chore(deps): update node.js to v24.21.0 #223

Open
renovate wants to merge 1 commit from renovate/node-24.x into main
Collaborator

This PR contains the following updates:

Package Update Change
node (source) minor 24.16.024.21.0

Release Notes

nodejs/node (node)

v24.21.0: 2026-09-08, Version 24.21.0 'Krypton' (LTS), @​aduh95

Compare Source

Notable Changes
  • [71106e1f17] - crypto: update root certificates to NSS 3.126 (Node.js GitHub Bot) #​65495
  • [afca0a912d] - (SEMVER-MINOR) crypto: support loading private keys through STORE loaders (Filip Skokan) #​63949
  • [6274fccbd9] - deps: update OpenSSL to 3.5.8 (Node.js GitHub Bot) #​65542
  • [53cba013c7] - deps: update Undici to 7.29.1 (Node.js GitHub Bot) #​65789
  • [0529772798] - (SEMVER-MINOR) lib,src: improve histogram implementation (James M Snell) #​65024
  • [41c7062b81] - (SEMVER-MINOR) net: improve performance of net.BlockList (James M Snell) #​64974
  • [5197b5a3c5] - (SEMVER-MINOR) perf_hooks: add statistical hypothesis testing to histogram (James M Snell) #​65416
  • [35c635b032] - (SEMVER-MINOR) util: add non-throwing MIMEType.parse (James M Snell) #​64965
Commits

v24.20.0: 2026-08-26, Version 24.20.0 'Krypton' (LTS), @​aduh95

Compare Source

Notable Changes
Commits

v24.19.0: 2026-08-03, Version 24.19.0 'Krypton' (LTS), @​aduh95

Compare Source

Notable Changes
  • [d08872b530] - (SEMVER-MINOR) buffer: implement blob.textStream() (Matthew Aitken) #​64036
  • [35222948be] - (SEMVER-MINOR) deps: update OpenSSL build config to support compression (Tim Perry) #​62217
  • [d6ab039f24] - (SEMVER-MINOR) doc: update blockList stability status to release candidate (alphaleadership) #​63050
  • [1da05fb79d] - doc: mark stream.compose stable (Matteo Collina) #​62562
  • [3c1636dabf] - (SEMVER-MINOR) esm: add --experimental-import-text flag (Efe) #​62300
  • [e323e877be] - (SEMVER-MINOR) fs: support caller-supplied readFile() buffers (Matteo Collina) #​63634
  • [c1248c9544] - (SEMVER-MINOR) http: add httpValidation option to configure header value validation (RajeshKumar11) #​61597
  • [a534b65815] - (SEMVER-MINOR) net: support TCP_KEEPINTVL and TCP_KEEPCNT in setKeepAlive (Guy Bedford) #​63825
  • [a23cdec683] - (SEMVER-MINOR) perf_hooks: sample delay per event loop iteration (Pablo Erhard) #​62935
  • [7428b57a37] - (SEMVER-MINOR) src: allow empty --experimental-config-file (Marco Ippolito) #​61610
  • [e57597173c] - (SEMVER-MINOR) stream: expose ReadableStreamTee (Matteo Collina) #​64195
  • [5396235993] - (SEMVER-MINOR) tls: report negotiated TLS groups (Filip Skokan) #​64119
  • [5e901b5cd9] - (SEMVER-MINOR) tls: add certificateCompression option (Tim Perry) #​62217
Commits

v24.18.1: 2026-07-29, Version 24.18.1 'Krypton' (LTS), @​juanarbol

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High
  • (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
  • (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
  • (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
  • (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
  • (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium
  • (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
  • (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
  • (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
  • (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
  • (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
  • deps: update llhttp to 9.4.3 (Paolo Insogna)
  • deps: update undici to 7.29.0 (Node.js GitHub Bot)
Commits

v24.18.0: 2026-06-23, Version 24.18.0 'Krypton' (LTS), @​richardlau prepared by @​sxa

Compare Source

Notable Changes
  • [e07e7a31e1] - crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #​63527
  • [44c8ebcbd6] - http: avoid stream listeners on idle agent sockets (Matteo Collina) #​64004
  • [d3ef4122ee] - (SEMVER-MINOR) buffer: increase Buffer.poolSize default to 64 KiB (Matteo Collina) #​63597
  • [bb2857b85a] - (SEMVER-MINOR) crypto: align key argument names in docs and error messages (Filip Skokan) #​62527
  • [b9d5e87880] - (SEMVER-MINOR) crypto: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) #​62527
  • [ccd756d61e] - (SEMVER-MINOR) crypto: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) #​62183
  • [4c9251fc09] - (SEMVER-MINOR) http: add writeInformation to send arbitrary 1xx status codes (Tim Perry) #​63155
  • [8c989ec4a3] - (SEMVER-MINOR) inspector: expose precise coverage start to JS runtime (sangwook) #​63079
  • [3f54c8ba32] - Revert "stream: noop pause/resume on destroyed streams" (Stewart X Addison) #​63834
Commits

v24.17.0: 2026-06-18, Version 24.17.0 'Krypton' (LTS), @​aduh95

Compare Source

This is a security release.

Notable Changes
  • (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High
  • (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High
  • (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium
  • (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium
  • (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium
  • (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium
  • (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium
  • (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 – Medium
  • (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low
  • (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low
  • (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low
Commits

