Weekly Project News

Archives
Subscribe

Weekly GitHub Report for Node: September 21, 2026 - September 28, 2026 (20:38:50)

Weekly GitHub Report for Node

Thank you for subscribing to our weekly newsletter! Each week, we deliver a comprehensive summary of your GitHub project's latest activity right to your inbox, including an overview of your project's issues, pull requests, contributors, and commit activity.


Table of Contents

  • I. News
    • 1.1. Recent Version Releases
    • 1.2. Other Noteworthy Updates
  • II. Issues
    • 2.1. Top 5 Active Issues
    • 2.2. Top 5 Stale Issues
    • 2.3. Open Issues
    • 2.4. Closed Issues
    • 2.5. Issue Discussion Insights
  • III. Pull Requests
    • 3.1. Open Pull Requests
    • 3.2. Closed Pull Requests
    • 3.3. Pull Request Discussion Insights
  • IV. Contributors
    • 4.1. Contributors

I. News

1.1 Recent Version Releases:

The current version of this repository is v23.10.0

1.2 Version Information:

Released on March 13, 2025, this version introduces the --experimental-config-file feature, allowing developers to use JSON configuration files to simplify flag management for the test runner and other experimental features, enhancing developer experience. Additionally, it includes updates to root certificates, new TLS and V8 methods, improved error handling, and various tooling and documentation enhancements.

II. Issues

2.1 Top 5 Active Issues:

We consider active issues to be issues that that have been commented on most frequently within the last week. Bot comments are omitted.

  1. fetch() and http.request() disagree when a lower-cased proxy env var is empty: This issue describes an inconsistency between fetch() and http.request() in Node.js when handling proxy environment variables that have a lower-cased variable set to an empty string and an upper-cased counterpart set to a proxy URL. The problem arises because http.request() uses a logical OR (||) to select the proxy variable, causing it to fall back to the upper-cased variable when the lower-cased one is empty, while fetch() uses nullish coalescing (??), treating the empty lower-cased variable as an explicit override, leading to conflicting proxy usage behavior.

    • The comments discuss the root cause and potential fixes, with the original reporter offering a patch that aligns the behavior by changing || to ?? in the built-in HTTP implementation to match fetch(). There is a request for maintainer preference on which interpretation to adopt, and a PR has been submitted to address the inconsistency, with recommendations to follow established proxy handling practices similar to curl.
    • Number of comments this week: 4
  2. [STALE] SEA: embedder main cannot dynamically import non-builtin modules on Node 25.5+: This issue reports a regression in Node.js versions 25.5 and above where the SEA embedder main process cannot dynamically import non-builtin modules, causing dynamic import() and require() calls on user scripts to fail with an ERR_UNKNOWN_BUILTIN_MODULE error. The problem breaks the established pattern of SEA mains handing off control to user entrypoints on disk, and a workaround involving a vm.Script with a special dynamic import loader is suggested while a proper fix involving configuration options is being discussed.

    • The comments discuss a user-space workaround using vm.USE_MAIN_CONTEXT_DEFAULT_LOADER to enable dynamic imports with top-level await, acknowledge the regression introduced by recent changes, and propose gating the fix behind an explicit configuration flag in the SEA config to allow dynamic imports from the filesystem, with ongoing work to implement and review this solution.
    • Number of comments this week: 3
  3. [FEATURE REQUEST] [ALPINE] Promote Alpine Linux out of experimental to be a tier 2 platform: This issue proposes promoting Alpine Linux builds from experimental status to a formal Tier 2 platform in the Node.js release process, primarily due to significant user demand and the need for timely security updates and consistent release cycles. It also calls for volunteers to maintain the platform, handle failures, and ensure alignment between CI and build environments, while discussing the scope of architectures to include and the creation of a dedicated Alpine platform team.

