Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
119 commits
Select commit Hold shift + click to select a range
dcaded9
src: seed V8 from the OS CSPRNG instead of OpenSSL's DRBG
colinhacks Sep 10, 2026
a0ea1d9
buffer: fix unaligned UTF-16LE decoding
mcollina Sep 10, 2026
efdc04d
doc: add inoway46 as triager
inoway46 Sep 10, 2026
6ab4e1e
test: try fixing windows build replacing WMIC
jasnell Sep 10, 2026
bf534f6
tools: fix commit queue error summary matching
panva Sep 10, 2026
9187d58
crypto: read EC curve metadata directly
panva Sep 7, 2026
2f3d342
crypto: export EC JWK coordinates directly
panva Sep 7, 2026
fead604
crypto: avoid EC raw export reconstruction
panva Sep 7, 2026
7a33e61
crypto: avoid EC reconstruction for signature sizing
panva Sep 7, 2026
9422638
test: skip C++ symbols in tick-processor-arguments
pipobscure Sep 10, 2026
bedf7e7
src: fix Stop() terminating the next Environment on the isolate
codebytere Sep 2, 2026
480710e
tools: bump js-yaml from 4.3.1 to 4.3.2 in /tools/lint-md
dependabot[bot] Sep 11, 2026
82feeab
tools: bump js-yaml from 4.3.1 to 4.3.2 in /tools/eslint
dependabot[bot] Sep 11, 2026
c0cbf01
zlib: fix zstd reset
jasnell Sep 6, 2026
6f9c1a7
doc: fill in missing zstd docs
jasnell Sep 6, 2026
7bc1586
zlib: reject invalid zstd dictionaries
jasnell Sep 6, 2026
8b1ffe7
src: keep the first snapshot blob alive for later isolates
codebytere Sep 2, 2026
0afb165
tls: defer re-entrant calls to SSL state machine from JS
pimterry Sep 11, 2026
0f5a75b
test: deflake node-api test-free-called
christianaurichzm Sep 10, 2026
f2d04f0
fs: throw on existing dir in cpSync with errorOnExist
watilde Sep 12, 2026
3ed6493
url: add Symbol.toStringTag to URLPattern
XadillaX Sep 12, 2026
6229af3
src: don't kill own process group on failed spawn
lazerg Sep 12, 2026
55153ec
stream: fix ERR_INVALID_STATE when cancelling Readable.toWeb()
richardscarrott Sep 12, 2026
db19499
stream: reject closed only after sink abort settles
lazerg Sep 12, 2026
023c32d
lib: fix for FileHandle.readableWebStream
pdaehne Jun 25, 2025
415c54e
perf_hooks: validate import normalization offset
mcollina Sep 12, 2026
bf2a8db
stream: keep webstream stream states in fast-mode objects
mcollina Aug 28, 2026
1ac4174
stream: avoid promise allocation for parked transform writes
mcollina Aug 28, 2026
2a98e70
meta: expand on collaborator restoration process
legendecas Sep 12, 2026
8de8ed7
meta: add joyeecheung as v8 currency strategic initiative champion
joyeecheung Sep 12, 2026
7721d01
assert: fix TypeError on deepStrictEqual with null Map key or Set member
semx Sep 12, 2026
d32b496
test_runner: fix quote escaping in JUnit
hanityx Sep 12, 2026
0bdf4b3
test: close WebAssembly test HTTP servers
panva Sep 11, 2026
6fb3fb9
tools: reduce test runner timing overhead
panva Sep 11, 2026
a421a74
test: avoid idle HTTP/HTTPS connections
panva Sep 11, 2026
67312ab
test: synchronize ordered runner events
panva Sep 11, 2026
f6e6ec4
test: skip retries in DNS timeout coverage
panva Sep 11, 2026
02ce44d
test: collect timeout signals explicitly
panva Sep 11, 2026
e7d2186
test: unref cancelled broadcast source timer
panva Sep 11, 2026
9b91c2e
test: overlap SLH-DSA signature checks
panva Sep 11, 2026
346a82e
