalStorage` (Stephen Belanger) [#61674](nodejs/node#61674) * \[[`62d2cd473b`](nodejs/node@62d2cd473b)] - **(SEMVER-MINOR)** **cli**: add `--max-heap-size` option (tannal) [#58708](nodejs/node#58708) * \[[`d0ebf0e44b`](nodejs/node@d0ebf0e44b)] - **(SEMVER-MINOR)** **crypto**: add `TurboSHAKE` and `KangarooTwelve` Web Cryptography algorithms (Filip Skokan) [#62183](nodejs/node#62183) * \[[`f85b9d9fa8`](nodejs/node@f85b9d9fa8)] - **(SEMVER-MINOR)** **repl**: add customizable error handling (Anna Henningsen) [#62188](nodejs/node#62188) * \[[`67b854d407`](nodejs/node@67b854d407)] - **(SEMVER-MINOR)** **repl**: remove dependency on `node:domain` (Matteo Collina) [#61227](nodejs/node#61227) * \[[`966b700623`](nodejs/node@966b700623)] - **(SEMVER-MINOR)** **sea**: support code cache for ESM entrypoint in SEA (Joyee Cheung) [#62158](nodejs/node#62158) *… (truncated) ### v26.0.0 We're excited to announce the release of Node.js 26! Highlights include the Temporal API enabled by default, updates to the V8 JavaScript engine to 14.6, Undici to 8.0, and several important deprecations and removals as we continue to modernize the platform. As a reminder, Node.js 26 will enter long-term support (LTS) in October, but until then, it will be the "Current" release for the next six months. We encourage you to explore the new features and benefits offered by this latest release and evaluate their potential impact on your applications. ### Notable Changes #### Temporal API The Temporal API is now enabled by default in Node.js 26. Temporal is a modern date/time API for JavaScript that provides a more robust and feature-rich alternative to the legacy `Date` object. Contributed by Richard Lau in [#61806](nodejs/node#61806). #### V8 14.6 The V8 engine is updated to version 14.6.202.33, which is part of Chromium 134. This version also includes: * Upsert (<https://github.com/tc39/proposal-upsert>): `[Weak]Map.prototype.getOrInsert()`, `[Weak]Map.prototype.getOrInsertComputed()` * Iterator sequencing (<https://github.com/tc39/proposal-iterator-sequencing>): `Iterator.concat()` Contributed by Michaël Zasso in [#61898](nodejs/node#61898). #### Undici 8 Undici has been updated to version 8.0.2, bringing new features and improvements to Node.js's HTTP client implementation. #### Deprecations and Removals * \[[`dff46c07c3`](nodejs/node@dff46c07c3)] - **(SEMVER-MAJOR)** **crypto**: move DEP0182 to End-of-Life (Tobias Nießen) [#61084](nodejs/node#61084) * \[[`93c25815ee`](nodejs/node@93c25815ee)] - **(SEMVER-MAJOR)** **http**: move writeHeader to end-of-life (Sebastian Beltran) [#60635](nodejs/node#60635) `http.Server.prototype.writeHeader()` is now fully removed. Use `http.Server.prototype.write… (truncated) ### v26.1.0 ### Notable Changes #### Experimental `node:ffi` module Node.js now includes an experimental `node:ffi` module for loading dynamic libraries and calling native symbols from JavaScript. The API is gated behind the `--experimental-ffi` flag and, when the Permission Model is enabled, requires `--allow-ffi`. This API is inherently unsafe. Invalid pointers, incorrect signatures, or accessing memory after it has been freed can crash the process or corrupt memory. Contributed by Paolo Insogna in [#62072](nodejs/node#62072). #### Other Notable Changes * \[[`34a6454fe3`](nodejs/node@34a6454fe3)] - **(SEMVER-MINOR)** **buffer**: add `end` parameter (Robert Nagy) [#62390](nodejs/node#62390) * \[[`073e84d7fe`](nodejs/node@073e84d7fe)] - **(SEMVER-MINOR)** **crypto**: accept key data in `crypto.diffieHellman()` and cleanup DH jobs (Filip Skokan) [#62527](nodejs/node#62527) * \[[`5b9cb10a5f`](nodejs/node@5b9cb10a5f)] - **(SEMVER-MINOR)** **crypto**: implement `randomUUIDv7()` (nabeel378) [#62553](nodejs/node#62553) * \[[`98f9becd16`](nodejs/node@98f9becd16)] - **(SEMVER-MINOR)** **debugger**: add edit-free runtime expression probes to `node inspect` (Joyee Cheung) [#62713](nodejs/node#62713) * \[[`06defaa2ea`](nodejs/node@06defaa2ea)] - **(SEMVER-MINOR)** **fs**: add `signal` option to `fs.stat()` (Mert Can Altin) [#57775](nodejs/node#57775) * \[[`db66a963bf`](nodejs/node@db66a963bf)] - **(SEMVER-MINOR)** **fs**: expose `frsize` field in `statfs` (Jinho Jang) [#62277](nodejs/node#62277) * \[[`87adb3472b`](nodejs/node@87adb3472b)] - **(SEMVER-MINOR)** **http**: harden `ClientRequest` options merge (Matteo Collina) [#6… (truncated) ### v26.2.0 ### Notable Changes * \[[`189d43a193`](nodejs/node@189d43a193)] - **doc**: mark `stream.compose` stable (Matteo Collina) [#62562](nodejs/node#62562) * \[[`f858c6140e`](nodejs/node@f858c6140e)] - **(SEMVER-MINOR)** **fs**: add `Temporal.Instant` support to `Stats` and `BigIntStats` (Livia Medeiros) [#60789](nodejs/node#60789) * \[[`0cbb3895df`](nodejs/node@0cbb3895df)] - **(SEMVER-MINOR)** **http**: add `writeInformation` to send arbitrary 1xx status codes (Tim Perry) [#63155](nodejs/node#63155) ### Commits * \[[`9a394bab84`](nodejs/node@9a394bab84)] - **benchmark**: respect stream/iter broadcast backpressure (Trivikram Kamat) [#63314](nodejs/node#63314) * \[[`ad98b4620b`](nodejs/node@ad98b4620b)] - **crypto**: align verifyOneShot accepted types (Anshika