    • The comments include clarifications on current testing coverage (x64 only), discussions about the need for a dedicated Alpine team, offers from volunteers to help triage Alpine-specific issues, considerations about Alpine version lifecycles relative to Node.js releases, and updates on progress such as the creation of the Alpine team and the promotion of Alpine x64 builds to Tier 2, while arm64 remains experimental; there is also ongoing discussion about whether to keep the issue open and the importance of supporting ARM architectures equally.
    • Number of comments this week: 3
  4. [V8 ENGINE] Worker with large inline source map aborts process in V8 HandleDebugMagicComments: This issue describes a problem where a worker thread in Node.js aborts the entire process with an out-of-memory fatal error when loading a module containing a very large inline source map comment, due to V8's inability to handle the large data URL during parsing and internalization. The expected behavior is for the worker to fail gracefully without crashing the whole Node.js process, but currently, the large inline source map causes V8 to exhaust heap memory and trigger a fatal error during compilation.

    • The comments confirm the issue is an out-of-memory error occurring inside V8's parsing phase, making it unrecoverable by Node.js itself. A fix is being developed and reviewed upstream in V8 to address the problem by improving how large debug magic comments are handled during parsing and compilation.
    • Number of comments this week: 2
  5. [MODULE] [DEPRECATIONS] Describe alternatives to require.extensions: This issue discusses the deprecation of require.extensions in Node.js and the lack of clear alternatives for loading custom file extensions, particularly in the context of TypeScript support. The user requests either the reintroduction of require.extensions or a detailed description of proper alternatives, highlighting the challenges faced by the community due to the premature deprecation without a production-ready replacement.

    • The comments emphasize the need for a replacement mechanism such as loaders (like ESM), express frustration over the absence of a sanctioned alternative, and discuss the complexity added by recent changes in TypeScript handling; overall, there is a consensus that deprecation without a clear workaround is problematic and burdensome.
    • Number of comments this week: 1

2.2 Top 5 Stale Issues:

We consider stale issues to be issues that has had no activity within the last 30 days. The team should work together to get these issues resolved and closed as soon as possible.

As of our latest update, there are no stale issues for the project this week.

2.3 Open Issues

This section lists, groups, and then summarizes issues that were created within the last week in the repository.

Issues Opened This Week: 32

Summarized Issues:

  • ICU and Timezone Handling Issues: Multiple issues describe problems with ICU and timezone data handling, including failures to load timezone information in small ICU builds causing internal errors, and Intl.DateTimeFormat().resolvedOptions().timeZone returning undefined when the TZ environment variable is set to a POSIX offset string. These bugs lead to unexpected behavior in date/time functions and errors in Temporal.Instant.from usage.
  • [issues/66184, issues/66251]
  • Virtual File System (VFS) Bugs: Several issues report bugs in the VFS subsystem, such as RealFSProvider returning incorrect paths when recursively creating directories, failure to register listener callbacks causing process hangs, stale file handle content after file modifications, and incorrect promise resolution in promises.watch() with pre-aborted signals. These problems cause incorrect file system behavior, resource leaks, and unexpected process states.
  • [issues/66220, issues/66223, issues/66253, issues/66355]
  • Foreign Function Interface (FFI) Enhancements and Bugs: Issues cover proposals and bugs in the FFI module, including allowing safe integer numbers as int64/uint64 arguments without explicit BigInt conversion, adding support for creating callable JS functions from native pointers, a segmentation fault on macOS when closing dynamic libraries, and skipping BigInt range validation in optimized calls. These affect usability, stability, and correctness of native interop.
  • [issues/66198, issues/66272, issues/66367, issues/66370]
  • Watch and Test Runner Problems: Multiple issues describe problems with the watch subsystem and test runner, such as frequent restarts on Windows due to access-time updates, corrupted NODE_OPTIONS environment variables causing child process failures, failure to recognize underscore aliases leading to recursive spawning, and the --test-force-exit option not terminating tests with open child processes. These cause instability and unexpected behavior during development workflows.
  • [issues/66256, issues/66362, issues/66364, issues/66336]
  • HTTP and Network Module Inconsistencies and Bugs: Issues include inconsistent proxy environment variable interpretation between fetch() and http.request(), failure to send RST_STREAM frames on aborted HTTP/2 streams, and a proposed option to opt out of closing idle keep-alive connections during server shutdown. These affect network request handling and graceful shutdown behavior.
  • [issues/66202, issues/66306, issues/66274]
  • Filesystem Operation Failures and Crashes: Several issues report critical bugs such as an unbounded retry loop causing spinlocks when using fs.mkdir recursively on Linux, a heap buffer overflow in fs.readFileSync when reading from pipes with multiple short reads, and test failures on macOS due to socket path length limits. These lead to hangs, crashes, and test instability.
  • [issues/66268, issues/66341, issues/66324]
  • Regular Expression and Buffer Bugs: Issues describe a bug in RegExp modifier groups causing incorrect case sensitivity under certain conditions, and a bug in Buffer.prototype.indexOf returning incorrect negative positions for matches beyond 2 GiB, causing downstream failures and crashes. These affect pattern matching correctness and buffer operations.
  • [issues/66277, issues/66294]
  • Process and Environment Variable Handling Issues: Problems include misleading timeout messages blaming the main thread when a blocked Worker thread is responsible, lack of documentation on process.loadEnvFile() behavior with existing environment variables, and failure to resolve real paths inside Windows AppContainers due to permission errors. These cause confusion, incorrect diagnostics, and startup failures.
  • [issues/66360, issues/66315, issues/66375]
  • Stream and Async Iterator Bugs: Issues report data loss in QuicStream due to lazy reader allocation destroying streams before data is read, and a regression causing unhandled AbortErrors when using Duplex.from with async functions that do not consume input. These cause data loss and compatibility breaks in stream handling.
  • [issues/66347, issues/66349]
  • V8 and Wasm Stability Issues: A V8 bug causing CHECK failures related to wasm code deallocation during shared memory usage with wasm-bindgen modules leads to intermittent process aborts on Linux runners, with the fix upstream but not backported. This affects stability in wasm-enabled environments.
  • [issues/66366]
  • AbortController and Memory Retention: A proposal to eagerly format default abort reasons in AbortController aims to reduce memory retention caused by unformatted error stacks by reading stack traces immediately upon abort. This would improve memory usage during cancellation scenarios.
  • [issues/66192]