benchmark: add --csv option to compare.js with --analyze
jasnell Sep 9, 2026
412d5fa
test: improve sequential test performance
jasnell Sep 9, 2026
1d20a94
test_runner: avoid reusing v8 serializers
inoway46 Sep 14, 2026
0a14c25
http2: fix onread assert when destroying session from stream handler
sankalpsthakur Sep 2, 2026
a284bca
doc: clarify permission model scope for output paths
RafaelGSS Sep 14, 2026
f8756b6
perf_hooks: reuse buffer for uv metrics
HoonDongKang Sep 14, 2026
87bc357
tools: pass author to commit message validator
panva Sep 15, 2026
f091568
test: fix stderr Buffer assertion in exec encoding test
greenheadHQ Sep 13, 2026
6ea497a
tools: make checkout credential use explicit
panva Sep 13, 2026
dbc6649
tools: correct Slack action version comments
panva Sep 13, 2026
395fece
doc: clarify QUIC async write backpressure
johnfinnerty-nz Sep 15, 2026
fa572ac
deps: update googletest to 8eff9e336692fc95961e096564f1044c600b881d
nodejs-github-bot Sep 15, 2026
d6d1516
test: prevent parser reuse across close scenarios
panva Sep 15, 2026
0af0120
lib: fix AbortSignal.any() abort propagation
inoway46 Sep 16, 2026
fbe74a4
inspector: fix abort when two Environments own the inspector
codebytere Sep 2, 2026
91953dc
doc: note that default signal handling resets the signal mask
codebytere Sep 3, 2026
019b71b
http: don't destroy socket after request completes
barathraj048 Sep 16, 2026
30d005e
src,lib: add util.markPromiseAsHandled
jasnell Sep 7, 2026
815db82
test: implement low-risk test optimizations
jasnell Sep 9, 2026
f0bd85a
perf_hooks: implement qrde analysis support in Histogram
jasnell Sep 5, 2026
835b20f
perf_hooks: implement SlidingWindowHistogram
jasnell Sep 5, 2026
a638bd8
test: expand histogram test coverage
jasnell Sep 5, 2026
65dcf65
util: implement debounce
jasnell Sep 8, 2026
56f6cb1
util: implement util.throttle
jasnell Sep 13, 2026
f24f0b6
test: deflake util.throttle tests
panva Sep 15, 2026
5b379ef
http2: settle pending write callbacks on destroy
mcollina Sep 15, 2026
60fb699
crypto: optimize and benchmark key preparation
panva Sep 9, 2026
b45e5d0
src: print exception thrown during primordial initialization
joyeecheung Sep 16, 2026
e899d0e
tls: propagate singleUse to the secure context
ViniciusDev26 Sep 17, 2026
3e4e638
stream: update broadcast to retain buffered data with zero consumers
jasnell Aug 30, 2026
1942f10
stream: make share budget failures detach before throwing
jasnell Aug 30, 2026
c83778c
doc: remove obsolete mentioning of cl.exe on windows
legendecas Sep 17, 2026
cf31899
build: derive V8_LOGGING_LEVEL from dcheck_always_on
joyeecheung Sep 17, 2026
7278aed
test: unskip `test-watch-create-isolation-none`
aduh95 Sep 17, 2026
62b7303
tools: update pgo build doc for linux
legendecas Sep 17, 2026
0daf687
meta: bump github/codeql-action/autobuild from 4.37.9 to 4.38.0
dependabot[bot] Sep 18, 2026
82e2e99
meta: bump github/codeql-action/analyze from 4.37.9 to 4.38.0
dependabot[bot] Sep 18, 2026
cab61dc
meta: bump github/codeql-action/init from 4.37.9 to 4.38.0
dependabot[bot] Sep 18, 2026
6cf0c97
tools: bump the eslint group in /tools/eslint with 6 updates
dependabot[bot] Sep 18, 2026
c8f9e82
sqlite: throw on invalid URL path instead of abort
araujogui Sep 18, 2026
7c57ab8