Jain) [#63280](nodejs/node#63280) * \[[`ba0736a847`](nodejs/node@ba0736a847)] - **crypto**: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255) * \[[`5573a6a4a8`](nodejs/node@5573a6a4a8)] - **crypto**: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255) * \[[`7dc563b8d6`](nodejs/node@7dc563b8d6)] - **crypto**: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255) * \[[`b55e2b1f4d`](nodejs/node@b55e2b1f4d)] - **crypto**: improve system certificate enumeration logic on macOS (Robo) [#62576](nodejs/node#62576) * \[[`fd509a755a`](nodejs/node@fd509a755a)] - **crypto**: harden CryptoKey algorithm slots… (truncated) ### v26.3.0 ### Notable Changes #### Potential changes to macOS Universal Binary availability With Apple and its ecosystem progressively dropping support for Intel-based architectures, it has become apparent that the Node.js project may not be able to maintain the universal binaries we currently distribute for the full lifetime of Node.js 26. This change serves to communicate that risk. At present, our intention remains to continue shipping universal binaries supporting both Apple Silicon and Intel-based Macs for as long as practical. Contributed by Antoine du Hamel in [#63055](nodejs/node#63055). #### Other notable changes * \[[`a2a4b33dd8`](nodejs/node@a2a4b33dd8)] - **(SEMVER-MINOR)** **buffer**: increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) [#63597](nodejs/node#63597) * \[[`051a2152f7`](nodejs/node@051a2152f7)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#63527](nodejs/node#63527) * \[[`49462eca37`](nodejs/node@49462eca37)] - **(SEMVER-MINOR)** **http**: add `httpValidation` option to configure header value validation (RajeshKumar11) [#61597](nodejs/node#61597) * \[[`97b7ab19bd`](nodejs/node@97b7ab19bd)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#63079](nodejs/node#63079) * \[[`cfb80a2103`](nodejs/node@cfb80a2103)] - **(SEMVER-MINOR)** **lib,permission**: add `permission.drop` (Rafael Gonzaga) [#62672](nodejs/node#62672) ### Commits * \[[`a2a4b33dd8`](nodejs/node@a2a4b33dd8)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#63597](nodejs/node#63597) * \[[`0eff3e23b9`](https://github.com/nodejs/n… (truncated) ### v26.3.1 This is a security release. ### Notable Changes * (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High * (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High * (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium * (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium * (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium * (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium * (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium * (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low * (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low * (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low * (CVE-2026-48936) permission: guard pipe open and chmod with net scope (RafaelGSS) – Low ### Commits * \[[`98fbc89211`](nodejs/node@98fbc89211)] - **(CVE-2026-48933)** **crypto**: guard WebCrypto cipher output length (Filip Skokan) [nodejs-private/node-private#878](https://github.com/nodejs-private/node-private/pull/878) * \[[`110840f2c7`](nodejs/node@110840f2c7)] - **deps**: update llhttp to 9.4.2 (Antoine du Hamel) [nodejs-private/node-private#890](https://github.com/nodejs-private/node-private/pull/890) * \[[`8d36d522b2`](nodejs/node@8d36d522b2)] - **deps**: update undici to 8.5.0 (Node.js GitHub Bot) [#63903](nodejs/node#63903) * \[[`2e6d03993a`](nodejs/node@2e6d03993a)] - **deps**: update undici to 8.4.0 (Node.js GitHub Bot) [#63779](nodejs/node#63779) * \[[`5a17d5b07a`](nodejs/node@5a17d5b07a)] - **deps… (truncated) ### v26.4.0 ### Notable Changes * \[[`cde0daabcc`](nodejs/node@cde0daabcc)] - **(SEMVER-MINOR)** **doc**: update `blockList` stability status to release candidate (alphaleadership) [#63050](nodejs/node#63050) * \[[`b78f5a7537`](nodejs/node@b78f5a7537)] - **(SEMVER-MINOR)** **fs**: support caller-supplied `readFile()` buffers (Matteo Collina) [#63634](nodejs/node#63634) * \[[`417aacbc36`](nodejs/node@417aacbc36)] - **(SEMVER-MINOR)** **http**: close pre-request sockets in `closeIdleConnections` (semimikoh) [#63470](nodejs/node#63470) * \[[`fbb108be7d`](nodejs/node@fbb108be7d)] - **(SEMVER-MINOR)** **loader**: implement package maps (Maël Nison) [#62239](nodejs/node#62239) * \[[`45494d5a8a`](nodejs/node@45494d5a8a)] - **(SEMVER-MINOR)** **net**: support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` (Guy Bedford) [#63825](nodejs/node#63825) * \[[`ee29465e77`](nodejs/node@ee29465e77)] - **(SEMVER-MINOR)** **tls**: add certificateCompression option (Tim Perry) [#62217](nodejs/node#62217) * \[[`b17817eb2b`](nodejs/node@b17817eb2b)] - **(SEMVER-MINOR)** **vfs**: dispatch `node:fs/promises` to mounted VFS instances (Matteo Collina) [#63537](nodejs/node#63537) * \[[`7bc93a6ac5`](nodejs/node@7bc93a6ac5)] - **(SEMVER-MINOR)** **vfs**: add minimal `node:vfs` subsystem (Matteo Collina) [#63115](nodejs/node#63115) ### Commits * \[[`c7eb83b46a`](nodejs/node@c7eb83b46a)] - **benchmark**: add child\_process async path baselines (Yagiz Nizipli) [#63929](nodejs/node#63929) * \[[`066fff17a5`](https://github.com/nodejs/node/commit/066f… (truncated) ### v26.5.0 ### Notable Changes #### New release key Welcome to our newest releaser, [Stewart