2.4 Closed Issues

This section lists, groups, and then summarizes issues that were closed within the last week in the repository. This section also links the associated pull requests if applicable.

Issues Closed This Week: 61

Summarized Issues:

  • Buffer and Encoding Issues: The buffer.indexOf method behaves incorrectly when searching with UTF-16LE encoding starting at an odd byte offset, as it aligns offsets to even byte boundaries internally, conflicting with documented behavior. This causes failure to find expected substrings in buffers containing UTF-16LE strings starting at odd offsets.
    • issues/26448
  • Build and Architecture Compatibility: Recent changes to dependencies like zlib broke Node.js builds for x86 architectures, which, although unofficially supported, still require fixes to restore compatibility. Additionally, build failures occur with features like Temporal when configured with shared or no ICU due to missing headers and unresolved references.
    • issues/33019, issues/62676
  • HTTP and HTTPS Request Handling Bugs: Passing a URL instance with the CONNECT method to http.request() results in an invalid request path with a leading slash, violating HTTP specs and requiring manual workarounds. Also, https.get and https.request behave inconsistently with the same options, where https.request may hang or error due to missing req.end().
    • issues/34347, issues/45014
  • Performance and Optimization Concerns: The TextDecoder implementation in Node.js is significantly slower than in other environments, prompting exploration of optimizations. There is also an ongoing effort to implement Profile Guided Optimization (PGO) in CI release jobs to improve Windows build runtime performance.
    • issues/39879, issues/61964
  • Error Handling and Class Extension Issues: The native fs module improperly extends the native Error class by dynamically adding a code property instead of using a custom error class, complicating linting and testing. Additionally, bugs exist in abort listener disposal and worker thread event listener cleanup due to improper event handling or typos.
    • issues/40232, issues/65637, issues/65782
  • Platform-Specific Crashes and Errors: On arm64 macOS, perf_hooks.performance.timerify() causes a RangeError due to invalid histogram input. Node.js v20.11.1 crashes on macOS with parallel dynamic imports due to cache-related errors. A fatal error occurs on Linux with a proof-of-concept script causing a V8 ToLocalChecked failure. Also, a crash occurs in v24.5.0 when using https after rewriting Array.prototype.
    • issues/41641, issues/52187, issues/56531, issues/66205
  • Cryptography API Bugs and Feature Requests: Exceptions and segmentation faults occur with privateEncrypt and privateDecrypt using certain ciphers, with many algorithms unsupported or causing crashes. Proposals include adding a reset method to crypto.Hash for efficient reuse and extending AEAD algorithms to support multiple setAAD() calls for better authentication handling. Cached cipher lists are not invalidated after setFips() or setEngine(), causing stale results.
    • issues/45292, issues/45031, issues/48314, issues/62982
  • File System and Watcher Issues: The --watch feature monitors inodes rather than files, failing to detect replaced files such as those recreated by Docker Compose, and an infinite loop occurs when using NODE_OPTIONS=--watch. A bug in fs.globSync() causes incorrect directory entries when using withFileTypes and exclude with a custom cwd. Also, a bug causes file descriptor 0 to not be properly closed due to a falsy check.
    • issues/51621, issues/61740, issues/63535, issues/57905
  • Module and Package Resolution Bugs: Package map entries with directory-form URLs fail to match files within those directories due to inconsistent path normalization, causing module resolution errors. Yarn Plug'n'Play dependencies have undefined require.cache and require.extensions, breaking builds in tools like webpack-cli.