stream: destroy Duplex.from async function on early return
ac-mmi Sep 18, 2026
47741f8
fs: coerce FileHandle.read length like fs.read
xia-chao Sep 18, 2026
301d896
child_process: clear timeout timer on spawn-time error too
kishore280 Sep 18, 2026
2d42b03
doc: clarify sub-1000ms behavior in socket.setKeepAlive
haramj Sep 18, 2026
c0e8274
build: suppress OpenSSL asm warnings with clang
richardlau Sep 14, 2026
269adc3
quic: fix two small bugs in HTTP/3 stream internals
pimterry Sep 10, 2026
9d54c4b
tools: summarize auto-start-ci failures
panva Sep 18, 2026
a7cde45
tools: group CodeQL GHA updates
aduh95 Sep 18, 2026
2f496c9
doc: fix duplicate 'the' typo in `node_platform.cc`
almuzahidseyam Sep 18, 2026
6676b65
meta: bump github/codeql-action/upload-sarif from 4.37.9 to 4.38.0
dependabot[bot] Sep 18, 2026
8c1f341
meta: bump step-security/harden-runner from 2.21.0 to 2.21.1
dependabot[bot] Sep 18, 2026
e3915c2
doc: add araujogui to collaborators
araujogui Sep 17, 2026
bb9e733
test: deflake test-run-watch-cwd-isolation-none-*
aduh95 Sep 18, 2026
1838a4e
trace_events: fix abort when Node.js does not own the V8 platform
codebytere Sep 18, 2026
794e045
tools: bump eslint-plugin-jsdoc in /tools/eslint in the eslint group
dependabot[bot] Sep 20, 2026
ae17af6
crypto: read RSA-PSS restrictions from provider
panva Sep 8, 2026
d021bd6
tools: update `tools/v8` for Python 3.13
richardlau Sep 20, 2026
3be217e
test: update tests to run with OpenSSL >= 3.0 FIPS mode
panva Aug 2, 2026
6bbcbbc
crypto: disable non-FIPS WebCrypto paths in FIPS mode
panva Aug 11, 2026
b7d42af
lib: use Web IDL interface brand checks
panva Sep 8, 2026
936824f
lib: fix shared buffer growability validation
panva Sep 9, 2026
839498a
lib: avoid repeat internal receiver checks
panva Sep 10, 2026
80798e3
crypto: optimize private EC JWK import
panva Sep 7, 2026
968f6e1
test: use named parameters in DH stress test
panva Sep 11, 2026
536c80b
test: reuse fixed primes in DH tests
panva Sep 11, 2026
8680c7a
test: fix RSA/DSA wrong-passphrase flake
panva Sep 14, 2026
0a757ee
crypto: add Hybrid KEMs to Web Cryptography
panva Sep 5, 2026
d2876ac
test,benchmark: use OpenSSL feature helpers
panva Sep 5, 2026
312b9ee
doc,test: account for OpenSSL 4.1 behaviours
panva Sep 12, 2026
14720a2
crypto: add crypto.parsePKCS12()
bmuenzenmeyer Sep 12, 2026
96eb82d
crypto: use names for asymmetric key algorithms
panva Sep 17, 2026
e5bbf61
test: deflake user timing WPT assertions
panva Sep 18, 2026
06dcf91
crypto: derive keys through EVP_KDF
panva Sep 18, 2026
1e1681d
crypto: decode PKCS#1 keys through providers
panva Sep 18, 2026
c172d1e
crypto: fetch ciphers for private-key encoding
panva Sep 18, 2026
4886674
crypto: use provider EC group names
panva Sep 18, 2026
1e052ca
crypto: skip private RSA parameters in key details
panva Sep 7, 2026
06bbcb3
test: consolidate crypto provider cache coverage
panva Sep 18, 2026
3b4cc93
crypto: remove redundent `std::move` call
aduh95 Sep 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
5 changes: 5 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,11 @@ updates:
commit-message:
prefix: meta
open-pull-requests-limit: 10
groups:
codeql-action:
applies-to: version-updates
patterns:
- github/codeql-action