X Addison](https://github.com/sxa). Future Node.js releases may be signed with his [release key](https://github.com/nodejs/node/blob/main/README.md#release-keys), `655F3B5C1FB3FA8D1A0CA6BDE4A7D232B936D2FD`. #### Other notable changes * \[[`55f48446c7`](nodejs/node@55f48446c7)] - **(SEMVER-MINOR)** **buffer**: implement blob.textStream() (Matthew Aitken) [#64036](nodejs/node#64036) * \[[`b373202efc`](nodejs/node@b373202efc)] - **(SEMVER-MINOR)** **esm**: add `--experimental-import-text` flag (Efe) [#62300](nodejs/node#62300) * \[[`39e0c14455`](nodejs/node@39e0c14455)] - **(SEMVER-MINOR)** **perf\_hooks**: sample delay per event loop iteration (Pablo Erhard) [#62935](nodejs/node#62935) * \[[`999a83c937`](nodejs/node@999a83c937)] - **(SEMVER-MINOR)** **stream**: expose ReadableStreamTee (Matteo Collina) [#64195](nodejs/node#64195) * \[[`4e0236dc3d`](nodejs/node@4e0236dc3d)] - **(SEMVER-MINOR)** **tls**: report negotiated TLS groups (Filip Skokan) [#64119](nodejs/node#64119) ### Commits * \[[`87648c0a6c`](nodejs/node@87648c0a6c)] - **benchmark**: trim down the argon2 sets (Filip Skokan) [#64218](nodejs/node#64218) * \[[`a483bfd3f0`](nodejs/node@a483bfd3f0)] - **buffer**: remove unreachable overflow check in atob (haramjeong) [#60161](nodejs/node#60161) * \[[`6d14279688`](nodejs/node@6d14279688)] - **buffer**: add fast api for isUtf8 and isAscii (Gürgün Dayıoğlu) [#64169](nodejs/node#64169) * \[[`55f48446c7`](nodejs/node@55f48446c7)] -… (truncated) ### v26.5.1 This is a security release. ### Notable Changes * (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High * (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High * (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium * (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium * (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium * (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium * (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium * (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low * (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low * (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low * deps: update llhttp to 9.4.3 (Paolo Insogna) * deps: update undici to 8.9.0 (Node.js GitHub Bot) ### Commits * \[[`af0bf96877`](nodejs/node@af0bf96877)] - **deps**: update llhttp to 9.4.3 (Paolo Insogna) [nodejs-private/node-private#935](https://github.com/nodejs-private/node-private/pull/935) * \[[`0354678355`](nodejs/node@0354678355)] - **deps**: update undici to 8.9.0 (Node.js GitHub Bot) [#64712](nodejs/node#64712) * \[[`dbeeaeec13`](nodejs/node@dbeeaeec13)] - **(CVE-2026-58042)** **dns**: handle large resolveAny address replies (RafaelGSS) [nodejs-private/node-private#929](https://github.com/nodejs-private/node-private/pull/929) * \[[`064d339f56`](nodejs/node@064d339f56)] - **(CVE-2026-58044)** **http**: reject requests exceeding max header count (Matteo Collina) [nodejs-private/node-private#922](https://github.com/nodejs-private/node-private/pull/922) * \[[`23b94c843a`](https://github.… (truncated) _Omitted 12 older releases._ </details> </details> Modified files: - `.mise.toml`
jylenhof
pushed a commit
to jylenhof/mise-update-tool
that referenced
this pull request
Aug 10, 2026
Automated mise tool upgrades from local config. Updated tools: - `action-validator` - `actionlint` - `aube` - `editorconfig-checker` - `ghalint` - `node` - `pinact` - `pipx:gh-action-pulse` - `prek` - `rumdl` - `shellcheck` - `shfmt` - `tombi` - `uv` - `yamlfmt` - `yamllint` - `zizmor` Command: `mise upgrade --bump --local action-validator actionlint aube editorconfig-checker ghalint node pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor` <details> <summary>Version changelog (6 tools)</summary> | Tool | Requested | Installed | |------|-----------|-----------| | `editorconfig-checker` | `3.8.0` → `3.11.1` | `3.8.0` → `3.11.1` | | `node` | `24` → `26` | `24.19.0` → `26.7.0` | | `prek` | `0.4.11` → `0.4.12` | `0.4.11` → `0.4.12` | | `rumdl` | `0.2.49` → `0.2.52` | `0.2.49` → `0.2.52` | | `tombi` | `1.2.6` → `1.2.7` | `1.2.6` → `1.2.7` | | `uv` | `0.12.1` → `0.12.3` | `0.12.1` → `0.12.3` | </details> <details> <summary>Release notes (6 tools)</summary> <details> <summary>editorconfig-checker: `3.8.0` → `3.11.1` (editorconfig-checker/editorconfig-checker)</summary> ### v3.9.0 ## [3.9.0](editorconfig-checker/editorconfig-checker@v3.8.0...v3.9.0) (2026-07-31) ### Features * enable immutable releases ([6865c06](editorconfig-checker/editorconfig-checker@6865c06)) ### v3.10.0 ## editorconfig-checker v3.10.0 (2026-08-07T23:27:59Z) Welcome to this new release of editorconfig-checker! ## Changelog ### Others * 77a3415d6127cc892376837b85fd2a4b5c98d40d: Revert "feat(immutable-releases): set release-please to create draft releases" (@klaernie) * a85cd6ab82397f19bdd9bfa30730a487ead1ec74: chore(deps): bump docker/login-action from 4.5.2 to 4.6.0 (#590) (@dependabot[bot]) * 74cd03a2e91c1c42deff2bec2d120c06ff1be3e8: chore(main): release 3.10.0 (#588) (@editorconfig-checker-bot) * 8d4f96e7a838bfb0d8b98a40e66ce8cbd8c1e075: chore: allow triggering release-please manually (@klaernie) * a685b542509d0349ce6215adf6088a242fa93d84: feat(immutable-release): tell release-please to create draft releases (@klaernie) * 912f4a986b7da0b22cfa3a055cc24a355dee7cbc: feat(immutable-releases): ensure that despite the release being a draft the tag is created (@klaernie) * 2d48c2ecae1743614cefa660c2796e14cefd7520: feat(immutable-releases): set release-please to create draft releases (@klaernie) ## Thanks! Those were the changes on v3.10.0! ### v3.11.0 ## editorconfig-checker v3.11.0 (2026-08-08T10:40:38Z) Welcome to this new release of editorconfig-checker! ## Changelog ### Others * 174c5809baf06f2d8e82c1d2de1f6433cc569a1d: chore(main): release 3.11.0 (#592) (@editorconfig-checker-bot) * e9f143bc9d6cc5bb29030843ec42eae2a94b4dda: chore: replace deprecated goreleaser option with its current form (@klaernie) * 4c08f2ccd339734ff92f2f04d146cd91af02d225: feat(immutable-release): goreleaser should publish its release (@klaernie) ## Thanks! Those were the changes on v3.11.0! ### v3.11.1 ## [3.11.1](editorconfig-checker/editorconfig-checker@v3.11.0...v3.11.1) (2026-08-08) ### Features * **immutable-release:** tell goreleaser to use the existing draft release ([a8e6136](editorconfig-checker/editorconfig-checker@a8e6136)) </details> <details> <summary>node: `24.19.0` → `26.7.0` (nodejs/node)</summary> ### v26.0.0 We're excited to announce the release of Node.js 26! Highlights include the Temporal API enabled by default, updates to the V8 JavaScript engine to 14.6, Undici to 8.0, and several important deprecations and removals as we continue to modernize the platform. As a reminder, Node.js 26 will enter long-term support (LTS) in October, but until then, it will be the "Current" release for the next six months. We encourage you to explore the new features and benefits offered by this latest release and evaluate their potential impact on your applications. ### Notable Changes #### Temporal API The Temporal API is now enabled by default in Node.js 26. Temporal is a modern date/time API for JavaScript that provides a more robust and feature-rich alternative to the legacy `Date` object. Contributed by Richard Lau in [#61806](nodejs/node#61806). #### V8 14.6 The V8 engine is updated to version 14.6.202.33, which is part of Chromium 134. This version also includes: * Upsert (<https://github.com/tc39/proposal-upsert>): `[Weak]Map.prototype.getOrInsert()`, `[Weak]Map.prototype.getOrInsertComputed()` * Iterator sequencing (<https://github.com/tc39/proposal-iterator-sequencing>): `Iterator.concat()` Contributed by Michaël Zasso in [#61898](nodejs/node#61898). #### Undici 8 Undici has been updated to version 8.0.2, bringing new features and improvements to Node.js's HTTP client implementation. #### Deprecations and Removals * \[[`dff46c07c3`](nodejs/node@dff46c07c3)] - **(SEMVER-MAJOR)** **crypto**: move DEP0182 to End-of-Life (Tobias Nießen) [#61084](nodejs/node#61084) * \[[`93c25815ee`](nodejs/node@93c25815ee)] - **(SEMVER-MAJOR)** **http**: move writeHeader to end-of-life (Sebastian Beltran) [#60635](nodejs/node#60635) `http.Server.prototype.writeHeader()` is now fully removed. Use `http.Server.prototype.write… (truncated) ### v26.1.0 ### Notable Changes #### Experimental `node:ffi` module Node.js now includes an experimental `node:ffi` module for loading dynamic libraries and calling native symbols from JavaScript. The API is gated behind the `--experimental-ffi` flag and, when the Permission Model is enabled, requires `--allow-ffi`. This API is inherently unsafe. Invalid pointers, incorrect signatures, or accessing memory after it has been freed can crash the process or corrupt memory. Contributed by Paolo Insogna in [#62072](nodejs/node#62072). #### Other Notable Changes * \[[`34a6454fe3`](nodejs/node@34a6454fe3)] - **(SEMVER-MINOR)** **buffer**: add `end` parameter (Robert Nagy) [#62390](nodejs/node#62390) * \[[`073e84d7fe`](nodejs/node@073e84d7fe)] - **(SEMVER-MINOR)** **crypto**: accept key data in `crypto.diffieHellman()` and cleanup DH jobs (Filip Skokan) [#62527](nodejs/node#62527) * \[[`5b9cb10a5f`](nodejs/node@5b9cb10a5f)] - **(SEMVER-MINOR)** **crypto**: implement `randomUUIDv7()` (nabeel378) [#62553](nodejs/node#62553) * \[[`98f9becd16`](nodejs/node@98f9becd16)] - **(SEMVER-MINOR)** **debugger**: add edit-free runtime expression probes to `node inspect` (Joyee Cheung) [#62713](nodejs/node#62713) * \[[`06defaa2ea`](nodejs/node@06defaa2ea)] - **(SEMVER-MINOR)** **fs**: add `signal` option to `fs.stat()` (Mert Can Altin) [#57775](nodejs/node#57775) * \[[`db66a963bf`](nodejs/node@db66a963bf)] - **(SEMVER-MINOR)** **fs**: expose `frsize` field in `statfs` (Jinho Jang) [#62277](nodejs/node#62277) * \[[`87adb3472b`](nodejs/node@87adb3472b)] - **(SEMVER-MINOR)** **http**: harden `ClientRequest` options merge (Matteo Collina) [#6… (truncated) ### v26.2.0 ### Notable Changes * \[[`189d43a193`](nodejs/node@189d43a193)] - **doc**: mark `stream.compose` stable (Matteo Collina) [#62562](nodejs/node#62562) * \[[`f858c6140e`](nodejs/node@f858c6140e)] - **(SEMVER-MINOR)** **fs**: add `Temporal.Instant` support to `Stats` and `BigIntStats` (Livia Medeiros) [#60789](nodejs/node#60789) * \[[`0cbb3895df`](nodejs/node@0cbb3895df)] - **(SEMVER-MINOR)** **http**: add `writeInformation` to send arbitrary 1xx status codes (Tim Perry) [#63155](nodejs/node#63155) ### Commits * \[[`9a394bab84`](nodejs/node@9a394bab84)] - **benchmark**: respect stream/iter broadcast backpressure (Trivikram Kamat) [#63314](nodejs/node#63314) * \[[`ad98b4620b`](nodejs/node@ad98b4620b)] - **crypto**: align verifyOneShot accepted types (Anshika Jain) [#63280](nodejs/node#63280) * \[[`ba0736a847`](nodejs/node@ba0736a847)] - **crypto**: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255) * \[[`5573a6a4a8`](nodejs/node@5573a6a4a8)] - **crypto**: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255) * \[[`7dc563b8d6`](nodejs/node@7dc563b8d6)] - **crypto**: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255) * \[[`b55e2b1f4d`](nodejs/node@b55e2b1f4d)] - **crypto**: improve system certificate enumeration logic on macOS (Robo) [#62576](nodejs/node#62576) * \[[`fd509a755a`](nodejs/node@fd509a755a)] - **crypto**: harden CryptoKey algorithm slots… (truncated) ### v26.3.0 ### Notable Changes #### Potential changes to macOS Universal Binary availability With Apple and its ecosystem progressively dropping support for Intel-based architectures, it has become apparent that the Node.js project may not be able to maintain the universal binaries we currently distribute for the full lifetime of Node.js 26. This change serves to communicate that risk. At present, our intention remains to continue shipping universal binaries supporting both Apple Silicon and Intel-based Macs for as long as practical. Contributed by Antoine du Hamel in [#63055](nodejs/node#63055). #### Other notable changes * \[[`a2a4b33dd8`](nodejs/node@a2a4b33dd8)] - **(SEMVER-MINOR)** **buffer**: increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) [#63597](nodejs/node#63597) * \[[`051a2152f7`](nodejs/node@051a2152f7)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#63527](nodejs/node#63527) * \[[`49462eca37`](nodejs/node@49462eca37)] - **(SEMVER-MINOR)** **http**: add `httpValidation` option to configure header value validation (RajeshKumar11) [#61597](nodejs/node#61597) * \[[`97b7ab19bd`](nodejs/node@97b7ab19bd)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#63079](nodejs/node#63079) * \[[`cfb80a2103`](nodejs/node@cfb80a2103)] - **(SEMVER-MINOR)** **lib,permission**: add `permission.drop` (Rafael Gonzaga) [#62672](nodejs/node#62672) ### Commits * \[[`a2a4b33dd8`](nodejs/node@a2a4b33dd8)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#63597](nodejs/node#63597) * \[[`0eff3e23b9`](https://github.com/nodejs/n… (truncated) ### v26.3.1 This is a security release. ### Notable Changes * (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High * (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High * (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium * (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium * (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium * (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium * (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium * (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low * (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low * (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low * (CVE-2026-48936) permission: guard pipe open and chmod with net scope (RafaelGSS) – Low ### Commits * \[[`98fbc89211`](nodejs/node@98fbc89211)] - **(CVE-2026-48933)** **crypto**: guard WebCrypto cipher output length (Filip Skokan) [nodejs-private/node-private#878](https://github.com/nodejs-private/node-private/pull/878) * \[[`110840f2c7`](nodejs/node@110840f2c7)] - **deps**: update llhttp to 9.4.2 (Antoine du Hamel) [nodejs-private/node-private#890](https://github.com/nodejs-private/node-private/pull/890) * \[[`8d36d522b2`](nodejs/node@8d36d522b2)] - **deps**: update undici to 8.5.0 (Node.js GitHub Bot) [#63903](nodejs/node#63903) * \[[`2e6d03993a`](nodejs/node@2e6d03993a)] - **deps**: update undici to 8.4.0 (Node.js GitHub Bot) [#63779](nodejs/node#63779) * \[[`5a17d5b07a`](nodejs/node@5a17d5b07a)] - **deps… (truncated) ### v26.4.0 ### Notable Changes * \[[`cde0daabcc`](nodejs/node@cde0daabcc)] - **(SEMVER-MINOR)** **doc**: update `blockList` stability status to release candidate (alphaleadership) [#63050](nodejs/node#63050) * \[[`b78f5a7537`](nodejs/node@b78f5a7537)] - **(SEMVER-MINOR)** **fs**: support caller-supplied `readFile()` buffers (Matteo Collina) [#63634](nodejs/node#63634) * \[[`417aacbc36`](nodejs/node@417aacbc36)] - **(SEMVER-MINOR)** **http**: close pre-request sockets in `closeIdleConnections` (semimikoh) [#63470](nodejs/node#63470) * \[[`fbb108be7d`](nodejs/node@fbb108be7d)] - **(SEMVER-MINOR)** **loader**: implement package maps (Maël Nison) [#62239](nodejs/node#62239) * \[[`45494d5a8a`](nodejs/node@45494d5a8a)] - **(SEMVER-MINOR)** **net**: support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` (Guy Bedford) [#63825](nodejs/node#63825) * \[[`ee29465e77`](nodejs/node@ee29465e77)] - **(SEMVER-MINOR)** **tls**: add certificateCompression option (Tim Perry) [#62217](nodejs/node#62217) * \[[`b17817eb2b`](nodejs/node@b17817eb2b)] - **(SEMVER-MINOR)** **vfs**: dispatch `node:fs/promises` to mounted VFS instances (Matteo Collina) [#63537](nodejs/node#63537) * \[[`7bc93a6ac5`](nodejs/node@7bc93a6ac5)] - **(SEMVER-MINOR)** **vfs**: add minimal `node:vfs` subsystem (Matteo Collina) [#63115](nodejs/node#63115) ### Commits * \[[`c7eb83b46a`](nodejs/node@c7eb83b46a)] - **benchmark**: add child\_process async path baselines (Yagiz Nizipli) [#63929](nodejs/node#63929) * \[[`066fff17a5`](https://github.com/nodejs/node/commit/066f… (truncated) ### v26.5.0 ### Notable Changes #### New release key Welcome to our newest releaser, [Stewart X Addison](https://github.com/sxa). Future Node.js releases may be signed with his [release key](https://github.com/nodejs/node/blob/main/README.md#release-keys), `655F3B5C1FB3FA8D1A0CA6BDE4A7D232B936D2FD`. #### Other notable changes * \[[`55f48446c7`](nodejs/node@55f48446c7)] - **(SEMVER-MINOR)** **buffer**: implement blob.textStream() (Matthew Aitken) [#64036](nodejs/node#64036) * \[[`b373202efc`](nodejs/node@b373202efc)] - **(SEMVER-MINOR)** **esm**: add `--experimental-import-text` flag (Efe) [#62300](nodejs/node#62300) * \[[`39e0c14455`](nodejs/node@39e0c14455)] - **(SEMVER-MINOR)** **perf\_hooks**: sample delay per event loop iteration (Pablo Erhard) [#62935](nodejs/node#62935) * \[[`999a83c937`](nodejs/node@999a83c937)] - **(SEMVER-MINOR)** **stream**: expose ReadableStreamTee (Matteo Collina) [#64195](nodejs/node#64195) * \[[`4e0236dc3d`](nodejs/node@4e0236dc3d)] - **(SEMVER-MINOR)** **tls**: report negotiated TLS groups (Filip Skokan) [#64119](nodejs/node#64119) ### Commits * \[[`87648c0a6c`](nodejs/node@87648c0a6c)] - **benchmark**: trim down the argon2 sets (Filip Skokan) [#64218](nodejs/node#64218) * \[[`a483bfd3f0`](nodejs/node@a483bfd3f0)] - **buffer**: remove unreachable overflow check in atob (haramjeong) [#60161](nodejs/node#60161) * \[[`6d14279688`](nodejs/node@6d14279688)] - **buffer**: add fast api for isUtf8 and isAscii (Gürgün Dayıoğlu) [#64169](nodejs/node#64169) * \[[`55f48446c7`](nodejs/node@55f48446c7)] -… (truncated) ### v26.5.1 This is a security release. ### Notable Changes * (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High * (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High * (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium * (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium * (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium * (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium * (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium * (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low * (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low * (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low * deps: update llhttp to 9.4.3 (Paolo Insogna) * deps: update undici to 8.9.0 (Node.js GitHub Bot) ### Commits * \[[`af0bf96877`](nodejs/node@af0bf96877)] - **deps**: update llhttp to 9.4.3 (Paolo Insogna) [nodejs-private/node-private#935](https://github.com/nodejs-private/node-private/pull/935) * \[[`0354678355`](nodejs/node@0354678355)] - **deps**: update undici to 8.9.0 (Node.js GitHub Bot) [#64712](nodejs/node#64712) * \[[`dbeeaeec13`](nodejs/node@dbeeaeec13)] - **(CVE-2026-58042)** **dns**: handle large resolveAny address replies (RafaelGSS) [nodejs-private/node-private#929](https://github.com/nodejs-private/node-private/pull/929) * \[[`064d339f56`](nodejs/node@064d339f56)] - **(CVE-2026-58044)** **http**: reject requests exceeding max header count (Matteo Collina) [nodejs-private/node-private#922](https://github.com/nodejs-private/node-private/pull/922) * \[[`23b94c843a`](https://github.… (truncated) ### v26.6.0 ### Notable Changes * \[[`5a36018abc`](nodejs/node@5a36018abc)] - **doc**: add MikeMcC399 as collaborator (Mike McCready) [#64656](nodejs/node#64656) * \[[`9b04f82d7b`](nodejs/node@9b04f82d7b)] - **(SEMVER-MINOR)** **ffi**: add `getCurrentEventLoop` (Paolo Insogna) [#64323](nodejs/node#64323) * \[[`bb51f2c960`](nodejs/node@bb51f2c960)] - **(SEMVER-MINOR)** **test\_runner**: add `context.log()` and `test:log` event (Moshe Atlow) [#64389](nodejs/node#64389) * \[[`56ce83b3ee`](nodejs/node@56ce83b3ee)] - **(SEMVER-MINOR)** **test\_runner**: report `entryFile` in `TestStream` events (Moshe Atlow) [#64309](nodejs/node#64309) ### Commits * \[[`248ff9fa5c`](nodejs/node@248ff9fa5c)] - **assert,util**: fix TypeError on Maps with null keys (Paul Bouchon) [#64441](nodejs/node#64441) * \[[`3b5baceafe`](nodejs/node@3b5baceafe)] - **benchmark**: add bytes variant to webstreams async-iterator (Matteo Collina) [#64291](nodejs/node#64291) * \[[`0a46d1ef66`](nodejs/node@0a46d1ef66)] - **buffer**: normalize lone "\r" in Blob native line endings (Daijiro Wachi) [#64115](nodejs/node#64115) * \[[`d9ada18b70`](nodejs/node@d9ada18b70)] - **buffer**: fix Blob.stream() leaking source buffer (semimikoh) [#63577](nodejs/node#63577) * \[[`d05993bcf6`](nodejs/node@d05993bcf6)] - **build**: merge multiple on download artifact (Chengzhong Wu) [#64633](nodejs/node#64633) * \[[`6c25ac909a`](nodejs/node@6c25ac909a)] - **build**: extract temporal\_capi crate directory name into gyp variable (René) [#64482](https://githu… (truncated) ### v26.7.0 ### Notable Changes * \[[`58717685a1`](nodejs/node@58717685a1)] - **(SEMVER-MINOR)** **crypto**: support loading private keys through STORE loaders (Filip Skokan) [#63949](nodejs/node#63949) * \[[`44b940ee8c`](nodejs/node@44b940ee8c)] - **crypto**: update root certificates to NSS 3.125 (Node.js GitHub