    • issues/66043, issues/64709
  • Compression and Streaming Bugs: The zlib zstd compressor produces undecodable streams when reset() is called immediately after flush(), silently corrupting output. The Brotli compressor loses custom quality and dictionary settings if reset() is called before any data is written, reverting to defaults without error.
    • issues/66087, issues/66156
  • Node.js Core and Event Loop Behavior Changes: Starting in Node.js v26.4.0, the micro tasks queue is not automatically executed after returning from native modules, causing event loop blocking with pending Promise handlers and process.nextTick callbacks, notably affecting mocha tests with NAN native modules.
    • issues/66158
  • Windows Installer and Environment Issues: The Windows MSI installer incorrectly replaces the inherited access control entry for "ALL APPLICATION PACKAGES," causing sandboxed AppContainer processes to lose permissions. The Windows installer also adds a malformed trailing double quote to the system PATH, breaking commands like npx. Additionally, spawning child processes with stdio: 'pipe' or 'ipc' inside Windows AppContainers causes hangs and 100% CPU usage due to libuv pipe naming bugs.
    • issues/63590, issues/66357, issues/66374
  • Configuration and Diagnostics Improvements: Proposals include removing redundant namespace prefixes in config schema keys to simplify configuration and adding an opt-in suppression mechanism in diagnostics_channel to prevent recursive subscriber calls, improving performance and coordination among APM agents.
    • issues/60904, issues/63623
  • SQLite and Web Storage Bugs: SQLite connections leak when database initialization fails in the Web Storage implementation, increasing open file descriptors. A bug in the sqlite subsystem causes virtual-table cursor re-filtering to discard generators without cleanup, leading to resource leaks. Exposing SQLite virtual table API bindings is requested to enable virtual table creation.
    • issues/64640, issues/66193, issues/61539
  • Miscellaneous Bugs and Proposals: Other issues include a flaky benchmark crypto test failure, a bug causing assertion failure with negative zero file paths, a crash when setting Error.stackTraceLimit too high with --trace-uncaught, and proposals to enhance util.inspect() to show suppressed errors. There are also reports of excessive debug logs from doc-kit and incomplete diagnostic reports when Worker threads block synchronous native calls.
    • issues/52690, issues/65886, issues/66074, issues/66033, issues/66290, issues/66303

2.5 Issue Discussion Insights

This section will analyze the tone and sentiment of discussions within this project's open and closed issues that occurred within the past week. It aims to identify potentially heated exchanges and to maintain a constructive project environment.

Based on our analysis, there are no instances of toxic discussions in the project's open or closed issues from the past week.


III. Pull Requests

3.1 Open Pull Requests

This section provides a summary of pull requests that were opened in the repository over the past week. The top three pull requests with the highest number of commits are highlighted as 'key' pull requests. Other pull requests are grouped based on similar characteristics for easier analysis. Up to 25 pull requests are displayed in this section, while any remaining pull requests beyond this limit are omitted for brevity.

Pull Requests Opened This Week: 93

Key Open Pull Requests

1. test: fix timing and environment flakes: This pull request addresses and fixes timing and environment-related flakes in various Node.js tests—including inspector/debugger, HTTP, ESM loader, watch, cluster, and styleText tests—by removing flaky expectations and stale configurations, with verification through repeated local runs on macOS arm64 and Windows x64 platforms.