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [node](https://nodejs.org) ([source](https://github.com/nodejs/node)) | minor | `24.16.0` → `24.21.0` | --- ### Release Notes <details> <summary>nodejs/node (node)</summary> ### [`v24.21.0`](https://github.com/nodejs/node/releases/tag/v24.21.0): 2026-09-08, Version 24.21.0 'Krypton' (LTS), @&#8203;aduh95 [Compare Source](https://github.com/nodejs/node/compare/v24.20.0...v24.21.0) ##### Notable Changes - \[[`71106e1f17`](https://github.com/nodejs/node/commit/71106e1f17)] - **crypto**: update root certificates to NSS 3.126 (Node.js GitHub Bot) [#&#8203;65495](https://github.com/nodejs/node/pull/65495) - \[[`afca0a912d`](https://github.com/nodejs/node/commit/afca0a912d)] - **(SEMVER-MINOR)** **crypto**: support loading private keys through STORE loaders (Filip Skokan) [#&#8203;63949](https://github.com/nodejs/node/pull/63949) - \[[`6274fccbd9`](https://github.com/nodejs/node/commit/6274fccbd9)] - **deps**: update OpenSSL to 3.5.8 (Node.js GitHub Bot) [#&#8203;65542](https://github.com/nodejs/node/pull/65542) - \[[`53cba013c7`](https://github.com/nodejs/node/commit/53cba013c7)] - **deps**: update Undici to 7.29.1 (Node.js GitHub Bot) [#&#8203;65789](https://github.com/nodejs/node/pull/65789) - \[[`0529772798`](https://github.com/nodejs/node/commit/0529772798)] - **(SEMVER-MINOR)** **lib,src**: improve histogram implementation (James M Snell) [#&#8203;65024](https://github.com/nodejs/node/pull/65024) - \[[`41c7062b81`](https://github.com/nodejs/node/commit/41c7062b81)] - **(SEMVER-MINOR)** **net**: improve performance of `net.BlockList` (James M Snell) [#&#8203;64974](https://github.com/nodejs/node/pull/64974) - \[[`5197b5a3c5`](https://github.com/nodejs/node/commit/5197b5a3c5)] - **(SEMVER-MINOR)** **perf\_hooks**: add statistical hypothesis testing to histogram (James M Snell) [#&#8203;65416](https://github.com/nodejs/node/pull/65416) - \[[`35c635b032`](https://github.com/nodejs/node/commit/35c635b032)] - **(SEMVER-MINOR)** **util**: add non-throwing `MIMEType.parse` (James M Snell) [#&#8203;64965](https://github.com/nodejs/node/pull/64965) ##### Commits - \[[`84d706cb9b`](https://github.com/nodejs/node/commit/84d706cb9b)] - **assert**: improve documentation wording (Kamal Rawal) [#&#8203;64953](https://github.com/nodejs/node/pull/64953) - \[[`90d127db33`](https://github.com/nodejs/node/commit/90d127db33)] - **(SEMVER-MINOR)** **benchmark**: add --analyze mode to compare.js (James M Snell) [#&#8203;65416](https://github.com/nodejs/node/pull/65416) - \[[`ad1d7884c3`](https://github.com/nodejs/node/commit/ad1d7884c3)] - **benchmark**: add test-only and mock timers cases (Luan Muniz) [#&#8203;64097](https://github.com/nodejs/node/pull/64097) - \[[`1d8f045914`](https://github.com/nodejs/node/commit/1d8f045914)] - **benchmark**: apply `highWaterMark` in webstreams `pipe-to` (Matteo Collina) [#&#8203;65138](https://github.com/nodejs/node/pull/65138) - \[[`ed7ba3c993`](https://github.com/nodejs/node/commit/ed7ba3c993)] - **benchmark**: complete the sqlite is-transaction fix (Edy Silva) [#&#8203;65218](https://github.com/nodejs/node/pull/65218) - \[[`c8837e1aa3`](https://github.com/nodejs/node/commit/c8837e1aa3)] - **benchmark**: add test runner hooks and options (Luan Muniz) [#&#8203;63754](https://github.com/nodejs/node/pull/63754) - \[[`2ba8661e23`](https://github.com/nodejs/node/commit/2ba8661e23)] - **buffer**: prevent string write offset overflow (Matteo Collina) [#&#8203;65043](https://github.com/nodejs/node/pull/65043) - \[[`cc9ee6c2ae`](https://github.com/nodejs/node/commit/cc9ee6c2ae)] - **buffer**: treat detached ArrayBuffers as empty (Archkon) [#&#8203;64504](https://github.com/nodejs/node/pull/64504) - \[[`5a5d73e4c5`](https://github.com/nodejs/node/commit/5a5d73e4c5)] - **build**: pass target architecture to small-icu genccode (ulofiai) [#&#8203;65095](https://github.com/nodejs/node/pull/65095) - \[[`273e72d1a5`](https://github.com/nodejs/node/commit/273e72d1a5)] - **build**: deprecate always enabled `--enable-static` (Chengzhong Wu) [#&#8203;65103](https://github.com/nodejs/node/pull/65103) - \[[`89a67246e3`](https://github.com/nodejs/node/commit/89a67246e3)] - **build**: check FIPS option value in node.gyp (Filip Skokan) [#&#8203;64982](https://github.com/nodejs/node/pull/64982) - \[[`2d21f41cd5`](https://github.com/nodejs/node/commit/2d21f41cd5)] - **build**: handle malformed OpenSSL macros (Filip Skokan) [#&#8203;64982](https://github.com/nodejs/node/pull/64982) - \[[`f62bc0f862`](https://github.com/nodejs/node/commit/f62bc0f862)] - **build,win**: add PGO workload scripts (Stefan Stojanovic) [#&#8203;63696](https://github.com/nodejs/node/pull/63696) - \[[`33d0c7dc12`](https://github.com/nodejs/node/commit/33d0c7dc12)] - **child\_process**: keep SIGWINCH from killing on Win (Kirill Saied) [#&#8203;64510](https://github.com/nodejs/node/pull/64510) - \[[`71106e1f17`](https://github.com/nodejs/node/commit/71106e1f17)] - **crypto**: update root certificates to NSS 3.126 (Node.js GitHub Bot) [#&#8203;65495](https://github.com/nodejs/node/pull/65495) - \[[`419af8b86d`](https://github.com/nodejs/node/commit/419af8b86d)] - **crypto**: fix missing error checks on ASN1\_STRING\_to\_UTF8() (Nora Dossche) [#&#8203;65200](https://github.com/nodejs/node/pull/65200) - \[[`8029383f3f`](https://github.com/nodejs/node/commit/8029383f3f)] - **crypto**: use available BoringSSL APIs (Filip Skokan) [#&#8203;65423](https://github.com/nodejs/node/pull/65423) - \[[`a9bd780e19`](https://github.com/nodejs/node/commit/a9bd780e19)] - **crypto**: remove obsolete BoringSSL shims (Filip Skokan) [#&#8203;65423](https://github.com/nodejs/node/pull/65423) - \[[`7defefad3f`](https://github.com/nodejs/node/commit/7defefad3f)] - **crypto**: read WebCrypto inputs through primordials (Filip Skokan) [#&#8203;65115](https://github.com/nodejs/node/pull/65115) - \[[`6ed1e38627`](https://github.com/nodejs/node/commit/6ed1e38627)] - **crypto**: fix disabling FIPS mode (Filip Skokan) [#&#8203;64982](https://github.com/nodejs/node/pull/64982) - \[[`afca0a912d`](https://github.com/nodejs/node/commit/afca0a912d)] - **(SEMVER-MINOR)** **crypto**: support loading private keys through STORE loaders (Filip Skokan) [#&#8203;63949](https://github.com/nodejs/node/pull/63949) - \[[`9b9dd6e9cf`](https://github.com/nodejs/node/commit/9b9dd6e9cf)] - **debugger**: wait for target startup (Filip Skokan) [#&#8203;65194](https://github.com/nodejs/node/pull/65194) - \[[`07faaeeffd`](https://github.com/nodejs/node/commit/07faaeeffd)] - **deps**: update corepack to 0.36.0 (Node.js GitHub Bot) [#&#8203;65653](https://github.com/nodejs/node/pull/65653) - \[[`53cba013c7`](https://github.com/nodejs/node/commit/53cba013c7)] - **deps**: update undici to 7.29.1 (Node.js GitHub Bot) [#&#8203;65789](https://github.com/nodejs/node/pull/65789) - \[[`0268ca547c`](https://github.com/nodejs/node/commit/0268ca547c)] - **deps**: update archs files for openssl-3.5.8 (Node.js GitHub Bot) [#&#8203;65542](https://github.com/nodejs/node/pull/65542) - \[[`6274fccbd9`](https://github.com/nodejs/node/commit/6274fccbd9)] - **deps**: upgrade openssl sources to openssl-3.5.8 (Node.js GitHub Bot) [#&#8203;65542](https://github.com/nodejs/node/pull/65542) - \[[`6bdcd121fa`](https://github.com/nodejs/node/commit/6bdcd121fa)] - **deps**: update zlib to 1.3.2.1-motley-8002e91 (Node.js GitHub Bot) [#&#8203;65316](https://github.com/nodejs/node/pull/65316) - \[[`c2aa446b6d`](https://github.com/nodejs/node/commit/c2aa446b6d)] - **deps**: update simdjson to 4.6.7 (Node.js GitHub Bot) [#&#8203;65318](https://github.com/nodejs/node/pull/65318) - \[[`3e58e48ea8`](https://github.com/nodejs/node/commit/3e58e48ea8)] - **deps**: update googletest to [`49495ea`](https://github.com/nodejs/node/commit/49495eacfdbda3f4b6ba219923fedbb2e3f99376) (Node.js GitHub Bot) [#&#8203;65317](https://github.com/nodejs/node/pull/65317) - \[[`670b3665c0`](https://github.com/nodejs/node/commit/670b3665c0)] - **deps**: cherry-pick [libuv/libuv@`e640dc9`](https://github.com/libuv/libuv/commit/e640dc9) (ulofiai) [#&#8203;65118](https://github.com/nodejs/node/pull/65118) - \[[`ca1c67b021`](https://github.com/nodejs/node/commit/ca1c67b021)] - **deps**: float ICU-23262 patch for icu78 (René) [#&#8203;64678](https://github.com/nodejs/node/pull/64678) - \[[`4ad043b0aa`](https://github.com/nodejs/node/commit/4ad043b0aa)] - **deps**: enable AVX-512 OpenSSL asm with clang (Daniel Lemire) [#&#8203;65136](https://github.com/nodejs/node/pull/65136) - \[[`96b4af109b`](https://github.com/nodejs/node/commit/96b4af109b)] - **deps**: update googletest to [`d89aac5`](https://github.com/nodejs/node/commit/d89aac5f0dd4021198d903d39de16f896726de21) (Node.js GitHub Bot) [#&#8203;65153](https://github.com/nodejs/node/pull/65153) - \[[`774f663c56`](https://github.com/nodejs/node/commit/774f663c56)] - **dgram**: don't swallow bind errors when callback is provided (armanmikoyan) [#&#8203;62602](https://github.com/nodejs/node/pull/62602) - \[[`94b118d62e`](https://github.com/nodejs/node/commit/94b118d62e)] - **diagnostics\_channel**: validate before channel activation (Trivikram Kamat) [#&#8203;65313](https://github.com/nodejs/node/pull/65313) - \[[`09788665bd`](https://github.com/nodejs/node/commit/09788665bd)] - **dns**: validate address type in lookupService (Lazizbek Ergashev) [#&#8203;64878](https://github.com/nodejs/node/pull/64878) - \[[`15f95fc0e2`](https://github.com/nodejs/node/commit/15f95fc0e2)] - **dns**: validate port range in `setServers()` (René) [#&#8203;65021](https://github.com/nodejs/node/pull/65021) - \[[`37b9e9a154`](https://github.com/nodejs/node/commit/37b9e9a154)] - **dns**: fix crash on setServers with port 0 (Lazizbek Ergashev) [#&#8203;65009](https://github.com/nodejs/node/pull/65009) - \[[`cd6205fa0d`](https://github.com/nodejs/node/commit/cd6205fa0d)] - **doc**: update AHAFS reference link (Taeuk Ha) [#&#8203;65481](https://github.com/nodejs/node/pull/65481) - \[[`0e6f9ae42e`](https://github.com/nodejs/node/commit/0e6f9ae42e)] - **doc**: fix property names in os.networkInterfaces() example (Jihwan) [#&#8203;65469](https://github.com/nodejs/node/pull/65469) - \[[`034a827b41`](https://github.com/nodejs/node/commit/034a827b41)] - **doc**: fix broken links in cli.md (Donghoon Kang) [#&#8203;65412](https://github.com/nodejs/node/pull/65412) - \[[`eb364621d4`](https://github.com/nodejs/node/commit/eb364621d4)] - **doc**: remove outdated WASI version fallback (이혜미) [#&#8203;65303](https://github.com/nodejs/node/pull/65303) - \[[`b13f425bf8`](https://github.com/nodejs/node/commit/b13f425bf8)] - **doc**: fix broken GYP link in n-api.md (Donghoon Kang) [#&#8203;65413](https://github.com/nodejs/node/pull/65413) - \[[`45c4011067`](https://github.com/nodejs/node/commit/45c4011067)] - **doc**: document that an empty OPENSSL\_CONF skips config loading (Orgad Shaneh) [#&#8203;64949](https://github.com/nodejs/node/pull/64949) - \[[`fde6776c5f`](https://github.com/nodejs/node/commit/fde6776c5f)] - **doc**: fix broken TLS security level example (soreavis) [#&#8203;65391](https://github.com/nodejs/node/pull/65391) - \[[`290c1fec04`](https://github.com/nodejs/node/commit/290c1fec04)] - **doc**: clarify socket destroyed behavior (Dayun) [#&#8203;65395](https://github.com/nodejs/node/pull/65395) - \[[`a7e8269947`](https://github.com/nodejs/node/commit/a7e8269947)] - **doc**: update outdated nodejs.org guide links (Donghoon Kang) [#&#8203;65394](https://github.com/nodejs/node/pull/65394) - \[[`7809f11249`](https://github.com/nodejs/node/commit/7809f11249)] - **doc**: clarify that ipv4 mapped to ipv6 are classified as ipv6 (Vedant Kulkarni) [#&#8203;62117](https://github.com/nodejs/node/pull/62117) - \[[`64cd3a6e95`](https://github.com/nodejs/node/commit/64cd3a6e95)] - **doc**: clarify how fs.Dirent file types are determined (soreavis) [#&#8203;64532](https://github.com/nodejs/node/pull/64532) - \[[`9b92fdce14`](https://github.com/nodejs/node/commit/9b92fdce14)] - **doc**: update security release prepare command (Rafael Gonzaga) [#&#8203;64699](https://github.com/nodejs/node/pull/64699) - \[[`6f9b9df3c1`](https://github.com/nodejs/node/commit/6f9b9df3c1)] - **doc**: clarify copyFile symlink behavior (T) [#&#8203;62941](https://github.com/nodejs/node/pull/62941) - \[[`2480acb550`](https://github.com/nodejs/node/commit/2480acb550)] - **doc**: document setRawMode write access on Windows (Erik Demaine) [#&#8203;63856](https://github.com/nodejs/node/pull/63856) - \[[`a1e9c3a5db`](https://github.com/nodejs/node/commit/a1e9c3a5db)] - **doc**: add missing return types in fs.md (Chaseton Collins) [#&#8203;65307](https://github.com/nodejs/node/pull/65307) - \[[`4533572040`](https://github.com/nodejs/node/commit/4533572040)] - **doc**: add missing return types in buffer.md (Yuya Inoue) [#&#8203;65308](https://github.com/nodejs/node/pull/65308) - \[[`39ecedbbd2`](https://github.com/nodejs/node/commit/39ecedbbd2)] - **doc**: fix lint clean command (greenhead) [#&#8203;65274](https://github.com/nodejs/node/pull/65274) - \[[`0b1fb8fcd8`](https://github.com/nodejs/node/commit/0b1fb8fcd8)] - **doc**: fix typo in onboarding.md (서울민트초코) [#&#8203;65295](https://github.com/nodejs/node/pull/65295) - \[[`3165b5d38a`](https://github.com/nodejs/node/commit/3165b5d38a)] - **doc**: add missing `added:` tags to `fs.lchmod` (Lazizbek Ergashev) [#&#8203;65283](https://github.com/nodejs/node/pull/65283) - \[[`113b808e59`](https://github.com/nodejs/node/commit/113b808e59)] - **doc**: fix SQLite changeset constant descriptions (greenhead) [#&#8203;65265](https://github.com/nodejs/node/pull/65265) - \[[`c3eb51d5a1`](https://github.com/nodejs/node/commit/c3eb51d5a1)] - **doc**: document open pull request limit (Matteo Collina) [#&#8203;65250](https://github.com/nodejs/node/pull/65250) - \[[`d7accdcd52`](https://github.com/nodejs/node/commit/d7accdcd52)] - **doc**: document http2 header constants (Harjoth Khara) [#&#8203;64548](https://github.com/nodejs/node/pull/64548) - \[[`f47111416f`](https://github.com/nodejs/node/commit/f47111416f)] - **doc**: create ai-guidelines and include to CONTRIBUTING (Rafael Gonzaga) [#&#8203;62105](https://github.com/nodejs/node/pull/62105) - \[[`c3b120e737`](https://github.com/nodejs/node/commit/c3b120e737)] - **doc**: update synopsis (Augustin Mauroy) [#&#8203;65171](https://github.com/nodejs/node/pull/65171) - \[[`39f4c831fd`](https://github.com/nodejs/node/commit/39f4c831fd)] - **doc**: fix broken internal links (greenhead) [#&#8203;64901](https://github.com/nodejs/node/pull/64901) - \[[`be25cdd69e`](https://github.com/nodejs/node/commit/be25cdd69e)] - **doc**: report proper return type on urlPattern.test (Brian Muenzenmeyer) [#&#8203;64831](https://github.com/nodejs/node/pull/64831) - \[[`1bf7737810`](https://github.com/nodejs/node/commit/1bf7737810)] - **doc**: fix permission documentation examples (greenhead) [#&#8203;64897](https://github.com/nodejs/node/pull/64897) - \[[`b7932e68a1`](https://github.com/nodejs/node/commit/b7932e68a1)] - **doc**: document sqlite parameter binding (Guilherme Araújo) [#&#8203;65089](https://github.com/nodejs/node/pull/65089) - \[[`5234a5169c`](https://github.com/nodejs/node/commit/5234a5169c)] - **doc**: finalize statements in sqlite examples (Guilherme Araújo) [#&#8203;65088](https://github.com/nodejs/node/pull/65088) - \[[`39ea929da7`](https://github.com/nodejs/node/commit/39ea929da7)] - **doc**: document quic stopSending() and resetStream() (Issac) [#&#8203;64888](https://github.com/nodejs/node/pull/64888) - \[[`2ba198db73`](https://github.com/nodejs/node/commit/2ba198db73)] - **doc**: clarify sqlite bare parameter default (Sumit Kumar Das) [#&#8203;62009](https://github.com/nodejs/node/pull/62009) - \[[`314f9b200f`](https://github.com/nodejs/node/commit/314f9b200f)] - **doc**: remove usage of `util.inherits` (Augustin Mauroy) [#&#8203;60817](https://github.com/nodejs/node/pull/60817) - \[[`d82a61662c`](https://github.com/nodejs/node/commit/d82a61662c)] - **doc**: fix grammar in worker\_threads.md (이혜미) [#&#8203;64913](https://github.com/nodejs/node/pull/64913) - \[[`44c0c8ff5b`](https://github.com/nodejs/node/commit/44c0c8ff5b)] - **doc**: clarify OpenSSL FIPS configuration (Filip Skokan) [#&#8203;64982](https://github.com/nodejs/node/pull/64982) - \[[`9b2ca70e0d`](https://github.com/nodejs/node/commit/9b2ca70e0d)] - **doc**: remove `--expose-gc` flag from CLI documentation (Dario Piotrowicz) [#&#8203;58909](https://github.com/nodejs/node/pull/58909) - \[[`a0a12397b9`](https://github.com/nodejs/node/commit/a0a12397b9)] - **doc**: document ArrayBuffer support in pbkd2Sync (kyungrae2002) [#&#8203;64976](https://github.com/nodejs/node/pull/64976) - \[[`b48699e077`](https://github.com/nodejs/node/commit/b48699e077)] - **doc**: correct default highWaterMark values (Yilong Li) [#&#8203;64617](https://github.com/nodejs/node/pull/64617) - \[[`0312ee133c`](https://github.com/nodejs/node/commit/0312ee133c)] - **esm**: avoid super-linear data URL MIME regex (Sumit Kumar Das) [#&#8203;61951](https://github.com/nodejs/node/pull/61951) - \[[`cd84d55c81`](https://github.com/nodejs/node/commit/cd84d55c81)] - **esm**: only register text format when enabled (Efe Karasakal) [#&#8203;64992](https://github.com/nodejs/node/pull/64992) - \[[`c0a8ef611e`](https://github.com/nodejs/node/commit/c0a8ef611e)] - **esm**: fix wasm import name in error message (이혜미) [#&#8203;64950](https://github.com/nodejs/node/pull/64950) - \[[`e6c34f90c2`](https://github.com/nodejs/node/commit/e6c34f90c2)] - **events**: inline iterationCondition hybrid dispatch closure (Szymon Łągiewka) [#&#8203;64473](https://github.com/nodejs/node/pull/64473) - \[[`6ee4b40c91`](https://github.com/nodejs/node/commit/6ee4b40c91)] - **events**: inline createEvent hybrid dispatch closure (Szymon Łągiewka) [#&#8203;64473](https://github.com/nodejs/node/pull/64473) - \[[`367549eed5`](https://github.com/nodejs/node/commit/367549eed5)] - **fs**: use sized reads for large files in readFileUtf8 (Shelley Vohr) [#&#8203;65328](https://github.com/nodejs/node/pull/65328) - \[[`8a5b1ae4c2`](https://github.com/nodejs/node/commit/8a5b1ae4c2)] - **fs**: fix realpath of namespaced drive paths (Jason Zhang) [#&#8203;65378](https://github.com/nodejs/node/pull/65378) - \[[`c9233b950d`](https://github.com/nodejs/node/commit/c9233b950d)] - **fs**: fix glob early return skipping sibling entries (Srinu desetti) [#&#8203;64895](https://github.com/nodejs/node/pull/64895) - \[[`bc54dd8905`](https://github.com/nodejs/node/commit/bc54dd8905)] - **fs**: pass symlink type in cp when filter is provided (Jerry Zhao) [#&#8203;62654](https://github.com/nodejs/node/pull/62654) - \[[`fcb4333aca`](https://github.com/nodejs/node/commit/fcb4333aca)] - **fs**: allocate FSReqPromise stat arrays lazily (Samuel Attard) [#&#8203;63886](https://github.com/nodejs/node/pull/63886) - \[[`c35876154e`](https://github.com/nodejs/node/commit/c35876154e)] - **fs**: fix out-of-bounds write in mkdtemp for long prefixes (Hierax\_Umbra) [#&#8203;64770](https://github.com/nodejs/node/pull/64770) - \[[`b269616936`](https://github.com/nodejs/node/commit/b269616936)] - **fs**: treat `std::errc::permission_denied` as `EPERM` error (Kirill Saied) [#&#8203;64698](https://github.com/nodejs/node/pull/64698) - \[[`212fe77e76`](https://github.com/nodejs/node/commit/212fe77e76)] - **fs**: add windowsHandle option to file streams (Kirill Saied) [#&#8203;63851](https://github.com/nodejs/node/pull/63851) - \[[`75df6cb435`](https://github.com/nodejs/node/commit/75df6cb435)] - **http**: improve performance with known-length calls to end() (Tim Perry) [#&#8203;65466](https://github.com/nodejs/node/pull/65466) - \[[`48d9cd4a28`](https://github.com/nodejs/node/commit/48d9cd4a28)] - **http**: cache maxHeaderPairs per header section (GetThatCookie) [#&#8203;64988](https://github.com/nodejs/node/pull/64988) - \[[`04785c8f43`](https://github.com/nodejs/node/commit/04785c8f43)] - **http**: fix keylog listener setup on existing agent sockets (Shani Singh) [#&#8203;65066](https://github.com/nodejs/node/pull/65066) - \[[`4b90031534`](https://github.com/nodejs/node/commit/4b90031534)] - **http**: emit drain on socket takeover and avoid stale HWM reuse (Naman Trivedi) [#&#8203;64991](https://github.com/nodejs/node/pull/64991) - \[[`83a27559cd`](https://github.com/nodejs/node/commit/83a27559cd)] - **http2**: adapt receive deferral for Node.js 24 (Matteo Collina) [#&#8203;65093](https://github.com/nodejs/node/pull/65093) - \[[`f43bed0ecc`](https://github.com/nodejs/node/commit/f43bed0ecc)] - **http2**: avoid uaf while receiving and sending rst\_stream (esgor) [#&#8203;64166](https://github.com/nodejs/node/pull/64166) - \[[`b42d664321`](https://github.com/nodejs/node/commit/b42d664321)] - **inspector**: avoid calling into JS from V8 interrupts (Joyee Cheung) [#&#8203;65028](https://github.com/nodejs/node/pull/65028) - \[[`6bf852197d`](https://github.com/nodejs/node/commit/6bf852197d)] - **lib**: use bracket notation instead of startsWith/endsWith for single char (Taejin Kim) [#&#8203;61500](https://github.com/nodejs/node/pull/61500) - \[[`151ca7e104`](https://github.com/nodejs/node/commit/151ca7e104)] - **lib**: harden webidl dictionary member reads (Filip Skokan) [#&#8203;65115](https://github.com/nodejs/node/pull/65115) - \[[`7e8c2c9f44`](https://github.com/nodejs/node/commit/7e8c2c9f44)] - **lib**: use validateArray for array arguments (greenhead) [#&#8203;64959](https://github.com/nodejs/node/pull/64959) - \[[`424fe2bc5a`](https://github.com/nodejs/node/commit/424fe2bc5a)] - **lib**: add and test \[EnforceRange] in webcrypto dictionaries (Filip Skokan) [#&#8203;65091](https://github.com/nodejs/node/pull/65091) - \[[`0529772798`](https://github.com/nodejs/node/commit/0529772798)] - **(SEMVER-MINOR)** **lib,src**: improve histogram implementation (James M Snell) [#&#8203;65024](https://github.com/nodejs/node/pull/65024) - \[[`186e1b76e8`](https://github.com/nodejs/node/commit/186e1b76e8)] - **meta**: move targos to emeritus (Michaël Zasso) [#&#8203;65393](https://github.com/nodejs/node/pull/65393) - \[[`b41b07c72a`](https://github.com/nodejs/node/commit/b41b07c72a)] - **meta**: add unified http api initiative (James M Snell) [#&#8203;65139](https://github.com/nodejs/node/pull/65139) - \[[`f85b6ecd67`](https://github.com/nodejs/node/commit/f85b6ecd67)] - **meta**: move one or more collaborators to emeritus (Node.js GitHub Bot) [#&#8203;65182](https://github.com/nodejs/node/pull/65182) - \[[`8f3d01bdce`](https://github.com/nodejs/node/commit/8f3d01bdce)] - **meta**: add Aviv Keller to `.mailmap` (Aviv Keller) [#&#8203;65048](https://github.com/nodejs/node/pull/65048) - \[[`cfad1d5b28`](https://github.com/nodejs/node/commit/cfad1d5b28)] - **meta**: update sccache to 0.17.0 (René) [#&#8203;64985](https://github.com/nodejs/node/pull/64985) - \[[`349c53c441`](https://github.com/nodejs/node/commit/349c53c441)] - **module**: report unreadable package.json (Paul Bouchon) [#&#8203;65223](https://github.com/nodejs/node/pull/65223) - \[[`bd21e6706e`](https://github.com/nodejs/node/commit/bd21e6706e)] - **module**: cache nearest parent package.json per directory (Shelley Vohr) [#&#8203;65326](https://github.com/nodejs/node/pull/65326) - \[[`961bd04370`](https://github.com/nodejs/node/commit/961bd04370)] - **module**: fix --check on ambiguous ESM files (Paul Bouchon) [#&#8203;65203](https://github.com/nodejs/node/pull/65203) - \[[`f45ef73420`](https://github.com/nodejs/node/commit/f45ef73420)] - **net**: handle undefined parent in \_unrefTimer and \_destroy (Shivay-98) [#&#8203;64644](https://github.com/nodejs/node/pull/64644) - \[[`41c7062b81`](https://github.com/nodejs/node/commit/41c7062b81)] - **(SEMVER-MINOR)** **net**: improve performance of net.BlockList (James M Snell) [#&#8203;64974](https://github.com/nodejs/node/pull/64974) - \[[`5197b5a3c5`](https://github.com/nodejs/node/commit/5197b5a3c5)] - **(SEMVER-MINOR)** **perf\_hooks**: add statistical hypothesis testing to histogram (James M Snell) [#&#8203;65416](https://github.com/nodejs/node/pull/65416) - \[[`1722ddac28`](https://github.com/nodejs/node/commit/1722ddac28)] - **permission**: enforce addon permission in GetLinkedBinding (Rafael Gonzaga) [#&#8203;65432](https://github.com/nodejs/node/pull/65432) - \[[`dff2b675db`](https://github.com/nodejs/node/commit/dff2b675db)] - **process**: validate resource stats array offsets (Archkon) [#&#8203;65098](https://github.com/nodejs/node/pull/65098) - \[[`f277983e7b`](https://github.com/nodejs/node/commit/f277983e7b)] - **quic**: changes for nghttp3\_conn\_close\_stream2 (Marten Richter) [#&#8203;64574](https://github.com/nodejs/node/pull/64574) - \[[`a4c770c78e`](https://github.com/nodejs/node/commit/a4c770c78e)] - **quic**: mark drain promise handled (James M Snell) [#&#8203;65319](https://github.com/nodejs/node/pull/65319) - \[[`2460b171c5`](https://github.com/nodejs/node/commit/2460b171c5)] - **quic**: reset rejected HTTP/3 request streams with H3\_REQUEST\_REJECTED (trivenay) [#&#8203;65442](https://github.com/nodejs/node/pull/65442) - \[[`18a7ccf302`](https://github.com/nodejs/node/commit/18a7ccf302)] - **quic**: write desired size needs update on maxstream (Marten Richter) [#&#8203;64768](https://github.com/nodejs/node/pull/64768) - \[[`9017f4a780`](https://github.com/nodejs/node/commit/9017f4a780)] - **quic**: do not destroy incoming streams that have a consumer (trivenay) [#&#8203;65335](https://github.com/nodejs/node/pull/65335) - \[[`ddc41c1ef4`](https://github.com/nodejs/node/commit/ddc41c1ef4)] - **quic**: fix wake up blob (Marten Richter) [#&#8203;64044](https://github.com/nodejs/node/pull/64044) - \[[`88bee43d7c`](https://github.com/nodejs/node/commit/88bee43d7c)] - **quic**: convert incoming :status header to number (Hallison Pereira Melo) [#&#8203;63589](https://github.com/nodejs/node/pull/63589) - \[[`cd776fe97c`](https://github.com/nodejs/node/commit/cd776fe97c)] - **quic**: fix infinite loop if STOP\_SENDING received on a buffering stream (Tim Perry) [#&#8203;64715](https://github.com/nodejs/node/pull/64715) - \[[`4f6eda3c23`](https://github.com/nodejs/node/commit/4f6eda3c23)] - **repl**: keep entries added while history file is loading (Mhayk Whandson) [#&#8203;64513](https://github.com/nodejs/node/pull/64513) - \[[`cd1e6ce29b`](https://github.com/nodejs/node/commit/cd1e6ce29b)] - **repl**: add benchmarks (Aviv Keller) [#&#8203;64590](https://github.com/nodejs/node/pull/64590) - \[[`2ba740669d`](https://github.com/nodejs/node/commit/2ba740669d)] - **sea**: avoid dangling CLI option pointers (Archkon) [#&#8203;64755](https://github.com/nodejs/node/pull/64755) - \[[`ec5e2d6856`](https://github.com/nodejs/node/commit/ec5e2d6856)] - **sea**: handle NUL bytes in asset keys (Archkon) [#&#8203;64773](https://github.com/nodejs/node/pull/64773) - \[[`703b854293`](https://github.com/nodejs/node/commit/703b854293)] - **sea**: reject trailing content in config JSON (Archkon) [#&#8203;64774](https://github.com/nodejs/node/pull/64774) - \[[`a61a5fdd1c`](https://github.com/nodejs/node/commit/a61a5fdd1c)] - **sqlite**: prevent reentrant session.close() (Trivikram Kamat) [#&#8203;65349](https://github.com/nodejs/node/pull/65349) - \[[`6ae81be0a3`](https://github.com/nodejs/node/commit/6ae81be0a3)] - **sqlite**: reject statement-less SQL in prepare() (Trevor Burnham) [#&#8203;65157](https://github.com/nodejs/node/pull/65157) - \[[`043dfe4996`](https://github.com/nodejs/node/commit/043dfe4996)] - **sqlite**: reject statement-less SQL in SQLTagStore (Trevor Burnham) [#&#8203;65157](https://github.com/nodejs/node/pull/65157) - \[[`b8faee02e1`](https://github.com/nodejs/node/commit/b8faee02e1)] - **sqlite**: check null returns from sqlite value functions (Nora Dossche) [#&#8203;63288](https://github.com/nodejs/node/pull/63288) - \[[`d6d2a71bee`](https://github.com/nodejs/node/commit/d6d2a71bee)] - **sqlite**: validate maxSize argument in createTagStore() (Anshika Jain) [#&#8203;63792](https://github.com/nodejs/node/pull/63792) - \[[`61a046309f`](https://github.com/nodejs/node/commit/61a046309f)] - **sqlite**: reject non-positive backup rates (Trivikram Kamat) [#&#8203;64893](https://github.com/nodejs/node/pull/64893) - \[[`514e3f30fb`](https://github.com/nodejs/node/commit/514e3f30fb)] - **sqlite**: clear SQLTagStore bindings (Matteo Collina) [#&#8203;65041](https://github.com/nodejs/node/pull/65041) - \[[`c1542255b8`](https://github.com/nodejs/node/commit/c1542255b8)] - **sqlite**: bind Boolean (mike-git374) [#&#8203;62001](https://github.com/nodejs/node/pull/62001) - \[[`cdb732beb5`](https://github.com/nodejs/node/commit/cdb732beb5)] - **sqlite**: fix undefined behaviour in `Session::Changeset()` (Nora Dossche) [#&#8203;63637](https://github.com/nodejs/node/pull/63637) - \[[`fbe8861111`](https://github.com/nodejs/node/commit/fbe8861111)] - **sqlite**: bind ArrayBuffer (mike-git374) [#&#8203;62061](https://github.com/nodejs/node/pull/62061) - \[[`e3c6bd6bc8`](https://github.com/nodejs/node/commit/e3c6bd6bc8)] - **src**: add missing vector include (Filip Skokan) [#&#8203;65622](https://github.com/nodejs/node/pull/65622) - \[[`793cf69df8`](https://github.com/nodejs/node/commit/793cf69df8)] - **src**: fix heap value deduplication in embedder graph (Ilyas Shabi) [#&#8203;64801](https://github.com/nodejs/node/pull/64801) - \[[`ea5935b04c`](https://github.com/nodejs/node/commit/ea5935b04c)] - **src**: fix out-of-bounds write when transcoding odd-length ucs2 (nashit hayat) [#&#8203;64512](https://github.com/nodejs/node/pull/64512) - \[[`22e5023f4d`](https://github.com/nodejs/node/commit/22e5023f4d)] - **src**: escape Windows environment variables in task runner (Antoine du Hamel) [#&#8203;65217](https://github.com/nodejs/node/pull/65217) - \[[`a0f3c62bd9`](https://github.com/nodejs/node/commit/a0f3c62bd9)] - **src**: simplify c++ diagnostics channel API (James M Snell) [#&#8203;65158](https://github.com/nodejs/node/pull/65158) - \[[`8e831a3d2e`](https://github.com/nodejs/node/commit/8e831a3d2e)] - **src**: make minor cleanup to permission checks (James M Snell) [#&#8203;65158](https://github.com/nodejs/node/pull/65158) - \[[`968b2ca3a3`](https://github.com/nodejs/node/commit/968b2ca3a3)] - **src**: use DictionaryTemplate for permission diag channel message (James M Snell) [#&#8203;65158](https://github.com/nodejs/node/pull/65158) - \[[`18e16e7f8d`](https://github.com/nodejs/node/commit/18e16e7f8d)] - **src**: cache permission strings (James M Snell) [#&#8203;65158](https://github.com/nodejs/node/pull/65158) - \[[`c8625a4b6f`](https://github.com/nodejs/node/commit/c8625a4b6f)] - **src**: add SetAbortHandler (Max H Fisher) [#&#8203;64684](https://github.com/nodejs/node/pull/64684) - \[[`c990140d60`](https://github.com/nodejs/node/commit/c990140d60)] - **src**: match cmd.exe case-insensitively in task runner (Archkon) [#&#8203;64907](https://github.com/nodejs/node/pull/64907) - \[[`d7463b9dbc`](https://github.com/nodejs/node/commit/d7463b9dbc)] - **src**: reuse cached env strings in remaining files (Seongeun Lee) [#&#8203;65039](https://github.com/nodejs/node/pull/65039) - \[[`b055a43b93`](https://github.com/nodejs/node/commit/b055a43b93)] - **src**: expose Windows-only fs open flags (Kirill Saied) [#&#8203;64775](https://github.com/nodejs/node/pull/64775) - \[[`7f21e37496`](https://github.com/nodejs/node/commit/7f21e37496)] - **src**: report why --enable-fips failed (Filip Skokan) [#&#8203;64979](https://github.com/nodejs/node/pull/64979) - \[[`8c11beae27`](https://github.com/nodejs/node/commit/8c11beae27)] - **src**: update repeated use strings to env (James M Snell) [#&#8203;64760](https://github.com/nodejs/node/pull/64760) - \[[`9e2c477e26`](https://github.com/nodejs/node/commit/9e2c477e26)] - **stream**: normalize fused stateless transform results (Trivikram Kamat) [#&#8203;65367](https://github.com/nodejs/node/pull/65367) - \[[`107e96dd41`](https://github.com/nodejs/node/commit/107e96dd41)] - **stream**: encode whole chunks in TextEncoderStream (Matteo Collina) [#&#8203;65414](https://github.com/nodejs/node/pull/65414) - \[[`164068279b`](https://github.com/nodejs/node/commit/164068279b)] - **stream**: prevent share from eagerly draining source (Trivikram Kamat) [#&#8203;65338](https://github.com/nodejs/node/pull/65338) - \[[`93d822bdc1`](https://github.com/nodejs/node/commit/93d822bdc1)] - **stream**: drain pending writes before broadcast end (Trivikram Kamat) [#&#8203;65334](https://github.com/nodejs/node/pull/65334) - \[[`6b8b9c362f`](https://github.com/nodejs/node/commit/6b8b9c362f)] - **stream**: reuse unexposed managed read buffers (GetThatCookie) [#&#8203;64990](https://github.com/nodejs/node/pull/64990) - \[[`4ec4fab367`](https://github.com/nodejs/node/commit/4ec4fab367)] - **stream**: avoid duplicated endReadableNT scheduling (Matteo Collina) [#&#8203;65310](https://github.com/nodejs/node/pull/65310) - \[[`86d1196ebf`](https://github.com/nodejs/node/commit/86d1196ebf)] - **stream**: decouple transform backpressure changes (Matteo Collina) [#&#8203;65143](https://github.com/nodejs/node/pull/65143) - \[[`b8a7a75b19`](https://github.com/nodejs/node/commit/b8a7a75b19)] - **stream**: reject pull on signal abort during flush (Trivikram Kamat) [#&#8203;65346](https://github.com/nodejs/node/pull/65346) - \[[`386ed6a06d`](https://github.com/nodejs/node/commit/386ed6a06d)] - **stream**: avoid leaking consumers on signal failure (Trivikram Kamat) [#&#8203;65299](https://github.com/nodejs/node/pull/65299) - \[[`74d53bd73b`](https://github.com/nodejs/node/commit/74d53bd73b)] - **stream**: use validateObject for zlib/iter params (greenhead) [#&#8203;65015](https://github.com/nodejs/node/pull/65015) - \[[`3a174ce16b`](https://github.com/nodejs/node/commit/3a174ce16b)] - **stream**: use validateNumber for BYOB reader options.min (greenhead) [#&#8203;65014](https://github.com/nodejs/node/pull/65014) - \[[`859ea01cb2`](https://github.com/nodejs/node/commit/859ea01cb2)] - **stream**: consolidate non-op algorithm callbacks (Matteo Collina) [#&#8203;65138](https://github.com/nodejs/node/pull/65138) - \[[`c577669825`](https://github.com/nodejs/node/commit/c577669825)] - **stream**: cut promise churn in webstreams hot paths (Matteo Collina) [#&#8203;65138](https://github.com/nodejs/node/pull/65138) - \[[`d631e910db`](https://github.com/nodejs/node/commit/d631e910db)] - **stream**: preserve falsy cancellation reasons (Trivikram Kamat) [#&#8203;64705](https://github.com/nodejs/node/pull/64705) - \[[`f9c21eabbd`](https://github.com/nodejs/node/commit/f9c21eabbd)] - **stream**: use validateBuffer for BYOB reader view (greenhead) [#&#8203;65046](https://github.com/nodejs/node/pull/65046) - \[[`b89c8f5d1e`](https://github.com/nodejs/node/commit/b89c8f5d1e)] - **stream**: fix recursive WritableStream abort (Jeong SeokChan) [#&#8203;64825](https://github.com/nodejs/node/pull/64825) - \[[`39e0457e86`](https://github.com/nodejs/node/commit/39e0457e86)] - **test**: fix link-local dgram scope assertion (Filip Skokan) [#&#8203;65629](https://github.com/nodejs/node/pull/65629) - \[[`1433cf9d5b`](https://github.com/nodejs/node/commit/1433cf9d5b)] - **test**: account for varied OpenSSL CCM final behaviours (Filip Skokan) [#&#8203;65542](https://github.com/nodejs/node/pull/65542) - \[[`7d135d24b7`](https://github.com/nodejs/node/commit/7d135d24b7)] - **test**: convert forEach to for of test-messageevent-brandcheck file (Nachiketa Pathak) [#&#8203;65279](https://github.com/nodejs/node/pull/65279) - \[[`421ee11715`](https://github.com/nodejs/node/commit/421ee11715)] - **test**: use spawnSyncAndAssert in windowsHide test (Junsoo Ha) [#&#8203;65351](https://github.com/nodejs/node/pull/65351) - \[[`929d5705bc`](https://github.com/nodejs/node/commit/929d5705bc)] - **test**: remove test-debugger-run-after-quit-restart as flaky on macOS (Yuya Inoue) [#&#8203;65424](https://github.com/nodejs/node/pull/65424) - \[[`f38f154c14`](https://github.com/nodejs/node/commit/f38f154c14)] - **test**: simplify test-timers-interval-promisified.js (Donghoon Kang) [#&#8203;65322](https://github.com/nodejs/node/pull/65322) - \[[`a98e27f2a9`](https://github.com/nodejs/node/commit/a98e27f2a9)] - **test**: add Headers coverage and benchmark (Yagiz Nizipli) [#&#8203;65365](https://github.com/nodejs/node/pull/65365) - \[[`38fdbb62aa`](https://github.com/nodejs/node/commit/38fdbb62aa)] - **test**: deflake test-net-listen-ipv6only (sangwook) [#&#8203;64173](https://github.com/nodejs/node/pull/64173) - \[[`06c7684b01`](https://github.com/nodejs/node/commit/06c7684b01)] - **test**: use common/child\_process spawnSync helpers (Junsoo Ha) [#&#8203;65377](https://github.com/nodejs/node/pull/65377) - \[[`6438c70004`](https://github.com/nodejs/node/commit/6438c70004)] - **test**: fix Linux debug skip in SEA test guard (구현우) [#&#8203;63751](https://github.com/nodejs/node/pull/63751) - \[[`fe0e4f1b65`](https://github.com/nodejs/node/commit/fe0e4f1b65)] - **test**: avoid timer race in event loop delay test (Trivikram Kamat) [#&#8203;64728](https://github.com/nodejs/node/pull/64728) - \[[`6ff69baea8`](https://github.com/nodejs/node/commit/6ff69baea8)] - **test**: enforce exit code in `test-http-server-stale-close` (Antoine du Hamel) [#&#8203;65198](https://github.com/nodejs/node/pull/65198) - \[[`ba87603016`](https://github.com/nodejs/node/commit/ba87603016)] - **test**: convert test-async-local-storage-bind to async loop (freida-code) [#&#8203;65270](https://github.com/nodejs/node/pull/65270) - \[[`8d6b89f454`](https://github.com/nodejs/node/commit/8d6b89f454)] - **test**: replace `forEach()` with `for...of` in parallel tests (Phillip Markert) [#&#8203;65272](https://github.com/nodejs/node/pull/65272) - \[[`a60572a7bb`](https://github.com/nodejs/node/commit/a60572a7bb)] - **test**: convert forEach to for in test-constant.js file (NIxxy25) [#&#8203;65271](https://github.com/nodejs/node/pull/65271) - \[[`f82060c6ce`](https://github.com/nodejs/node/commit/f82060c6ce)] - **test**: use for-of instead of forEach (Felix P.) [#&#8203;65268](https://github.com/nodejs/node/pull/65268) - \[[`5ded71f9cc`](https://github.com/nodejs/node/commit/5ded71f9cc)] - **test**: cover `realpathSync` resolving symlinks after a FIFO stat (Hendrik Liebau) [#&#8203;65113](https://github.com/nodejs/node/pull/65113) - \[[`ac9835225e`](https://github.com/nodejs/node/commit/ac9835225e)] - **test**: account for \[EnforceRange] in test-webcrypto-prototype-pollution (Filip Skokan) [#&#8203;65173](https://github.com/nodejs/node/pull/65173) - \[[`550d24277e`](https://github.com/nodejs/node/commit/550d24277e)] - **test**: update WPT for WebCryptoAPI to [`4c2fd05`](https://github.com/nodejs/node/commit/4c2fd05ed5) (Node.js GitHub Bot) [#&#8203;65150](https://github.com/nodejs/node/pull/65150) - \[[`2aa26559f0`](https://github.com/nodejs/node/commit/2aa26559f0)] - **test**: update WPT for urlpattern to [`4832db4`](https://github.com/nodejs/node/commit/4832db4761) (Node.js GitHub Bot) [#&#8203;65151](https://github.com/nodejs/node/pull/65151) - \[[`d45c010108`](https://github.com/nodejs/node/commit/d45c010108)] - **test**: fix hidden error in test-http-server-stale-close.js (Meghan Denny) [#&#8203;59357](https://github.com/nodejs/node/pull/59357) - \[[`881f8d092d`](https://github.com/nodejs/node/commit/881f8d092d)] - **test**: avoid deadlock issue in pipeline http2 tests to fix flakiness (Tim Perry) [#&#8203;65079](https://github.com/nodejs/node/pull/65079) - \[[`e4b1e3ee75`](https://github.com/nodejs/node/commit/e4b1e3ee75)] - **test**: allow half-open CONNECT tunnel sockets (Trivikram Kamat) [#&#8203;64973](https://github.com/nodejs/node/pull/64973) - \[[`00f4240d48`](https://github.com/nodejs/node/commit/00f4240d48)] - **test**: update passphrases to comply with the next OpenSSL FIPS mode (Filip Skokan) [#&#8203;65077](https://github.com/nodejs/node/pull/65077) - \[[`cf7680efb7`](https://github.com/nodejs/node/commit/cf7680efb7)] - **test**: use libuv clock for immediate queue test (Trivikram Kamat) [#&#8203;64889](https://github.com/nodejs/node/pull/64889) - \[[`b0c12772ff`](https://github.com/nodejs/node/commit/b0c12772ff)] - **test**: increase timeout in probe-failure-hang-during-evaluate (Joyee Cheung) [#&#8203;64719](https://github.com/nodejs/node/pull/64719) - \[[`7e279104b4`](https://github.com/nodejs/node/commit/7e279104b4)] - **test**: update WPT for WebCryptoAPI to [`82c3d90`](https://github.com/nodejs/node/commit/82c3d9069c) (Node.js GitHub Bot) [#&#8203;64977](https://github.com/nodejs/node/pull/64977) - \[[`ac11f88d16`](https://github.com/nodejs/node/commit/ac11f88d16)] - **test,doc**: cover and document multi-byte offset/size in randomFill (kyungrae2002) [#&#8203;64834](https://github.com/nodejs/node/pull/64834) - \[[`67da38cada`](https://github.com/nodejs/node/commit/67da38cada)] - **test\_runner**: match dotfiles in default coverage exclude (semimikoh) [#&#8203;63401](https://github.com/nodejs/node/pull/63401) - \[[`b06c61a08f`](https://github.com/nodejs/node/commit/b06c61a08f)] - **test\_runner**: print coverage and diagnostic info with dot reporter (mag123c) [#&#8203;61423](https://github.com/nodejs/node/pull/61423) - \[[`7cb9c9c126`](https://github.com/nodejs/node/commit/7cb9c9c126)] - **test\_runner**: use run options with isolation="none" (Sylvester Keil) [#&#8203;62269](https://github.com/nodejs/node/pull/62269) - \[[`339acf4201`](https://github.com/nodejs/node/commit/339acf4201)] - **test\_runner**: mock dual-package with conditional exports (Maruthan G) [#&#8203;62943](https://github.com/nodejs/node/pull/62943) - \[[`e7a68bca08`](https://github.com/nodejs/node/commit/e7a68bca08)] - **test\_runner**: add classname hierarchy for JUnit reporter (mag123c) [#&#8203;60220](https://github.com/nodejs/node/pull/60220) - \[[`6a248acefe`](https://github.com/nodejs/node/commit/6a248acefe)] - **test\_runner**: fix junit report on empty diagnostic (Lazizbek Ergashev) [#&#8203;65357](https://github.com/nodejs/node/pull/65357) - \[[`d01dda79b6`](https://github.com/nodejs/node/commit/d01dda79b6)] - **test\_runner**: do not tag-filter test file wrappers (Chemi Atlow) [#&#8203;65170](https://github.com/nodejs/node/pull/65170) - \[[`32ead10ddd`](https://github.com/nodejs/node/commit/32ead10ddd)] - **test\_runner**: fix env option validation (Jihwan) [#&#8203;64865](https://github.com/nodejs/node/pull/64865) - \[[`b0ef155440`](https://github.com/nodejs/node/commit/b0ef155440)] - **tls**: throw on invalid ALPNProtocols instead of aborting (Sankalp Thakur) [#&#8203;65076](https://github.com/nodejs/node/pull/65076) - \[[`dcf65c50ce`](https://github.com/nodejs/node/commit/dcf65c50ce)] - **tls**: fix authorized state on no-cert TLS1.3 client cert resumption (Tim Perry) [#&#8203;64677](https://github.com/nodejs/node/pull/64677) - \[[`b0f54bda78`](https://github.com/nodejs/node/commit/b0f54bda78)] - **tools**: improve commit queue failure comment (Filip Skokan) [#&#8203;65433](https://github.com/nodejs/node/pull/65433) - \[[`bc1f2718d5`](https://github.com/nodejs/node/commit/bc1f2718d5)] - **tools**: fix max body length handler in `create-release-proposal.sh` (Antoine du Hamel) [#&#8203;65455](https://github.com/nodejs/node/pull/65455) - \[[`bbe76516a9`](https://github.com/nodejs/node/commit/bbe76516a9)] - **tools**: bump brace-expansion in `/tools/clang-format` (dependabot\[bot]) [#&#8203;64984](https://github.com/nodejs/node/pull/64984) - \[[`67697debdf`](https://github.com/nodejs/node/commit/67697debdf)] - **tools**: make env variables consistent in cron jobs (Antoine du Hamel) [#&#8203;65168](https://github.com/nodejs/node/pull/65168) - \[[`ac8a68ec92`](https://github.com/nodejs/node/commit/ac8a68ec92)] - **tools**: only include fast-tracked and old enough PRs in CQ (Antoine du Hamel) [#&#8203;65197](https://github.com/nodejs/node/pull/65197) - \[[`6d9999fa2e`](https://github.com/nodejs/node/commit/6d9999fa2e)] - **tools**: remove skip logic in `commit-queue.sh` (Antoine du Hamel) [#&#8203;65162](https://github.com/nodejs/node/pull/65162) - \[[`60bfa1694e`](https://github.com/nodejs/node/commit/60bfa1694e)] - **tools**: bump js-yaml from 4.2.0 to 4.3.1 in /tools/lint-md (dependabot\[bot]) [#&#8203;65129](https://github.com/nodejs/node/pull/65129) - \[[`782748527e`](https://github.com/nodejs/node/commit/782748527e)] - **tools**: bump js-yaml from 4.2.0 to 4.3.1 in /tools/eslint (dependabot\[bot]) [#&#8203;65130](https://github.com/nodejs/node/pull/65130) - \[[`dac257340f`](https://github.com/nodejs/node/commit/dac257340f)] - **tools**: fix GITHUB\_TOKEN permissions for CQ workflow (Antoine du Hamel) [#&#8203;65192](https://github.com/nodejs/node/pull/65192) - \[[`e624785846`](https://github.com/nodejs/node/commit/e624785846)] - **tools**: use the read-only token when filtering PRs in CQ (Antoine du Hamel) [#&#8203;65169](https://github.com/nodejs/node/pull/65169) - \[[`7d9dcfaaa7`](https://github.com/nodejs/node/commit/7d9dcfaaa7)] - **tools**: delay removal of `commit-queue` label (Antoine du Hamel) [#&#8203;65101](https://github.com/nodejs/node/pull/65101) - \[[`0d7c7936e7`](https://github.com/nodejs/node/commit/0d7c7936e7)] - **tools**: move ncu config to global for commit queue (Filip Skokan) [#&#8203;65132](https://github.com/nodejs/node/pull/65132) - \[[`5e1db5a38a`](https://github.com/nodejs/node/commit/5e1db5a38a)] - **tools**: prefilter commit queue metadata (Filip Skokan) [#&#8203;64343](https://github.com/nodejs/node/pull/64343) - \[[`f41509b91d`](https://github.com/nodejs/node/commit/f41509b91d)] - **tools**: lazy-abort failed PR merges in CQ (Antoine du Hamel) [#&#8203;65004](https://github.com/nodejs/node/pull/65004) - \[[`ceb0e99acd`](https://github.com/nodejs/node/commit/ceb0e99acd)] - **tools**: sync mk-ca-bundle.pl with curl (Archkon) [#&#8203;64753](https://github.com/nodejs/node/pull/64753) - \[[`600663b23f`](https://github.com/nodejs/node/commit/600663b23f)] - **tty**: add raw-vt and io raw modes (Samuel Williams) [#&#8203;64140](https://github.com/nodejs/node/pull/64140) - \[[`a40bfc742e`](https://github.com/nodejs/node/commit/a40bfc742e)] - **typings**: add signal\_wrap internal binding types (Seongeun Lee) [#&#8203;65229](https://github.com/nodejs/node/pull/65229) - \[[`b103a4a3b9`](https://github.com/nodejs/node/commit/b103a4a3b9)] - **typings**: add diagnostics\_channel typings (Seongeun Lee) [#&#8203;65227](https://github.com/nodejs/node/pull/65227) - \[[`e64de34b89`](https://github.com/nodejs/node/commit/e64de34b89)] - **typings**: add watchdog internal binding types (Seongeun Lee) [#&#8203;65228](https://github.com/nodejs/node/pull/65228) - \[[`c57c83b4d1`](https://github.com/nodejs/node/commit/c57c83b4d1)] - **typings**: add internal\_only\_v8 binding typeis (Donghoon Kang) [#&#8203;65071](https://github.com/nodejs/node/pull/65071) - \[[`f15e8c9dcd`](https://github.com/nodejs/node/commit/f15e8c9dcd)] - **typings**: add credentials internal binding types (Donghoon Kang) [#&#8203;65036](https://github.com/nodejs/node/pull/65036) - \[[`a500256b0b`](https://github.com/nodejs/node/commit/a500256b0b)] - **url**: skip unused href reuse comparison (Yagiz Nizipli) [#&#8203;65361](https://github.com/nodejs/node/pull/65361) - \[[`58390f8bec`](https://github.com/nodejs/node/commit/58390f8bec)] - **url**: speed up WHATWG URL parsing (Yagiz Nizipli) [#&#8203;65361](https://github.com/nodejs/node/pull/65361) - \[[`7d5428c812`](https://github.com/nodejs/node/commit/7d5428c812)] - **url**: speed up URLSearchParams (Yagiz Nizipli) [#&#8203;65363](https://github.com/nodejs/node/pull/65363) - \[[`8e2461d819`](https://github.com/nodejs/node/commit/8e2461d819)] - **url**: bounds-check short Windows file URL paths (Archkon) [#&#8203;64788](https://github.com/nodejs/node/pull/64788) - \[[`9ffc0da90c`](https://github.com/nodejs/node/commit/9ffc0da90c)] - **url**: handle unparsable serialized URLs in setters (Matteo Collina) [#&#8203;64651](https://github.com/nodejs/node/pull/64651) - \[[`fa9d4e075d`](https://github.com/nodejs/node/commit/fa9d4e075d)] - **util**: allow single-line format when break length is infinite (Hamid Reza Ghavami) [#&#8203;64238](https://github.com/nodejs/node/pull/64238) - \[[`b68a7c3862`](https://github.com/nodejs/node/commit/b68a7c3862)] - **util**: fix OSC 8 hyperlink stripping in stripVTControlCharacters (Dushyant Singh Hada) [#&#8203;64319](https://github.com/nodejs/node/pull/64319) - \[[`10cbb6dc00`](https://github.com/nodejs/node/commit/10cbb6dc00)] - **util**: fix formatting of functions returned from getters (Richard Gibson) [#&#8203;64839](https://github.com/nodejs/node/pull/64839) - \[[`64c20b449e`](https://github.com/nodejs/node/commit/64c20b449e)] - **util**: use more primordials in `comparisons.js` (Ayoub Mabrouk) [#&#8203;61198](https://github.com/nodejs/node/pull/61198) - \[[`cea9786de8`](https://github.com/nodejs/node/commit/cea9786de8)] - **util**: preserve function names without source map names (Hiroki Osame) [#&#8203;65108](https://github.com/nodejs/node/pull/65108) - \[[`35c635b032`](https://github.com/nodejs/node/commit/35c635b032)] - **(SEMVER-MINOR)** **util**: add non-throwing MIMEType.parse (James M Snell) [#&#8203;64965](https://github.com/nodejs/node/pull/64965) - \[[`5858c2ba9a`](https://github.com/nodejs/node/commit/5858c2ba9a)] - **zlib**: validate pledgedSrcSize for sync zstd (Archkon) [#&#8203;64601](https://github.com/nodejs/node/pull/64601) ### [`v24.20.0`](https://github.com/nodejs/node/releases/tag/v24.20.0): 2026-08-26, Version 24.20.0 'Krypton' (LTS), @&#8203;aduh95 [Compare Source](https://github.com/nodejs/node/compare/v24.19.0...v24.20.0) ##### Notable Changes - \[[`b12bcc9ae1`](https://github.com/nodejs/node/commit/b12bcc9ae1)] - **(SEMVER-MINOR)** **async\_hooks**: add `using` scopes to `AsyncLocalStorage` (Stephen Belanger) [#&#8203;61674](https://github.com/nodejs/node/pull/61674) - \[[`e2eb88b36b`](https://github.com/nodejs/node/commit/e2eb88b36b)] - **(SEMVER-MINOR)** **buffer**: add `end` parameter (Robert Nagy) [#&#8203;62390](https://github.com/nodejs/node/pull/62390) - \[[`1fefdda18e`](https://github.com/nodejs/node/commit/1fefdda18e)] - **crypto**: update root certificates to NSS 3.125 (Node.js GitHub Bot) [#&#8203;64746](https://github.com/nodejs/node/pull/64746) - \[[`4a158cf1ab`](https://github.com/nodejs/node/commit/4a158cf1ab)] - **doc**: add MikeMcC399 as collaborator (Mike McCready) [#&#8203;64656](https://github.com/nodejs/node/pull/64656) - \[[`d4cafce076`](https://github.com/nodejs/node/commit/d4cafce076)] - **(SEMVER-MINOR)** **lib,permission**: add `permission.drop` (Rafael Gonzaga) [#&#8203;62672](https://github.com/nodejs/node/pull/62672) - \[[`b3cfb55267`](https://github.com/nodejs/node/commit/b3cfb55267)] - **(SEMVER-MINOR)** **loader**: implement package maps (Maël Nison) [#&#8203;62239](https://github.com/nodejs/node/pull/62239) - \[[`cd1eb3e60b`](https://github.com/nodejs/node/commit/cd1eb3e60b)] - **(SEMVER-MINOR)** **src,permission**: add `--permission-audit` (RafaelGSS) [#&#8203;61869](https://github.com/nodejs/node/pull/61869) - \[[`28dc85d8d2`](https://github.com/nodejs/node/commit/28dc85d8d2)] - **(SEMVER-MINOR)** **stream**: add `node:stream/iter` implementation (James M Snell) [#&#8203;62066](https://github.com/nodejs/node/pull/62066) - \[[`d31c168740`](https://github.com/nodejs/node/commit/d31c168740)] - **(SEMVER-MINOR)** **test\_runner**: add `context.log()` and test:log event (Moshe Atlow) [#&#8203;64389](https://github.com/nodejs/node/pull/64389) - \[[`add1edbc42`](https://github.com/nodejs/node/commit/add1edbc42)] - **(SEMVER-MINOR)** **test\_runner**: report `entryFile` in `TestStream` events (Moshe Atlow) [#&#8203;64309](https://github.com/nodejs/node/pull/64309) - \[[`d937c8c6cd`](https://github.com/nodejs/node/commit/d937c8c6cd)] - **(SEMVER-MINOR)** **wasm**: enable JSPI (Guy Bedford) [#&#8203;59941](https://github.com/nodejs/node/pull/59941) ##### Commits - \[[`1822c0f335`](https://github.com/nodejs/node/commit/1822c0f335)] - **assert,util**: fix TypeError on Maps with null keys (Paul Bouchon) [#&#8203;64441](https://github.com/nodejs/node/pull/64441) - \[[`b12bcc9ae1`](https://github.com/nodejs/node/commit/b12bcc9ae1)] - **(SEMVER-MINOR)** **async\_hooks**: add using scopes to AsyncLocalStorage (Stephen Belanger) [#&#8203;61674](https://github.com/nodejs/node/pull/61674) - \[[`984260bf44`](https://github.com/nodejs/node/commit/984260bf44)] - **async\_hooks**: use validateBoolean for trackPromises (Soul Lee) [#&#8203;64731](https://github.com/nodejs/node/pull/64731) - \[[`ba2612cca2`](https://github.com/nodejs/node/commit/ba2612cca2)] - **benchmark**: fix calibrate-n option handling (Luan Muniz) [#&#8203;64146](https://github.com/nodejs/node/pull/64146) - \[[`236dc4d2d7`](https://github.com/nodejs/node/commit/236dc4d2d7)] - **benchmark**: add bytes variant to webstreams async-iterator (Matteo Collina) [#&#8203;64291](https://github.com/nodejs/node/pull/64291) - \[[`b022a1419c`](https://github.com/nodejs/node/commit/b022a1419c)] - **benchmark**: respect stream/iter broadcast backpressure (Trivikram Kamat) [#&#8203;63314](https://github.com/nodejs/node/pull/63314) - \[[`a290f51f15`](https://github.com/nodejs/node/commit/a290f51f15)] - **(SEMVER-MINOR)** **benchmark**: add benchmarks for experimental stream/iter (James M Snell) [#&#8203;62066](https://github.com/nodejs/node/pull/62066) - \[[`465f2bfb74`](https://github.com/nodejs/node/commit/465f2bfb74)] - **buffer**: use Clamp conversion in Blob slice (Donghoon Kang) [#&#8203;64739](https://github.com/nodejs/node/pull/64739) - \[[`74a22cd0c5`](https://github.com/nodejs/node/commit/74a22cd0c5)] - **buffer**: validate copyArrayBuffer offsets against buffer length (Ilia Alshanetsky) [#&#8203;63904](https://github.com/nodejs/node/pull/63904) - \[[`21e24208dc`](https://github.com/nodejs/node/commit/21e24208dc)] - **buffer**: normalize lone "\r" in Blob native line endings (Daijiro Wachi) [#&#8203;64115](https://github.com/nodejs/node/pull/64115) - \[[`ddacb3ff10`](https://github.com/nodejs/node/commit/ddacb3ff10)] - **buffer**: fix Blob.stream() leaking source buffer (semimikoh) [#&#8203;63577](https://github.com/nodejs/node/pull/63577) - \[[`49198d2313`](https://github.com/nodejs/node/commit/49198d2313)] - **buffer**: fix end parameter bugs in indexOf/lastIndexOf (Robert Nagy) [#&#8203;62711](https://github.com/nodejs/node/pull/62711) - \[[`e2eb88b36b`](https://github.com/nodejs/node/commit/e2eb88b36b)] - **(SEMVER-MINOR)** **buffer**: add end parameter (Robert Nagy) [#&#8203;62390](https://github.com/nodejs/node/pull/62390) - \[[`e2e5c4fe88`](https://github.com/nodejs/node/commit/e2e5c4fe88)] - **build**: update binary-upload to use correct tarball name (Stewart X Addison) [#&#8203;65282](https://github.com/nodejs/node/pull/65282) - \[[`b78a212553`](https://github.com/nodejs/node/commit/b78a212553)] - **build**: pin envinfo versions in github actions (Joyee Cheung) [#&#8203;64117](https://github.com/nodejs/node/pull/64117) - \[[`094fb840aa`](https://github.com/nodejs/node/commit/094fb840aa)] - **build**: add QUIC CI job for PRs matching QUIC related paths (Tim Perry) [#&#8203;63875](https://github.com/nodejs/node/pull/63875) - \[[`91f5003cad`](https://github.com/nodejs/node/commit/91f5003cad)] - **build**: fix flags for ngtcp2 on IBM i (SRAVANI GUNDEPALLI) [#&#8203;60073](https://github.com/nodejs/node/pull/60073) - \[[`e83648effd`](https://github.com/nodejs/node/commit/e83648effd)] - **build,test**: add tests for binary linked with shared libnode (Joyee Cheung) [#&#8203;61463](https://github.com/nodejs/node/pull/61463) - \[[`4a425b41d9`](https://github.com/nodejs/node/commit/4a425b41d9)] - **build,tools**: fix shared library cross-compile (Kirill Saied) [#&#8203;63963](https://github.com/nodejs/node/pull/63963) - \[[`fe8fa45ff2`](https://github.com/nodejs/node/commit/fe8fa45ff2)] - **cli**: style node --help output with util.styleText (Adrián Estrada) [#&#8203;64484](https://github.com/nodejs/node/pull/64484) - \[[`3cd1576cb2`](https://github.com/nodejs/node/commit/3cd1576cb2)] - **crypto**: preserve OpenSSL errors from KDF failures (Filip Skokan) [#&#8203;64776](https://github.com/nodejs/node/pull/64776) - \[[`74b3023565`](https://github.com/nodejs/node/commit/74b3023565)] - **crypto**: handle XOF output allocation failure (Filip Skokan) [#&#8203;64851](https://github.com/nodejs/node/pull/64851) - \[[`fea0666a1b`](https://github.com/nodejs/node/commit/fea0666a1b)] - **crypto**: clarify missing cipher error (Filip Skokan) [#&#8203;64852](https://github.com/nodejs/node/pull/64852) - \[[`33fec91b54`](https://github.com/nodejs/node/commit/33fec91b54)] - **crypto**: reuse X509 issuer result (Filip Skokan) [#&#8203;64852](https://github.com/nodejs/node/pull/64852) - \[[`44c1473348`](https://github.com/nodejs/node/commit/44c1473348)] - **crypto**: validate key generation options (Filip Skokan) [#&#8203;64852](https://github.com/nodejs/node/pull/64852) - \[[`c2c53a18e5`](https://github.com/nodejs/node/commit/c2c53a18e5)] - **crypto**: fix Argon2 validation errors (Filip Skokan) [#&#8203;64852](https://github.com/nodejs/node/pull/64852) - \[[`edc1f2126d`](https://github.com/nodejs/node/commit/edc1f2126d)] - **crypto**: initialize KeyObjectData mutex eagerly (Filip Skokan) [#&#8203;64851](https://github.com/nodejs/node/pull/64851) - \[[`be8237240c`](https://github.com/nodejs/node/commit/be8237240c)] - **crypto**: handle DH operation failures (Filip Skokan) [#&#8203;64851](https://github.com/nodejs/node/pull/64851) - \[[`b65a8f3875`](https://github.com/nodejs/node/commit/b65a8f3875)] - **crypto**: preserve RSA-PSS legacy pubkey DER (Filip Skokan) [#&#8203;64547](https://github.com/nodejs/node/pull/64547) - \[[`49f2ae204b`](https://github.com/nodejs/node/commit/49f2ae204b)] - **crypto**: cleanse provider private key copies (Filip Skokan) [#&#8203;64547](https://github.com/nodejs/node/pull/64547) - \[[`a5d4ac8208`](https://github.com/nodejs/node/commit/a5d4ac8208)] - **crypto**: handle incomplete RSA private keys (Filip Skokan) [#&#8203;64547](https://github.com/nodejs/node/pull/64547) - \[[`b72c0b9616`](https://github.com/nodejs/node/commit/b72c0b9616)] - **crypto**: retain legacy DH validation (Filip Skokan) [#&#8203;64547](https://github.com/nodejs/node/pull/64547) - \[[`24a1be5886`](https://github.com/nodejs/node/commit/24a1be5886)] - **crypto**: limit KangarooTwelveParams customization to 512 bytes (Filip Skokan) [#&#8203;64557](https://github.com/nodejs/node/pull/64557) - \[[`0290e0a61e`](https://github.com/nodejs/node/commit/0290e0a61e)] - **crypto**: split OpenSSL 3, BoringSSL, and legacy backends (Filip Skokan) [#&#8203;64211](https://github.com/nodejs/node/pull/64211) - \[[`ba27e72ff8`](https://github.com/nodejs/node/commit/ba27e72ff8)] - **crypto**: fix Argon2 bypassing FIPS mode (Filip Skokan) [#&#8203;64776](https://github.com/nodejs/node/pull/64776) - \[[`1fefdda18e`](https://github.com/nodejs/node/commit/1fefdda18e)] - **crypto**: update root certificates to NSS 3.125 (Node.js GitHub Bot) [#&#8203;64746](https://github.com/nodejs/node/pull/64746) - \[[`c0dd022081`](https://github.com/nodejs/node/commit/c0dd022081)] - **crypto**: use user-facing error for output encoding changes (Archkon) [#&#8203;64692](https://github.com/nodejs/node/pull/64692) - \[[`ff485a9410`](https://github.com/nodejs/node/commit/ff485a9410)] - **crypto**: make --use-system-ca per-env rather than per-process (Aditi) [#&#8203;60678](https://github.com/nodejs/node/pull/60678) - \[[`1329d9b9f1`](https://github.com/nodejs/node/commit/1329d9b9f1)] - **debugger**: preserve overlapping CDP request state (Trivikram Kamat) [#&#8203;64467](https://github.com/nodejs/node/pull/64467) - \[[`82a02336aa`](https://github.com/nodejs/node/commit/82a02336aa)] - **deps**: V8: backport [`d259a9e`](https://github.com/nodejs/node/commit/d259a9e2ead7) (Leszek Swirski) [#&#8203;63865](https://github.com/nodejs/node/pull/63865) - \[[`f0fc82d404`](https://github.com/nodejs/node/commit/f0fc82d404)] - **deps**: update ngtcp2 to 1.25.0 (Node.js GitHub Bot) [#&#8203;64944](https://github.com/nodejs/node/pull/64944) - \[[`c4e02f0fbc`](https://github.com/nodejs/node/commit/c4e02f0fbc)] - **deps**: upgrade npm to 11.19.0 (npm team) [#&#8203;64883](https://github.com/nodejs/node/pull/64883) - \[[`d5a57ed4dd`](https://github.com/nodejs/node/commit/d5a57ed4dd)] - **deps**: update nghttp3 to 1.18.0 (Node.js GitHub Bot) [#&#8203;64943](https://github.com/nodejs/node/pull/64943) - \[[`51d413150a`](https://github.com/nodejs/node/commit/51d413150a)] - **deps**: update minimatch to 10.2.6 (Node.js GitHub Bot) [#&#8203;64945](https://github.com/nodejs/node/pull/64945) - \[[`21f79ce140`](https://github.com/nodejs/node/commit/21f79ce140)] - **deps**: update simdjson to 4.6.6 (Node.js GitHub Bot) [#&#8203;64942](https://github.com/nodejs/node/pull/64942) - \[[`7a4960d6a9`](https://github.com/nodejs/node/commit/7a4960d6a9)] - **deps**: update acorn to 8.18.0 (Node.js GitHub Bot) [#&#8203;64941](https://github.com/nodejs/node/pull/64941) - \[[`5c423aa113`](https://github.com/nodejs/node/commit/5c423aa113)] - **deps**: update googletest to [`1b6f64d`](https://github.com/nodejs/node/commit/1b6f64d659944658a4c685b7bd9f04c1c3b8a39b) (Node.js GitHub Bot) [#&#8203;64940](https://github.com/nodejs/node/pull/64940) - \[[`40561e61b0`](https://github.com/nodejs/node/commit/40561e61b0)] - **deps**: update nghttp2 to 1.70.0 (Node.js GitHub Bot) [#&#8203;64939](https://github.com/nodejs/node/pull/64939) - \[[`51090925b0`](https://github.com/nodejs/node/commit/51090925b0)] - **deps**: update zlib to 1.3.2.1-motley-42c2f19 (Node.js GitHub Bot) [#&#8203;64744](https://github.com/nodejs/node/pull/64744) - \[[`7c534bf8e5`](https://github.com/nodejs/node/commit/7c534bf8e5)] - **deps**: V8: backport [`5177b10`](https://github.com/nodejs/node/commit/5177b10891e6) (avivkeller) [#&#8203;64631](https://github.com/nodejs/node/pull/64631) - \[[`7b1898a341`](https://github.com/nodejs/node/commit/7b1898a341)] - **deps**: update ada to 4.0.0 (Node.js GitHub Bot) [#&#8203;64790](https://github.com/nodejs/node/pull/64790) - \[[`9209cc4095`](https://github.com/nodejs/node/commit/9209cc4095)] - **deps**: update sqlite to 3.53.4 (Node.js GitHub Bot) [#&#8203;64745](https://github.com/nodejs/node/pull/64745) - \[[`3833fceff6`](https://github.com/nodejs/node/commit/3833fceff6)] - **deps**: update googletest to [`fa005b2`](https://github.com/nodejs/node/commit/fa005b296f90faec4f352d7ab382287bf6548c8d) (Node.js GitHub Bot) [#&#8203;64587](https://github.com/nodejs/node/pull/64587) - \[[`bc7ce488d1`](https://github.com/nodejs/node/commit/bc7ce488d1)] - **deps**: histogram: cherry-pick [`62ea52b`](https://github.com/nodejs/node/commit/62ea52b07ee9b195) (StefanStojanovic) [#&#8203;64296](https://github.com/nodejs/node/pull/64296) - \[[`e3fa05841d`](https://github.com/nodejs/node/commit/e3fa05841d)] - **deps**: update histogram to 0.11.10 (Node.js GitHub Bot) [#&#8203;64296](https://github.com/nodejs/node/pull/64296) - \[[`e75bdb9bbe`](https://github.com/nodejs/node/commit/e75bdb9bbe)] - **deps**: update amaro to 1.1.11 (Node.js GitHub Bot) [#&#8203;64586](https://github.com/nodejs/node/pull/64586) - \[[`1e034e6e40`](https://github.com/nodejs/node/commit/1e034e6e40)] - **deps**: update timezone to 2026c (Node.js GitHub Bot) [#&#8203;64588](https://github.com/nodejs/node/pull/64588) - \[[`2b8f1f27bd`](https://github.com/nodejs/node/commit/2b8f1f27bd)] - **deps**: update googletest to [`8240fa7`](https://github.com/nodejs/node/commit/8240fa7d62f73e01c7af27d61ed965d6d66698fa) (Node.js GitHub Bot) [#&#8203;64439](https://github.com/nodejs/node/pull/64439) - \[[`241ece0417`](https://github.com/nodejs/node/commit/241ece0417)] - **deps**: enable OpenSSL asm support for riscv64 (Jamie