Bot) [#64746](nodejs/node#64746) * \[[`c1e4f7365e`](nodejs/node@c1e4f7365e)] - **(SEMVER-MINOR)** **lib**: add perfetto support (Chengzhong Wu) [#64565](nodejs/node#64565) * \[[`11c2f9c642`](nodejs/node@11c2f9c642)] - **(SEMVER-MINOR)** **module**: implement `Symbol.dispose` in `ModuleHooks` (Remco Haszing) [#63928](nodejs/node#63928) * \[[`a646319f61`](nodejs/node@a646319f61)] - **(SEMVER-MINOR)** **test\_runner**: add support for `--test-coverage-include-all` (avivkeller) [#64830](nodejs/node#64830) ### Commits * \[[`a2d3f891d3`](nodejs/node@a2d3f891d3)] - **async\_hooks**: use validateBoolean for trackPromises (Soul Lee) [#64731](nodejs/node#64731) * \[[`d7266cdd99`](nodejs/node@d7266cdd99)] - **benchmark**: fix calibrate-n option handling (Luan Muniz) [#64146](nodejs/node#64146) * \[[`2e64293e3f`](nodejs/node@2e64293e3f)] - **buffer**: use Clamp conversion in Blob slice (Donghoon Kang) [#64739](nodejs/node#64739) * \[[`5fda0958bd`](nodejs/node@5fda0958bd)] - **buffer**: validate copyArrayBuffer offsets against buffer length (Ilia Alshanetsky) [#63904](nodejs/node#63904) * \[[`5298db40f9`](nodejs/node@5298db40f9)] - **build**: run perfetto build and test on GHA (Chengzhong Wu) [#6472… (truncated) _Omitted 14 older releases._ </details> <details> <summary>prek: `0.4.11` → `0.4.12` (j178/prek)</summary> ### v0.4.12 ## Release Notes Released on 2026-08-03. ### Enhancements - Add `--require-group` for hook group intersections ([#2472](j178/prek#2472)) - Align fast-path and builtin pre-commit hooks ([#2433](j178/prek#2433)) - Do not shuffle file list for verbose output ([#2431](j178/prek#2431)) - Improve top-level command descriptions ([#2429](j178/prek#2429)) - Install `uv` from Astral CDN and drop source racing ([#2455](j178/prek#2455)) - Make `prek install --force` bypass external hooks paths ([#2437](j178/prek#2437)) - Show builtin hook flags in verbose list output ([#2427](j178/prek#2427)) - Verify uv release archive checksums ([#2456](j178/prek#2456)) ### Performance - Precompute file tags in parallel ([#2440](j178/prek#2440)) - Skip diffs after known hook modifications ([#2447](j178/prek#2447)) - Skip worktree diffs for read-only languages ([#2432](j178/prek#2432)) - Track builtin hook file changes directly ([#2404](j178/prek#2404)) ### Bug fixes - Use full object IDs in diff snapshots ([#2448](j178/prek#2448)) ### Documentation - Add a multi-repository configuration example ([#2434](j178/prek#2434)) - Rewrite benchmark documentation ([#2469](j178/prek#2469)) ### Contributors - @j178 - @BitWeaverDev - @allanlewis ## Install prek 0.4.12 ### Install prebuilt binaries via shell script ```sh curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.4.12/prek-installer.sh | sh ``` ### Install prebuilt binaries via powershell script ```sh powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.4.12/prek-installer.ps1 | iex" ```… (truncated) </details> <details> <summary>rumdl: `0.2.49` → `0.2.52` (rvben/rumdl)</summary> ### v0.2.50 ### Added - **md077**: support fixed continuation indent config (#786) ([fea6322](rvben/rumdl@fea6322)) ### Fixed - **md065**: leave markers alone inside a block that hides its content ([2654364](rvben/rumdl@2654364)) - **md065**: report thematic breaks written with spaces between markers ([1d29236](rvben/rumdl@1d29236)) - **md076**: ask the parser whether a list item's block is really fenced ([fd616c2](rvben/rumdl@fd616c2)) - **md022**: require a blank line below a heading above a spaced thematic break ([27120f2](rvben/rumdl@27120f2)) - **MD076**: preserve fenced list item spacing (#788) ([2d60067](rvben/rumdl@2d60067)) - **md022**: use the same list test below a heading in check and fix (#790) ([ef926b7](rvben/rumdl@ef926b7)) - **md040**: locate the fence a list marker holds instead of assuming the indent ([6099a6c](rvben/rumdl@6099a6c)) - **md077**: keep the strict-flavor minimum as a floor under a configured indent ([cfaad2e](rvben/rumdl@cfaad2e)) - **md077**: reject a configured indent of 0 ([1ac97a3](rvben/rumdl@1ac97a3)) - **md077**: accept the indent option instead of reporting it as unknown ([cba175c](rvben/rumdl@cba175c)) - **md013**: stop exempting a complete link followed by a parenthesized aside ([722fad6](rvben/rumdl@722fad6)) - **md013**: ke… (truncated) ### v0.2.51 ### Added - **md088**: normalize quotes and dashes to ASCII (#763) ([52e9844](rvben/rumdl@52e9844)) ### Fixed - **config**: keep a file's per-file-ignores out of the workspace index it feeds ([2bb0ce7](rvben/rumdl@2bb0ce7)) - **md051**: validate cross-file link fragments for a document read from stdin ([e215c65](rvben/rumdl@e215c65)) - **md051**: report a broken fragment on a query-string destination once ([7c8390f](rvben/rumdl@7c8390f)) - **md088**: leave modifier letters and math notation alone ([56dbf0f](rvben/rumdl@56dbf0f)) - **config**: report the effective rule lists from `config get global.