  • URL: pull/66320
  • Associated Commits: 30dd6, c81cd, 924f8, d494c, 97371, ba3fc, 26b5e, 138db, 11d76

2. src: compress ICU data into a shared cache file: This pull request introduces an optional feature to compress the ICU data file into a zstd-compressed shared cache file that is decompressed and memory-mapped at startup to reduce binary size and maintain clean, shareable pages across processes, while ensuring data integrity through SHA-256 verification and falling back to the original uncompressed data if necessary.

  • URL: pull/66211
  • Associated Commits: 34ea2, b094e, 8afd2, 465e7, 9ce7f, 8e075, 248ac

3. [v22.x] deps: update sqlite to 3.53.4: This pull request updates the SQLite dependency in the v22.x branch from version 3.51.3 to 3.53.4 to align with the main branch, incorporating important upstream fixes including FTS5 bounds checks that address security vulnerabilities CVE-2026-11822 and CVE-2026-11824.

  • URL: pull/66246
  • Associated Commits: c70cb, 1b70c, ee285, 7709f, 32606, 077d7

Other Open Pull Requests

  • Web Worker Specification Fixes: This pull request fixes five deviations in the Web Worker implementation from the HTML and Web IDL specifications by correcting postMessage() overload resolution, argument conversion in importScripts(), and preserving serialization errors after worker exit. It also discards queued messages on terminate() while allowing the current event to finish, ensuring compliance with the specifications.
    pull/66354
  • V8 Engine Stack Frame Optimization Backport: This pull request backports several V8 engine stack frame optimization changes to the v24.x branch, improving stack trace capture performance and correctness. These changes address related issues such as Node.js issue 64879 to enhance debugging reliability.
    pull/66241
  • Crypto and Filesystem Encoding Validation: This pull request improves the Node.js crypto and filesystem modules by rejecting invalid or unknown input and output encodings in various methods, preventing silent fallback to defaults. It ensures errors are thrown for unrecognized encodings to avoid incorrect data processing.
    pull/66247
  • Test Runner Crash Fix and Test Reliability Improvements: One pull request fixes a crash in the test runner caused by user stdout containing byte sequences mimicking V8 report frames by improving frame parsing logic. Another pull request improves test reliability by handling unhandled promise rejections, scoping Blob constructor test failures, removing flaky expectations, and re-enabling a skipped test.
    [pull/66273](https://github.com/nodejs/node/pull/66273, pull/66322](https://github.com/nodejs/node/pull/66322)
  • ffi Module Enhancement for 64-bit Integers: This pull request enhances the ffi module to accept safe integer numbers for 64-bit int64 and uint64 arguments alongside BigInt values. It implements validation and conversion across multiple API paths while preserving existing BigInt checks and improving usability.
    pull/66197
  • InspectorIo Null Pointer Dereference Fix: This pull request addresses a null pointer dereference issue in InspectorIo by ensuring request_queue_ is properly assigned on the IO thread before use. It adds safeguards in the destructor and handles spurious wakeups during thread startup to prevent premature access.
    pull/66201
  • fs.watchFile() Listener Forwarding Fix: This pull request fixes an issue where fs.watchFile() on real-directory mounts ignored the supplied listener by forwarding it through RealFSProvider.watchFile(). This ensures the user callback fires on file changes and allows fs.unwatchFile() to properly remove the listener.
    pull/66224
  • InternalCallbackScope Performance Optimization: This pull request optimizes InternalCallbackScope by reducing redundant environment lookups and avoiding unnecessary global handle creation. These changes significantly improve performance for native-to-JS calls such as MakeCallback, CallbackScope, AsyncWrap, and Node-API.
    pull/66316
  • Centralized Build Configuration for CI and Benchmarks: This pull request centralizes build configuration for continuous integration, benchmark builds, and the V8 cache job by defining common build defaults in a Nix shell. This ensures consistent settings and prevents unnecessary rebuilds.
    pull/66351
  • URL and URLPattern Performance Improvements: This pull request improves the performance of URL setters, URLSearchParams, and URLPattern by optimizing setter operations to avoid unnecessary reparsing and redundant string conversions. It also utilizes a faster one-byte API for URL.canParse and URLPattern.test, resulting in significant benchmark speedups.
    pull/66188
  • WebAssembly Module Compile Cache Extension: This pull request extends the module compile cache to support caching of compiled WebAssembly modules loaded via ES module integration. It introduces a new cache entry type keyed on module URL and serialized compiled bytes, enabling deserialization with consistent compile options and requiring specific V8 flags.