Magee) [#&#8203;62606](https://github.com/nodejs/node/pull/62606) - \[[`215105eb90`](https://github.com/nodejs/node/commit/215105eb90)] - **deps**: update c-ares to 1.34.8 (Node.js GitHub Bot) [#&#8203;64330](https://github.com/nodejs/node/pull/64330) - \[[`7ac97fc84e`](https://github.com/nodejs/node/commit/7ac97fc84e)] - **deps**: upgrade npm to 11.18.0 (npm team) [#&#8203;64199](https://github.com/nodejs/node/pull/64199) - \[[`8d4cb9ae46`](https://github.com/nodejs/node/commit/8d4cb9ae46)] - **deps**: update zlib to 1.3.2.1-motley-8b3aa8a (Node.js GitHub Bot) [#&#8203;64295](https://github.com/nodejs/node/pull/64295) - \[[`564c0f4592`](https://github.com/nodejs/node/commit/564c0f4592)] - **deps**: update ngtcp2 to 1.24.0 (Node.js GitHub Bot) [#&#8203;64297](https://github.com/nodejs/node/pull/64297) - \[[`e3304cd31a`](https://github.com/nodejs/node/commit/e3304cd31a)] - **deps**: update nghttp3 to 1.17.0 (Node.js GitHub Bot) [#&#8203;64182](https://github.com/nodejs/node/pull/64182) - \[[`345d6ad4eb`](https://github.com/nodejs/node/commit/345d6ad4eb)] - **deps**: update ngtcp2 to 1.23.0 (Node.js GitHub Bot) [#&#8203;63777](https://github.com/nodejs/node/pull/63777) - \[[`a53db015e6`](https://github.com/nodejs/node/commit/a53db015e6)] - **deps**: update nghttp3 to 1.16.0 (Node.js GitHub Bot) [#&#8203;63776](https://github.com/nodejs/node/pull/63776) - \[[`1f4a5c1c76`](https://github.com/nodejs/node/commit/1f4a5c1c76)] - **deps**: update ngtcp2 to 1.22.1 (Node.js GitHub Bot) [#&#8203;62812](https://github.com/nodejs/node/pull/62812) - \[[`080c4d7cda`](https://github.com/nodejs/node/commit/080c4d7cda)] - **deps**: update ngtcp2 to 1.22.0 (Node.js GitHub Bot) [#&#8203;62595](https://github.com/nodejs/node/pull/62595) - \[[`4309e7c82f`](https://github.com/nodejs/node/commit/4309e7c82f)] - **deps**: update ngtcp2 to 1.21.0 (Node.js GitHub Bot) [#&#8203;62051](https://github.com/nodejs/node/pull/62051) - \[[`90cf11cfb5`](https://github.com/nodejs/node/commit/90cf11cfb5)] - **deps**: update nghttp3 to 1.15.0 (Node.js GitHub Bot) [#&#8203;61512](https://github.com/nodejs/node/pull/61512) - \[[`e1f315a554`](https://github.com/nodejs/node/commit/e1f315a554)] - **deps**: update ngtcp2 to 1.20.0 (Node.js GitHub Bot) [#&#8203;61511](https://github.com/nodejs/node/pull/61511) - \[[`9a3f690c9d`](https://github.com/nodejs/node/commit/9a3f690c9d)] - **deps**: update ngtcp2 to 1.19.0 (Node.js GitHub Bot) [#&#8203;61156](https://github.com/nodejs/node/pull/61156) - \[[`fe88f31764`](https://github.com/nodejs/node/commit/fe88f31764)] - **deps**: add ngtcp2 test binaries (James M Snell) [#&#8203;59946](https://github.com/nodejs/node/pull/59946) - \[[`6d60fce138`](https://github.com/nodejs/node/commit/6d60fce138)] - **diagnostics\_channel**: grow native channel storage (Stephen Belanger) [#&#8203;64497](https://github.com/nodejs/node/pull/64497) - \[[`30ae8ab091`](https://github.com/nodejs/node/commit/30ae8ab091)] - **doc**: document --permission-audit audit mode behavior (Adrián Estrada) [#&#8203;64791](https://github.com/nodejs/node/pull/64791) - \[[`8cefc6efa8`](https://github.com/nodejs/node/commit/8cefc6efa8)] - **doc**: fix guaranteed typo (lilianakatrina684-a11y) [#&#8203;62374](https://github.com/nodejs/node/pull/62374) - \[[`2e78e4b120`](https://github.com/nodejs/node/commit/2e78e4b120)] - **doc**: add throwIfNoEntry version history to fs.stat (kovan) [#&#8203;62204](https://github.com/nodejs/node/pull/62204) - \[[`c7a04401cb`](https://github.com/nodejs/node/commit/c7a04401cb)] - **doc**: fix grammar and punctuation in dgram documentation (Kamal Rawal) [#&#8203;64957](https://github.com/nodejs/node/pull/64957) - \[[`331e5e8f62`](https://github.com/nodejs/node/commit/331e5e8f62)] - **doc**: fix grammar and editorial issues in addons documentation (Kamal Rawal) [#&#8203;64952](https://github.com/nodejs/node/pull/64952) - \[[`232287fcc6`](https://github.com/nodejs/node/commit/232287fcc6)] - **doc**: formalize fn/name as part of TestOptions API (Christopher Hiller) [#&#8203;64946](https://github.com/nodejs/node/pull/64946) - \[[`7f9efeb445`](https://github.com/nodejs/node/commit/7f9efeb445)] - **doc**: remove references to `ca`/`crl` as per-context QuicSession options (René) [#&#8203;64769](https://github.com/nodejs/node/pull/64769) - \[[`b54aa83cc6`](https://github.com/nodejs/node/commit/b54aa83cc6)] - **doc**: fix typo in maintaining-dependencies.md (greenhead) [#&#8203;64896](https://github.com/nodejs/node/pull/64896) - \[[`f4e427803c`](https://github.com/nodejs/node/commit/f4e427803c)] - **doc**: add RafaelGSS as last security release stewards (Rafael Gonzaga) [#&#8203;64843](https://github.com/nodejs/node/pull/64843) - \[[`f2cd6df3f3`](https://github.com/nodejs/node/commit/f2cd6df3f3)] - **doc**: fix typos in documentation (greenhead) [#&#8203;64900](https://github.com/nodejs/node/pull/64900) - \[[`d5627162bd`](https://github.com/nodejs/node/commit/d5627162bd)] - **doc**: improve TestContext hook descriptions (Kamal Rawal) [#&#8203;64899](https://github.com/nodejs/node/pull/64899) - \[[`72ee03bd2e`](https://github.com/nodejs/node/commit/72ee03bd2e)] - **doc**: document stream.isDestroyed() (YspritanHyzygy) [#&#8203;64789](https://github.com/nodejs/node/pull/64789) - \[[`995141eb81`](https://github.com/nodejs/node/commit/995141eb81)] - **doc**: add contributing detail for git Signed-off-by trailer (Mike McCready) [#&#8203;64862](https://github.com/nodejs/node/pull/64862) - \[[`dc30379310`](https://github.com/nodejs/node/commit/dc30379310)] - **doc**: fix duplicated word in test snapshot docs (Kamal Rawal) [#&#8203;64837](https://github.com/nodejs/node/pull/64837) - \[[`205d4d0472`](https://github.com/nodejs/node/commit/205d4d0472)] - **doc**: remove obsolete cctest node.gyp instructions (Soul Lee) [#&#8203;64814](https://github.com/nodejs/node/pull/64814) - \[[`108b883d0b`](https://github.com/nodejs/node/commit/108b883d0b)] - **doc**: report proper return type on url.format (Brian Muenzenmeyer) [#&#8203;64806](https://github.com/nodejs/node/pull/64806) - \[[`b03bd3a8ed`](https://github.com/nodejs/node/commit/b03bd3a8ed)] - **doc**: clarify tlsSocket.authorized on resumption (soreavis) [#&#8203;64584](https://github.com/nodejs/node/pull/64584) - \[[`093098ad7f`](https://github.com/nodejs/node/commit/093098ad7f)] - **doc**: stabilize --disable-warning (Jean Michelet) [#&#8203;64742](https://github.com/nodejs/node/pull/64742) - \[[`2de1d76d80`](https://github.com/nodejs/node/commit/2de1d76d80)] - **doc**: add MDN links for explicit resource management in fs (lluisemper) [#&#8203;59557](https://github.com/nodejs/node/pull/59557) - \[[`2e0f36a891`](https://github.com/nodejs/node/commit/2e0f36a891)] - **doc**: mention constructor check in deepStrictEqual (Sumit Kumar Das) [#&#8203;62010](https://github.com/nodejs/node/pull/62010) - \[[`1c9d354d09`](https://github.com/nodejs/node/commit/1c9d354d09)] - **doc**: update technical priorities (Jacob Smith) [#&#8203;64505](https://github.com/nodejs/node/pull/64505) - \[[`30c99bf08f`](https://github.com/nodejs/node/commit/30c99bf08f)] - **doc**: deprecation add more codemod (Augustin Mauroy) [#&#8203;63175](https://github.com/nodejs/node/pull/63175) - \[[`8a971a09eb`](https://github.com/nodejs/node/commit/8a971a09eb)] - **doc**: run license-builder (Node.js GitHub Bot) [#&#8203;63918](https://github.com/nodejs/node/pull/63918) - \[[`707f6eacfc`](https://github.com/nodejs/node/commit/707f6eacfc)] - **doc**: clarify rules for adding new built-in modules (Antoine du Hamel) [#&#8203;64648](https://github.com/nodejs/node/pull/64648) - \[[`928208cffc`](https://github.com/nodejs/node/commit/928208cffc)] - **doc**: mention DEPENDENCY custom field for H1 reports (Rafael Gonzaga) [#&#8203;64634](https://github.com/nodejs/node/pull/64634) - \[[`ee593cadf5`](https://github.com/nodejs/node/commit/ee593cadf5)] - **doc**: fix dnsPromises.lookup verbatim default (Shivam S) [#&#8203;64658](https://github.com/nodejs/node/pull/64658) - \[[`9c228b32d1`](https://github.com/nodejs/node/commit/9c228b32d1)] - **doc**: fix typo in releases guide (Jihwan) [#&#8203;64621](https://github.com/nodejs/node/pull/64621) - \[[`4a158cf1ab`](https://github.com/nodejs/node/commit/4a158cf1ab)] - **doc**: add MikeMcC399 as collaborator (Mike McCready) [#&#8203;64656](https://github.com/nodejs/node/pull/64656) - \[[`8125809853`](https://github.com/nodejs/node/commit/8125809853)] - **doc**: use promote wording in release guide (Md Muhtasim Munif Fahim) [#&#8203;64371](https://github.com/nodejs/node/pull/64371) - \[[`2a2effadf6`](https://github.com/nodejs/node/commit/2a2effadf6)] - **doc**: fix import.meta example for vm.SourceTextModule (Muhammad Zeeshan) [#&#8203;64112](https://github.com/nodejs/node/pull/64112) - \[[`c879f912bf`](https://github.com/nodejs/node/commit/c879f912bf)] - **doc**: mention crypto.hash() for better perf (Steven) [#&#8203;63420](https://github.com/nodejs/node/pull/63420) - \[[`634afda904`](https://github.com/nodejs/node/commit/634afda904)] - **doc**: update sea example by fixing wrong code example (Maxence Robinet) [#&#8203;64025](https://github.com/nodejs/node/pull/64025) - \[[`bced1433a3`](https://github.com/nodejs/node/commit/bced1433a3)] - **doc**: fix socket.readyState state descriptions (YuSheng Chen) [#&#8203;64468](https://github.com/nodejs/node/pull/64468) - \[[`4b2c18938f`](https://github.com/nodejs/node/commit/4b2c18938f)] - **doc**: replace large tables in crypto.md and webcrypto.md with lists (Filip Skokan) [#&#8203;64582](https://github.com/nodejs/node/pull/64582) - \[[`5207231996`](https://github.com/nodejs/node/commit/5207231996)] - **doc**: note --env-file is not applied to --run (Paul Bouchon) [#&#8203;64442](https://github.com/nodejs/node/pull/64442) - \[[`329a2884fd`](https://github.com/nodejs/node/commit/329a2884fd)] - **doc**: fix typo in embedding.md (greenhead) [#&#8203;64425](https://github.com/nodejs/node/pull/64425) - \[[`fab3f56aa1`](https://github.com/nodejs/node/commit/fab3f56aa1)] - **doc**: fix typos in contributing docs (Donghoon Kang) [#&#8203;64520](https://github.com/nodejs/node/pull/64520) - \[[`cbc2bed4e8`](https://github.com/nodejs/node/commit/cbc2bed4e8)] - **doc**: document TLS alpnProtocol and servername fields (Tim Perry) [#&#8203;64362](https://github.com/nodejs/node/pull/64362) - \[[`dada3ae60e`](https://github.com/nodejs/node/commit/dada3ae60e)] - **doc**: fix spelling in devcontainer guide (한만욱) [#&#8203;64459](https://github.com/nodejs/node/pull/64459) - \[[`71343b28aa`](https://github.com/nodejs/node/commit/71343b28aa)] - **doc**: clarify PEM format for signing keys (Harjoth Khara) [#&#8203;64404](https://github.com/nodejs/node/pull/64404) - \[[`0544ec1c78`](https://github.com/nodejs/node/commit/0544ec1c78)] - **doc**: fix typo in tls.md (Daijiro Wachi) [#&#8203;64458](https://github.com/nodejs/node/pull/64458) - \[[`8fe58078e7`](https://github.com/nodejs/node/commit/8fe58078e7)] - **doc**: document net Socket server property (Efe Karasakal) [#&#8203;64364](https://github.com/nodejs/node/pull/64364) - \[[`d54fd03fa4`](https://github.com/nodejs/node/commit/d54fd03fa4)] - **doc**: update a Dispatcher undici doc link (Filip Skokan) [#&#8203;64358](https://github.com/nodejs/node/pull/64358) - \[[`1bdebecd41`](https://github.com/nodejs/node/commit/1bdebecd41)] - **doc**: fix typos in documentation (Jungwon Sohn) [#&#8203;64466](https://github.com/nodejs/node/pull/64466) - \[[`86bca58641`](https://github.com/nodejs/node/commit/86bca58641)] - **doc**: clarify fixes and refs trailer guidance (Trivikram Kamat) [#&#8203;64421](https://github.com/nodejs/node/pull/64421) - \[[`b5b84c9394`](https://github.com/nodejs/node/commit/b5b84c9394)] - **doc**: add scope overview tables for TestsStream events (Moshe Atlow) [#&#8203;64386](https://github.com/nodejs/node/pull/64386) - \[[`004238d77c`](https://github.com/nodejs/node/commit/004238d77c)] - **doc**: clarify proxy threat model (Matteo Collina) [#&#8203;64366](https://github.com/nodejs/node/pull/64366) - \[[`6851b8d55f`](https://github.com/nodejs/node/commit/6851b8d55f)] - **doc**: add note about restricted CI to pull-requests.md (Stewart X Addison) [#&#8203;64321](https://github.com/nodejs/node/pull/64321) - \[[`662e33714a`](https://github.com/nodejs/node/commit/662e33714a)] - **doc**: various updates to releases.md (Stewart X Addison) [#&#8203;64198](https://github.com/nodejs/node/pull/64198) - \[[`949bc3cfd3`](https://github.com/nodejs/node/commit/949bc3cfd3)] - **doc**: remove obsolete --napi-modules doc entry (Chengzhong Wu) [#&#8203;64220](https://github.com/nodejs/node/pull/64220) - \[[`830d16067f`](https://github.com/nodejs/node/commit/830d16067f)] - **doc**: clarify QUIC stream state wording (EduardF1) [#&#8203;63660](https://github.com/nodejs/node/pull/63660) - \[[`79b6704630`](https://github.com/nodejs/node/commit/79b6704630)] - **doc**: fix typo in node-config-schema.json (Hamid Reza Ghavami) [#&#8203;64188](https://github.com/nodejs/node/pull/64188) - \[[`9f5bf554db`](https://github.com/nodejs/node/commit/9f5bf554db)] - **doc**: fix broken link (Antoine du Hamel) [#&#8203;65078](https://github.com/nodejs/node/pull/65078) - \[[`42b27ed428`](https://github.com/nodejs/node/commit/42b27ed428)] - **doc**: remove unsupported syntax from `stream_iter.md` (Antoine du Hamel) [#&#8203;64649](https://github.com/nodejs/node/pull/64649) - \[[`f1a9df7f22`](https://github.com/nodejs/node/commit/f1a9df7f22)] - **doc**: clarify fromReadable() duck-typed contract (Trivikram Kamat) [#&#8203;63682](https://github.com/nodejs/node/pull/63682) - \[[`c7a3d450ac`](https://github.com/nodejs/node/commit/c7a3d450ac)] - **doc**: improve quic documentation (James M Snell) [#&#8203;63157](https://github.com/nodejs/node/pull/63157) - \[[`cc425bc659`](https://github.com/nodejs/node/commit/cc425bc659)] - **doc**: fix promise nomenclature in `stream_iter.md` (Antoine du Hamel) [#&#8203;63406](https://github.com/nodejs/node/pull/63406) - \[[`859a02da96`](https://github.com/nodejs/node/commit/859a02da96)] - **doc**: minor structural stream/iter edits (René) [#&#8203;63089](https://github.com/nodejs/node/pull/63089) - \[[`630b15eb20`](https://github.com/nodejs/node/commit/630b15eb20)] - **doc**: fix doubled word typo in stream\_iter.md (Daijiro Wachi) [#&#8203;62916](https://github.com/nodejs/node/pull/62916) - \[[`50791fa8fa`](https://github.com/nodejs/node/commit/50791fa8fa)] - **doc,test**: widen fsPromises.appendFile()'s data type, add missing tests (Jimmy Leung) [#&#8203;64279](https://github.com/nodejs/node/pull/64279) - \[[`9e39360a09`](https://github.com/nodejs/node/commit/9e39360a09)] - **esm**: improve ERR\_REQUIRE\_ASYNC\_MODULE (Joyee Cheung) [#&#8203;64260](https://github.com/nodejs/node/pull/64260) - \[[`d2b02e443a`](https://github.com/nodejs/node/commit/d2b02e443a)] - **esm**: print required top-level await locations without evaluating (Joyee Cheung) [#&#8203;64154](https://github.com/nodejs/node/pull/64154) - \[[`e8c153f3f4`](https://github.com/nodejs/node/commit/e8c153f3f4)] - **events**: avoid retaining removed event names (Matteo Collina) [#&#8203;64475](https://github.com/nodejs/node/pull/64475) - \[[`73e1701bad`](https://github.com/nodejs/node/commit/73e1701bad)] - **events**: optimize once() and removeListener() (Matteo Collina) [#&#8203;64373](https://github.com/nodejs/node/pull/64373) - \[[`12f7fc0558`](https://github.com/nodejs/node/commit/12f7fc0558)] - **fs**: key glob matcher cache by platform (Archkon) [#&#8203;64571](https://github.com/nodejs/node/pull/64571) - \[[`e5af022302`](https://github.com/nodejs/node/commit/e5af022302)] - **fs**: add pattern cache for matchGlobPattern() (bq) [#&#8203;63915](https://github.com/nodejs/node/pull/63915) - \[[`63321eeb11`](https://github.com/nodejs/node/commit/63321eeb11)] - **fs**: fix cp symlink and EEXIST handling on Windows (Kirill Saied) [#&#8203;64353](https://github.com/nodejs/node/pull/64353) - \[[`0ad55e5618`](https://github.com/nodejs/node/commit/0ad55e5618)] - **http**: fix writableFinished and 'finish' after write errors (Tim Perry) [#&#8203;64847](https://github.com/nodejs/node/pull/64847) - \[[`ee54d9d4d2`](https://github.com/nodejs/node/commit/ee54d9d4d2)] - **http**: avoid aborting IncomingMessage signal on normal close (Archkon) [#&#8203;64392](https://github.com/nodejs/node/pull/64392) - \[[`14cb8b0a06`](https://github.com/nodejs/node/commit/14cb8b0a06)] - **http**: guard invalid timeout values in checkConnections (Efe Karasakal) [#&#8203;64506](https://github.com/nodejs/node/pull/64506) - \[[`f24177ccc6`](https://github.com/nodejs/node/commit/f24177ccc6)] - **http**: propagate highWaterMark to ClientRequest OutgoingMessage (trivenay) [#&#8203;64653](https://github.com/nodejs/node/pull/64653) - \[[`55e2c2da8c`](https://github.com/nodejs/node/commit/55e2c2da8c)] - **http**: fix perf\_hooks detail.req.url port and proxied path (Stefano Baghino) [#&#8203;64311](https://github.com/nodejs/node/pull/64311) - \[[`b57350fe27`](https://github.com/nodejs/node/commit/b57350fe27)] - **http**: remove unused n arg from IncomingMessage.\_read (Efe Karasakal) [#&#8203;64370](https://github.com/nodejs/node/pull/64370) - \[[`af3a17e0b3`](https://github.com/nodejs/node/commit/af3a17e0b3)] - **http2**: avoid copying the options in respond() (Matteo Collina) [#&#8203;64265](https://github.com/nodejs/node/pull/64265) - \[[`f11ac0da37`](https://github.com/nodejs/node/commit/f11ac0da37)] - **http2**: avoid per-write closures in kWriteGeneric (Matteo Collina) [#&#8203;64265](https://github.com/nodejs/node/pull/64265) - \[[`157bd07b6e`](https://github.com/nodejs/node/commit/157bd07b6e)] - **http2**: reduce per-request allocations (Matteo Collina) [#&#8203;64265](https://github.com/nodejs/node/pull/64265) - \[[`b075b33429`](https://github.com/nodejs/node/commit/b075b33429)] - **http2**: don't throw when destroying socket proxy (Matteo Collina) [#&#8203;64427](https://github.com/nodejs/node/pull/64427) - \[[`445bcce079`](https://github.com/nodejs/node/commit/445bcce079)] - **inspector**: add --cond to node inspect probe mode (Joyee Cheung) [#&#8203;64328](https://github.com/nodejs/node/pull/64328) - \[[`06b54fe7d3`](https://github.com/nodejs/node/commit/06b54fe7d3)] - **lib**: fix AbortSignal.any() observed-composite leak (Paul Bouchon) [#&#8203;64481](https://github.com/nodejs/node/pull/64481) - \[[`d8fac094d1`](https://github.com/nodejs/node/commit/d8fac094d1)] - **lib**: fix typo in comment in \_http\_client.js (agape1225) [#&#8203;64729](https://github.com/nodejs/node/pull/64729) - \[[`9ce72fd6fb`](https://github.com/nodejs/node/commit/9ce72fd6fb)] - **lib**: use `assignFunctionName` util where it makes sense (Antoine du Hamel) [#&#8203;64515](https://github.com/nodejs/node/pull/64515) - \[[`c40d1473e6`](https://github.com/nodejs/node/commit/c40d1473e6)] - **lib,permission**: fix addon permission drop (Martin Wagner) [#&#8203;64007](https://github.com/nodejs/node/pull/64007) - \[[`d4cafce076`](https://github.com/nodejs/node/commit/d4cafce076)] - **(SEMVER-MINOR)** **lib,permission**: add permission.drop (Rafael Gonzaga) [#&#8203;62672](https://github.com/nodejs/node/pull/62672) - \[[`6b09d30a76`](https://github.com/nodejs/node/commit/6b09d30a76)] - **lib,tools**: add `node-core/func-name-matching` lint rule (Livia Medeiros) [#&#8203;57901](https://github.com/nodejs/node/pull/57901) - \[[`d7d4f0e2ac`](https://github.com/nodejs/node/commit/d7d4f0e2ac)] - **loader**: enforce path normalization before lookup (Maël Nison) [#&#8203;63917](https://github.com/nodejs/node/pull/63917) - \[[`b3cfb55267`](https://github.com/nodejs/node/commit/b3cfb55267)] - **(SEMVER-MINOR)** **loader**: implement package maps (Maël Nison) [#&#8203;62239](https://github.com/nodejs/node/pull/62239) - \[[`cf425ad935`](https://github.com/nodejs/node/commit/cf425ad935)] - **meta**: bump actions/stale from 10.3.0 to 11.0.0 (dependabot\[bot]) [#&#8203;64935](https://github.com/nodejs/node/pull/64935) - \[[`26fa9cc32b`](https://github.com/nodejs/node/commit/26fa9cc32b)] - **meta**: bump github/codeql-action/analyze from 4.36.2 to 4.37.3 (dependabot\[bot]) [#&#8203;64934](https://github.com/nodejs/node/pull/64934) - \[[`c90fa82cd7`](https://github.com/nodejs/node/commit/c90fa82cd7)] - **meta**: bump github/codeql-action/autobuild from 4.36.2 to 4.37.3 (dependabot\[bot]) [#&#8203;64933](https://github.com/nodejs/node/pull/64933) - \[[`314893253a`](https://github.com/nodejs/node/commit/314893253a)] - **meta**: bump actions/setup-python from 6.3.0 to 7.0.0 (dependabot\[bot]) [#&#8203;64932](https://github.com/nodejs/node/pull/64932) - \[[`6ab711278f`](https://github.com/nodejs/node/commit/6ab711278f)] - **meta**: bump github/codeql-action/init from 4.36.2 to 4.37.3 (dependabot\[bot]) [#&#8203;64931](https://github.com/nodejs/node/pull/64931) - \[[`9138f5892a`](https://github.com/nodejs/node/commit/9138f5892a)] - **meta**: bump Mozilla-Actions/sccache-action from 0.0.10 to 0.0.11 (dependabot\[bot]) [#&#8203;64930](https://github.com/nodejs/node/pull/64930) - \[[`3ef3f934d4`](https://github.com/nodejs/node/commit/3ef3f934d4)] - **meta**: bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.3 (dependabot\[bot]) [#&#8203;64927](https://github.com/nodejs/node/pull/64927) - \[[`a0a33127ae`](https://github.com/nodejs/node/commit/a0a33127ae)] - **meta**: bump step-security/harden-runner from 2.19.4 to 2.20.0 (dependabot\[bot]) [#&#8203;64926](https://github.com/nodejs/node/pull/64926) - \[[`4ad2afbf33`](https://github.com/nodejs/node/commit/4ad2afbf33)] - **meta**: bump ossf/scorecard-action from 2.4.3 to 2.4.4 (dependabot\[bot]) [#&#8203;64925](https://github.com/nodejs/node/pull/64925) - \[[`d9b2ee4083`](https://github.com/nodejs/node/commit/d9b2ee4083)] - **meta**: add [@&#8203;nodejs/url](https://github.com/nodejs/url) as codeowner for node\_url\_pattern.\* (Efe Karasakal) [#&#8203;64737](https://github.com/nodejs/node/pull/64737) - \[[`2b43b78e82`](https://github.com/nodejs/node/commit/2b43b78e82)] - **meta**: lower stale to 3 months (Aviv Keller) [#&#8203;64569](https://github.com/nodejs/node/pull/64569) - \[[`0ffe8352ae`](https://github.com/nodejs/node/commit/0ffe8352ae)] - **meta**: move one or more collaborators to emeritus (Node.js GitHub Bot) [#&#8203;64315](https://github.com/nodejs/node/pull/64315) - \[[`afd922cd8a`](https://github.com/nodejs/node/commit/afd922cd8a)] - **meta**: bump actions/checkout from 6.0.2 to 7.0.0 (dependabot\[bot]) [#&#8203;64245](https://github.com/nodejs/node/pull/64245) - \[[`b6149a2976`](https://github.com/nodejs/node/commit/b6149a2976)] - **meta**: bump actions/setup-python from 6.2.0 to 6.3.0 (dependabot\[bot]) [#&#8203;64241](https://github.com/nodejs/node/pull/64241) - \[[`8f4a5c622f`](https://github.com/nodejs/node/commit/8f4a5c622f)] - **meta**: update sccache version in test-linux-quic (René) [#&#8203;64043](https://github.com/nodejs/node/pull/64043) - \[[`9040b08696`](https://github.com/nodejs/node/commit/9040b08696)] - **net**: support TCP handle transfer on Windows (Matteo Collina) [#&#8203;64460](https://github.com/nodejs/node/pull/64460) - \[[`1216481a09`](https://github.com/nodejs/node/commit/1216481a09)] - **net**: support AF\_UNIX paths in net.BoundSocket (Guy Bedford) [#&#8203;64399](https://github.com/nodejs/node/pull/64399) - \[[`f6bf3f8a5d`](https://github.com/nodejs/node/commit/f6bf3f8a5d)] - **net**: support sync connect for BoundSocket (Guy Bedford) [#&#8203;64375](https://github.com/nodejs/node/pull/64375) - \[[`fb8a7e15ca`](https://github.com/nodejs/node/commit/fb8a7e15ca)] - **net**: make TCP Server and Socket transferable across worker threads (Matteo Collina) [#&#8203;64225](https://github.com/nodejs/node/pull/64225) - \[[`224d2c7886`](https://github.com/nodejs/node/commit/224d2c7886)] - **path**: add benchmarks for path.matchesGlob() (bq) [#&#8203;63915](https://github.com/nodejs/node/pull/63915) - \[[`980c651de5`](https://github.com/nodejs/node/commit/980c651de5)] - **permission**: add unique warning codes (David Evans) [#&#8203;64414](https://github.com/nodejs/node/pull/64414) - \[[`9f9a96030d`](https://github.com/nodejs/node/commit/9f9a96030d)] - **permission**: support v8.setHeapSnapshotNearHeapLimit (Ilyas Shabi) [#&#8203;64808](https://github.com/nodejs/node/pull/64808) - \[[`8a00872183`](https://github.com/nodejs/node/commit/8a00872183)] - **quic**: fix stop sending behaviour & callback (Tim Perry) [#&#8203;64710](https://github.com/nodejs/node/pull/64710) - \[[`7aab0c3183`](https://github.com/nodejs/node/commit/7aab0c3183)] - **quic**: fix coverage comment typo (Jungwon Sohn) [#&#8203;64486](https://github.com/nodejs/node/pull/64486) - \[[`b4ecb3040b`](https://github.com/nodejs/node/commit/b4ecb3040b)] - **quic**: fix segfault after fragmented client hello (Tim Perry) [#&#8203;64720](https://github.com/nodejs/node/pull/64720) - \[[`6386540dad`](https://github.com/nodejs/node/commit/6386540dad)] - **quic**: serialize stream reset code as string (한만욱) [#&#8203;64577](https://github.com/nodejs/node/pull/64577) - \[[`82717741c9`](https://github.com/nodejs/node/commit/82717741c9)] - **quic**: defer server session emit until TLS ClientHello is processed (Tim Perry) [#&#8203;64132](https://github.com/nodejs/node/pull/64132) - \[[`7cb3099907`](https://github.com/nodejs/node/commit/7cb3099907)] - **quic**: preserve session stats after close (한만욱) [#&#8203;64489](https://github.com/nodejs/node/pull/64489) - \[[`50e639b578`](https://github.com/nodejs/node/commit/50e639b578)] - **quic**: add support for TLS certificate compression (Sebastian Beltran) [#&#8203;64434](https://github.com/nodejs/node/pull/64434) - \[[`e2e28292cc`](https://github.com/nodejs/node/commit/e2e28292cc)] - **quic**: extract transport logic from Application to Session (Tim Perry) [#&#8203;64127](https://github.com/nodejs/node/pull/64127) - \[[`2ef4b7ebf2`](https://github.com/nodejs/node/commit/2ef4b7ebf2)] - **quic**: correct http3 callback and fix revealed errs (Marten Richter) [#&#8203;64289](https://github.com/nodejs/node/pull/64289) - \[[`a682b53456`](https://github.com/nodejs/node/commit/a682b53456)] - **quic**: fix no onstream handler crash quic (Efe) [#&#8203;64158](https://github.com/nodejs/node/pull/64158) - \[[`9445e2719a`](https://github.com/nodejs/node/commit/9445e2719a)] - **quic**: fix stall datagrams, if no pending streams (Marten Richter) [#&#8203;64303](https://github.com/nodejs/node/pull/64303) - \[[`2ea9d193bd`](https://github.com/nodejs/node/commit/2ea9d193bd)] - **quic**: fix potential crash from unobserved closed (Tim Perry) [#&#8203;64134](https://github.com/nodejs/node/pull/64134) - \[[`3b7f4fc1fb`](https://github.com/nodejs/node/commit/3b7f4fc1fb)] - **quic**: drop version negotiation packets with oversized CIDs (Mohamed Sayed) [#&#8203;64228](https://github.com/nodejs/node/pull/64228) - \[[`bd477a3202`](https://github.com/nodejs/node/commit/bd477a3202)] - **quic**: fixes undefined handle in QuicStream kInspect (Marten Richter) [#&#8203;64170](https://github.com/nodejs/node/pull/64170) - \[[`3dd04b3ec6`](https://github.com/nodejs/node/commit/3dd04b3ec6)] - **quic**: fix get\_reader bug that dropped data on FIN (Tim Perry) [#&#8203;63946](https://github.com/nodejs/node/pull/63946) - \[[`4be8abe8f9`](https://github.com/nodejs/node/commit/4be8abe8f9)] - **quic**: expose QUIC certificates as JS X509Certificate, not raw handles (Tim Perry) [#&#8203;63191](https://github.com/nodejs/node/pull/63191) - \[[`e264c5c0cb`](https://github.com/nodejs/node/commit/e264c5c0cb)] - **quic**: fix reader backpressure deadlock on idle connections (Tim Perry) [#&#8203;63950](https://github.com/nodejs/node/pull/63950) - \[[`2f749dde18`](https://github.com/nodejs/node/commit/2f749dde18)] - **quic**: impl. cb for http/3 settings/app. options (Marten Richter) [#&#8203;63558](https://github.com/nodejs/node/pull/63558) - \[[`5ca7ef3202`](https://github.com/nodejs/node/commit/5ca7ef3202)] - **quic**: fix broken listEndpoints export, test callbacks & nghttp3 include (Tim Perry) [#&#8203;63874](https://github.com/nodejs/node/pull/63874) - \[[`147150cfdd`](https://github.com/nodejs/node/commit/147150cfdd)] - **quic**: add listEndpoints API (James M Snell) [#&#8203;63536](https://github.com/nodejs/node/pull/63536) - \[[`3b59d12f5d`](https://github.com/nodejs/node/commit/3b59d12f5d)] - **quic**: add proper error codes & messages for QUIC failures (Tim Perry) [#&#8203;63198](https://github.com/nodejs/node/pull/63198) - \[[`b68f8eadb9`](https://github.com/nodejs/node/commit/b68f8eadb9)] - **quic**: support hostname verification (James M Snell) [#&#8203;63483](https://github.com/nodejs/node/pull/63483) - \[[`7652bd9c6d`](https://github.com/nodejs/node/commit/7652bd9c6d)] - **quic**: add stream idle timeout (James M Snell) [#&#8203;63483](https://github.com/nodejs/node/pull/63483) - \[[`e493f04214`](https://github.com/nodejs/node/commit/e493f04214)] - **quic**: add block list support for endpoints (James M Snell) [#&#8203;63483](https://github.com/nodejs/node/pull/63483) - \[[`6d6cd45f8b`](https://github.com/nodejs/node/commit/6d6cd45f8b)] - **quic**: improve peer cert verification (James M Snell) [#&#8203;63483](https://github.com/nodejs/node/pull/63483) - \[[`dbe0b371ee`](https://github.com/nodejs/node/commit/dbe0b371ee)] - **quic**: handle h3 max header size option (James M Snell) [#&#8203;63483](https://github.com/nodejs/node/pull/63483) - \[[`39dca4150c`](https://github.com/nodejs/node/commit/39dca4150c)] - **quic**: add rate limiting docs (James M Snell) [#&#8203;63483](https://github.com/nodejs/node/pull/63483) - \[[`c726a893d6`](https://github.com/nodejs/node/commit/c726a893d6)] - **quic**: cache timestamp for address lru cache (James M Snell) [#&#8203;63483](https://github.com/nodejs/node/pull/63483) - \[[`11778a7925`](https://github.com/nodejs/node/commit/11778a7925)] - **quic**: add session creation rate limiting (James M Snell) [#&#8203;63483](https://github.com/nodejs/node/pull/63483) - \[[`8107f1b3ed`](https://github.com/nodejs/node/commit/8107f1b3ed)] - **quic**: refine rate limiting (James M Snell) [#&#8203;63483](https://github.com/nodejs/node/pull/63483) - \[[`3f0d7371e0`](https://github.com/nodejs/node/commit/3f0d7371e0)] - **quic**: flip preferred address policy default to 'ignore' (James M Snell) [#&#8203;63483](https://github.com/nodejs/node/pull/63483) - \[[`97c8a96774`](https://github.com/nodejs/node/commit/97c8a96774)] - **quic**: add doc note about certificate size limitations (James M Snell) [#&#8203;63483](https://github.com/nodejs/node/pull/63483) - \[[`42aa3f6612`](https://github.com/nodejs/node/commit/42aa3f6612)] - **quic**: add applicationOptions to session (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`4c00ab9d29`](https://github.com/nodejs/node/commit/4c00ab9d29)] - **quic**: add getters for local and remote transport parameters (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`858b636576`](https://github.com/nodejs/node/commit/858b636576)] - **quic**: improve recv coalescing test sizes (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`84d3100256`](https://github.com/nodejs/node/commit/84d3100256)] - **quic**: add initial RTT option to session options (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`a2b6a81c66`](https://github.com/nodejs/node/commit/a2b6a81c66)] - **quic**: enable recvmmsg batching in Endpoint (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`46a0868994`](https://github.com/nodejs/node/commit/46a0868994)] - **quic**: improve stream header collection performance (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`bc7f4efdb7`](https://github.com/nodejs/node/commit/bc7f4efdb7)] - **quic**: coalesce received data into fewer buffers (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`f727efb8b2`](https://github.com/nodejs/node/commit/f727efb8b2)] - **quic**: apply multiple additional minor improvements (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`ee0a0f1540`](https://github.com/nodejs/node/commit/ee0a0f1540)] - **quic**: fix tests that are missing serverEndpoint close (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`f8a1fdad07`](https://github.com/nodejs/node/commit/f8a1fdad07)] - **quic**: fixup some v8:: qualifiers (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`c66605609c`](https://github.com/nodejs/node/commit/c66605609c)] - **quic**: fix premature unref of endpoint when listening (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`9a72949b0b`](https://github.com/nodejs/node/commit/9a72949b0b)] - **quic**: fixup UAFs in bindingdata, streams, and app (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`a4db12198e`](https://github.com/nodejs/node/commit/a4db12198e)] - **quic**: fix UAF in Application::OnTimeout() (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`0a11b2ccde`](https://github.com/nodejs/node/commit/0a11b2ccde)] - **quic**: improve the quic js structure (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`1bc25d2a03`](https://github.com/nodejs/node/commit/1bc25d2a03)] - **quic**: improve internal structure of QuicStream (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`69e48aed02`](https://github.com/nodejs/node/commit/69e48aed02)] - **quic**: add aliased struct arenas (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`6b7185351b`](https://github.com/nodejs/node/commit/6b7185351b)] - **quic**: add handshake timeout and default connection limits (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`91e3c39097`](https://github.com/nodejs/node/commit/91e3c39097)] - **quic**: fix crash in early handshake failure (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`098e3d715d`](https://github.com/nodejs/node/commit/098e3d715d)] - **quic**: eliminate per-received datagram allocation (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`53b05e2ab2`](https://github.com/nodejs/node/commit/53b05e2ab2)] - **quic**: cache the timestamp on send and receive (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`1592a11219`](https://github.com/nodejs/node/commit/1592a11219)] - **quic**: add support for future ECN marking (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`80e6bf9539`](https://github.com/nodejs/node/commit/80e6bf9539)] - **quic**: improve batching of packet sending (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`ff0cd5b95f`](https://github.com/nodejs/node/commit/ff0cd5b95f)] - **quic**: improve backend quic packet processing (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`c4eb6a95da`](https://github.com/nodejs/node/commit/c4eb6a95da)] - **quic**: send correct OpenSSL alert for ALPN mismatches (Tim Perry) [#&#8203;63193](https://github.com/nodejs/node/pull/63193) - \[[`575dc7d100`](https://github.com/nodejs/node/commit/575dc7d100)] - **quic**: fixup quic stream variable chunk len (James M Snell) [#&#8203;63230](https://github.com/nodejs/node/pull/63230) - \[[`2551f9e6dd`](https://github.com/nodejs/node/commit/2551f9e6dd)] - **quic**: remove unused env\_ variable in session\_manager.h/cc (James M Snell) [#&#8203;63177](https://github.com/nodejs/node/pull/63177) - \[[`bea62a14b3`](https://github.com/nodejs/node/commit/bea62a14b3)] - **quic**: ignore coverage for quic files (James M Snell) [#&#8203;63149](https://github.com/nodejs/node/pull/63149) - \[[`9788bbff97`](https://github.com/nodejs/node/commit/9788bbff97)] - **quic**: complete the internal implementation of QUIC (James M Snell) [#&#8203;62876](https://github.com/nodejs/node/pull/62876) - \[[`54c094d245`](https://github.com/nodejs/node/commit/54c094d245)] - **quic**: continue working on quic api bits (James M Snell) [#&#8203;60123](https://github.com/nodejs/node/pull/60123) - \[[`ea82bc418d`](https://github.com/nodejs/node/commit/ea82bc418d)] - **readline**: reduce createInterface overhead (Matteo Collina) [#&#8203;64585](https://github.com/nodejs/node/pull/64585) - \[[`90a8b23db0`](https://github.com/nodejs/node/commit/90a8b23db0)] - **sqlite**: invalidate sessions when closing database (Trivikram Kamat) [#&#8203;64783](https://github.com/nodejs/node/pull/64783) - \[[`6abd00ed65`](https://github.com/nodejs/node/commit/6abd00ed65)] - **sqlite**: check database state before calling SQLite (Trivikram Kamat) [#&#8203;64812](https://github.com/nodejs/node/pull/64812) - \[[`c2a52514d6`](https://github.com/nodejs/node/commit/c2a52514d6)] - **sqlite**: fix crash when a session outlives its database (Mohamed Sayed) [#&#8203;63797](https://github.com/nodejs/node/pull/63797) - \[[`f9126923ef`](https://github.com/nodejs/node/commit/f9126923ef)] - **sqlite**: fix use-after-free in Exec() and ApplyChangeset() (Matteo Collina) [#&#8203;64535](https://github.com/nodejs/node/pull/64535) - \[[`c010131bc3`](https://github.com/nodejs/node/commit/c010131bc3)] - **sqlite**: read column count after step in StatementSync.all() (Guilherme Araújo) [#&#8203;64219](https://github.com/nodejs/node/pull/64219) - \[[`782ad5d5b0`](https://github.com/nodejs/node/commit/782ad5d5b0)] - **src**: implement MemoryRetainer protocol for ByteSource (Filip Skokan) [#&#8203;64660](https://github.com/nodejs/node/pull/64660) - \[[`4afc15bf1d`](https://github.com/nodejs/node/commit/4afc15bf1d)] - **src**: avoid redundant KEM encapsulation copies (Filip Skokan) [#&#8203;64553](https://github.com/nodejs/node/pull/64553) - \[[`37085f850d`](https://github.com/nodejs/node/commit/37085f850d)] - **src**: fix crash when writing odd-length hex string via Writev (RajeshKumar11) [#&#8203;63658](https://github.com/nodejs/node/pull/63658) - \[[`f58ac8224c`](https://github.com/nodejs/node/commit/f58ac8224c)] - **src**: avoid using ToLocalChecked in crypto\_hash (James M Snell) [#&#8203;64668](https://github.com/nodejs/node/pull/64668) - \[[`05ec9c4771`](https://github.com/nodejs/node/commit/05ec9c4771)] - **src**: fix libuv assertion on windows (liuxingbaoyu) [#&#8203;61999](https://github.com/nodejs/node/pull/61999) - \[[`308a589ee9`](https://github.com/nodejs/node/commit/308a589ee9)] - **src**: avoid redundant DataPointer reallocations (Filip Skokan) [#&#8203;64552](https://github.com/nodejs/node/pull/64552) - \[[`3650fabcb4`](https://github.com/nodejs/node/commit/3650fabcb4)] - **src**: fix comment typos (Jungwon Sohn) [#&#8203;64509](https://github.com/nodejs/node/pull/64509) - \[[`06b3441ea2`](https://github.com/nodejs/node/commit/06b3441ea2)] - **src**: zero-initialize cap\_data in node\_credentials.cc (Samuel Kapust) [#&#8203;64347](https://github.com/nodejs/node/pull/64347) - \[[`bb24a88b99`](https://github.com/nodejs/node/commit/bb24a88b99)] - **src**: fix some typo errors and rename some variables (Archkon) [#&#8203;64301](https://github.com/nodejs/node/pull/64301) - \[[`ba36ab71fd`](https://github.com/nodejs/node/commit/ba36ab71fd)] - **src**: make node.config.json throw at unknown fields (Marco Ippolito) [#&#8203;62992](https://github.com/nodejs/node/pull/62992) - \[[`fbb3960189`](https://github.com/nodejs/node/commit/fbb3960189)] - **src**: show original file name in FileHandle GC close errors (Anna Henningsen) [#&#8203;60593](https://github.com/nodejs/node/pull/60593) - \[[`d53d582be7`](https://github.com/nodejs/node/commit/d53d582be7)] - **src,permission**: do not throw on denied access in audit mode (Adrián Estrada) [#&#8203;64426](https://github.com/nodejs/node/pull/64426) - \[[`cd1eb3e60b`](https://github.com/nodejs/node/commit/cd1eb3e60b)] - **(SEMVER-MINOR)** **src,permission**: add --permission-audit (RafaelGSS) [#&#8203;61869](https://github.com/nodejs/node/pull/61869) - \[[`b1596c2b65`](https://github.com/nodejs/node/commit/b1596c2b65)] - **stream**: cut per-chunk allocations in pipeTo (Matteo Collina) [#&#8203;64890](https://github.com/nodejs/node/pull/64890) - \[[`2cfa96f5cb`](https://github.com/nodejs/node/commit/2cfa96f5cb)] - **stream**: preserve push signal abort reason (Trivikram Kamat) [#&#8203;64798](https://github.com/nodejs/node/pull/64798) - \[[`fc80ff5f7a`](https://github.com/nodejs/node/commit/fc80ff5f7a)] - **stream**: skip zero-byte broadcast writes (Trivikram Kamat) [#&#8203;64772](https://github.com/nodejs/node/pull/64772) - \[[`486cff4c08`](https://github.com/nodejs/node/commit/486cff4c08)] - **stream**: honor AbortSignal in Writer.end() (Trivikram Kamat) [#&#8203;64727](https://github.com/nodejs/node/pull/64727) - \[[`59ef1789f7`](https://github.com/nodejs/node/commit/59ef1789f7)] - **stream**: use validateString for consumer encoding (Jungwon Sohn) [#&#8203;64754](https://github.com/nodejs/node/pull/64754) - \[[`8aba47536a`](https://github.com/nodejs/node/commit/8aba47536a)] - **stream**: use the ring buffer for pending BYOB pull-into descriptors (Matteo Collina) [#&#8203;64818](https://github.com/nodejs/node/pull/64818) - \[[`b20217cb56`](https://github.com/nodejs/node/commit/b20217cb56)] - **stream**: fix uncatchable error closing half-open Duplex.toWeb() writable (Mohamed Sayed) [#&#8203;64161](https://github.com/nodejs/node/pull/64161) - \[[`8accb0c4c0`](https://github.com/nodejs/node/commit/8accb0c4c0)] - **stream**: abort pending single-source merge reads (Trivikram Kamat) [#&#8203;64445](https://github.com/nodejs/node/pull/64445) - \[[`ed5b04027c`](https://github.com/nodejs/node/commit/ed5b04027c)] - **stream**: use RangeError for broadcast overflow (Trivikram Kamat) [#&#8203;64420](https://github.com/nodejs/node/pull/64420) - \[[`136d4e7628`](https://github.com/nodejs/node/commit/136d4e7628)] - **stream**: skip null output from stateful transforms (Trivikram Kamat) [#&#8203;64462](https://github.com/nodejs/node/pull/64462) - \[[`193091f1ba`](https://github.com/nodejs/node/commit/193091f1ba)] - **stream**: update iterable streams to use budget backpressure (James M Snell) [#&#8203;64464](https://github.com/nodejs/node/pull/64464) - \[[`e2b32fce77`](https://github.com/nodejs/node/commit/e2b32fce77)] - **stream**: remove custom `CloneableDOMException` implementation (Antoine du Hamel) [#&#8203;64469](https://github.com/nodejs/node/pull/64469) - \[[`d77788eafe`](https://github.com/nodejs/node/commit/d77788eafe)] - **stream**: fix drop-newest behavior in share() (Trivikram Kamat) [#&#8203;64417](https://github.com/nodejs/node/pull/64417) - \[[`de4ca2c962`](https://github.com/nodejs/node/commit/de4ca2c962)] - **stream**: fold desired-size check into WHATWG backpressure update (Matteo Collina) [#&#8203;64451](https://github.com/nodejs/node/pull/64451) - \[[`2a3babb8d7`](https://github.com/nodejs/node/commit/2a3babb8d7)] - **stream**: validate writer options signal (Trivikram Kamat) [#&#8203;64385](https://github.com/nodejs/node/pull/64385) - \[[`0ab8f269b0`](https://github.com/nodejs/node/commit/0ab8f269b0)] - **stream**: reject push iterator.throw() with error (Trivikram Kamat) [#&#8203;64380](https://github.com/nodejs/node/pull/64380) - \[[`262e6545d1`](https://github.com/nodejs/node/commit/262e6545d1)] - **stream**: simplify nested `PromisePrototypeThen`s (Antoine du Hamel) [#&#8203;64470](https://github.com/nodejs/node/pull/64470) - \[[`0ddfc6af91`](https://github.com/nodejs/node/commit/0ddfc6af91)] - **stream**: use the ring buffer for WHATWG stream request queues (Matteo Collina) [#&#8203;64431](https://github.com/nodejs/node/pull/64431) - \[[`a5e7d89f9e`](https://github.com/nodejs/node/commit/a5e7d89f9e)] - **stream**: validate writevSync chunks before queuing (Trivikram Kamat) [#&#8203;64300](https://github.com/nodejs/node/pull/64300) - \[[`8044f895bf`](https://github.com/nodejs/node/commit/8044f895bf)] - **stream**: speed up reads and iteration over default WHATWG streams (Matteo Collina) [#&#8203;64320](https://github.com/nodejs/node/pull/64320) - \[[`d4dfb66bdf`](https://github.com/nodejs/node/commit/d4dfb66bdf)] - **stream**: copy SAB-backed chunks in iter consumers (Trivikram Kamat) [#&#8203;64382](https://github.com/nodejs/node/pull/64382) - \[[`9c9ade337f`](https://github.com/nodejs/node/commit/9c9ade337f)] - **stream**: reject nested async streamables in from() (Trivikram Kamat) [#&#8203;64352](https://github.com/nodejs/node/pull/64352) - \[[`271c7454f4`](https://github.com/nodejs/node/commit/271c7454f4)] - **stream**: avoid draining merged iter sources (Trivikram Kamat) [#&#8203;64293](https://github.com/nodejs/node/pull/64293) - \[[`cbb2568a04`](https://github.com/nodejs/node/commit/cbb2568a04)] - **stream**: use ring buffer for WHATWG stream queues (Yagiz Nizipli) [#&#8203;64312](https://github.com/nodejs/node/pull/64312) - \[[`67688cc651`](https://github.com/nodejs/node/commit/67688cc651)] - **stream**: hoist repeated loads in readable paths (Yagiz Nizipli) [#&#8203;64312](https://github.com/nodejs/node/pull/64312) - \[[`3f8b446a67`](https://github.com/nodejs/node/commit/3f8b446a67)] - **stream**: prefer sync iterator in fromSync (Trivikram Kamat) [#&#8203;64294](https://github.com/nodejs/node/pull/64294) - \[[`3043b2a68a`](https://github.com/nodejs/node/commit/3043b2a68a)] - **stream**: speed up async iteration over WHATWG byte streams (Antoine du Hamel) [#&#8203;64291](https://github.com/nodejs/node/pull/64291) - \[[`870273ccde`](https://github.com/nodejs/node/commit/870273ccde)] - **stream**: reject iter consumers on abort (Trivikram Kamat) [#&#8203;64066](https://github.com/nodejs/node/pull/64066) - \[[`8a4a997f3e`](https://github.com/nodejs/node/commit/8a4a997f3e)] - **stream**: fix merge abort for pending sources (Trivikram Kamat) [#&#8203;64013](https://github.com/nodejs/node/pull/64013) - \[[`ac5e5d5dec`](https://github.com/nodejs/node/commit/ac5e5d5dec)] - **stream**: refactor unnecessary optional chaining away (Antoine du Hamel) [#&#8203;64253](https://github.com/nodejs/node/pull/64253) - \[[`cb298cfb15`](https://github.com/nodejs/node/commit/cb298cfb15)] - **stream**: normalize Broadcast.from() byte inputs (Trivikram Kamat) [#&#8203;64082](https://github.com/nodejs/node/pull/64082) - \[[`bbbb4aadef`](https://github.com/nodejs/node/commit/bbbb4aadef)] - **stream**: observe abort while awaiting pipeTo source (Trivikram Kamat) [#&#8203;64015](https://github.com/nodejs/node/pull/64015) - \[[`4387ad412f`](https://github.com/nodejs/node/commit/4387ad412f)] - **stream**: respect iter consumer abort signals (Trivikram Kamat) [#&#8203;63997](https://github.com/nodejs/node/pull/63997) - \[[`4ba1fa0062`](https://github.com/nodejs/node/commit/4ba1fa0062)] - **stream**: handle falsy push writer fail reasons (Trivikram Kamat) [#&#8203;63569](https://github.com/nodejs/node/pull/63569) - \[[`3b8c30c096`](https://github.com/nodejs/node/commit/3b8c30c096)] - **stream**: handle setEncoding after buffered data (Matteo Collina) [#&#8203;63973](https://github.com/nodejs/node/pull/63973) - \[[`97ef13c84e`](https://github.com/nodejs/node/commit/97ef13c84e)] - **stream**: keep overlapping broadcast reads pending (Trivikram Kamat) [#&#8203;63500](https://github.com/nodejs/node/pull/63500) - \[[`a46ddad9fa`](https://github.com/nodejs/node/commit/a46ddad9fa)] - **stream**: refine the stream/iter backpressure (James M Snell) [#&#8203;63697](https://github.com/nodejs/node/pull/63697) - \[[`557bf99245`](https://github.com/nodejs/node/commit/557bf99245)] - **stream**: remove transform-writer handling in pipeTo (Trivikram Kamat) [#&#8203;63684](https://github.com/nodejs/node/pull/63684) - \[[`24b7831a1a`](https://github.com/nodejs/node/commit/24b7831a1a)] - **stream**: fix pipeToSync byte accounting (Trivikram Kamat) [#&#8203;63564](https://github.com/nodejs/node/pull/63564) - \[[`3b5f1b56bc`](https://github.com/nodejs/node/commit/3b5f1b56bc)] - **stream**: reject pull() reads on abort (Trivikram Kamat) [#&#8203;63498](https://github.com/nodejs/node/pull/63498) - \[[`e48e287633`](https://github.com/nodejs/node/commit/e48e287633)] - **stream**: fast-path stateless transform flush results (Trivikram Kamat) [#&#8203;63605](https://github.com/nodejs/node/pull/63605) - \[[`f0ee316f45`](https://github.com/nodejs/node/commit/f0ee316f45)] - **stream**: handle sync writev completion in pipeTo (Trivikram Kamat) [#&#8203;63561](https://github.com/nodejs/node/pull/63561) - \[[`fbed90b2fb`](https://github.com/nodejs/node/commit/fbed90b2fb)] - **stream**: settle pending broadcast reads on return (Trivikram Kamat) [#&#8203;63603](https://github.com/nodejs/node/pull/63603) - \[[`568dcc250f`](https://github.com/nodejs/node/commit/568dcc250f)] - **stream**: serialize concurrent share consumer reads (Trivikram Kamat) [#&#8203;63478](https://github.com/nodejs/node/pull/63478) - \[[`5e2b4c4ade`](https://github.com/nodejs/node/commit/5e2b4c4ade)] - **stream**: fix lint error (Antoine du Hamel) [#&#8203;63598](https://github.com/nodejs/node/pull/63598) - \[[`74bd0cd35a`](https://github.com/nodejs/node/commit/74bd0cd35a)] - **stream**: reject pending reads on iterator throw (Trivikram Kamat) [#&#8203;63555](https://github.com/nodejs/node/pull/63555) - \[[`45780df841`](https://github.com/nodejs/node/commit/45780df841)] - **stream**: wait for push writer end fallback to drain (Trivikram Kamat) [#&#8203;63503](https://github.com/nodejs/node/pull/63503) - \[[`217b495e0a`](https://github.com/nodejs/node/commit/217b495e0a)] - **stream**: flush each fused stateless transform (Trivikram Kamat) [#&#8203;63468](https://github.com/nodejs/node/pull/63468) - \[[`2e8685592e`](https://github.com/nodejs/node/commit/2e8685592e)] - **stream**: avoid duplicate writes in toWritable (Trivikram Kamat) [#&#8203;63360](https://github.com/nodejs/node/pull/63360) - \[[`88a3392a78`](https://github.com/nodejs/node/commit/88a3392a78)] - **stream**: propagate abort reason in share and broadcast (Trivikram Kamat) [#&#8203;63358](https://github.com/nodejs/node/pull/63358) - \[[`fce3df74e9`](https://github.com/nodejs/node/commit/fce3df74e9)] - **stream**: disallow writing string chunk with 'buffer' encoding (René) [#&#8203;63062](https://github.com/nodejs/node/pull/63062) - \[[`5658c631fa`](https://github.com/nodejs/node/commit/5658c631fa)] - **stream**: align `Readable.toWeb` termination with eos (ikeyan) [#&#8203;62394](https://github.com/nodejs/node/pull/62394) - \[[`02a51a746b`](https://github.com/nodejs/node/commit/02a51a746b)] - **stream**: add sync iterable fast path to pipeTo (Trivikram Kamat) [#&#8203;63318](https://github.com/nodejs/node/pull/63318) - \[[`4c9f3edb64`](https://github.com/nodejs/node/commit/4c9f3edb64)] - **stream**: fix merge handling for object-like sources (Trivikram Kamat) [#&#8203;63356](https://github.com/nodejs/node/pull/63356) - \[[`c50d8e49cc`](https://github.com/nodejs/node/commit/c50d8e49cc)] - **stream**: limit iter from sync iterable batches (Trivikram Kamat) [#&#8203;63324](https://github.com/nodejs/node/pull/63324) - \[[`1d7c86d577`](https://github.com/nodejs/node/commit/1d7c86d577)] - **stream**: cache minimum cursor count in broadcast (Trivikram Kamat) [#&#8203;63322](https://github.com/nodejs/node/pull/63322) - \[[`ec2666edbe`](https://github.com/nodejs/node/commit/ec2666edbe)] - **stream**: avoid retrying accepted pipeTo writes (Trivikram Kamat) [#&#8203;63297](https://github.com/nodejs/node/pull/63297) - \[[`f63143fd83`](https://github.com/nodejs/node/commit/f63143fd83)] - **stream**: validate broadcast writer writev chunks (Trivikram Kamat) [#&#8203;63300](https://github.com/nodejs/node/pull/63300) - \[[`944470b08a`](https://github.com/nodejs/node/commit/944470b08a)] - **stream**: uncork fromWritable writev on chunk error (Trivikram Kamat) [#&#8203;63295](https://github.com/nodejs/node/pull/63295) - \[[`ae79f2b67a`](https://github.com/nodejs/node/commit/ae79f2b67a)] - **stream**: validate fromWritable() options before cache (Trivikram Kamat) [#&#8203;63278](https://github.com/nodejs/node/pull/63278) - \[[`c98cc67f33`](https://github.com/nodejs/node/commit/c98cc67f33)] - **stream**: optimize single-slot push queue drain (Trivikram Kamat) [#&#8203;63274](https://github.com/nodejs/node/pull/63274) - \[[`9a45ff5d8f`](https://github.com/nodejs/node/commit/9a45ff5d8f)] - **stream**: preserve toReadableSync batch after backpressure (Trivikram Kamat) [#&#8203;63276](https://github.com/nodejs/node/pull/63276) - \[[`eb72fe94fc`](https://github.com/nodejs/node/commit/eb72fe94fc)] - **stream**: cache minimum cursor count in share (Trivikram Kamat) [#&#8203;63262](https://github.com/nodejs/node/pull/63262) - \[[`b57b51eeed`](https://github.com/nodejs/node/commit/b57b51eeed)] - **stream**: minor stream/iter implementation edits (René) [#&#8203;63132](https://github.com/nodejs/node/pull/63132) - \[[`274b3a2ea1`](https://github.com/nodejs/node/commit/274b3a2ea1)] - **stream**: remove redundant method check from iter.pipeToSync (René) [#&#8203;63099](https://github.com/nodejs/node/pull/63099) - \[[`baf98faa06`](https://github.com/nodejs/node/commit/baf98faa06)] - **stream**: add stream/iter to classic stream adapters (James M Snell) [#&#8203;62469](https://github.com/nodejs/node/pull/62469) - \[[`28dc85d8d2`](https://github.com/nodejs/node/commit/28dc85d8d2)] - **(SEMVER-MINOR)** **stream**: add stream/iter Implementation (James M Snell) [#&#8203;62066](https://github.com/nodejs/node/pull/62066) - \[[`125c19da43`](https://github.com/nodejs/node/commit/125c19da43)] - **stream, quic**: update iterable streams backpressure (James M Snell) [#&#8203;64464](https://github.com/nodejs/node/pull/64464) - \[[`11d1bd3ba7`](https://github.com/nodejs/node/commit/11d1bd3ba7)] - **test**: split test-embedding.js and run tests in parallel (Joyee Cheung) [#&#8203;61571](https://github.com/nodejs/node/pull/61571) - \[[`e59346b704`](https://github.com/nodejs/node/commit/e59346b704)] - **test**: ensure assertions are reached on all tests (Antoine du Hamel) [#&#8203;64716](https://github.com/nodejs/node/pull/64716) - \[[`42a967d7ed`](https://github.com/nodejs/node/commit/42a967d7ed)] - **test**: unflake debugger and REPL tests (Matteo Collina) [#&#8203;64718](https://github.com/nodejs/node/pull/64718) - \[[`d80a45fdc4`](https://github.com/nodejs/node/commit/d80a45fdc4)] - **test**: update WPT for url to [`4832db4`](https://github.com/nodejs/node/commit/4832db4761) (Node.js GitHub Bot) [#&#8203;64829](https://github.com/nodejs/node/pull/64829) - \[[`7264efb21b`](https://github.com/nodejs/node/commit/7264efb21b)] - **test**: update WPT for url to [`b63305b`](https://github.com/nodejs/node/commit/b63305b743) (Node.js GitHub Bot) [#&#8203;64790](https://github.com/nodejs/node/pull/64790) - \[[`539f5dc8f9`](https://github.com/nodejs/node/commit/539f5dc8f9)] - **test**: cover worker throwing primitive values (varshitha) [#&#8203;64365](https://github.com/nodejs/node/pull/64365) - \[[`087d9e8dd0`](https://github.com/nodejs/node/commit/087d9e8dd0)] - **test**: mark test-repl-user-error-handler as flaky (Aviv Keller) [#&#8203;64612](https://github.com/nodejs/node/pull/64612) - \[[`dd1e7139a5`](https://github.com/nodejs/node/commit/dd1e7139a5)] - **test**: update quic tests for stream/iter update (James M Snell) [#&#8203;64464](https://github.com/nodejs/node/pull/64464) - \[[`eee0e84537`](https://github.com/nodejs/node/commit/eee0e84537)] - **test**: fix flaky http2 socket proxy test (Tim Perry) [#&#8203;64673](https://github.com/nodejs/node/pull/64673) - \[[`a5ce44dd75`](https://github.com/nodejs/node/commit/a5ce44dd75)] - **test**: apply correction to comment (Rich Trott) [#&#8203;64524](https://github.com/nodejs/node/pull/64524) - \[[`da8508c5a0`](https://github.com/nodejs/node/commit/da8508c5a0)] - **test**: keep finalization before-exit ref alive (Tim Perry) [#&#8203;64521](https://github.com/nodejs/node/pull/64521) - \[[`14b710c415`](https://github.com/nodejs/node/commit/14b710c415)] - **test**: copyedit `test-tls-psk-alpn-callback-exception-handling` (Antoine du Hamel) [#&#8203;63485](https://github.com/nodejs/node/pull/63485) - \[[`99b7382c6a`](https://github.com/nodejs/node/commit/99b7382c6a)] - **test**: fix stale async-context-frame status entries (Kirill Saied) [#&#8203;64141](https://github.com/nodejs/node/pull/64141) - \[[`6da6ca730d`](https://github.com/nodejs/node/commit/6da6ca730d)] - **test**: update WPT for urlpattern to [`5847ee5`](https://github.com/nodejs/node/commit/5847ee5cfa) (Node.js GitHub Bot) [#&#8203;64436](https://github.com/nodejs/node/pull/64436) - \[[`73bf0f07f1`](https://github.com/nodejs/node/commit/73bf0f07f1)] - **test**: update WPT for WebCryptoAPI to [`ec2fee3`](https://github.com/nodejs/node/commit/ec2fee39a4) (Node.js GitHub Bot) [#&#8203;64435](https://github.com/nodejs/node/pull/64435) - \[[`9a7ec52e6f`](https://github.com/nodejs/node/commit/9a7ec52e6f)] - **test**: fix flaky http2 maxOriginSetSize test (Tim Perry) [#&#8203;64407](https://github.com/nodejs/node/pull/64407) - \[[`59af7e0ed9`](https://github.com/nodejs/node/commit/59af7e0ed9)] - **test**: fix 2nd flaky blob test case (Tim Perry) [#&#8203;64391](https://github.com/nodejs/node/pull/64391) - \[[`7fd5f66376`](https://github.com/nodejs/node/commit/7fd5f66376)] - **test**: fix flaky watch + cwd + argv test-runner test (Tim Perry) [#&#8203;64372](https://github.com/nodejs/node/pull/64372) - \[[`d5b47d2fae`](https://github.com/nodejs/node/commit/d5b47d2fae)] - **test**: normalize Windows crash in debugger test normalization (Joyee Cheung) [#&#8203;64332](https://github.com/nodejs/node/pull/64332) - \[[`a8ae44096d`](https://github.com/nodejs/node/commit/a8ae44096d)] - **test**: unmark flaky http2-large-file for Win (Kirill Saied) [#&#8203;64255](https://github.com/nodejs/node/pull/64255) - \[[`8461d18597`](https://github.com/nodejs/node/commit/8461d18597)] - **test**: increase timeout in consumed-timeout test (Trivikram Kamat) [#&#8203;64204](https://github.com/nodejs/node/pull/64204) - \[[`af52410d70`](https://github.com/nodejs/node/commit/af52410d70)] - **test**: handle null stdio streams in spawnSyncAndAssert helper (Joyee Cheung) [#&#8203;64273](https://github.com/nodejs/node/pull/64273) - \[[`0ea079be7b`](https://github.com/nodejs/node/commit/0ea079be7b)] - **test**: remove impact of tier-up changes in worker stack size test (Joyee Cheung) [#&#8203;64271](https://github.com/nodejs/node/pull/64271) - \[[`1bde0ef053`](https://github.com/nodejs/node/commit/1bde0ef053)] - **test**: update WPT for WebCryptoAPI to [`0c413fb`](https://github.com/nodejs/node/commit/0c413fb56b) (Node.js GitHub Bot) [#&#8203;63647](https://github.com/nodejs/node/pull/63647) - \[[`f32b412867`](https://github.com/nodejs/node/commit/f32b412867)] - **test**: get rid of unnecessary `AbortController` instanciations (Antoine du Hamel) [#&#8203;63489](https://github.com/nodejs/node/pull/63489) - \[[`8cbd90161b`](https://github.com/nodejs/node/commit/8cbd90161b)] - **test**: update WPT for wasm/jsapi to [`288c467`](https://github.com/nodejs/node/commit/288c467d35) (Node.js GitHub Bot) [#&#8203;63136](https://github.com/nodejs/node/pull/63136) - \[[`f200aaccf0`](https://github.com/nodejs/node/commit/f200aaccf0)] - **test**: fixup quic tests (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`14c547351b`](https://github.com/nodejs/node/commit/14c547351b)] - **(SEMVER-MINOR)** **test**: add tests for experimental stream/iter implementation (James M Snell) [#&#8203;62066](https://github.com/nodejs/node/pull/62066) - \[[`2cc54e1793`](https://github.com/nodejs/node/commit/2cc54e1793)] - **test**: skip quic tests that IBM i does not support (SRAVANI GUNDEPALLI) [#&#8203;60160](https://github.com/nodejs/node/pull/60160) - \[[`8ec80b311b`](https://github.com/nodejs/node/commit/8ec80b311b)] - **test\_runner**: wait for filtered suite build (semimikoh) [#&#8203;64208](https://github.com/nodejs/node/pull/64208) - \[[`9ed7146851`](https://github.com/nodejs/node/commit/9ed7146851)] - **test\_runner**: convert to uint during deserialization (Aviv Keller) [#&#8203;64706](https://github.com/nodejs/node/pull/64706) - \[[`d31c168740`](https://github.com/nodejs/node/commit/d31c168740)] - **(SEMVER-MINOR)** **test\_runner**: add context.log() and test:log event (Moshe Atlow) [#&#8203;64389](https://github.com/nodejs/node/pull/64389) - \[[`add1edbc42`](https://github.com/nodejs/node/commit/add1edbc42)] - **(SEMVER-MINOR)** **test\_runner**: report `entryFile` in `TestStream` events (Moshe Atlow) [#&#8203;64309](https://github.com/nodejs/node/pull/64309) - \[[`8d97dee696`](https://github.com/nodejs/node/commit/8d97dee696)] - **tests**: start adding quic test server utilities (James M Snell) [#&#8203;59946](https://github.com/nodejs/node/pull/59946) - \[[`e5278b7f7d`](https://github.com/nodejs/node/commit/e5278b7f7d)] - **timers**: do not retain a reference to the async store after firing (Matteo Collina) [#&#8203;53443](https://github.com/nodejs/node/pull/53443) - \[[`e277bc4608`](https://github.com/nodejs/node/commit/e277bc4608)] - **tls**: fix SNICallback certificate selection (Matteo Collina) [#&#8203;64700](https://github.com/nodejs/node/pull/64700) - \[[`b9104decc3`](https://github.com/nodejs/node/commit/b9104decc3)] - **tls**: match IPv6 hosts against IP-Address SANs (Pascal Garber) [#&#8203;64145](https://github.com/nodejs/node/pull/64145) - \[[`b50139e89f`](https://github.com/nodejs/node/commit/b50139e89f)] - **tools**: bump the eslint group in /tools/eslint with 4 updates (dependabot\[bot]) [#&#8203;64928](https://github.com/nodejs/node/pull/64928) - \[[`5460c464a0`](https://github.com/nodejs/node/commit/5460c464a0)] - **tools**: bump brace-expansion from 5.0.7 to 5.0.9 in /tools/eslint (dependabot\[bot]) [#&#8203;64904](https://github.com/nodejs/node/pull/64904) - \[[`f8a13811cd`](https://github.com/nodejs/node/commit/f8a13811cd)] - **tools**: use 'readonly' for EventSource global (Honey Tyagi) [#&#8203;64787](https://github.com/nodejs/node/pull/64787) - \[[`6e10012c0d`](https://github.com/nodejs/node/commit/6e10012c0d)] - **tools**: bump brace-expansion from 5.0.6 to 5.0.7 in /tools/eslint (dependabot\[bot]) [#&#8203;64636](https://github.com/nodejs/node/pull/64636) - \[[`d66b7588ac`](https://github.com/nodejs/node/commit/d66b7588ac)] - **tools**: reference 'git node land' in PR-URL: error message in merge.sh (Stewart X Addison) [#&#8203;64495](https://github.com/nodejs/node/pull/64495) - \[[`5d90e48175`](https://github.com/nodejs/node/commit/5d90e48175)] - **tools**: disable zipping tarballs on GHA (Antoine du Hamel) [#&#8203;64423](https://github.com/nodejs/node/pull/64423) - \[[`8a909f4540`](https://github.com/nodejs/node/commit/8a909f4540)] - **tools**: fix redundant conditions in v8.gyp for riscv64 and loong64 (Jamie Magee) [#&#8203;62608](https://github.com/nodejs/node/pull/62608) - \[[`9e171710fa`](https://github.com/nodejs/node/commit/9e171710fa)] - **tools**: remove `envinfo` from our workflows (Antoine du Hamel) [#&#8203;64259](https://github.com/nodejs/node/pull/64259) - \[[`3fb722054f`](https://github.com/nodejs/node/commit/3fb722054f)] - **tools**: avoid test/fixtures/wpt/README.md conflicts (Filip Skokan) [#&#8203;63938](https://github.com/nodejs/node/pull/63938) - \[[`5755712920`](https://github.com/nodejs/node/commit/5755712920)] - **tools**: add lint rule for aborted AbortController (Trivikram Kamat) [#&#8203;63541](https://github.com/nodejs/node/pull/63541) - \[[`e88d5b78bc`](https://github.com/nodejs/node/commit/e88d5b78bc)] - **typings**: add heap\_utils internalBinding types (Donghoon Kang) [#&#8203;64816](https://github.com/nodejs/node/pull/64816) - \[[`ae93bc8ad1`](https://github.com/nodejs/node/commit/ae93bc8ad1)] - **typings**: remove isDataView from types binding (Archkon) [#&#8203;64738](https://github.com/nodejs/node/pull/64738) - \[[`c00bd1427d`](https://github.com/nodejs/node/commit/c00bd1427d)] - **url**: create URLPattern result properties in WebIDL order (Archkon) [#&#8203;64733](https://github.com/nodejs/node/pull/64733) - \[[`8a07969e28`](https://github.com/nodejs/node/commit/8a07969e28)] - **util**: make MIMEParams accessors case-insensitive (Daijiro Wachi) [#&#8203;64123](https://github.com/nodejs/node/pull/64123) - \[[`bf86741167`](https://github.com/nodejs/node/commit/bf86741167)] - **v8**: report minor mark-sweep in GCProfiler (Archkon) [#&#8203;64688](https://github.com/nodejs/node/pull/64688) - \[[`d937c8c6cd`](https://github.com/nodejs/node/commit/d937c8c6cd)] - **(SEMVER-MINOR)** **wasm**: enable JSPI (Guy Bedford) [#&#8203;59941](https://github.com/nodejs/node/pull/59941) - \[[`9016ddabb9`](https://github.com/nodejs/node/commit/9016ddabb9)] - **wasm**: register missing SetURL function (Archkon) [#&#8203;64679](https://github.com/nodejs/node/pull/64679) - \[[`e599b9428b`](https://github.com/nodejs/node/commit/e599b9428b)] - **zlib**: validate pledgedSrcSize as a safe integer (Archkon) [#&#8203;64604](https://github.com/nodejs/node/pull/64604) - \[[`1f1adc89da`](https://github.com/nodejs/node/commit/1f1adc89da)] - **zlib**: accept ArrayBuffer dictionary in Zstd (Ryuhei Shima) [#&#8203;64599](https://github.com/nodejs/node/pull/64599) - \[[`0ee91ead8b`](https://github.com/nodejs/node/commit/0ee91ead8b)] - **zlib**: reject truncated zstd input (Archkon) [#&#8203;64593](https://github.com/nodejs/node/pull/64593) ### [`v24.19.0`](https://github.com/nodejs/node/releases/tag/v24.19.0): 2026-08-03, Version 24.19.0 'Krypton' (LTS), @&#8203;aduh95 [Compare Source](https://github.com/nodejs/node/compare/v24.18.1...v24.19.0) ##### Notable Changes - \[[`d08872b530`](https://github.com/nodejs/node/commit/d08872b530)] - **(SEMVER-MINOR)** **buffer**: implement `blob.textStream()` (Matthew Aitken) [#&#8203;64036](https://github.com/nodejs/node/pull/64036) - \[[`35222948be`](https://github.com/nodejs/node/commit/35222948be)] - **(SEMVER-MINOR)** **deps**: update OpenSSL build config to support compression (Tim Perry) [#&#8203;62217](https://github.com/nodejs/node/pull/62217) - \[[`d6ab039f24`](https://github.com/nodejs/node/commit/d6ab039f24)] - **(SEMVER-MINOR)** **doc**: update `blockList` stability status to release candidate (alphaleadership) [#&#8203;63050](https://github.com/nodejs/node/pull/63050) - \[[`1da05fb79d`](https://github.com/nodejs/node/commit/1da05fb79d)] - **doc**: mark `stream.compose` stable (Matteo Collina) [#&#8203;62562](https://github.com/nodejs/node/pull/62562) - \[[`3c1636dabf`](https://github.com/nodejs/node/commit/3c1636dabf)] - **(SEMVER-MINOR)** **esm**: add `--experimental-import-text` flag (Efe) [#&#8203;62300](https://github.com/nodejs/node/pull/62300) - \[[`e323e877be`](https://github.com/nodejs/node/commit/e323e877be)] - **(SEMVER-MINOR)** **fs**: support caller-supplied `readFile()` buffers (Matteo Collina) [#&#8203;63634](https://github.com/nodejs/node/pull/63634) - \[[`c1248c9544`](https://github.com/nodejs/node/commit/c1248c9544)] - **(SEMVER-MINOR)** **http**: add `httpValidation` option to configure header value validation (RajeshKumar11) [#&#8203;61597](https://github.com/nodejs/node/pull/61597) - \[[`a534b65815`](https://github.com/nodejs/node/commit/a534b65815)] - **(SEMVER-MINOR)** **net**: support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` (Guy Bedford) [#&#8203;63825](https://github.com/nodejs/node/pull/63825) - \[[`a23cdec683`](https://github.com/nodejs/node/commit/a23cdec683)] - **(SEMVER-MINOR)** **perf\_hooks**: sample delay per event loop iteration (Pablo Erhard) [#&#8203;62935](https://github.com/nodejs/node/pull/62935) - \[[`7428b57a37`](https://github.com/nodejs/node/commit/7428b57a37)] - **(SEMVER-MINOR)** **src**: allow empty `--experimental-config-file` (Marco Ippolito) [#&#8203;61610](https://github.com/nodejs/node/pull/61610) - \[[`e57597173c`](https://github.com/nodejs/node/commit/e57597173c)] - **(SEMVER-MINOR)** **stream**: expose `ReadableStreamTee` (Matteo Collina) [#&#8203;64195](https://github.com/nodejs/node/pull/64195) - \[[`5396235993`](https://github.com/nodejs/node/commit/5396235993)] - **(SEMVER-MINOR)** **tls**: report negotiated TLS groups (Filip Skokan) [#&#8203;64119](https://github.com/nodejs/node/pull/64119) - \[[`5e901b5cd9`](https://github.com/nodejs/node/commit/5e901b5cd9)] - **(SEMVER-MINOR)** **tls**: add `certificateCompression` option (Tim Perry) [#&#8203;62217](https://github.com/nodejs/node/pull/62217) ##### Commits - \[[`676467fa9f`](https://github.com/nodejs/node/commit/676467fa9f)] - **benchmark**: trim down the argon2 sets (Filip Skokan) [#&#8203;64218](https://github.com/nodejs/node/pull/64218) - \[[`a77a2000b7`](https://github.com/nodejs/node/commit/a77a2000b7)] - **benchmark**: add child\_process async path baselines (Yagiz Nizipli) [#&#8203;63929](https://github.com/nodejs/node/pull/63929) - \[[`dd4482e915`](https://github.com/nodejs/node/commit/dd4482e915)] - **buffer**: remove unreachable overflow check in atob (haramjeong) [#&#8203;60161](https://github.com/nodejs/node/pull/60161) - \[[`081c41eb86`](https://github.com/nodejs/node/commit/081c41eb86)] - **buffer**: add fast api for isUtf8 and isAscii (Gürgün Dayıoğlu) [#&#8203;64169](https://github.com/nodejs/node/pull/64169) - \[[`d08872b530`](https://github.com/nodejs/node/commit/d08872b530)] - **(SEMVER-MINOR)** **buffer**: implement blob.textStream() (Matthew Aitken) [#&#8203;64036](https://github.com/nodejs/node/pull/64036) - \[[`6e2f7e6013`](https://github.com/nodejs/node/commit/6e2f7e6013)] - **build**: remove redundant intermediate node\_aix\_shared (Chengzhong Wu) [#&#8203;63747](https://github.com/nodejs/node/pull/63747) - \[[`87e0675f51`](https://github.com/nodejs/node/commit/87e0675f51)] - **build**: build codecache and snapshot with libnode (Chengzhong Wu) [#&#8203;63626](https://github.com/nodejs/node/pull/63626) - \[[`32174a7bae`](https://github.com/nodejs/node/commit/32174a7bae)] - **build**: support setting an emulator from configure script (Ivan Trubach) [#&#8203;53899](https://github.com/nodejs/node/pull/53899) - \[[`69cfb2f240`](https://github.com/nodejs/node/commit/69cfb2f240)] - **build**: remove duplicated node\_use\_sqlite and node\_use\_ffi conditions (Chengzhong Wu) [#&#8203;63629](https://github.com/nodejs/node/pull/63629) - \[[`37ac6e8cb5`](https://github.com/nodejs/node/commit/37ac6e8cb5)] - **build**: add manually-dispatched stress-test workflow (Joyee Cheung) [#&#8203;64118](https://github.com/nodejs/node/pull/64118) - \[[`2424207191`](https://github.com/nodejs/node/commit/2424207191)] - **build**: suppress compiler warnings for histogram (Richard Lau) [#&#8203;63980](https://github.com/nodejs/node/pull/63980) - \[[`63502b7404`](https://github.com/nodejs/node/commit/63502b7404)] - **build,win**: fix VS2022 arm64 PGO build (Stefan Stojanovic) [#&#8203;63413](https://github.com/nodejs/node/pull/63413) - \[[`fe4e4055d0`](https://github.com/nodejs/node/commit/fe4e4055d0)] - **child\_process**: fix permission model propagation via NODE\_OPTIONS (Matteo Collina) [#&#8203;63972](https://github.com/nodejs/node/pull/63972) - \[[`aa2f3c066e`](https://github.com/nodejs/node/commit/aa2f3c066e)] - **child\_process**: pass spawn options to the binding positionally (Yagiz Nizipli) [#&#8203;63930](https://github.com/nodejs/node/pull/63930) - \[[`fcf32cf77a`](https://github.com/nodejs/node/commit/fcf32cf77a)] - **child\_process**: serialize advanced IPC messages natively (Yagiz Nizipli) [#&#8203;63933](https://github.com/nodejs/node/pull/63933) - \[[`7907134734`](https://github.com/nodejs/node/commit/7907134734)] - **crypto**: reject small-order EdDSA points during verify (Filip Skokan) [#&#8203;64026](https://github.com/nodejs/node/pull/64026) - \[[`b505cd5465`](https://github.com/nodejs/node/commit/b505cd5465)] - **crypto**: support non-byte WebCrypto lengths and cSHAKE (Filip Skokan) [#&#8203;63988](https://github.com/nodejs/node/pull/63988) - \[[`0f54a872e2`](https://github.com/nodejs/node/commit/0f54a872e2)] - **crypto**: share WebCrypto method and usage helpers (Filip Skokan) [#&#8203;63975](https://github.com/nodejs/node/pull/63975) - \[[`824ec11c05`](https://github.com/nodejs/node/commit/824ec11c05)] - **crypto**: refactor keyObject.toCryptoKey() and SubtleCrypto.getPublicKey() (Filip Skokan) [#&#8203;63622](https://github.com/nodejs/node/pull/63622) - \[[`73aba92689`](https://github.com/nodejs/node/commit/73aba92689)] - **crypto**: coerce -0 to +0 before native calls (Filip Skokan) [#&#8203;63556](https://github.com/nodejs/node/pull/63556) - \[[`c83b79874e`](https://github.com/nodejs/node/commit/c83b79874e)] - **crypto**: reject invalid raw key imports (Filip Skokan) [#&#8203;63134](https://github.com/nodejs/node/pull/63134) - \[[`934fda64b9`](https://github.com/nodejs/node/commit/934fda64b9)] - **crypto**: improve accuracy of SubtleCrypto.supports (Filip Skokan) [#&#8203;63104](https://github.com/nodejs/node/pull/63104) - \[[`e392e1f791`](https://github.com/nodejs/node/commit/e392e1f791)] - **crypto**: fix large DH generator validation (Tobias Nießen) [#&#8203;64092](https://github.com/nodejs/node/pull/64092) - \[[`e75a363e70`](https://github.com/nodejs/node/commit/e75a363e70)] - **crypto**: use EVP\_MAC for HMAC on OpenSSL >=3 (Filip Skokan) [#&#8203;63942](https://github.com/nodejs/node/pull/63942) - \[[`adbaf7af9b`](https://github.com/nodejs/node/commit/adbaf7af9b)] - **crypto**: make webcrypto aliasKeyFormat directional (Filip Skokan) [#&#8203;63910](https://github.com/nodejs/node/pull/63910) - \[[`bb1aea8897`](https://github.com/nodejs/node/commit/bb1aea8897)] - **crypto**: fix unhandled error in Hash.\_transform (Haram Jeong) [#&#8203;63261](https://github.com/nodejs/node/pull/63261) - \[[`12c87732c1`](https://github.com/nodejs/node/commit/12c87732c1)] - **crypto**: handle cipher context allocation failures (Tian Teng) [#&#8203;63542](https://github.com/nodejs/node/pull/63542) - \[[`858496b453`](https://github.com/nodejs/node/commit/858496b453)] - **crypto**: deduplicate X509 subject matching logic (Tobias Nießen) [#&#8203;63644](https://github.com/nodejs/node/pull/63644) - \[[`9a29cb0964`](https://github.com/nodejs/node/commit/9a29cb0964)] - **crypto**: fix warnings in test\_node\_crypto.cc (Maya Lekova) [#&#8203;63490](https://github.com/nodejs/node/pull/63490) - \[[`8bb536066d`](https://github.com/nodejs/node/commit/8bb536066d)] - **crypto**: optimize normalizeAlgorithm dispatch hot path (Filip Skokan) [#&#8203;62756](https://github.com/nodejs/node/pull/62756) - \[[`329e5496ff`](https://github.com/nodejs/node/commit/329e5496ff)] - **crypto,tls**: do not ignore BN\_get\_word error (Tobias Nießen) [#&#8203;63895](https://github.com/nodejs/node/pull/63895) - \[[`97b7a3f9c7`](https://github.com/nodejs/node/commit/97b7a3f9c7)] - **debugger**: add --max-hit option to probe mode (Joyee Cheung) [#&#8203;63704](https://github.com/nodejs/node/pull/63704) - \[[`9098585c5e`](https://github.com/nodejs/node/commit/9098585c5e)] - **debugger**: add more logs to probe mode (Joyee Cheung) [#&#8203;63663](https://github.com/nodejs/node/pull/63663) - \[[`59cca26cd5`](https://github.com/nodejs/node/commit/59cca26cd5)] - **debugger**: surface inspector failures in probe mode (Joyee Cheung) [#&#8203;63437](https://github.com/nodejs/node/pull/63437) - \[[`2922290eae`](https://github.com/nodejs/node/commit/2922290eae)] - **debugger**: disambiguate probe location binding (Joyee Cheung) [#&#8203;63286](https://github.com/nodejs/node/pull/63286) - \[[`6fb2c2c7e2`](https://github.com/nodejs/node/commit/6fb2c2c7e2)] - **debugger**: lazily wait for initial break output (Trivikram Kamat) [#&#8203;63969](https://github.com/nodejs/node/pull/63969) - \[[`688e792551`](https://github.com/nodejs/node/commit/688e792551)] - **debugger**: defer probe pause handling until startup (Trivikram Kamat) [#&#8203;63608](https://github.com/nodejs/node/pull/63608) - \[[`1ac93cc05a`](https://github.com/nodejs/node/commit/1ac93cc05a)] - **debugger**: await initialization after run and restart (Trivikram Kamat) [#&#8203;63607](https://github.com/nodejs/node/pull/63607) - \[[`92a909cf72`](https://github.com/nodejs/node/commit/92a909cf72)] - **debugger,test**: deflake resume failure test and add debug logs (Joyee Cheung) [#&#8203;63524](https://github.com/nodejs/node/pull/63524) - \[[`8b37af8b11`](https://github.com/nodejs/node/commit/8b37af8b11)] - **deps**: V8: backport [`bef0d9c`](https://github.com/nodejs/node/commit/bef0d9c1bc90) (Joyee Cheung) [#&#8203;62132](https://github.com/nodejs/node/pull/62132) - \[[`8832126422`](https://github.com/nodejs/node/commit/8832126422)] - **deps**: V8: cherry-pick [`64b36b4`](https://github.com/nodejs/node/commit/64b36b441179) (Dan Carney) [#&#8203;61712](https://github.com/nodejs/node/pull/61712) - \[[`75990c2cd6`](https://github.com/nodejs/node/commit/75990c2cd6)] - **deps**: update googletest to [`8b53336`](https://github.com/nodejs/node/commit/8b53336594cc52213c6c2c7a0b29194fa896d039) (Node.js GitHub Bot) [#&#8203;64181](https://github.com/nodejs/node/pull/64181) - \[[`8500c7ba86`](https://github.com/nodejs/node/commit/8500c7ba86)] - **deps**: update sqlite to 3.53.3 (Node.js GitHub Bot) [#&#8203;64180](https://github.com/nodejs/node/pull/64180) - \[[`dc78091b45`](https://github.com/nodejs/node/commit/dc78091b45)] - **deps**: c-ares: cherry-pick [`8ba37af`](https://github.com/nodejs/node/commit/8ba37af8e3fb) (René) [#&#8203;64110](https://github.com/nodejs/node/pull/64110) - \[[`873cc72125`](https://github.com/nodejs/node/commit/873cc72125)] - **deps**: update googletest to [`0b1e895`](https://github.com/nodejs/node/commit/0b1e895ba4226c2fda5ee0178c9b5b1195a741aa) (Node.js GitHub Bot) [#&#8203;64039](https://github.com/nodejs/node/pull/64039) - \[[`1d3d166538`](https://github.com/nodejs/node/commit/1d3d166538)] - **deps**: update acorn to 8.17.0 (Node.js GitHub Bot) [#&#8203;63901](https://github.com/nodejs/node/pull/63901) - \[[`35222948be`](https://github.com/nodejs/node/commit/35222948be)] - **(SEMVER-MINOR)** **deps**: update OpenSSL build config to support compression (Tim Perry) [#&#8203;62217](https://github.com/nodejs/node/pull/62217) - \[[`e40cee5f79`](https://github.com/nodejs/node/commit/e40cee5f79)] - **deps**: upgrade npm to 11.17.0 (npm team) [#&#8203;63857](https://github.com/nodejs/node/pull/63857) - \[[`85c6d46606`](https://github.com/nodejs/node/commit/85c6d46606)] - **deps**: add ngtcp2\_fmt.c to build configuration (ngtcp2.gyp) (沈鸿飞) [#&#8203;63821](https://github.com/nodejs/node/pull/63821) - \[[`d2ea8b7a8c`](https://github.com/nodejs/node/commit/d2ea8b7a8c)] - **deps**: update googletest to [`7140cd4`](https://github.com/nodejs/node/commit/7140cd416cecd7462a8aae488024abeee55598e4) (Node.js GitHub Bot) [#&#8203;63775](https://github.com/nodejs/node/pull/63775) - \[[`25b4d57bb6`](https://github.com/nodejs/node/commit/25b4d57bb6)] - **deps**: update sqlite to 3.53.2 (Node.js GitHub Bot) [#&#8203;63774](https://github.com/nodejs/node/pull/63774) - \[[`a96368e4c7`](https://github.com/nodejs/node/commit/a96368e4c7)] - **deps**: update zlib to 1.3.2.1-motley-3246f1b (Node.js GitHub Bot) [#&#8203;63773](https://github.com/nodejs/node/pull/63773) - \[[`b59f1f5f37`](https://github.com/nodejs/node/commit/b59f1f5f37)] - **deps**: update amaro to 1.1.10 (Node.js GitHub Bot) [#&#8203;63670](https://github.com/nodejs/node/pull/63670) - \[[`0b3b56ee95`](https://github.com/nodejs/node/commit/0b3b56ee95)] - **deps**: update googletest to [`8736d2c`](https://github.com/nodejs/node/commit/8736d2cd5c1dcba41170ed2fddca14021d4916c3) (Node.js GitHub Bot) [#&#8203;63669](https://github.com/nodejs/node/pull/63669) - \[[`aa67b5b9c4`](https://github.com/nodejs/node/commit/aa67b5b9c4)] - **dgram**: add synchronous Socket connectSync() (Guy Bedford) [#&#8203;63932](https://github.com/nodejs/node/pull/63932) - \[[`ef38374875`](https://github.com/nodejs/node/commit/ef38374875)] - **dgram**: add synchronous Socket.prototype.bindSync() (Guy Bedford) [#&#8203;63838](https://github.com/nodejs/node/pull/63838) - \[[`6edc3a9967`](https://github.com/nodejs/node/commit/6edc3a9967)] - **dgram**: skip dns.lookup() for literal IP addresses (Ruben Bridgewater) [#&#8203;64133](https://github.com/nodejs/node/pull/64133) - \[[`d4cfe2d8ac`](https://github.com/nodejs/node/commit/d4cfe2d8ac)] - **dns**: coerce -0 to +0 in lookup and resolver inputs (Filip Skokan) [#&#8203;63556](https://github.com/nodejs/node/pull/63556) - \[[`91c9ce5a45`](https://github.com/nodejs/node/commit/91c9ce5a45)] - **doc**: improve `fs.StatFs` properties descriptions (aymanxdev) [#&#8203;62578](https://github.com/nodejs/node/pull/62578) - \[[`54e21675fa`](https://github.com/nodejs/node/commit/54e21675fa)] - **doc**: fix inconsistencies in CJS code snippets (Antoine du Hamel) [#&#8203;63199](https://github.com/nodejs/node/pull/63199) - \[[`64c23daa76`](https://github.com/nodejs/node/commit/64c23daa76)] - **doc**: remove typo comma from man page (Vas Sudanagunta) [#&#8203;63080](https://github.com/nodejs/node/pull/63080) - \[[`bc943cd34a`](https://github.com/nodejs/node/commit/bc943cd34a)] - **doc**: update Http2SecureServer.on("timeout") default value (YuSheng Chen) [#&#8203;64187](https://github.com/nodejs/node/pull/64187) - \[[`a46bc452a6`](https://github.com/nodejs/node/commit/a46bc452a6)] - **doc**: add note on visibility of CI failures to new contributor guide (Stewart X Addison) [#&#8203;64256](https://github.com/nodejs/node/pull/64256) - \[[`c0fb52506c`](https://github.com/nodejs/node/commit/c0fb52506c)] - **doc**: clarify HTTP/1.1 response ordering (Matteo Collina) [#&#8203;64213](https://github.com/nodejs/node/pull/64213) - \[[`d3073a7ba6`](https://github.com/nodejs/node/commit/d3073a7ba6)] - **doc**: recommend node-stress-single-test for flaky tests (Trivikram Kamat) [#&#8203;64223](https://github.com/nodejs/node/pull/64223) - \[[`bb9951ead0`](https://github.com/nodejs/node/commit/bb9951ead0)] - **doc**: fix typo in examples (Vas Sudanagunta) [#&#8203;64184](https://github.com/nodejs/node/pull/64184) - \[[`fe674e96fc`](https://github.com/nodejs/node/commit/fe674e96fc)] - **doc**: clarify defense-in-depth issues (Matteo Collina) [#&#8203;64215](https://github.com/nodejs/node/pull/64215) - \[[`faad042184`](https://github.com/nodejs/node/commit/faad042184)] - **doc**: add guide and answers to FAQs for first-time contributors (Joyee Cheung) [#&#8203;63685](https://github.com/nodejs/node/pull/63685) - \[[`79d685adf3`](https://github.com/nodejs/node/commit/79d685adf3)] - **doc**: update `Http2Server.close` & `Http2SecureServer.close` (YuSheng Chen) [#&#8203;63298](https://github.com/nodejs/node/pull/63298) - \[[`744e40e05e`](https://github.com/nodejs/node/commit/744e40e05e)] - **doc**: update list of people in `SECURITY.md` (Richard Lau) [#&#8203;64152](https://github.com/nodejs/node/pull/64152) - \[[`185f57c4a4`](https://github.com/nodejs/node/commit/185f57c4a4)] - **doc**: add missing option to man page (Richard Lau) [#&#8203;64156](https://github.com/nodejs/node/pull/64156) - \[[`8933303568`](https://github.com/nodejs/node/commit/8933303568)] - **doc**: fix callback example import in fs docs (Kamal Rawal) [#&#8203;63912](https://github.com/nodejs/node/pull/63912) - \[[`3a0549dacb`](https://github.com/nodejs/node/commit/3a0549dacb)] - **doc**: fix keepAliveTimeout default in http.createServer options (Jahanzaib iqbal) [#&#8203;63974](https://github.com/nodejs/node/pull/63974) - \[[`5a35e48d08`](https://github.com/nodejs/node/commit/5a35e48d08)] - **doc**: add sxa GPG key ([`ed25519`](https://github.com/nodejs/node/commit/ed25519)) (Stewart X Addison) [#&#8203;64193](https://github.com/nodejs/node/pull/64193) - \[[`66e7f815f1`](https://github.com/nodejs/node/commit/66e7f815f1)] - **doc**: add aduh95 to last security release steward (Antoine du Hamel) [#&#8203;63981](https://github.com/nodejs/node/pull/63981) - \[[`a7e35040dd`](https://github.com/nodejs/node/commit/a7e35040dd)] - **doc**: fix typo in util.md (Daijiro Wachi) [#&#8203;63961](https://github.com/nodejs/node/pull/63961) - \[[`d74b3a7e90`](https://github.com/nodejs/node/commit/d74b3a7e90)] - **doc**: clarify callback exceptions (Matteo Collina) [#&#8203;63939](https://github.com/nodejs/node/pull/63939) - \[[`b7a8f8fabd`](https://github.com/nodejs/node/commit/b7a8f8fabd)] - **doc**: fix incorrect test runner mock examples (Kimaswa Emmanuel Yusufu) [#&#8203;63656](https://github.com/nodejs/node/pull/63656) - \[[`f11aa690cd`](https://github.com/nodejs/node/commit/f11aa690cd)] - **doc**: fix typo in cli.md (Daijiro Wachi) [#&#8203;63883](https://github.com/nodejs/node/pull/63883) - \[[`df85f50269`](https://github.com/nodejs/node/commit/df85f50269)] - **doc**: fix typo in vm.md (Daijiro Wachi) [#&#8203;63881](https://github.com/nodejs/node/pull/63881) - \[[`a00a567175`](https://github.com/nodejs/node/commit/a00a567175)] - **doc**: fix typo in packages.md (Daijiro Wachi) [#&#8203;63882](https://github.com/nodejs/node/pull/63882) - \[[`206c1b8437`](https://github.com/nodejs/node/commit/206c1b8437)] - **doc**: fix a/an article typos in module, util, and dns (Daijiro Wachi) [#&#8203;63766](https://github.com/nodejs/node/pull/63766) - \[[`e3e5ef1cff`](https://github.com/nodejs/node/commit/e3e5ef1cff)] - **doc**: update npm supported versions link (hojeong park) [#&#8203;63672](https://github.com/nodejs/node/pull/63672) - \[[`e3c4852413`](https://github.com/nodejs/node/commit/e3c4852413)] - **doc**: fix AES-OCB IV length in SubtleCrypto.supports example (Anshika Jain) [#&#8203;63717](https://github.com/nodejs/node/pull/63717) - \[[`0b3fbc82d7`](https://github.com/nodejs/node/commit/0b3fbc82d7)] - **doc**: add webstreams to args for `pipeline` from `stream/promises` (David Sanders) [#&#8203;63628](https://github.com/nodejs/node/pull/63628) - \[[`62078a8328`](https://github.com/nodejs/node/commit/62078a8328)] - **doc**: fix "used to sent" → "used to send" in http2 (Daijiro Wachi) [#&#8203;63700](https://github.com/nodejs/node/pull/63700) - \[[`fd74eefb23`](https://github.com/nodejs/node/commit/fd74eefb23)] - **doc**: clarify tty raw mode applies to input processing only (Muhammad Zeeshan) [#&#8203;63438](https://github.com/nodejs/node/pull/63438) - \[[`42cd7e47de`](https://github.com/nodejs/node/commit/42cd7e47de)] - **doc**: add worker\_threads history entries (Bob Put) [#&#8203;63545](https://github.com/nodejs/node/pull/63545) - \[[`d6ab039f24`](https://github.com/nodejs/node/commit/d6ab039f24)] - **(SEMVER-MINOR)** **doc**: update `blockList` stability status to release candidate (alphaleadership) [#&#8203;63050](https://github.com/nodejs/node/pull/63050) - \[[`56bdd87378`](https://github.com/nodejs/node/commit/56bdd87378)] - **doc**: move hyperlinks outside of text blocks (Aviv Keller) [#&#8203;63493](https://github.com/nodejs/node/pull/63493) - \[[`1da05fb79d`](https://github.com/nodejs/node/commit/1da05fb79d)] - **doc**: mark stream.compose stable (Matteo Collina) [#&#8203;62562](https://github.com/nodejs/node/pull/62562) - \[[`7bb6dab70c`](https://github.com/nodejs/node/commit/7bb6dab70c)] - **doc,crypto**: mark argon2 and encap/decap as stable (Filip Skokan) [#&#8203;63924](https://github.com/nodejs/node/pull/63924) - \[[`1a4edb3c22`](https://github.com/nodejs/node/commit/1a4edb3c22)] - **doc,lib**: align WebCrypto names with spec (Filip Skokan) [#&#8203;63518](https://github.com/nodejs/node/pull/63518) - \[[`3c1636dabf`](https://github.com/nodejs/node/commit/3c1636dabf)] - **(SEMVER-MINOR)** **esm**: add `--experimental-import-text` flag (Efe) [#&#8203;62300](https://github.com/nodejs/node/pull/62300) - \[[`e0f211ca79`](https://github.com/nodejs/node/commit/e0f211ca79)] - **events**: improve `addAbortListener` perf by caching options object (Raz Luvaton) [#&#8203;52367](https://github.com/nodejs/node/pull/52367) - \[[`a124429b36`](https://github.com/nodejs/node/commit/a124429b36)] - **fs**: do not treat EPERM as ENOTEMPTY on Windows (Kirill Saied) [#&#8203;63709](https://github.com/nodejs/node/pull/63709) - \[[`e323e877be`](https://github.com/nodejs/node/commit/e323e877be)] - **(SEMVER-MINOR)** **fs**: support caller-supplied readFile() buffers (Matteo Collina) [#&#8203;63634](https://github.com/nodejs/node/pull/63634) - \[[`a41b4824d7`](https://github.com/nodejs/node/commit/a41b4824d7)] - **fs**: prevent spurious recursive watch events on prefix siblings (Marco) [#&#8203;63095](https://github.com/nodejs/node/pull/63095) - \[[`c63e00e3a5`](https://github.com/nodejs/node/commit/c63e00e3a5)] - **fs**: ignore deleted dirs in recursive watch scan (Trivikram Kamat) [#&#8203;63686](https://github.com/nodejs/node/pull/63686) - \[[`d3d7cd05e3`](https://github.com/nodejs/node/commit/d3d7cd05e3)] - **fs**: coerce -0 to +0 in mode flags and watch intervals (Filip Skokan) [#&#8203;63556](https://github.com/nodejs/node/pull/63556) - \[[`6f6387ecb3`](https://github.com/nodejs/node/commit/6f6387ecb3)] - **gyp**: update deps gypfiles (Nad Alaba) [#&#8203;63117](https://github.com/nodejs/node/pull/63117) - \[[`592544af44`](https://github.com/nodejs/node/commit/592544af44)] - **http**: document and validate options.path when it's in absolute-form (Joyee Cheung) [#&#8203;64108](https://github.com/nodejs/node/pull/64108) - \[[`c1248c9544`](https://github.com/nodejs/node/commit/c1248c9544)] - **(SEMVER-MINOR)** **http**: add httpValidation option to configure header value validation (RajeshKumar11) [#&#8203;61597](https://github.com/nodejs/node/pull/61597) - \[[`85a223bf15`](https://github.com/nodejs/node/commit/85a223bf15)] - **http**: fix drain event with cork/uncork (David Evans) [#&#8203;64038](https://github.com/nodejs/node/pull/64038) - \[[`8b060a9628`](https://github.com/nodejs/node/commit/8b060a9628)] - **inspector**: fix crash when writing to closed inspector socket (ympark2011) [#&#8203;64209](https://github.com/nodejs/node/pull/64209) - \[[`e68a3d33ac`](https://github.com/nodejs/node/commit/e68a3d33ac)] - **inspector**: fix inspector.close() documented behavior (Chengzhong Wu) [#&#8203;63837](https://github.com/nodejs/node/pull/63837) - \[[`d3682930b7`](https://github.com/nodejs/node/commit/d3682930b7)] - **lib**: fix missing lazyDOMException import (Filip Skokan) [#&#8203;64033](https://github.com/nodejs/node/pull/64033) - \[[`af9ea9cfcf`](https://github.com/nodejs/node/commit/af9ea9cfcf)] - **lib**: reject string "0" in validatePort when allowZero is false (Daijiro Wachi) [#&#8203;64174](https://github.com/nodejs/node/pull/64174) - \[[`cd1ea26110`](https://github.com/nodejs/node/commit/cd1ea26110)] - **lib**: use `__proto__: null` when calling `ObjectDefineProperty` (Antoine du Hamel) [#&#8203;64239](https://github.com/nodejs/node/pull/64239) - \[[`5b264398ce`](https://github.com/nodejs/node/commit/5b264398ce)] - **lib**: lazily initialize kEvents and kHandlers maps (Guilherme Araújo) [#&#8203;63702](https://github.com/nodejs/node/pull/63702) - \[[`823efe8c71`](https://github.com/nodejs/node/commit/823efe8c71)] - **lib**: improve control abstraction coverage in frozen intrinsics (Renegade334) [#&#8203;63698](https://github.com/nodejs/node/pull/63698) - \[[`7f4af5568f`](https://github.com/nodejs/node/commit/7f4af5568f)] - **lib**: add Iterator global to primordials (Renegade334) [#&#8203;63698](https://github.com/nodejs/node/pull/63698) - \[[`c8f3f5e5a5`](https://github.com/nodejs/node/commit/c8f3f5e5a5)] - **lib**: make `Navigator#language` getter throw on invalid `this` (Mohamed Sayed) [#&#8203;63601](https://github.com/nodejs/node/pull/63601) - \[[`1ebbbd59cf`](https://github.com/nodejs/node/commit/1ebbbd59cf)] - **lib**: optimize webidl conversion options (Filip Skokan) [#&#8203;62756](https://github.com/nodejs/node/pull/62756) - \[[`88590d1bb7`](https://github.com/nodejs/node/commit/88590d1bb7)] - **meta**: bump actions/checkout from 6.0.2 to 6.0.3 (dependabot\[bot]) [#&#8203;63726](https://github.com/nodejs/node/pull/63726) - \[[`0ea9cb9630`](https://github.com/nodejs/node/commit/0ea9cb9630)] - **meta**: bump actions/upload-artifact from 7.0.0 to 7.0.1 (dependabot\[bot]) [#&#8203;62850](https://github.com/nodejs/node/pull/62850) - \[[`f7275a0864`](https://github.com/nodejs/node/commit/f7275a0864)] - **meta**: fix linter warning in `stale.yml` (Antoine du Hamel) [#&#8203;64281](https://github.com/nodejs/node/pull/64281) - \[[`3a77d21d8c`](https://github.com/nodejs/node/commit/3a77d21d8c)] - **meta**: bump actions/cache from 5.0.5 to 6.1.0 (dependabot\[bot]) [#&#8203;64248](https://github.com/nodejs/node/pull/64248) - \[[`84e2836c95`](https://github.com/nodejs/node/commit/84e2836c95)] - **meta**: bump github/codeql-action/autobuild from 4.36.1 to 4.36.2 (dependabot\[bot]) [#&#8203;64247](https://github.com/nodejs/node/pull/64247) - \[[`09f800eec6`](https://github.com/nodejs/node/commit/09f800eec6)] - **meta**: bump github/codeql-action/analyze from 4.36.1 to 4.36.2 (dependabot\[bot]) [#&#8203;64246](https://github.com/nodejs/node/pull/64246) - \[[`6df1f97e64`](https://github.com/nodejs/node/commit/6df1f97e64)] - **meta**: bump codecov/codecov-action from 6.0.1 to 7.0.0 (dependabot\[bot]) [#&#8203;64244](https://github.com/nodejs/node/pull/64244) - \[[`737eb89651`](https://github.com/nodejs/node/commit/737eb89651)] - **meta**: bump rtCamp/action-slack-notify from 2.3.3 to 2.4.0 (dependabot\[bot]) [#&#8203;64243](https://github.com/nodejs/node/pull/64243) - \[[`dac3cd8b8f`](https://github.com/nodejs/node/commit/dac3cd8b8f)] - **meta**: bump github/codeql-action/init from 4.36.1 to 4.36.2 (dependabot\[bot]) [#&#8203;64242](https://github.com/nodejs/node/pull/64242) - \[[`108a6bc481`](https://github.com/nodejs/node/commit/108a6bc481)] - **meta**: bump github/codeql-action/upload-sarif from 4.36.1 to 4.36.2 (dependabot\[bot]) [#&#8203;64240](https://github.com/nodejs/node/pull/64240) - \[[`34d09a725d`](https://github.com/nodejs/node/commit/34d09a725d)] - **meta**: clarify V8 flags are outside threat model (Matteo Collina) [#&#8203;64224](https://github.com/nodejs/node/pull/64224) - \[[`944d9bc25f`](https://github.com/nodejs/node/commit/944d9bc25f)] - **meta**: move one or more collaborators to emeritus (Node.js GitHub Bot) [#&#8203;64057](https://github.com/nodejs/node/pull/64057) - \[[`cc22555402`](https://github.com/nodejs/node/commit/cc22555402)] - **meta**: update status of past strategic initiatives (Joyee Cheung) [#&#8203;63480](https://github.com/nodejs/node/pull/63480) - \[[`da7a21931e`](https://github.com/nodejs/node/commit/da7a21931e)] - **meta**: speed up stale bot (Aviv Keller) [#&#8203;64075](https://github.com/nodejs/node/pull/64075) - \[[`7bfcf7ca56`](https://github.com/nodejs/node/commit/7bfcf7ca56)] - **meta**: bump github/codeql-action from 4.35.3 to 4.36.1 (dependabot\[bot]) [#&#8203;63724](https://github.com/nodejs/node/pull/63724) - \[[`db6c983cdd`](https://github.com/nodejs/node/commit/db6c983cdd)] - **meta**: bump actions/cache from 5.0.4 to 5.0.5 (dependabot\[bot]) [#&#8203;62847](https://github.com/nodejs/node/pull/62847) - \[[`9e4f1339d1`](https://github.com/nodejs/node/commit/9e4f1339d1)] - **meta**: bump codecov/codecov-action from 6.0.0 to 6.0.1 (dependabot\[bot]) [#&#8203;63725](https://github.com/nodejs/node/pull/63725) - \[[`92c98d3ade`](https://github.com/nodejs/node/commit/92c98d3ade)] - **meta**: bump actions/stale from 10.2.0 to 10.3.0 (dependabot\[bot]) [#&#8203;63728](https://github.com/nodejs/node/pull/63728) - \[[`bbd3ffde89`](https://github.com/nodejs/node/commit/bbd3ffde89)] - **meta**: bump step-security/harden-runner from 2.19.0 to 2.19.4 (dependabot\[bot]) [#&#8203;63727](https://github.com/nodejs/node/pull/63727) - \[[`a6dd675c82`](https://github.com/nodejs/node/commit/a6dd675c82)] - **module**: enable import support for addons by default (Chengzhong Wu) [#&#8203;64221](https://github.com/nodejs/node/pull/64221) - \[[`fb2ccb15a1`](https://github.com/nodejs/node/commit/fb2ccb15a1)] - **module**: use file: URL as sourceURL for type-stripped CommonJS (Joyee Cheung) [#&#8203;63705](https://github.com/nodejs/node/pull/63705) - \[[`b9e17dc424`](https://github.com/nodejs/node/commit/b9e17dc424)] - **net**: early TCP binding via synchronous net.BoundSocket (Guy Bedford) [#&#8203;63951](https://github.com/nodejs/node/pull/63951) - \[[`a534b65815`](https://github.com/nodejs/node/commit/a534b65815)] - **(SEMVER-MINOR)** **net**: support TCP\_KEEPINTVL and TCP\_KEEPCNT in setKeepAlive (Guy