*` ([5db8f0c](rvben/rumdl@5db8f0c)) - **config**: answer `config get` for every key rumdl accepts ([ecce820](rvben/rumdl@ecce820)) - **md035**: publish the horizontal rule style the rule enforces ([77c8c65](rvben/rumdl@77c8c65)) - **config**: accept every config key a rule actually reads ([8ec7bba](rvben/rumdl@8ec7bba)) - **lsp**: identify documents by the same resolved path as the index ([78f4aa0](rvben/rumdl@78f4aa0)) - **lsp**: keep frontmatter values out of find-references results ([499b005](rvben/rumdl@499b005)) - **md051**: index cross-file links independently of frontmatter config ([ca7b93e](rvben/rumdl@ca7b93e)) - **lsp**: build the workspace index from t… (truncated) ### v0.2.52 ### Fixed - **md012**: report blank lines before a code block that ends the document (#791) ([e897556](rvben/rumdl@e897556)) - **rules**: treat a template shortcode tag as opaque markup ([6962184](rvben/rumdl@6962184)) - **cli**: report a piped document's findings on stdout like every other run ([47f8a50](rvben/rumdl@47f8a50)) ## Downloads | File | Platform | Checksum | |------|----------|----------| | [rumdl-v0.2.52-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-unknown-linux-gnu.tar.gz.sha256) | | [rumdl-v0.2.52-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-unknown-linux-musl.tar.gz.sha256) | | [rumdl-v0.2.52-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-unknown-linux-gnu.tar.gz.sha256) | | [rumdl-v0.2.52-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-unknown-linux-musl.tar.gz.sha256) | | [rumdl-v0.2.52-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/r… (truncated) </details> <details> <summary>tombi: `1.2.6` → `1.2.7` (tombi-toml/tombi)</summary> ### v1.2.7 <!-- Release notes generated using configuration in .github/release.yml at v1.2.7 --> ## What's Changed ### 🦅 New Features * feat(config): support per-schema strict mode by @ya7010 in tombi-toml/tombi#2061 ### 🛠️ Other Changes * fix: improve config file load error reporting by @ya7010 in tombi-toml/tombi#2062 **Full Changelog**: tombi-toml/tombi@v1.2.6...v1.2.7 </details> <details> <summary>uv: `0.12.1` → `0.12.3` (astral-sh/uv)</summary> ### 0.12.2 ## Release Notes Released on 2026-08-05. ### Python - Add CPython 3.15.0rc1 ([#20948](astral-sh/uv#20948)) - Add CPython 3.14.7 ([#20971](astral-sh/uv#20971)) ### Enhancements - Ensure diagnostic hints end with a newline to prevent malformed terminal output ([#20959](astral-sh/uv#20959)) ### Preview features - Audit one or all installed tools with `uv tool audit` ([#20921](astral-sh/uv#20921)) - Report physically reclaimed disk space during cache cleanup with the `cache-physical-space` preview feature ([#20925](astral-sh/uv#20925)) ### Configuration - Add `UV_RUN_RLIMIT_NOFILE` to set the open-file limit for commands launched by `uv run` ([#20926](astral-sh/uv#20926)) ### Performance - Speed up `uv.lock` parsing for wheel entries ([#20881](astral-sh/uv#20881)) - Speed up `uv.lock` parsing for source distribution entries ([#20882](astral-sh/uv#20882)) - Speed up filename extraction from distribution URLs ([#20879](astral-sh/uv#20879)) - Reduce filesystem metadata lookups during bytecode compilation ([#20928](astral-sh/uv#20928)) - Reuse file metadata when building source distributions ([#20927](astral-sh/uv#20927)) ### Bug fixes - Preserve compatibility with older uv versions when recording artifact sizes in cached wheels and source distributions ([#20963](astral-sh/uv#20963)) - Avoid including workspace-root default dependency groups when syncing or exporting a selected workspace member unless explicitly requested ([#20930](astral-sh/uv#20930)) ### Documentation - Separate build and publish jobs in the GitHub Actions publishing guide ([#20946](astral-sh/uv#20946)) - Ensure the GitHub Actions publishing exampl… (truncated) ### 0.12.3 ## Release Notes Released on 2026-08-07. ### Python - Add CPython 3.13.15 ([#20997](astral-sh/uv#20997)) ### Preview features - Add `--output-format` to select automatic, human-readable, or raw-byte output for `uv cache size` ([#20992](astral-sh/uv#20992)) - Preserve JSON output from `uv workspace metadata --quiet` while suppressing diagnostics ([#20991](astral-sh/uv#20991)) - Reduce memory usage for large workspaces by streaming `uv workspace metadata` JSON output ([#20990](astral-sh/uv#20990)) ### Performance - Reduce Linux startup latency by initializing the workspace cache before spawning another thread ([#20989](astral-sh/uv#20989)) - Reuse compiled workspace exclusion patterns during workspace discovery ([#20988](astral-sh/uv#20988)) - Speed up conflict-heavy resolutions by avoiding materialized range complements ([#20982](astral-sh/uv#20982)) - Avoid slow procfs reads during Python interpreter discovery on Linux ([#20987](astral-sh/uv#20987)) ### Documentation - Add PEP 740 attestations to the GitHub Actions publishing example ([#20986](astral-sh/uv#20986)) - Restrict the GitHub Actions publishing example to Python version tags ([#20973](astral-sh/uv#20973)) - Correct `--python-pin` to `--pin-python` in the `uv init --bare` example ([#20876](astral-sh/uv#20876)) ## Install uv 0.12.3 ### Install prebuilt binaries via shell script ```sh curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.3/uv-installer.sh | sh ``` ### Install prebuilt binaries via powershell script ```sh powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.3/uv-installer.ps1 | iex" ``` ## Download uv 0.12.3 | Fi… (truncated) </details> </details> Modified files: - `.mise.toml`
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This is an automated update of root-certificates to 3.123.1.