- package-ecosystem: npm
directory: /tools/eslint
Expand Down
8 changes: 5 additions & 3 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,18 +25,20 @@ jobs:
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
with:
languages: ${{ matrix.language }}
config-file: ./.github/codeql-config.yml

- name: Autobuild
uses: github/codeql-action/autobuild@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
uses: github/codeql-action/autobuild@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
with:
category: /language:${{matrix.language}}
6 changes: 5 additions & 1 deletion .github/workflows/commit-lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,11 @@ jobs:
'--no-validate-metadata', '--tap', '-',
], {
cwd: process.env.RUNNER_TEMP,
input: Buffer.from(JSON.stringify([{ id: commit.sha, message: commit.commit.message }])),
input: Buffer.from(JSON.stringify([{
id: commit.sha,
message: commit.commit.message,
author: commit.commit.author,
}])),
silent: true,
ignoreReturnCode: true,
});
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/commit-queue.yml
Original file line number Diff line number Diff line change
Expand Up @@ -188,6 +188,7 @@ jobs:
# to be set here because `checkout` configures GitHub authentication
# for push as well.
token: ${{ secrets.GH_USER_TOKEN }}
persist-credentials: true

- name: Start the Commit Queue
if: steps.get_mergeable_prs.outputs.numbers != ''
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/notify-on-push.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:
runs-on: ubuntu-24.04-arm
steps:
- name: Slack Notification
uses: rtCamp/action-slack-notify@33ca3be66c6f378fe1610fd1d5258632dbed5e58 # 2.4.0
uses: rtCamp/action-slack-notify@33ca3be66c6f378fe1610fd1d5258632dbed5e58 # v2.4.0
env:
SLACK_COLOR: '#DE512A'
SLACK_ICON: https://github.com/nodejs.png?size=48
Expand Down Expand Up @@ -50,7 +50,7 @@ jobs:
COMMITS: ${{ toJSON(github.event.commits) }}
- name: Slack Notification
if: ${{ failure() && steps.commit-check.conclusion == 'failure' && github.repository == 'nodejs/node' }}
uses: rtCamp/action-slack-notify@33ca3be66c6f378fe1610fd1d5258632dbed5e58 # 2.4.0
uses: rtCamp/action-slack-notify@33ca3be66c6f378fe1610fd1d5258632dbed5e58 # v2.4.0
env:
SLACK_COLOR: '#DE512A'
SLACK_ICON: https://github.com/nodejs.png?size=48
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/notify-on-review-wanted.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ jobs:
fi

- name: Slack Notification
uses: rtCamp/action-slack-notify@33ca3be66c6f378fe1610fd1d5258632dbed5e58 # 2.4.0
uses: rtCamp/action-slack-notify@33ca3be66c6f378fe1610fd1d5258632dbed5e58 # v2.4.0
env:
MSG_MINIMAL: actions url
SLACK_COLOR: '#3d85c6'
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ jobs:

steps:
- name: Harden Runner
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs

Expand Down Expand Up @@ -76,6 +76,6 @@ jobs:

# Upload the results to GitHub's code scanning dashboard.
- name: Upload to code-scanning
uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
with:
sarif_file: results.sarif
17 changes: 1 addition & 16 deletions BUILDING.md
Original file line number Diff line number Diff line change
Expand Up @@ -776,16 +776,7 @@ Follow <https://github.com/ccache/ccache/wiki/MS-Visual-Studio>, and you
should notice that obj file will be bigger than the normal one.

First, install ccache. Assuming the installation of ccache is in `c:\ccache`
(where you can find `ccache.exe`), copy `c:\ccache\ccache.exe` to `c:\ccache\cl.exe`
with this command.

```powershell
cp c:\ccache\ccache.exe c:\ccache\cl.exe
```

With newer version of Visual Studio, it may need the copy to be `clang-cl.exe`
instead. If the output of `vcbuild.bat` suggests missing `clang-cl.exe`, copy
it differently:
(where you can find `ccache.exe`), setup aliases as the following commands:

```powershell
cp c:\ccache\ccache.exe c:\ccache\clang-cl.exe
Expand All @@ -800,12 +791,6 @@ When building Node.js, provide a path to your ccache via the option:
This will allow for near-instantaneous rebuilds when switching branches back
and forth that were built with cache.

To use it with ClangCL, run this instead:

```powershell
.\vcbuild.bat clang-cl ccache c:\ccache\
```

### Android

Android is not a supported platform. Patches to improve the Android build are
Expand Down
30 changes: 29 additions & 1 deletion GOVERNANCE.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@
* [Ideal Nominees](#ideal-nominees)
* [Nominating a new Collaborator](#nominating-a-new-collaborator)
* [Onboarding](#onboarding)
* [Restoring emeritus Collaborators](#restoring-emeritus-collaborators)
* [Consensus seeking process](#consensus-seeking-process)

<!-- /TOC -->
Expand Down Expand Up @@ -68,7 +69,8 @@ See:
* Merging pull requests

The TSC can remove inactive collaborators or provide them with _emeritus_
status. Emeriti may request that the TSC restore them to active status.
status. Emeriti may request that the TSC restore them to active status. See
[Restoring emeritus Collaborators](#restoring-emeritus-collaborators).

A collaborator is automatically made emeritus (and removed from active
collaborator status) if it has been more than 12 months since the collaborator
Expand Down Expand Up @@ -335,6 +337,29 @@ After the nomination passes, a TSC member onboards the new collaborator. See
[the onboarding guide](./onboarding.md) for details of the onboarding
process.

### Restoring emeritus Collaborators

An emeritus collaborator who has resumed contributing may request restoration to
active status by opening an issue in [the TSC issue tracker][]. The request
describes their recent contributions and their intent to take on collaborator
responsibilities again. There is no new nomination and no vote. The request
stays open for one week, matching the window for a collaborator nomination. If
no TSC member objects, the request passes.

Before restoring access, a TSC member confirms that the account making the
request is still under the control of the same person. See
[The Authenticity of Contributors](#the-authenticity-of-contributors).

After the request passes, a TSC member re-onboards the returning collaborator,
reversing the applicable
[offboarding tasks](./doc/contributing/offboarding.md). As in
[the onboarding guide][], the returning collaborator authors the pull request
moving themselves from the emeriti list back to the active list in the README.
That restarts the activity clock the [inactive collaborator workflow][] measures.

An emeritus TSC member returning as a collaborator rejoins the TSC through a TSC
motion under [Section 3 of the TSC Charter][TSC Charter].

## Consensus seeking process

The TSC follows a [Consensus Seeking][] decision-making model per the
Expand All @@ -343,5 +368,8 @@ The TSC follows a [Consensus Seeking][] decision-making model per the
[Consensus Seeking]: https://en.wikipedia.org/wiki/Consensus-seeking_decision-making
[TSC Charter]: https://github.com/nodejs/TSC/blob/HEAD/TSC-Charter.md
[discussion in the nodejs/collaborators]: https://github.com/nodejs/collaborators/discussions/categories/collaborator-nominations
[inactive collaborator workflow]: https://github.com/nodejs/node/blob/HEAD/.github/workflows/find-inactive-collaborators.yml
[nodejs/help]: https://github.com/nodejs/help
[nodejs/node]: https://github.com/nodejs/node
[the TSC issue tracker]: https://github.com/nodejs/TSC/issues
[the onboarding guide]: ./onboarding.md#exercise-make-a-pull-request-adding-yourself-to-the-readme
4 changes: 4 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -285,6 +285,8 @@ For information about the governance of the Node.js project, see
**Antoine du Hamel** <<duhamelantoine1995@gmail.com>> (he/him) - [Support me](https://github.com/sponsors/aduh95)
* [anonrig](https://github.com/anonrig) -
**Yagiz Nizipli** <<yagiz@nizipli.com>> (he/him) - [Support me](https://github.com/sponsors/anonrig)
* [araujogui](https://github.com/araujogui) -
**Guilherme Araújo** <<arauujogui@gmail.com>> (he/him)
* [atlowChemi](https://github.com/atlowChemi) -
**Chemi Atlow** <<chemi@atlow.co.il>> (he/him)
* [avivkeller](https://github.com/avivkeller) -
Expand Down Expand Up @@ -761,6 +763,8 @@ maintaining the Node.js project.
**Wiyeong Seo** <<hbsps.dev@gmail.com>>
* [iam-frankqiu](https://github.com/iam-frankqiu) -
**Frank Qiu** <<iam.frankqiu@gmail.com>> (he/him)
* [inoway46](https://github.com/inoway46) -
**Yuya Inoue** <<inoueyuya416@gmail.com>> (he/him)
* [milesguicent](https://github.com/milesguicent) -
**Miles Guicent** <<guicent@pm.me>> (he/him)
* [preveen-stack](https://github.com/preveen-stack) -
Expand Down
10 changes: 9 additions & 1 deletion SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -500,7 +500,15 @@ The following are **not** vulnerabilities in Node.js:
* **Operator-controlled flags**: Behavior unlocked by flags the operator
explicitly passes (e.g., `--localstorage-file`) is the operator's
responsibility. The permission model does not restrict how Node.js behaves
when the operator intentionally configures it.
when the operator intentionally configures it. This includes any file or
resource that Node.js itself creates, writes, or reads at a location the
operator selected through a flag, including every path derived from a
template or pattern in that flag. For example, trace files rotated by
`--trace-event-file-pattern` (`${rotation}`) being written without a
matching `--allow-fs-write` entry is not a permission model bypass. Such
paths are part of the operator's configuration, not application file-system
access. Inconsistent checks on these paths are treated as regular bugs and
should be reported through the public issue tracker.

* **`node:sqlite` and the permission model**: `DatabaseSync` operates with the
same file-system privileges as the process. Using SQL pragmas or built-in
Expand Down
Loading
Loading