Bedford) [#&#8203;63825](https://github.com/nodejs/node/pull/63825) - \[[`c55dd030e6`](https://github.com/nodejs/node/commit/c55dd030e6)] - **net**: coerce -0 to +0 in BlockList prefixes (Filip Skokan) [#&#8203;63556](https://github.com/nodejs/node/pull/63556) - \[[`a23cdec683`](https://github.com/nodejs/node/commit/a23cdec683)] - **(SEMVER-MINOR)** **perf\_hooks**: sample delay per event loop iteration (Pablo Erhard) [#&#8203;62935](https://github.com/nodejs/node/pull/62935) - \[[`f08b83bc1d`](https://github.com/nodejs/node/commit/f08b83bc1d)] - **perf\_hooks**: add NODE\_PERFORMANCE\_GC\_MINOR\_MARK\_SWEEP constant (Attila Szegedi) [#&#8203;63877](https://github.com/nodejs/node/pull/63877) - \[[`8d58e1b415`](https://github.com/nodejs/node/commit/8d58e1b415)] - **process**: fix finalization cleanup ref tracking (Trivikram Kamat) [#&#8203;64087](https://github.com/nodejs/node/pull/64087) - \[[`c757e3ef59`](https://github.com/nodejs/node/commit/c757e3ef59)] - **sqlite**: do not leave database open after failed open (Yagiz Nizipli) [#&#8203;63854](https://github.com/nodejs/node/pull/63854) - \[[`87064a096b`](https://github.com/nodejs/node/commit/87064a096b)] - **sqlite**: fix stack-use-after-scope with function callback (ndossche) [#&#8203;63640](https://github.com/nodejs/node/pull/63640) - \[[`7428b57a37`](https://github.com/nodejs/node/commit/7428b57a37)] - **(SEMVER-MINOR)** **src**: allow empty --experimental-config-file (Marco Ippolito) [#&#8203;61610](https://github.com/nodejs/node/pull/61610) - \[[`d7946c9c07`](https://github.com/nodejs/node/commit/d7946c9c07)] - **src**: add test flag to config file (Marco Ippolito) [#&#8203;60798](https://github.com/nodejs/node/pull/60798) - \[[`a642657d71`](https://github.com/nodejs/node/commit/a642657d71)] - **src**: rename config file testRunner to test (Marco Ippolito) [#&#8203;60798](https://github.com/nodejs/node/pull/60798) - \[[`818b43d09e`](https://github.com/nodejs/node/commit/818b43d09e)] - **src**: do not enable wasm trap handler if there's not enough vmem (Joyee Cheung) [#&#8203;62132](https://github.com/nodejs/node/pull/62132) - \[[`af5e1a9729`](https://github.com/nodejs/node/commit/af5e1a9729)] - **src**: fix escaping of single quotes in task runner (Antoine du Hamel) [#&#8203;64089](https://github.com/nodejs/node/pull/64089) - \[[`8a5d3bc168`](https://github.com/nodejs/node/commit/8a5d3bc168)] - **src**: abstract tracing agent for both legacy and perfetto (Chengzhong Wu) [#&#8203;64053](https://github.com/nodejs/node/pull/64053) - \[[`ce6f29e45b`](https://github.com/nodejs/node/commit/ce6f29e45b)] - **src**: avoid redundant call to `std::get_if<>()` (Tobias Nießen) [#&#8203;64094](https://github.com/nodejs/node/pull/64094) - \[[`96478050f2`](https://github.com/nodejs/node/commit/96478050f2)] - **src**: omit unconvertible names in cjs\_lexer::Parse (Yagiz Nizipli) [#&#8203;63943](https://github.com/nodejs/node/pull/63943) - \[[`0147ed746e`](https://github.com/nodejs/node/commit/0147ed746e)] - **src**: guard OpenSSL compression header include (Filip Skokan) [#&#8203;64009](https://github.com/nodejs/node/pull/64009) - \[[`8d2858a9c4`](https://github.com/nodejs/node/commit/8d2858a9c4)] - **src**: handle empty MaybeLocal in cjs\_lexer::Parse (Yagiz Nizipli) [#&#8203;63885](https://github.com/nodejs/node/pull/63885) - \[[`e5289d180f`](https://github.com/nodejs/node/commit/e5289d180f)] - **src**: do not track weak `BaseObject`s as childrens of `Realm`s (Anna Henningsen) [#&#8203;63842](https://github.com/nodejs/node/pull/63842) - \[[`e8352ff754`](https://github.com/nodejs/node/commit/e8352ff754)] - **src**: allow tracking children in `MemoryTracker` with weak edges (Anna Henningsen) [#&#8203;63842](https://github.com/nodejs/node/pull/63842) - \[[`a408f279c5`](https://github.com/nodejs/node/commit/a408f279c5)] - **src**: use C++14 deprecated attribute for `NODE_DEPRECATED` (Anna Henningsen) [#&#8203;63755](https://github.com/nodejs/node/pull/63755) - \[[`4b5eb7b72d`](https://github.com/nodejs/node/commit/4b5eb7b72d)] - **src**: add cleanup hooks to `node::ObjectWrap` (Anna Henningsen) [#&#8203;63642](https://github.com/nodejs/node/pull/63642) - \[[`44976c6071`](https://github.com/nodejs/node/commit/44976c6071)] - **src**: fix edge case when deflateInit2() fails with Z\_VERSION\_ERROR (Nora Dossche) [#&#8203;63476](https://github.com/nodejs/node/pull/63476) - \[[`5b3bb284f3`](https://github.com/nodejs/node/commit/5b3bb284f3)] - **src**: add Latin1 fast path in StringBytes::Encode utf8 (Mert Can Altin) [#&#8203;63385](https://github.com/nodejs/node/pull/63385) - \[[`7cdad636c4`](https://github.com/nodejs/node/commit/7cdad636c4)] - **src**: fix crash when reading length on Storage.prototype (Mohamed Sayed) [#&#8203;63529](https://github.com/nodejs/node/pull/63529) - \[[`c438250c68`](https://github.com/nodejs/node/commit/c438250c68)] - **stream**: cut per-chunk overhead in WHATWG streams (Matteo Collina) [#&#8203;64252](https://github.com/nodejs/node/pull/64252) - \[[`291c127947`](https://github.com/nodejs/node/commit/291c127947)] - **stream**: reduce allocations on WHATWG streams hot paths (Matteo Collina) [#&#8203;63876](https://github.com/nodejs/node/pull/63876) - \[[`3d91aeb434`](https://github.com/nodejs/node/commit/3d91aeb434)] - **stream**: optimize pipeTo promise handling (Matteo Collina) [#&#8203;63572](https://github.com/nodejs/node/pull/63572) - \[[`fcbff00a44`](https://github.com/nodejs/node/commit/fcbff00a44)] - **stream**: preserve half-open duplexes in async iteration (Efe) [#&#8203;64275](https://github.com/nodejs/node/pull/64275) - \[[`e57597173c`](https://github.com/nodejs/node/commit/e57597173c)] - **(SEMVER-MINOR)** **stream**: expose ReadableStreamTee (Matteo Collina) [#&#8203;64195](https://github.com/nodejs/node/pull/64195) - \[[`a48edf40e8`](https://github.com/nodejs/node/commit/a48edf40e8)] - **stream**: proxy first own method in Readable.wrap() (Daijiro Wachi) [#&#8203;64048](https://github.com/nodejs/node/pull/64048) - \[[`f58c5bafcf`](https://github.com/nodejs/node/commit/f58c5bafcf)] - **stream**: fix Writable.toWeb() desiredSize for non-object-mode (Matteo Collina) [#&#8203;62986](https://github.com/nodejs/node/pull/62986) - \[[`7261276f45`](https://github.com/nodejs/node/commit/7261276f45)] - **stream**: fix Utf8Stream stall after full write of multi-byte data (Daijiro Wachi) [#&#8203;63964](https://github.com/nodejs/node/pull/63964) - \[[`1558986b78`](https://github.com/nodejs/node/commit/1558986b78)] - **stream**: only pass the expected number of parameters to callbacks (Antoine du Hamel) [#&#8203;63909](https://github.com/nodejs/node/pull/63909) - \[[`edef89ba6a`](https://github.com/nodejs/node/commit/edef89ba6a)] - **stream**: fix dropped first chunk in Utf8Stream buffer mode (Daijiro Wachi) [#&#8203;63833](https://github.com/nodejs/node/pull/63833) - \[[`915e3e2f42`](https://github.com/nodejs/node/commit/915e3e2f42)] - **stream**: check done before backpressure in stream reader (Daijiro Wachi) [#&#8203;63699](https://github.com/nodejs/node/pull/63699) - \[[`2d29628b5b`](https://github.com/nodejs/node/commit/2d29628b5b)] - **test**: update WPT for WebCryptoAPI to [`03a1476`](https://github.com/nodejs/node/commit/03a1476844) (Node.js GitHub Bot) [#&#8203;63900](https://github.com/nodejs/node/pull/63900) - \[[`89e23b70c4`](https://github.com/nodejs/node/commit/89e23b70c4)] - **test**: deflake test-debugger-probe-timeout (Joyee Cheung) [#&#8203;63547](https://github.com/nodejs/node/pull/63547) - \[[`54ca514414`](https://github.com/nodejs/node/commit/54ca514414)] - **test**: make blob desiredSize assertion robust (Trivikram Kamat) [#&#8203;64106](https://github.com/nodejs/node/pull/64106) - \[[`01cbe530eb`](https://github.com/nodejs/node/commit/01cbe530eb)] - **test**: update WPT for urlpattern to [`11a459a`](https://github.com/nodejs/node/commit/11a459a2b1) (Node.js GitHub Bot) [#&#8203;64037](https://github.com/nodejs/node/pull/64037) - \[[`6fcd3cf516`](https://github.com/nodejs/node/commit/6fcd3cf516)] - **test**: improve lcov reporter snapshot diagnostics (Trivikram Kamat) [#&#8203;64049](https://github.com/nodejs/node/pull/64049) - \[[`f50a55d7e5`](https://github.com/nodejs/node/commit/f50a55d7e5)] - **test**: keep finalization close fixture ref alive (Trivikram Kamat) [#&#8203;64085](https://github.com/nodejs/node/pull/64085) - \[[`3085714530`](https://github.com/nodejs/node/commit/3085714530)] - **test**: fix typo from overriden to overridden (parkhojeong) [#&#8203;63403](https://github.com/nodejs/node/pull/63403) - \[[`9f5347e8df`](https://github.com/nodejs/node/commit/9f5347e8df)] - **test**: mark hr-time WPT flaky on macos15-x64 (Trivikram Kamat) [#&#8203;64054](https://github.com/nodejs/node/pull/64054) - \[[`44b4fe4246`](https://github.com/nodejs/node/commit/44b4fe4246)] - **test**: use one-off agent in http consumed timeout test (Trivikram Kamat) [#&#8203;64052](https://github.com/nodejs/node/pull/64052) - \[[`2f567edaca`](https://github.com/nodejs/node/commit/2f567edaca)] - **test**: fix flaky test-runner coverage threshold test (Trivikram Kamat) [#&#8203;64051](https://github.com/nodejs/node/pull/64051) - \[[`a56fbb2d36`](https://github.com/nodejs/node/commit/a56fbb2d36)] - **test**: tolerate duplicate watch change events (Trivikram Kamat) [#&#8203;63937](https://github.com/nodejs/node/pull/63937) - \[[`b636f4769c`](https://github.com/nodejs/node/commit/b636f4769c)] - **test**: mark test-debugger-run-after-quit-restart as flaky on macOS (Matteo Collina) [#&#8203;64006](https://github.com/nodejs/node/pull/64006) - \[[`ba23eb9717`](https://github.com/nodejs/node/commit/ba23eb9717)] - **test**: update WPT for url to [`d4598eb`](https://github.com/nodejs/node/commit/d4598eba09) (Node.js GitHub Bot) [#&#8203;63899](https://github.com/nodejs/node/pull/63899) - \[[`bc420f20d8`](https://github.com/nodejs/node/commit/bc420f20d8)] - **test**: update WPT for urlpattern to [`23aac92`](https://github.com/nodejs/node/commit/23aac92784) (Node.js GitHub Bot) [#&#8203;63898](https://github.com/nodejs/node/pull/63898) - \[[`d2c9c07af8`](https://github.com/nodejs/node/commit/d2c9c07af8)] - **test**: add tests for 3 methods in utils (Daijiro Wachi) [#&#8203;63765](https://github.com/nodejs/node/pull/63765) - \[[`4e00c8ec2e`](https://github.com/nodejs/node/commit/4e00c8ec2e)] - **test**: mark SEA tests flaky on linux arm debug (Trivikram Kamat) [#&#8203;63743](https://github.com/nodejs/node/pull/63743) - \[[`a17cf06d12`](https://github.com/nodejs/node/commit/a17cf06d12)] - **test**: validate ERR\_INVALID\_THIS for scheduler methods (Daijiro Wachi) [#&#8203;63764](https://github.com/nodejs/node/pull/63764) - \[[`d59d7fdd16`](https://github.com/nodejs/node/commit/d59d7fdd16)] - **test**: add coverage outside SEA (Daijiro Wachi) [#&#8203;63744](https://github.com/nodejs/node/pull/63744) - \[[`71a32d31bf`](https://github.com/nodejs/node/commit/71a32d31bf)] - **test**: update WPT for urlpattern to [`2f28df5`](https://github.com/nodejs/node/commit/2f28df545c) (Node.js GitHub Bot) [#&#8203;63771](https://github.com/nodejs/node/pull/63771) - \[[`28c77ab174`](https://github.com/nodejs/node/commit/28c77ab174)] - **test**: make Brotli 16GB test wait for backpressure (Trivikram Kamat) [#&#8203;63389](https://github.com/nodejs/node/pull/63389) - \[[`9a81921d4a`](https://github.com/nodejs/node/commit/9a81921d4a)] - **test**: add regression test for using `ObjectWrap` in worker (Mohamed Akram) [#&#8203;63642](https://github.com/nodejs/node/pull/63642) - \[[`88ab61f2f8`](https://github.com/nodejs/node/commit/88ab61f2f8)] - **test**: accept SIGILL aborts in async-hooks tests (Trivikram Kamat) [#&#8203;63687](https://github.com/nodejs/node/pull/63687) - \[[`b4f5c86463`](https://github.com/nodejs/node/commit/b4f5c86463)] - **test**: add more test cases for pathToFileURL (Rafael Gonzaga) [#&#8203;63293](https://github.com/nodejs/node/pull/63293) - \[[`812a66f0ac`](https://github.com/nodejs/node/commit/812a66f0ac)] - **test**: update test426-fixtures to [`2965987`](https://github.com/nodejs/node/commit/2965987bf4c96afa400c9356c8e620cb340aaee) (Node.js GitHub Bot) [#&#8203;63668](https://github.com/nodejs/node/pull/63668) - \[[`2bf0de838d`](https://github.com/nodejs/node/commit/2bf0de838d)] - **test**: cover webcrypto prototype pollution systematically (Filip Skokan) [#&#8203;63520](https://github.com/nodejs/node/pull/63520) - \[[`bec6856ae8`](https://github.com/nodejs/node/commit/bec6856ae8)] - **test,debugger**: add test for type stripping in debugger probe mode (Joyee Cheung) [#&#8203;63748](https://github.com/nodejs/node/pull/63748) - \[[`a2b9095e03`](https://github.com/nodejs/node/commit/a2b9095e03)] - **test\_runner**: avoid recompiling coverage globs for every file (sangwook) [#&#8203;63675](https://github.com/nodejs/node/pull/63675) - \[[`02fbff446f`](https://github.com/nodejs/node/commit/02fbff446f)] - **test\_runner**: cache `shouldSkipFileCoverage` result per URL (sangwook) [#&#8203;63675](https://github.com/nodejs/node/pull/63675) - \[[`094869354a`](https://github.com/nodejs/node/commit/094869354a)] - **test\_runner**: ignore erased TS lines in coverage (Matteo Collina) [#&#8203;63510](https://github.com/nodejs/node/pull/63510) - \[[`68edc2b009`](https://github.com/nodejs/node/commit/68edc2b009)] - **test\_runner**: fix suite diagnostic chanel end (Moshe Atlow) [#&#8203;63533](https://github.com/nodejs/node/pull/63533) - \[[`659d5bf068`](https://github.com/nodejs/node/commit/659d5bf068)] - **test\_runner**: add parentId to test events with testId (Moshe Atlow) [#&#8203;63435](https://github.com/nodejs/node/pull/63435) - \[[`eaebeb8b88`](https://github.com/nodejs/node/commit/eaebeb8b88)] - **test\_runner**: fix hooks test context (Moshe Atlow) [#&#8203;63285](https://github.com/nodejs/node/pull/63285) - \[[`d03d96889b`](https://github.com/nodejs/node/commit/d03d96889b)] - **test\_runner**: add tags option and tag-name filter (Chemi Atlow) [#&#8203;63221](https://github.com/nodejs/node/pull/63221) - \[[`e8c3db1364`](https://github.com/nodejs/node/commit/e8c3db1364)] - **test\_runner**: add `getTestContext()` (Moshe Atlow) [#&#8203;62501](https://github.com/nodejs/node/pull/62501) - \[[`345c591d10`](https://github.com/nodejs/node/commit/345c591d10)] - **test\_runner**: filter execArgv fallback for child tests (Trivikram Kamat) [#&#8203;64056](https://github.com/nodejs/node/pull/64056) - \[[`2f47fb23bf`](https://github.com/nodejs/node/commit/2f47fb23bf)] - **test\_runner**: improve coverage failure diagnostics (Trivikram Kamat) [#&#8203;64050](https://github.com/nodejs/node/pull/64050) - \[[`260cf1ac89`](https://github.com/nodejs/node/commit/260cf1ac89)] - **test\_runner**: add timestamp to JUnit reporter testsuites (sangwook) [#&#8203;64029](https://github.com/nodejs/node/pull/64029) - \[[`24140eafdf`](https://github.com/nodejs/node/commit/24140eafdf)] - **test\_runner**: remove unused shuffleArrayWithSeed (Daijiro Wachi) [#&#8203;63847](https://github.com/nodejs/node/pull/63847) - \[[`b7fdb4891a`](https://github.com/nodejs/node/commit/b7fdb4891a)] - **test\_runner**: fix watch cwd with isolation none (Trivikram Kamat) [#&#8203;63690](https://github.com/nodejs/node/pull/63690) - \[[`e48b307e09`](https://github.com/nodejs/node/commit/e48b307e09)] - **timers**: reuse Timeout objects in setStreamTimeout (Matteo Collina) [#&#8203;64254](https://github.com/nodejs/node/pull/64254) - \[[`5396235993`](https://github.com/nodejs/node/commit/5396235993)] - **(SEMVER-MINOR)** **tls**: report negotiated TLS groups (Filip Skokan) [#&#8203;64119](https://github.com/nodejs/node/pull/64119) - \[[`a653e9bb57`](https://github.com/nodejs/node/commit/a653e9bb57)] - **tls**: handle large RSA exponents in X.509 cert (Tobias Nießen) [#&#8203;64093](https://github.com/nodejs/node/pull/64093) - \[[`5e901b5cd9`](https://github.com/nodejs/node/commit/5e901b5cd9)] - **(SEMVER-MINOR)** **tls**: add certificateCompression option (Tim Perry) [#&#8203;62217](https://github.com/nodejs/node/pull/62217) - \[[`3abcfa723c`](https://github.com/nodejs/node/commit/3abcfa723c)] - **tls**: route event listener exceptions through error handlers (Antoine du Hamel) [#&#8203;63822](https://github.com/nodejs/node/pull/63822) - \[[`eaba4cd59d`](https://github.com/nodejs/node/commit/eaba4cd59d)] - **tools**: bump the eslint group in /tools/eslint with 8 updates (dependabot\[bot]) [#&#8203;64249](https://github.com/nodejs/node/pull/64249) - \[[`7d7ea1dbca`](https://github.com/nodejs/node/commit/7d7ea1dbca)] - **tools**: update c-ares updater script (Antoine du Hamel) [#&#8203;64194](https://github.com/nodejs/node/pull/64194) - \[[`976827cd71`](https://github.com/nodejs/node/commit/976827cd71)] - **tools**: validate version number in release proposal commit message lint (Antoine du Hamel) [#&#8203;64070](https://github.com/nodejs/node/pull/64070) - \[[`cc0c586b52`](https://github.com/nodejs/node/commit/cc0c586b52)] - **tools**: update sccache to v0.16.0 (Michaël Zasso) [#&#8203;63078](https://github.com/nodejs/node/pull/63078) - \[[`f0a35fa56a`](https://github.com/nodejs/node/commit/f0a35fa56a)] - **tools**: bump js-yaml from 4.1.1 to 4.2.0 in /tools/lint-md (dependabot\[bot]) [#&#8203;63948](https://github.com/nodejs/node/pull/63948) - \[[`dafbd23240`](https://github.com/nodejs/node/commit/dafbd23240)] - **tools**: bump js-yaml from 4.1.1 to 4.2.0 in /tools/eslint (dependabot\[bot]) [#&#8203;63947](https://github.com/nodejs/node/pull/63947) - \[[`0ae1552650`](https://github.com/nodejs/node/commit/0ae1552650)] - **tools**: update the llhttp updater script (Antoine du Hamel) [#&#8203;63819](https://github.com/nodejs/node/pull/63819) - \[[`3623586d1f`](https://github.com/nodejs/node/commit/3623586d1f)] - **tools**: align Bash snippets in GHA with `lint-sh` conventions (Antoine du Hamel) [#&#8203;63829](https://github.com/nodejs/node/pull/63829) - \[[`64b130ce1d`](https://github.com/nodejs/node/commit/64b130ce1d)] - **tools**: bump the eslint group in /tools/eslint with 7 updates (dependabot\[bot]) [#&#8203;63730](https://github.com/nodejs/node/pull/63730) - \[[`4900cac251`](https://github.com/nodejs/node/commit/4900cac251)] - **tools**: fix zlib updater script (Antoine du Hamel) [#&#8203;63707](https://github.com/nodejs/node/pull/63707) - \[[`8edf3abafc`](https://github.com/nodejs/node/commit/8edf3abafc)] - **typings**: add typing for crypto (Filip Skokan) [#&#8203;64122](https://github.com/nodejs/node/pull/64122) - \[[`d5be94e820`](https://github.com/nodejs/node/commit/d5be94e820)] - **url**: fix URLSearchParams(null) to prudce null= per spec (Marco) [#&#8203;63782](https://github.com/nodejs/node/pull/63782) - \[[`ee66a3851c`](https://github.com/nodejs/node/commit/ee66a3851c)] - **util**: fix OOM in inspect color stack formatting (Ijtihed Kilani) [#&#8203;64022](https://github.com/nodejs/node/pull/64022) - \[[`e26f183699`](https://github.com/nodejs/node/commit/e26f183699)] - **util**: fix scientific notation formatting (Daijiro Wachi) [#&#8203;63823](https://github.com/nodejs/node/pull/63823) - \[[`7993e3e476`](https://github.com/nodejs/node/commit/7993e3e476)] - **util**: fix -0 formatting when numericSeparator is enabled (Daijiro Wachi) [#&#8203;63815](https://github.com/nodejs/node/pull/63815) - \[[`38758a7789`](https://github.com/nodejs/node/commit/38758a7789)] - **util**: remove style caches from styleText slow path (Guilherme Araújo) [#&#8203;63706](https://github.com/nodejs/node/pull/63706) - \[[`46a0ca256a`](https://github.com/nodejs/node/commit/46a0ca256a)] - **watch**: print name of changed file that triggers restart (Marco) [#&#8203;63781](https://github.com/nodejs/node/pull/63781) - \[[`e1582818ad`](https://github.com/nodejs/node/commit/e1582818ad)] - **watch**: cancel pending restart on shutdown (Trivikram Kamat) [#&#8203;63383](https://github.com/nodejs/node/pull/63383) - \[[`9a208668b0`](https://github.com/nodejs/node/commit/9a208668b0)] - **zlib**: validate flush king for all streams (Ic3b3rg) [#&#8203;63746](https://github.com/nodejs/node/pull/63746) - \[[`928981d803`](https://github.com/nodejs/node/commit/928981d803)] - **zlib**: validate flush kind for brotli streams (Ic3b3rg) [#&#8203;63746](https://github.com/nodejs/node/pull/63746) - \[[`fd0fb00164`](https://github.com/nodejs/node/commit/fd0fb00164)] - **zlib**: expose rejectGarbageAfterEnd option (Filip Skokan) [#&#8203;64023](https://github.com/nodejs/node/pull/64023) - \[[`e334d30b4c`](https://github.com/nodejs/node/commit/e334d30b4c)] - **zlib**: reject trailing gzip members in web streams (Filip Skokan) [#&#8203;64023](https://github.com/nodejs/node/pull/64023) - \[[`7433c3df2e`](https://github.com/nodejs/node/commit/7433c3df2e)] - **zlib**: coerce -0 to +0 for crc32 seeds (Filip Skokan) [#&#8203;63556](https://github.com/nodejs/node/pull/63556) ### [`v24.18.1`](https://github.com/nodejs/node/releases/tag/v24.18.1): 2026-07-29, Version 24.18.1 'Krypton' (LTS), @&#8203;juanarbol [Compare Source](https://github.com/nodejs/node/compare/v24.18.0...v24.18.1) This is a security release. ##### Notable Changes - (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High - (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High - (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High - (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium - (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium - (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium - (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium - (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium - (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low - (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low - (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low - deps: update llhttp to 9.4.3 (Paolo Insogna) - deps: update undici to 7.29.0 (Node.js GitHub Bot) ##### Commits - \[[`6cb0475751`](https://github.com/nodejs/node/commit/6cb0475751)] - **deps**: update llhttp to 9.4.3 (Paolo Insogna) [nodejs-private/node-private#935](https://github.com/nodejs-private/node-private/pull/935) - \[[`bcfe21d3dc`](https://github.com/nodejs/node/commit/bcfe21d3dc)] - **deps**: update undici to 7.29.0 (Node.js GitHub Bot) [#&#8203;64713](https://github.com/nodejs/node/pull/64713) - \[[`9d0d36cffd`](https://github.com/nodejs/node/commit/9d0d36cffd)] - **(CVE-2026-58042)** **dns**: handle large resolveAny address replies (RafaelGSS) [nodejs-private/node-private#929](https://github.com/nodejs-private/node-private/pull/929) - \[[`8a008fb523`](https://github.com/nodejs/node/commit/8a008fb523)] - **(CVE-2026-58044)** **http**: reject requests exceeding max header count (Matteo Collina) [nodejs-private/node-private#922](https://github.com/nodejs-private/node-private/pull/922) - \[[`a77c7f7354`](https://github.com/nodejs/node/commit/a77c7f7354)] - **(CVE-2026-56848)** **http2**: defer rst stream while in scope (Matteo Collina) [nodejs-private/node-private#921](https://github.com/nodejs-private/node-private/pull/921) - \[[`34ed88a069`](https://github.com/nodejs/node/commit/34ed88a069)] - **(CVE-2026-56846)** **http2**: retain header memory in session accounting (Matteo Collina) [#&#8203;63752](https://github.com/nodejs/node/pull/63752) - \[[`95ba2cfde7`](https://github.com/nodejs/node/commit/95ba2cfde7)] - **(CVE-2026-58040)** **https**: bind identity checks to session reuse (Matteo Collina) [nodejs-private/node-private#904](https://github.com/nodejs-private/node-private/pull/904) - \[[`fcbdbe47ea`](https://github.com/nodejs/node/commit/fcbdbe47ea)] - **(CVE-2026-56850)** **https**: distinguish PFX object-array agent keys (RafaelGSS) [nodejs-private/node-private#930](https://github.com/nodejs-private/node-private/pull/930) - \[[`ea26c12b56`](https://github.com/nodejs/node/commit/ea26c12b56)] - **(CVE-2026-58043)** **permission**: avoid granting radix split nodes (RafaelGSS) [nodejs-private/node-private#911](https://github.com/nodejs-private/node-private/pull/911) - \[[`9a6b7e343a`](https://github.com/nodejs/node/commit/9a6b7e343a)] - **(CVE-2026-58039)** **permission**: check final report output path (RafaelGSS) [nodejs-private/node-private#926](https://github.com/nodejs-private/node-private/pull/926) - \[[`6c0c990880`](https://github.com/nodejs/node/commit/6c0c990880)] - **(CVE-2026-56847)** **permission**: enforce fs write permission for trace events (RafaelGSS) [nodejs-private/node-private#927](https://github.com/nodejs-private/node-private/pull/927) - \[[`af9ff0490c`](https://github.com/nodejs/node/commit/af9ff0490c)] - **(CVE-2026-58041)** **sqlite**: invalidate tag store iterators on statement reset (Matteo Collina) [nodejs-private/node-private#896](https://github.com/nodejs-private/node-private/pull/896) - \[[`05f541b5c0`](https://github.com/nodejs/node/commit/05f541b5c0)] - **(CVE-2026-58045)** **zlib**: throw on out-of-bounds write buffers (RafaelGSS) [nodejs-private/node-private#931](https://github.com/nodejs-private/node-private/pull/931) ### [`v24.18.0`](https://github.com/nodejs/node/releases/tag/v24.18.0): 2026-06-23, Version 24.18.0 'Krypton' (LTS), @&#8203;richardlau prepared by @&#8203;sxa [Compare Source](https://github.com/nodejs/node/compare/v24.17.0...v24.18.0) ##### Notable Changes - \[[`e07e7a31e1`](https://github.com/nodejs/node/commit/e07e7a31e1)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#&#8203;63527](https://github.com/nodejs/node/pull/63527) - \[[`44c8ebcbd6`](https://github.com/nodejs/node/commit/44c8ebcbd6)] - **http**: avoid stream listeners on idle agent sockets (Matteo Collina) [#&#8203;64004](https://github.com/nodejs/node/pull/64004) - \[[`d3ef4122ee`](https://github.com/nodejs/node/commit/d3ef4122ee)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#&#8203;63597](https://github.com/nodejs/node/pull/63597) - \[[`bb2857b85a`](https://github.com/nodejs/node/commit/bb2857b85a)] - **(SEMVER-MINOR)** **crypto**: align key argument names in docs and error messages (Filip Skokan) [#&#8203;62527](https://github.com/nodejs/node/pull/62527) - \[[`b9d5e87880`](https://github.com/nodejs/node/commit/b9d5e87880)] - **(SEMVER-MINOR)** **crypto**: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) [#&#8203;62527](https://github.com/nodejs/node/pull/62527) - \[[`ccd756d61e`](https://github.com/nodejs/node/commit/ccd756d61e)] - **(SEMVER-MINOR)** **crypto**: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) [#&#8203;62183](https://github.com/nodejs/node/pull/62183) - \[[`4c9251fc09`](https://github.com/nodejs/node/commit/4c9251fc09)] - **(SEMVER-MINOR)** **http**: add writeInformation to send arbitrary 1xx status codes (Tim Perry) [#&#8203;63155](https://github.com/nodejs/node/pull/63155) - \[[`8c989ec4a3`](https://github.com/nodejs/node/commit/8c989ec4a3)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#&#8203;63079](https://github.com/nodejs/node/pull/63079) - \[[`3f54c8ba32`](https://github.com/nodejs/node/commit/3f54c8ba32)] - ***Revert*** "**stream**: noop pause/resume on destroyed streams" (Stewart X Addison) [#&#8203;63834](https://github.com/nodejs/node/pull/63834) ##### Commits - \[[`d3ef4122ee`](https://github.com/nodejs/node/commit/d3ef4122ee)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#&#8203;63597](https://github.com/nodejs/node/pull/63597) - \[[`9ff36e40f0`](https://github.com/nodejs/node/commit/9ff36e40f0)] - **build**: add --enable-all-experimentals build flag (Paolo Insogna) [#&#8203;62755](https://github.com/nodejs/node/pull/62755) - \[[`7c22ee23aa`](https://github.com/nodejs/node/commit/7c22ee23aa)] - **build**: def `NODE_USE_NODE_CODE_CACHE` only used in node\_mksnapshot (Chengzhong Wu) [#&#8203;63588](https://github.com/nodejs/node/pull/63588) - \[[`2551abdb4a`](https://github.com/nodejs/node/commit/2551abdb4a)] - **build,win**: enable x64 PGO (Stefan Stojanovic) [#&#8203;62761](https://github.com/nodejs/node/pull/62761) - \[[`e8a55ce9b1`](https://github.com/nodejs/node/commit/e8a55ce9b1)] - **crypto**: strengthen argument CHECKs in TurboSHAKE (Tobias Nießen) [#&#8203;62763](https://github.com/nodejs/node/pull/62763) - \[[`ae61cd68f3`](https://github.com/nodejs/node/commit/ae61cd68f3)] - **crypto**: harden WebCrypto against prototype pollution (Filip Skokan) [#&#8203;63363](https://github.com/nodejs/node/pull/63363) - \[[`3d05a1d396`](https://github.com/nodejs/node/commit/3d05a1d396)] - **crypto**: pass CryptoKey handles to KDF jobs (Filip Skokan) [#&#8203;63363](https://github.com/nodejs/node/pull/63363) - \[[`f9d10a3f6b`](https://github.com/nodejs/node/commit/f9d10a3f6b)] - **crypto**: remove async from WebCrypto methods (Filip Skokan) [#&#8203;63363](https://github.com/nodejs/node/pull/63363) - \[[`e431d93e9e`](https://github.com/nodejs/node/commit/e431d93e9e)] - **crypto**: add WebCrypto CryptoJob mode (Filip Skokan) [#&#8203;63363](https://github.com/nodejs/node/pull/63363) - \[[`56e2505e48`](https://github.com/nodejs/node/commit/56e2505e48)] - **crypto**: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) [#&#8203;63255](https://github.com/nodejs/node/pull/63255) - \[[`3bac77f2a8`](https://github.com/nodejs/node/commit/3bac77f2a8)] - **crypto**: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) [#&#8203;63255](https://github.com/nodejs/node/pull/63255) - \[[`1bff901b09`](https://github.com/nodejs/node/commit/1bff901b09)] - **crypto**: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) [#&#8203;63255](https://github.com/nodejs/node/pull/63255) - \[[`4433fca3df`](https://github.com/nodejs/node/commit/4433fca3df)] - **crypto**: harden CryptoKey algorithm slots (Filip Skokan) [#&#8203;63111](https://github.com/nodejs/node/pull/63111) - \[[`b5cf01217a`](https://github.com/nodejs/node/commit/b5cf01217a)] - **crypto**: harden KeyObject internal slots (Filip Skokan) [#&#8203;63111](https://github.com/nodejs/node/pull/63111) - \[[`ce84aef37d`](https://github.com/nodejs/node/commit/ce84aef37d)] - **crypto**: add guards and adjust tests for BoringSSL (Filip Skokan) [#&#8203;62883](https://github.com/nodejs/node/pull/62883) - \[[`26781689b0`](https://github.com/nodejs/node/commit/26781689b0)] - **crypto**: reject duplicate ML-KEM JWK key\_ops (Filip Skokan) [#&#8203;62905](https://github.com/nodejs/node/pull/62905) - \[[`aeea8f4970`](https://github.com/nodejs/node/commit/aeea8f4970)] - **crypto**: add JWK support for ML-KEM and SLH-DSA key types (Filip Skokan) [#&#8203;62706](https://github.com/nodejs/node/pull/62706) - \[[`407cf91656`](https://github.com/nodejs/node/commit/407cf91656)] - **crypto**: guard against size\_t overflow on experimental 32-bit arch (Filip Skokan) [#&#8203;62626](https://github.com/nodejs/node/pull/62626) - \[[`bb2857b85a`](https://github.com/nodejs/node/commit/bb2857b85a)] - **(SEMVER-MINOR)** **crypto**: align key argument names in docs and error messages (Filip Skokan) [#&#8203;62527](https://github.com/nodejs/node/pull/62527) - \[[`b9d5e87880`](https://github.com/nodejs/node/commit/b9d5e87880)] - **(SEMVER-MINOR)** **crypto**: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) [#&#8203;62527](https://github.com/nodejs/node/pull/62527) - \[[`b46d52b283`](https://github.com/nodejs/node/commit/b46d52b283)] - **crypto**: unify asymmetric key import through KeyObjectHandle::Init (Filip Skokan) [#&#8203;62499](https://github.com/nodejs/node/pull/62499) - \[[`ccd756d61e`](https://github.com/nodejs/node/commit/ccd756d61e)] - **(SEMVER-MINOR)** **crypto**: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) [#&#8203;62183](https://github.com/nodejs/node/pull/62183) - \[[`e07e7a31e1`](https://github.com/nodejs/node/commit/e07e7a31e1)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#&#8203;63527](https://github.com/nodejs/node/pull/63527) - \[[`61826df455`](https://github.com/nodejs/node/commit/61826df455)] - **crypto**: coerce -0 keylen to +0 in pbkdf2 and scrypt (Jordan Harband) [#&#8203;63531](https://github.com/nodejs/node/pull/63531) - \[[`16d2fd3c07`](https://github.com/nodejs/node/commit/16d2fd3c07)] - **crypto**: align verifyOneShot accepted types (Anshika Jain) [#&#8203;63280](https://github.com/nodejs/node/pull/63280) - \[[`3b8330deda`](https://github.com/nodejs/node/commit/3b8330deda)] - **crypto**: improve system certificate enumeration logic on macOS (Robo) [#&#8203;62576](https://github.com/nodejs/node/pull/62576) - \[[`141de35399`](https://github.com/nodejs/node/commit/141de35399)] - **debugger**: add --help to `node inspect` and improve docs (Joyee Cheung) [#&#8203;63201](https://github.com/nodejs/node/pull/63201) - \[[`b76bfcd4fa`](https://github.com/nodejs/node/commit/b76bfcd4fa)] - **deps**: upgrade npm to 11.16.0 (npm team) [#&#8203;63602](https://github.com/nodejs/node/pull/63602) - \[[`4ec142314c`](https://github.com/nodejs/node/commit/4ec142314c)] - **deps**: SQLite: cherry-pick [`b869ed6`](https://github.com/nodejs/node/commit/b869ed6b067d623cb1383549f2a18aa35508385d) (Junsu Han) [#&#8203;63525](https://github.com/nodejs/node/pull/63525) - \[[`19e8ce1c36`](https://github.com/nodejs/node/commit/19e8ce1c36)] - **deps**: upgrade npm to 11.15.0 (npm team) [#&#8203;63463](https://github.com/nodejs/node/pull/63463) - \[[`8a264260e2`](https://github.com/nodejs/node/commit/8a264260e2)] - **deps**: update sqlite to 3.53.1 (Node.js GitHub Bot) [#&#8203;63217](https://github.com/nodejs/node/pull/63217) - \[[`50c8ff3f94`](https://github.com/nodejs/node/commit/50c8ff3f94)] - **deps**: update simdjson to 4.6.4 (Node.js GitHub Bot) [#&#8203;62811](https://github.com/nodejs/node/pull/62811) - \[[`6e56f01c4b`](https://github.com/nodejs/node/commit/6e56f01c4b)] - **deps**: V8: cherry-pick [`435a2cd`](https://github.com/nodejs/node/commit/435a2cdf664c) (Matthias Liedtke) [#&#8203;63136](https://github.com/nodejs/node/pull/63136) - \[[`3ba813b242`](https://github.com/nodejs/node/commit/3ba813b242)] - **deps**: cherry-pick [libuv/libuv@`a43e543`](https://github.com/libuv/libuv/commit/a43e543) (Ali Hassan) [#&#8203;63222](https://github.com/nodejs/node/pull/63222) - \[[`2390e3a5ac`](https://github.com/nodejs/node/commit/2390e3a5ac)] - **doc**: remove duplicated sentences in large-pull-requests.md (Joyee Cheung) [#&#8203;63650](https://github.com/nodejs/node/pull/63650) - \[[`52a1c18374`](https://github.com/nodejs/node/commit/52a1c18374)] - **doc**: update `git node land` instructions for security releases (Antoine du Hamel) [#&#8203;63586](https://github.com/nodejs/node/pull/63586) - \[[`3e6b4da037`](https://github.com/nodejs/node/commit/3e6b4da037)] - **doc**: drop --experimental from --permission (Rafael Gonzaga) [#&#8203;63583](https://github.com/nodejs/node/pull/63583) - \[[`84d05163b9`](https://github.com/nodejs/node/commit/84d05163b9)] - **doc**: explicitly ask for reproducible in JS (Rafael Gonzaga) [#&#8203;63479](https://github.com/nodejs/node/pull/63479) - \[[`7da2a4450e`](https://github.com/nodejs/node/commit/7da2a4450e)] - **doc**: fix URL postMessage example in worker\_threads (Kit Dallege) [#&#8203;62203](https://github.com/nodejs/node/pull/62203) - \[[`3d79bd8b29`](https://github.com/nodejs/node/commit/3d79bd8b29)] - **doc**: clarify `filter` option of `sqlite.database.applyChangeset` (Antoine du Hamel) [#&#8203;63515](https://github.com/nodejs/node/pull/63515) - \[[`4f4174aace`](https://github.com/nodejs/node/commit/4f4174aace)] - **doc**: fix double spaces in ERR\_TLS\_INVALID\_PROTOCOL\_METHOD (Daijiro Wachi) [#&#8203;63511](https://github.com/nodejs/node/pull/63511) - \[[`388323ca4b`](https://github.com/nodejs/node/commit/388323ca4b)] - **doc**: fix double space in modules.md (Daijiro Wachi) [#&#8203;63512](https://github.com/nodejs/node/pull/63512) - \[[`5258ccc058`](https://github.com/nodejs/node/commit/5258ccc058)] - **doc**: fix "options" to "option" in tls.createServer (Daijiro Wachi) [#&#8203;63453](https://github.com/nodejs/node/pull/63453) - \[[`43e83e6507`](https://github.com/nodejs/node/commit/43e83e6507)] - **doc**: fix typo in deprecations (Daijiro Wachi) [#&#8203;63434](https://github.com/nodejs/node/pull/63434) - \[[`f05a61d54c`](https://github.com/nodejs/node/commit/f05a61d54c)] - **doc**: remove unsupported template type from v8.md (René) [#&#8203;63410](https://github.com/nodejs/node/pull/63410) - \[[`c39d5fc820`](https://github.com/nodejs/node/commit/c39d5fc820)] - **doc**: fix article usage before vowel-sound acronyms (joao-oliveira-softtor) [#&#8203;62696](https://github.com/nodejs/node/pull/62696) - \[[`398261f911`](https://github.com/nodejs/node/commit/398261f911)] - **doc**: remove the bi-monthly contributor spotlight section (Claudio Wunder) [#&#8203;62734](https://github.com/nodejs/node/pull/62734) - \[[`fd9e14c405`](https://github.com/nodejs/node/commit/fd9e14c405)] - **doc**: update http2's `push` and `trailers` events with `rawHeaders` param (YuSheng Chen) [#&#8203;63259](https://github.com/nodejs/node/pull/63259) - \[[`b943ce6933`](https://github.com/nodejs/node/commit/b943ce6933)] - **doc**: remove inactive members from Triagers list (Antoine du Hamel) [#&#8203;63329](https://github.com/nodejs/node/pull/63329) - \[[`4b9cdfc022`](https://github.com/nodejs/node/commit/4b9cdfc022)] - **doc**: reference correct function in Module docs (Robin Malfait) [#&#8203;63247](https://github.com/nodejs/node/pull/63247) - \[[`bed84b6df2`](https://github.com/nodejs/node/commit/bed84b6df2)] - **doc**: replace Visual Studio 2022 Evergreen version reference with 17.14 (Mike McCready) [#&#8203;63211](https://github.com/nodejs/node/pull/63211) - \[[`32ea70569b`](https://github.com/nodejs/node/commit/32ea70569b)] - **doc**: recommend explicitly Tier 1 or 2 for production applications (Mike McCready) [#&#8203;63187](https://github.com/nodejs/node/pull/63187) - \[[`4627bcfd82`](https://github.com/nodejs/node/commit/4627bcfd82)] - **doc**: run license-builder (github-actions\[bot]) [#&#8203;63232](https://github.com/nodejs/node/pull/63232) - \[[`28eba71845`](https://github.com/nodejs/node/commit/28eba71845)] - **doc**: add large pull requests contributing guide (Matteo Collina) [#&#8203;62829](https://github.com/nodejs/node/pull/62829) - \[[`2648efd438`](https://github.com/nodejs/node/commit/2648efd438)] - **doc**: remove unnecessary `<!-- eslint-` magic comments (Antoine du Hamel) [#&#8203;63200](https://github.com/nodejs/node/pull/63200) - \[[`a95fc1f8fc`](https://github.com/nodejs/node/commit/a95fc1f8fc)] - **doc**: clarify SEA platform support excludes darwin-x64 (MJSHANG) [#&#8203;63181](https://github.com/nodejs/node/pull/63181) - \[[`aaef29e2e1`](https://github.com/nodejs/node/commit/aaef29e2e1)] - **doc**: update release steps when post-release fails (Rafael Gonzaga) [#&#8203;63131](https://github.com/nodejs/node/pull/63131) - \[[`7d81419cf2`](https://github.com/nodejs/node/commit/7d81419cf2)] - **doc**: add Hmac.digest() documentation-only deprecation (DEP0206) (Anshika Jain) [#&#8203;63121](https://github.com/nodejs/node/pull/63121) - \[[`ececd80d81`](https://github.com/nodejs/node/commit/ececd80d81)] - **doc**: document the latest-vX.x schema (Marco Ippolito) [#&#8203;63033](https://github.com/nodejs/node/pull/63033) - \[[`27c1c1d842`](https://github.com/nodejs/node/commit/27c1c1d842)] - **doc**: remove list of versions in `BUILDING.md` (Antoine du Hamel) [#&#8203;63113](https://github.com/nodejs/node/pull/63113) - \[[`e369886a65`](https://github.com/nodejs/node/commit/e369886a65)] - **doc,sqlite**: document entryPoint argument for loadExtension (Edy Silva) [#&#8203;63152](https://github.com/nodejs/node/pull/63152) - \[[`e4e5137cbd`](https://github.com/nodejs/node/commit/e4e5137cbd)] - **errors**: handle V8 warnings in DisallowJavascriptExecutionScope (Divyanshu Sharma) [#&#8203;63491](https://github.com/nodejs/node/pull/63491) - \[[`6d1f6048d2`](https://github.com/nodejs/node/commit/6d1f6048d2)] - **fs**: make `Date` properties on `Stats` enumerable (LiviaMedeiros) [#&#8203;63328](https://github.com/nodejs/node/pull/63328) - \[[`44c8ebcbd6`](https://github.com/nodejs/node/commit/44c8ebcbd6)] - **http**: avoid stream listeners on idle agent sockets (Matteo Collina) [#&#8203;64004](https://github.com/nodejs/node/pull/64004) - \[[`4c9251fc09`](https://github.com/nodejs/node/commit/4c9251fc09)] - **(SEMVER-MINOR)** **http**: add writeInformation to send arbitrary 1xx status codes (Tim Perry) [#&#8203;63155](https://github.com/nodejs/node/pull/63155) - \[[`39f61fb06c`](https://github.com/nodejs/node/commit/39f61fb06c)] - **http2**: emit session close before stream close (Matteo Collina) [#&#8203;63414](https://github.com/nodejs/node/pull/63414) - \[[`8a8f2127d1`](https://github.com/nodejs/node/commit/8a8f2127d1)] - **http2**: validate non-link headers in writeEarlyHints (Matteo Collina) [#&#8203;62017](https://github.com/nodejs/node/pull/62017) - \[[`8c989ec4a3`](https://github.com/nodejs/node/commit/8c989ec4a3)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#&#8203;63079](https://github.com/nodejs/node/pull/63079) - \[[`c05f38229b`](https://github.com/nodejs/node/commit/c05f38229b)] - **lib**: cleanup stateless diffiehellman key handling (Filip Skokan) [#&#8203;62645](https://github.com/nodejs/node/pull/62645) - \[[`1c16b45d35`](https://github.com/nodejs/node/commit/1c16b45d35)] - **lib**: refactor internal webidl converters (Filip Skokan) [#&#8203;62979](https://github.com/nodejs/node/pull/62979) - \[[`02f35d6dce`](https://github.com/nodejs/node/commit/02f35d6dce)] - **lib**: define `kEnumerableProperty` atomically (Antoine du Hamel) [#&#8203;63609](https://github.com/nodejs/node/pull/63609) - \[[`12c51547ba`](https://github.com/nodejs/node/commit/12c51547ba)] - **lib**: fix typos in esm loader comments (RonGamzu) [#&#8203;63465](https://github.com/nodejs/node/pull/63465) - \[[`9b03b84262`](https://github.com/nodejs/node/commit/9b03b84262)] - **lib**: fix typo idenity => identity (Daijiro Wachi) [#&#8203;63112](https://github.com/nodejs/node/pull/63112) - \[[`a84e6b0567`](https://github.com/nodejs/node/commit/a84e6b0567)] - **lib**: fixes validator message (Daijiro Wachi) [#&#8203;62823](https://github.com/nodejs/node/pull/62823) - \[[`11734166a8`](https://github.com/nodejs/node/commit/11734166a8)] - **lib**: narrow ReadableStreamBYOBRequest.view return type to Uint8Array (RoomWithOutRoof) [#&#8203;63017](https://github.com/nodejs/node/pull/63017) - \[[`7cead61d21`](https://github.com/nodejs/node/commit/7cead61d21)] - **meta**: flip mcollina emails in .mailmap (Matteo Collina) [#&#8203;63621](https://github.com/nodejs/node/pull/63621) - \[[`a08cfcfd35`](https://github.com/nodejs/node/commit/a08cfcfd35)] - **meta**: label "source maps" PRs (Chengzhong Wu) [#&#8203;63591](https://github.com/nodejs/node/pull/63591) - \[[`d56e8d2512`](https://github.com/nodejs/node/commit/d56e8d2512)] - **meta**: add `vfs` subsystem label (René) [#&#8203;62331](https://github.com/nodejs/node/pull/62331) - \[[`6201cfe488`](https://github.com/nodejs/node/commit/6201cfe488)] - **meta**: skip scheduled workflows on forks (Jamie Magee) [#&#8203;63565](https://github.com/nodejs/node/pull/63565) - \[[`f095e2bd31`](https://github.com/nodejs/node/commit/f095e2bd31)] - **meta**: add additional gitignore entries (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`1ea52c444c`](https://github.com/nodejs/node/commit/1ea52c444c)] - **meta**: move one or more collaborators to emeritus (Node.js GitHub Bot) [#&#8203;63402](https://github.com/nodejs/node/pull/63402) - \[[`b1b2327611`](https://github.com/nodejs/node/commit/b1b2327611)] - **meta**: move one or more collaborators to emeritus (Node.js GitHub Bot) [#&#8203;63235](https://github.com/nodejs/node/pull/63235) - \[[`7d88e130a9`](https://github.com/nodejs/node/commit/7d88e130a9)] - **meta**: ignore AI assistants files (Matteo Collina) [#&#8203;62612](https://github.com/nodejs/node/pull/62612) - \[[`a53b51df38`](https://github.com/nodejs/node/commit/a53b51df38)] - **module**: load ESM helpers eagerly in the snapshot (Joyee Cheung) [#&#8203;63550](https://github.com/nodejs/node/pull/63550) - \[[`69df688fff`](https://github.com/nodejs/node/commit/69df688fff)] - **module**: fix sync hook short-circuit in require() in imported CJS (Joyee Cheung) [#&#8203;62920](https://github.com/nodejs/node/pull/62920) - \[[`75d9a4ed47`](https://github.com/nodejs/node/commit/75d9a4ed47)] - **node-api**: support SharedArrayBuffer in napi\_create\_typedarray (Yilong Li) [#&#8203;62710](https://github.com/nodejs/node/pull/62710) - \[[`c20aa4c47b`](https://github.com/nodejs/node/commit/c20aa4c47b)] - **quic**: add reusePort option to QuicEndpoint (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`26a30d8a7f`](https://github.com/nodejs/node/commit/26a30d8a7f)] - **quic**: implement rate limiting for version nego and immediate close (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`0b534b5770`](https://github.com/nodejs/node/commit/0b534b5770)] - **quic**: fixup linting issue after other changes (James M Snell) [#&#8203;63267](https://github.com/nodejs/node/pull/63267) - \[[`4b367cbe09`](https://github.com/nodejs/node/commit/4b367cbe09)] - **quic**: remove unused binding variable in session.cc (James M Snell) [#&#8203;63177](https://github.com/nodejs/node/pull/63177) - \[[`2574bef5a6`](https://github.com/nodejs/node/commit/2574bef5a6)] - **repl**: fix dedup comparing normalized line against raw history (Daijiro Wachi) [#&#8203;62886](https://github.com/nodejs/node/pull/62886) - \[[`30e71c7e49`](https://github.com/nodejs/node/commit/30e71c7e49)] - **sqlite**: keep source database alive during backup (Matteo Collina) [#&#8203;62673](https://github.com/nodejs/node/pull/62673) - \[[`677ca7e76c`](https://github.com/nodejs/node/commit/677ca7e76c)] - **src**: simplify OpenSSL feature gates (Filip Skokan) [#&#8203;63255](https://github.com/nodejs/node/pull/63255) - \[[`c863c75c39`](https://github.com/nodejs/node/commit/c863c75c39)] - **src**: add BoringSSL EVP enumeration fallback (Filip Skokan) [#&#8203;63206](https://github.com/nodejs/node/pull/63206) - \[[`f6b2466921`](https://github.com/nodejs/node/commit/f6b2466921)] - **src**: decouple KeyObject and CryptoKey and move CryptoKey to src (Filip Skokan) [#&#8203;62924](https://github.com/nodejs/node/pull/62924) - \[[`92d4f07dd2`](https://github.com/nodejs/node/commit/92d4f07dd2)] - **src**: remove license headers for new node\_profiling files (Chengzhong Wu) [#&#8203;63066](https://github.com/nodejs/node/pull/63066) - \[[`8ac5d771c8`](https://github.com/nodejs/node/commit/8ac5d771c8)] - **src**: split profiling helpers from util (Ilyas Shabi) [#&#8203;63008](https://github.com/nodejs/node/pull/63008) - \[[`85d1639495`](https://github.com/nodejs/node/commit/85d1639495)] - **src**: remove TOCTOU race condition when encoding SAB-backed `Buffer`s (Antoine du Hamel) [#&#8203;63517](https://github.com/nodejs/node/pull/63517) - \[[`9473c5f05c`](https://github.com/nodejs/node/commit/9473c5f05c)] - **src**: skip duplicate UTF-8 validation in TextDecoder fatal path (Mert Can Altin) [#&#8203;63231](https://github.com/nodejs/node/pull/63231) - \[[`f35c91ee68`](https://github.com/nodejs/node/commit/f35c91ee68)] - **src**: improve token return value check (James M Snell) [#&#8203;63483](https://github.com/nodejs/node/pull/63483) - \[[`26f677c1c5`](https://github.com/nodejs/node/commit/26f677c1c5)] - **src**: expose `node::RegisterContext` to make a node managed context (Chengzhong Wu) [#&#8203;62322](https://github.com/nodejs/node/pull/62322) - \[[`275cf909b6`](https://github.com/nodejs/node/commit/275cf909b6)] - **src,sqlite**: only pass `xFilter` when user provided a callback (Antoine du Hamel) [#&#8203;63516](https://github.com/nodejs/node/pull/63516) - \[[`287e02303f`](https://github.com/nodejs/node/commit/287e02303f)] - **src,sqlite**: remove dead code (Edy Silva) [#&#8203;63204](https://github.com/nodejs/node/pull/63204) - \[[`58fa2ee189`](https://github.com/nodejs/node/commit/58fa2ee189)] - **stream**: switch to internal `sleep` binding (Antoine du Hamel) [#&#8203;63611](https://github.com/nodejs/node/pull/63611) - \[[`f954ab3f1a`](https://github.com/nodejs/node/commit/f954ab3f1a)] - **stream**: use data listener for compose forwarding (Trivikram Kamat) [#&#8203;63593](https://github.com/nodejs/node/pull/63593) - \[[`dc57173003`](https://github.com/nodejs/node/commit/dc57173003)] - **stream**: fix Writable.toWeb() hang on synchronous drain (sangwook) [#&#8203;61197](https://github.com/nodejs/node/pull/61197) - \[[`3f54c8ba32`](https://github.com/nodejs/node/commit/3f54c8ba32)] - ***Revert*** "**stream**: noop pause/resume on destroyed streams" (Stewart X Addison) [#&#8203;63834](https://github.com/nodejs/node/pull/63834) - \[[`cee279c5d6`](https://github.com/nodejs/node/commit/cee279c5d6)] - **stream**: remove unnecessary check (Antoine du Hamel) [#&#8203;63030](https://github.com/nodejs/node/pull/63030) - \[[`61b20f60a3`](https://github.com/nodejs/node/commit/61b20f60a3)] - **test**: update tls/crypto behaviour expectations when using BoringSSL (Filip Skokan) [#&#8203;63161](https://github.com/nodejs/node/pull/63161) - \[[`a835363808`](https://github.com/nodejs/node/commit/a835363808)] - **test**: update WPT for WebCryptoAPI to [`97bbc72`](https://github.com/nodejs/node/commit/97bbc7247a) (Node.js GitHub Bot) [#&#8203;63417](https://github.com/nodejs/node/pull/63417) - \[[`a00297480b`](https://github.com/nodejs/node/commit/a00297480b)] - **test**: update WPT resources, interfaces and WebCryptoAPI (Node.js GitHub Bot) [#&#8203;62389](https://github.com/nodejs/node/pull/62389) - \[[`5a95a2b055`](https://github.com/nodejs/node/commit/5a95a2b055)] - **test**: shorten path in net pipe connect errors (Matteo Collina) [#&#8203;63405](https://github.com/nodejs/node/pull/63405) - \[[`5e8ff22d8f`](https://github.com/nodejs/node/commit/5e8ff22d8f)] - **test**: remove test-node-output-v8-warning (Joyee Cheung) [#&#8203;63469](https://github.com/nodejs/node/pull/63469) - \[[`ee15380950`](https://github.com/nodejs/node/commit/ee15380950)] - **test**: update test426-fixtures to [`9b9e225`](https://github.com/nodejs/node/commit/9b9e225b5a63139e9a95cdd1bf874a8f0b9d131) (Node.js GitHub Bot) [#&#8203;63373](https://github.com/nodejs/node/pull/63373) - \[[`9e063d9bea`](https://github.com/nodejs/node/commit/9e063d9bea)] - **test**: update WPT for url to [`e4a4672`](https://github.com/nodejs/node/commit/e4a4672e9e) (Node.js GitHub Bot) [#&#8203;63372](https://github.com/nodejs/node/pull/63372) - \[[`503bee4b43`](https://github.com/nodejs/node/commit/503bee4b43)] - **test**: deflake async-hooks statwatcher test (Trivikram Kamat) [#&#8203;63396](https://github.com/nodejs/node/pull/63396) - \[[`cccc7c32d8`](https://github.com/nodejs/node/commit/cccc7c32d8)] - **test**: avoid test\_runner watch restart in spec snapshot (Trivikram Kamat) [#&#8203;63392](https://github.com/nodejs/node/pull/63392) - \[[`c89489258c`](https://github.com/nodejs/node/commit/c89489258c)] - **test**: reduce watch mode restart flakiness (Trivikram Kamat) [#&#8203;63390](https://github.com/nodejs/node/pull/63390) - \[[`e4d5e2578e`](https://github.com/nodejs/node/commit/e4d5e2578e)] - **test**: isolate rerun-failures state file under tmpdir (Chemi Atlow) [#&#8203;63449](https://github.com/nodejs/node/pull/63449) - \[[`362644a9ba`](https://github.com/nodejs/node/commit/362644a9ba)] - **test**: wait for ok before initial break after restart (Yuya Inoue) [#&#8203;62807](https://github.com/nodejs/node/pull/62807) - \[[`c4058d0e05`](https://github.com/nodejs/node/commit/c4058d0e05)] - **test**: disable Maglev in near-heap-limit worker test (Trivikram Kamat) [#&#8203;63398](https://github.com/nodejs/node/pull/63398) - \[[`214da630a7`](https://github.com/nodejs/node/commit/214da630a7)] - **test**: deflake connection refused proxy tests (Trivikram Kamat) [#&#8203;63395](https://github.com/nodejs/node/pull/63395) - \[[`1d61a29876`](https://github.com/nodejs/node/commit/1d61a29876)] - **test**: avoid repeated writes in watch helper (Trivikram Kamat) [#&#8203;63386](https://github.com/nodejs/node/pull/63386) - \[[`2004e25387`](https://github.com/nodejs/node/commit/2004e25387)] - **test**: deflake watch mode worker test (Trivikram Kamat) [#&#8203;63384](https://github.com/nodejs/node/pull/63384) - \[[`d691cccfc1`](https://github.com/nodejs/node/commit/d691cccfc1)] - **test**: relax test-memory-usage arrayBuffers check (inoway46) [#&#8203;63244](https://github.com/nodejs/node/pull/63244) - \[[`0ff6bf853c`](https://github.com/nodejs/node/commit/0ff6bf853c)] - **test**: reduce flakiness of `different-registry-per-thread` (Antoine du Hamel) [#&#8203;63244](https://github.com/nodejs/node/pull/63244) - \[[`d9f4e8e503`](https://github.com/nodejs/node/commit/d9f4e8e503)] - **test**: fix flaky test-watch-mode-inspect timeout (Matteo Collina) [#&#8203;63361](https://github.com/nodejs/node/pull/63361) - \[[`6d7cd50328`](https://github.com/nodejs/node/commit/6d7cd50328)] - **test**: relax min assertion in test-performance-eventloopdelay (Marco) [#&#8203;63100](https://github.com/nodejs/node/pull/63100) - \[[`9dafe1d2d8`](https://github.com/nodejs/node/commit/9dafe1d2d8)] - **test**: avoid flaky restart sync in debugger exceptions test (Yuya Inoue) [#&#8203;62055](https://github.com/nodejs/node/pull/62055) - \[[`989b2de973`](https://github.com/nodejs/node/commit/989b2de973)] - **test**: avoid initial-break wait in restart-message (inoway46) [#&#8203;62060](https://github.com/nodejs/node/pull/62060) - \[[`a072a25ee7`](https://github.com/nodejs/node/commit/a072a25ee7)] - **test**: move FFI tests to `NATIVE_SUITES` (Antoine du Hamel) [#&#8203;63165](https://github.com/nodejs/node/pull/63165) - \[[`64efbfd878`](https://github.com/nodejs/node/commit/64efbfd878)] - **test**: use ERM to destroy sqlite database handles after tests (René) [#&#8203;63076](https://github.com/nodejs/node/pull/63076) - \[[`7dee66cd94`](https://github.com/nodejs/node/commit/7dee66cd94)] - **test\_runner**: dont buffer unordered events in process isolation mode (Moshe Atlow) [#&#8203;63432](https://github.com/nodejs/node/pull/63432) - \[[`d257eec1e3`](https://github.com/nodejs/node/commit/d257eec1e3)] - **test\_runner**: fix --test-rerun-failures swallowing failures on retry (Chemi Atlow) [#&#8203;63431](https://github.com/nodejs/node/pull/63431) - \[[`288c320e2f`](https://github.com/nodejs/node/commit/288c320e2f)] - **test\_runner**: show replayed-from-attempt hint in spec reporter (Moshe Atlow) [#&#8203;63429](https://github.com/nodejs/node/pull/63429) - \[[`904bdf5bb4`](https://github.com/nodejs/node/commit/904bdf5bb4)] - **test\_runner**: preserve run duration when using test-rerun (Moshe Atlow) [#&#8203;63429](https://github.com/nodejs/node/pull/63429) - \[[`df183d7bfa`](https://github.com/nodejs/node/commit/df183d7bfa)] - **test\_runner**: avoid hanging on incomplete v8 frames (Ali Hassan) [#&#8203;62704](https://github.com/nodejs/node/pull/62704) - \[[`ec86c69726`](https://github.com/nodejs/node/commit/ec86c69726)] - **test\_runner**: fix diagnostics channel context tracking (Moshe Atlow) [#&#8203;63283](https://github.com/nodejs/node/pull/63283) - \[[`94e5f63b83`](https://github.com/nodejs/node/commit/94e5f63b83)] - **tls**: add unsupported renegotiation error (Filip Skokan) [#&#8203;63161](https://github.com/nodejs/node/pull/63161) - \[[`06d308fb61`](https://github.com/nodejs/node/commit/06d308fb61)] - **tools**: prevent lib code from reading KeyObject and CryptoKey accessors (Filip Skokan) [#&#8203;63111](https://github.com/nodejs/node/pull/63111) - \[[`2e4a0d0c91`](https://github.com/nodejs/node/commit/2e4a0d0c91)] - **tools**: bump brace-expansion from 5.0.5 to 5.0.6 in /tools/eslint (dependabot\[bot]) [#&#8203;63415](https://github.com/nodejs/node/pull/63415) - \[[`4c9666b366`](https://github.com/nodejs/node/commit/4c9666b366)] - **tools**: skip commit-lint on backport pull requests (Marco) [#&#8203;63378](https://github.com/nodejs/node/pull/63378) - \[[`67d0c490a8`](https://github.com/nodejs/node/commit/67d0c490a8)] - **tools**: fix skip of `test-internet` on forks (Antoine du Hamel) [#&#8203;63492](https://github.com/nodejs/node/pull/63492) - \[[`02f73c7cac`](https://github.com/nodejs/node/commit/02f73c7cac)] - **tools**: bump the eslint group in /tools/eslint with 4 updates (dependabot\[bot]) [#&#8203;63075](https://github.com/nodejs/node/pull/63075) - \[[`5d016d3241`](https://github.com/nodejs/node/commit/5d016d3241)] - **tools**: update gyp-next to 0.22.2 (Node.js GitHub Bot) [#&#8203;63374](https://github.com/nodejs/node/pull/63374) - \[[`55af0f0edb`](https://github.com/nodejs/node/commit/55af0f0edb)] - **tools**: fix test426 updater (Antoine du Hamel) [#&#8203;63271](https://github.com/nodejs/node/pull/63271) - \[[`d8475e167a`](https://github.com/nodejs/node/commit/d8475e167a)] - **tools**: use different branch for tool updates on staging branches (Antoine du Hamel) [#&#8203;63110](https://github.com/nodejs/node/pull/63110) - \[[`c605df9e50`](https://github.com/nodejs/node/commit/c605df9e50)] - **util**: remove unused functions (Antoine du Hamel) [#&#8203;63612](https://github.com/nodejs/node/pull/63612) - \[[`fe4540ebdb`](https://github.com/nodejs/node/commit/fe4540ebdb)] - **util**: create hex style cache and fast path (Guilherme Araújo) [#&#8203;62999](https://github.com/nodejs/node/pull/62999) ### [`v24.17.0`](https://github.com/nodejs/node/releases/tag/v24.17.0): 2026-06-18, Version 24.17.0 'Krypton' (LTS), @&#8203;aduh95 [Compare Source](https://github.com/nodejs/node/compare/v24.16.0...v24.17.0) This is a security release. ##### Notable Changes - (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High - (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High - (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium - (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium - (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium - (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium - (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium - (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 – Medium - (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low - (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low - (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low ##### Commits - \[[`9e4dfc7bba`](https://github.com/nodejs/node/commit/9e4dfc7bba)] - **(CVE-2026-48933)** **crypto**: guard WebCrypto cipher output length (Filip Skokan) [nodejs-private/node-private#878](https://github.com/nodejs-private/node-private/pull/878) - \[[`cb2aed980c`](https://github.com/nodejs/node/commit/cb2aed980c)] - **deps**: update llhttp to 9.4.2 (Antoine du Hamel) [nodejs-private/node-private#890](https://github.com/nodejs-private/node-private/pull/890) - \[[`a8a0d12875`](https://github.com/nodejs/node/commit/a8a0d12875)] - **(CVE-2026-48937)** **deps**: fix integration issues with the latest nghttp2 (Tim Perry) [#&#8203;62891](https://github.com/nodejs/node/pull/62891) - \[[`66e6203c1c`](https://github.com/nodejs/node/commit/66e6203c1c)] - **(SEMVER-MAJOR)** **deps**: update nghttp2 to 1.69.0 (Node.js GitHub Bot) [#&#8203;62891](https://github.com/nodejs/node/pull/62891) - \[[`dd627ced27`](https://github.com/nodejs/node/commit/dd627ced27)] - **deps**: update archs files for openssl-3.5.7 (Node.js GitHub Bot) [#&#8203;63820](https://github.com/nodejs/node/pull/63820) - \[[`684bae568f`](https://github.com/nodejs/node/commit/684bae568f)] - **deps**: upgrade openssl sources to openssl-3.5.7 (Node.js GitHub Bot) [#&#8203;63820](https://github.com/nodejs/node/pull/63820) - \[[`3a631e7f83`](https://github.com/nodejs/node/commit/3a631e7f83)] - **deps**: fix aix implicit declaration in OpenSSL (Abdirahim Musse) [#&#8203;62656](https://github.com/nodejs/node/pull/62656) - \[[`cf44df3996`](https://github.com/nodejs/node/commit/cf44df3996)] - **deps**: update undici to 7.28.0 (Node.js GitHub Bot) [#&#8203;63703](https://github.com/nodejs/node/pull/63703) - \[[`138c70294b`](https://github.com/nodejs/node/commit/138c70294b)] - **(CVE-2026-48930)** **dns,net**: reject hostnames with embedded NUL bytes (Matteo Collina) [nodejs-private/node-private#868](https://github.com/nodejs-private/node-private/pull/868) - \[[`be7e719c3f`](https://github.com/nodejs/node/commit/be7e719c3f)] - **(CVE-2026-48931)** **http**: fix response queue poisoning in http.Agent (Matteo Collina) [nodejs-private/node-private#846](https://github.com/nodejs-private/node-private/pull/846) - \[[`cc7c11b4d1`](https://github.com/nodejs/node/commit/cc7c11b4d1)] - **(CVE-2026-48619)** **http2**: cap originSet size to prevent unbounded memory growth (Matteo Collina) [nodejs-private/node-private#855](https://github.com/nodejs-private/node-private/pull/855) - \[[`9224427b92`](https://github.com/nodejs/node/commit/9224427b92)] - **(CVE-2026-48615)** **lib,test**: redact proxy credentials in tunnel errors (Matteo Collina) [nodejs-private/node-private#867](https://github.com/nodejs-private/node-private/pull/867) - \[[`cf85d54839`](https://github.com/nodejs/node/commit/cf85d54839)] - **(CVE-2026-48935)** **permission**: disable FileHandle utimes with permission model (RafaelGSS) [nodejs-private/node-private#873](https://github.com/nodejs-private/node-private/pull/873) - \[[`a1bbc24f96`](https://github.com/nodejs/node/commit/a1bbc24f96)] - **(CVE-2026-48617)** **permission**: handle process.chdir on writereport (RafaelGSS) [nodejs-private/node-private#870](https://github.com/nodejs-private/node-private/pull/870) - \[[`e3723ff2d6`](https://github.com/nodejs/node/commit/e3723ff2d6)] - **test**: add session reuse host verification regressions (Matteo Collina) [nodejs-private/node-private#854](https://github.com/nodejs-private/node-private/pull/854) - \[[`a77af4867b`](https://github.com/nodejs/node/commit/a77af4867b)] - **(CVE-2026-48934)** **tls**: bind reusable sessions to authenticated host (Matteo Collina) [nodejs-private/node-private#854](https://github.com/nodejs-private/node-private/pull/854) - \[[`31beb4f707`](https://github.com/nodejs/node/commit/31beb4f707)] - **(CVE-2026-48928)** **tls**: fix case-sensitive SNI context matching (Matteo Collina) [nodejs-private/node-private#857](https://github.com/nodejs-private/node-private/pull/857) - \[[`8e75c73f91`](https://github.com/nodejs/node/commit/8e75c73f91)] - **(CVE-2026-48618)** **tls**: normalize hostname for server identity checks (Matteo Collina) [nodejs-private/node-private#869](https://github.com/nodejs-private/node-private/pull/869) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
renovate changed title from chore(deps): update node.js to v24.18.1 to Update Node.js to v24.18.1 2026-08-03 15:00:35 +02:00
renovate force-pushed renovate/node-24.x from 9b8b0e601d to 1306f9b3c0 2026-08-03 18:00:34 +02:00 Compare
renovate changed title from Update Node.js to v24.18.1 to Update Node.js to v24.19.0 2026-08-03 18:00:36 +02:00
renovate force-pushed renovate/node-24.x from 1306f9b3c0 to 748b8404bf 2026-08-26 18:01:25 +02:00 Compare
renovate changed title from Update Node.js to v24.19.0 to Update Node.js to v24.20.0 2026-08-26 18:01:30 +02:00
renovate changed title from Update Node.js to v24.20.0 to chore(deps): update node.js to v24.20.0 2026-09-05 15:01:34 +02:00
renovate changed title from chore(deps): update node.js to v24.20.0 to Update Node.js to v24.20.0 2026-09-07 12:00:50 +02:00
renovate force-pushed renovate/node-24.x from 748b8404bf to f6fc957c03 2026-09-09 06:00:45 +02:00 Compare
renovate changed title from Update Node.js to v24.20.0 to Update Node.js to v24.21.0 2026-09-09 06:00:48 +02:00
renovate changed title from Update Node.js to v24.21.0 to chore(deps): update node.js to v24.21.0 2026-09-12 00:00:53 +02:00
This pull request can be merged automatically.
This branch is out-of-date with the base branch
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/node-24.x:renovate/node-24.x
git switch renovate/node-24.x
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
inhji/hajur!223
No description provided.