    pull/66191
  • RealFSProvider mkdir Path Normalization Fix: This pull request fixes mkdirSync() and mkdir() in RealFSProvider to correctly normalize and return provider-relative virtual file system paths instead of absolute backing-directory paths when creating directories recursively. This ensures compatibility with VirtualFileSystem#toMountedPath() and matches MemoryProvider behavior.
    pull/66221
  • Documentation Update for request.reusedSocket Timeout: This pull request updates the documentation for the request.reusedSocket timeout example to reflect the current default keepAliveTimeout of 65 seconds and the addition of the keepAliveTimeoutBuffer option. It corrects the example and includes the previously missing option in the documented options object.
    pull/66286
  • Filesystem Exception Handling Fix: This pull request fixes an issue where exceptions thrown by user completion callbacks or subsequent nextTick queue executions were swallowed due to an active TryCatch scope. It moves the TryCatch to a helper that completes before invoking JavaScript callbacks, ensuring exceptions are properly reported.
    pull/66308
  • Worker Startup Performance Enhancements: This pull request improves worker startup performance by preloading streams into the startup snapshot to restore their initialized state more efficiently. It adds a concurrent startup benchmark, verifies snapshot membership and stdio methods, and implements lazy loading for unused stream components.
    pull/66311
  • Virtual File System Feature Unflagged: This pull request updates the virtual file system feature by unflagging it to be enabled by default while allowing users to disable it via a negated experimental flag.
    pull/66318
  • Buffer.prototype.indexOf() Large Buffer Fix: This pull request fixes an issue where Buffer.prototype.indexOf() returned a negative index for matches beyond 2 GiB in large buffers by changing the result to a JavaScript number. It includes regression tests for searches involving numbers, Buffers, and strings.
    pull/66325
  • Non-Throwing HTTP Header Validation Functions: This pull request introduces non-throwing boolean-returning functions isValidHeaderName() and isValidHeaderValue() as efficient alternatives to existing validation methods. These improve performance when checking invalid HTTP headers and enable userland libraries to reuse core validation logic.
    pull/66334
  • Recursive mkdir() Infinite Retry Loop Fix: This pull request addresses an issue where recursive mkdir() could enter an infinite retry loop on ENOENT errors by retrying each path only once after attempting to create its parent directory. This prevents endless retries in cases like the /proc filesystem or concurrent directory removals.
    pull/66340
  • zlib zstdCompress() Performance Improvement: This pull request improves the asynchronous zstdCompress() function by defaulting the pledgedSrcSize parameter to the input's byte length, enabling better compression table sizing. This results in output identical to the synchronous version and significantly faster compression times for typical static asset files.
    pull/66358
  • Watch Mode Flag Normalization Fix: This pull request fixes an issue in watch mode where underscore aliases in watch flags were not normalized, causing child processes to repeatedly spawn. It normalizes option names before comparison while forwarding the original arguments unchanged.
    pull/66365
  • QUIC Macro Replacement for Build Compatibility: This pull request removes the HAVE_QUIC macro and replaces it with OPENSSL_NO_QUIC to prevent compilation failures in builds lacking both OpenSSL and QUIC dependencies.
    pull/66373
  • V8 WebAssembly Import Wrapper Lifetime Fixes: This pull request backports two V8 fixes addressing the WebAssembly import wrapper lifetime issue by adding wrapper reference count checks and preventing reuse of wrappers marked as "is_dying." These changes avoid a race condition that could cause crashes.
    pull/66376
  • Buffer.prototype.copy 32-bit Truncation Bug Fix: This pull request fixes a 32-bit truncation bug in Buffer.prototype.copy on the v24.x branch by changing parameter handling from 32-bit integers to doubles stored in size_t. This ensures correct copying behavior for offsets and lengths greater than or equal to 2^32 without altering the existing memmove path.
    pull/66187

3.2 Closed Pull Requests

This section provides a summary of pull requests that were closed in the repository over the past week. The top three pull requests with the highest number of commits are highlighted as 'key' pull requests. Other pull requests are grouped based on similar characteristics for easier analysis. Up to 25 pull requests are displayed in this section, while any remaining pull requests beyond this limit are omitted for brevity.

Pull Requests Closed This Week: 128

Key Closed Pull Requests

1. [v24.x backport] crypto and Web IDL fixes and features: This pull request backports a series of fixes and feature improvements related to the crypto module and Web IDL interface brand checks to the v24.x-staging branch, including enhancements in cryptographic key handling, provider integration, WebCrypto API compliance, and various bug fixes scoped to be applicable for the 24.x release line.

  • URL: pull/66233
  • Associated Commits: dcade, a0ea1, efdc0, 6ab4e, bf534, 9187d, 2f3d3, fead6, 7a33e, 94226, bedf7, 48071, 82fee, c0cbf, 6f9c1, 7bc15, 8b1ff, 0afb1, 0f5a7, f2d04, 3ed64, 6229a, 55153, db194, 023c3, 415c5, bf2a8, 1ac41, 2a98e, 8de8e, 7721d, d32b4, 0bdf4, 6fb3f, a421a, 67312, f6e6e, 02ce4, e7d21, 9b91c, 346a8, 412d5, 1d20a, 0a14c, a284b, f8756, 87bc3, f0915, 6ea49, dbc66, 395fe, fa572, d6d15, 0af01, fbe74, 91953, 019b7, 30d00, 815db, f0bd8, 835b2, a638b, 65dcf, 56f6c, f24f0, 5b379, 60fb6, b45e5, e899d, 3e4e6, 1942f, c8377, cf318, 7278a, 62b73, 0daf6, 82e2e, cab61, 6cf0c, c8f9e, 7c57a, 47741, 301d8, 2d42b, c0e82, 269ad, 9d54c, a7cde, 2f496, 6676b, 8c1f3, e3915, bb9e7, 1838a, 794e0, ae17a, d021b, 3be21, 6bbcb, b7d42, 93682, 83949, 80798, 968f6, 536c8, 8680c, 0a757, d2876, 312b9, 14720, 96eb8, e5bbf, 06dcf, 1e168, c172d, 48866, 1e052, 06bbc, 3b4cc

2. crypto: fix various edge cases: This pull request addresses numerous edge cases in the crypto module by improving Web IDL conversions and algorithm validations, correcting key handling and normalization for various cryptographic operations, refining random value generation with intrinsic buffer bounds, enhancing error isolation, updating key import/export processes including JWK validation, supporting backend-specific AES-GCM IV lengths, enforcing stricter input requirements for AES-KW and KMAC, integrating OpenSSL's cSHAKE and KMAC implementations, and ensuring robust handling of detached parameters, PBKDF2 iteration limits, and hybrid key material to increase overall security and correctness.

  • URL: pull/66237
  • Associated Commits: f82a8, 1cbd1, 131cc, 0e286, 5d64d, bd27c, 71296, 3d897, 7f417, 9b6c7, a4541, 67740, 4f7f1, 191d5, 2ae6b, e9374, 36bb4, 716fc, 02d6a, 6e998, baaf5, ac093, a9566, 3e45b, 1f701, 36d93, 4a5c4, a2164, 4f26a

3. stream: apply more stream/iter fixes, round 3: This pull request applies a series of fixes and improvements to the Node.js stream and async iterator implementations, including enhanced cancellation awareness, backpressure handling, cleanup of listeners on cancellation, protocol ordering adjustments, and documentation updates, building upon previous related work to refine stream and iterator behavior.

  • URL: pull/66079
  • Associated Commits: 37bec, 4acd6, 00f46, 8cc14, efc2f, a409c, d0ff9, 72e97, 1fd0d, 71498, 970dd, b2c76, 593fb, 8bc2e

Other Closed Pull Requests

  • Watch flag handling in child processes: This topic covers pull requests that fix issues related to the --watch feature in Node.js. One pull request strips watch-related flags from NODE_OPTIONS before spawning child processes to prevent infinite loops, while another changes the watch strategy on Linux to monitor the parent directory non-recursively to handle file replacements reliably.
  • [pull/62143, pull/63888]
  • perf_hooks module enhancements: Multiple pull requests improve the perf_hooks module by adding new histogram methods (snapshot() and diff()), enhancing importHistogram() with better validation and support for a new export format, tuning monitorEventLoopDelay() options, and allowing the RecordableHistogram to record zero values. These changes collectively improve performance monitoring capabilities and data integrity in Node.js.
  • [pull/66098, pull/66099, pull/66114, pull/66115]
  • HTTP module performance and normalization: Pull requests in this area focus on improving HTTP server performance and request handling. One PR normalizes CONNECT request paths to improve path validation, while others optimize HTTP/1 header processing by reducing string allocations and object creations, resulting in significant speed-ups and lower memory usage without changing behavior.
  • [pull/64876, pull/66120, pull/66257]
  • Thread-local storage and environment state management: This topic includes a pull request that relocates per-Environment state out of thread-local storage to avoid conflicts when multiple Environments share a thread. It also introduces a cpplint rule to restrict thread_local usage and adds tests to ensure correct behavior with shared embedder-owned isolates.
  • [pull/66313]
  • Build system and platform support updates: Pull requests here update the build system to support multiple LIEF versions and prepare for Mbed TLS 4 integration, downgrade official Intel macOS support to experimental due to Rosetta's end, and propose promoting Alpine Linux x64 builds to tier 2 status. These changes ensure compatibility and clarify platform support moving forward.
  • [pull/65427, pull/66240, pull/63737]
  • Error handling and resource management improvements: This includes fixes for malformed localStorage backing files to throw specific errors instead of aborting, resource leak fixes on failed database opens, improved error reporting in the DOM storage inspector, and proper V8 handle scope management in the remote debugger to prevent fatal errors.
  • [pull/65879]
  • CI and tooling enhancements: Pull requests add support for the [resume-ci] label in CI workflows, improve tooling to select mergeable PRs and check Jenkins availability before removing labels, and introduce configurable repository variables for batch size and workload limits. These changes streamline CI operations and improve automation reliability.
  • [pull/65945, pull/66280]
  • Test suite maintenance and flakiness fixes: This topic covers removal of outdated flaky test entries, fixes for flaky crypto benchmark and HTTP/2 debug tests by increasing buffer sizes and capturing debug output, and adding tests to remove restrictions on dynamic imports with code caching. These efforts improve test reliability and accuracy.
  • [pull/62678, pull/66132, pull/66319]
  • Documentation and naming consistency: Pull requests clarify Worker execArgv option behavior in relation to Permission Model grants, rename DatabaseSync and related helpers for consistency while maintaining backward compatibility, and fix documentation tool crashes related to export syntax. These changes improve clarity and maintainability.
  • [pull/65988, pull/66124]
  • Compression and messaging improvements: This includes a fix to preserve quality parameters and dictionaries in Brotli compressor/decompressor resets, and adding Symbol.toStringTag properties to messaging classes to improve object inspection and address a specific issue.
  • [pull/66151, pull/65532]

3.3 Pull Request Discussion Insights

This section will analyze the tone and sentiment of discussions within this project's open and closed pull requests that occurred within the past week. It aims to identify potentially heated exchanges and to maintain a constructive project environment.

Based on our analysis, there are no instances of toxic discussions in the project's open or closed pull requests from the past week.


IV. Contributors

4.1 Contributors

Active Contributors:

We consider an active contributor in this project to be any contributor who has made at least 1 commit, opened at least 1 issue, created at least 1 pull request, or made more than 2 comments in the last month.

If there are more than 10 active contributors, the list is truncated to the top 10 based on contribution metrics for better clarity.

Contributor Commits Pull Requests Issues Comments
panva 291 45 0 41
jasnell 184 14 2 23
aduh95 80 11 1 32
martenrichter 77 0 1 1
codebytere 70 7 0 0
mcollina 56 15 0 3
trivikr 38 21 13 2
christianaurichzm 40 12 1 7
anonrig 25 14 0 4
wen2go 32 0 0 0

Don't miss what's next. Subscribe to Weekly Project News:
Powered by Buttondown, the easiest way to start and grow your newsletter.