Skip to content

chore(dockerfile): upgrade node version - #9284

Merged
updateclibot[bot] merged 2 commits into
mainfrom
updatecli_main_node_version
Jun 29, 2026
Merged

chore(dockerfile): upgrade node version#9284
updateclibot[bot] merged 2 commits into
mainfrom
updatecli_main_node_version

Conversation

@updateclibot

@updateclibot updateclibot Bot commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

chore(node): upgrade node version

deps: update pnpm version to 11.9.0"

change detected: * key "$.jobs.*.steps[?(@.uses =~ /^pnpm\\/action-setup/)].with.version" updated from "11.5.0" to "11.9.0", in file ".github/workflows/go.yaml" (doc 0)

v11.9.0
## Minor Changes

- bae694f: Some registries generate tarballs on-demand and cannot provide an integrity checksum in their package metadata. In that case pnpm now computes the integrity from the downloaded tarball and stores it in the lockfile, so the entry is verifiable on subsequent installs instead of being written without an integrity (which would fail the next install). This also applies to `--lockfile-only`: the tarball is downloaded so its integrity can be computed. A lockfile entry that is still missing its integrity is rejected as a `ERR_PNPM_MISSING_TARBALL_INTEGRITY` lockfile verification violation (the install fails closed) rather than being silently re-fetched.
- 6c35a43: Added `--exclude-peers` to `pnpm sbom`. With `auto-install-peers` (the default), peer dependencies resolve into the lockfile and are otherwise indistinguishable from the package's own dependencies. The flag drops peer dependencies (and any transitive subtree reachable only through them) from the SBOM. CycloneDX 1.7 has no scope or relationship that expresses "consumer-provided peer", so omission is the only spec-clean handling. The flag name matches `pnpm list --exclude-peers`; note the SBOM flag prunes a peer's exclusive subtree, which is stricter than `pnpm list` (which only hides leaf peers).

## Patch Changes

- 25a829e: `pnpm audit --fix` now writes a single combined `minimumReleaseAgeExclude` entry per package (e.g. `axios@0.18.1 || 0.21.1`) instead of one entry per version, matching the format documented for the setting. Existing per-version entries in `pnpm-workspace.yaml` are merged into the combined form rather than left as duplicates. Installs that auto-collect immature versions into `minimumReleaseAgeExclude` now report the same combined entries, so the "Added N entries" message matches what is written to the manifest [#12534](https://github.com/pnpm/pnpm/issues/12534).
- 1cbb5f2: Fixed non-deterministic peer resolution that could add or remove an optional transitive peer — for example `@babel/core`, reached through `styled-jsx` — from a package's peer-dependency suffix across otherwise identical installs, churning the lockfile and causing intermittent `pnpm dedupe --check` failures in CI. When a package's children are resolved by one occurrence (the "owner") and reused by a deeper consumer, whether that consumer inherited the owner's missing peers depended on whether the owner's resolution had finished yet — a race under concurrent resolution. The decision is now a function of the dependency graph's structure rather than resolution-completion order.
- d577eea: Fixed a Windows flakiness in `pnpm dlx` where a failed install could surface a spurious `EBUSY: resource busy or locked` error. The cleanup of a partially-populated dlx cache is now best-effort with retries and no longer masks the original error.
- ec7cf70: Shortened the `pnpm dlx` cache path so deep dependency trees no longer overflow Windows' `MAX_PATH`, which could make a dependency's lifecycle script fail with `spawn cmd.exe ENOENT`.
- 05b95ab: Fixed `pnpm` hanging (and crashing with an unhandled promise rejection) when a non-retryable network error such as `SELF_SIGNED_CERT_IN_CHAIN` occurs while fetching from a registry. The error is now rejected through the returned promise instead of being thrown inside the detached retry callback.
- d3f68e2: Fix a `pnpm audit` performance regression on lockfiles that contain dependency cycles. The reachable-vulnerability pruning added in pnpm 11.5.1 only memoized acyclic subtrees, so any node whose subtree touched a cycle — together with all of its ancestors — was recomputed on every query, making the path walk quadratic. Reachability is now computed once per node using Tarjan's strongly-connected-components algorithm, so cyclic graphs are handled in linear time [#12212](https://github.com/pnpm/pnpm/issues/12212).

  The audit path walk also no longer recurses, so a deeply nested dependency graph can no longer overflow the call stack, and the install path to each finding is tracked without per-node copying, keeping memory linear in the graph depth.

- 322f88f: Fix failed optional dependency updates so they don't rewrite unrelated dependency specs [#11267](https://github.com/pnpm/pnpm/issues/11267).
- 1488db1: When `enableGlobalVirtualStore` is toggled on for a project that was previously installed without it, stale hoisted symlinks under `node_modules/.pnpm/node_modules` are now replaced instead of being left pointing at the old per-project virtual store location [#9739](https://github.com/pnpm/pnpm/issues/9739).
- 6545793: Fixed `pnpm install --ignore-workspace` overwriting the `allowBuilds` map in `pnpm-workspace.yaml`. The ignored builds of a package with a build script were auto-populated into `allowBuilds` even though `--ignore-workspace` was passed, clobbering committed `true`/`false` values with the `set this to true or false` placeholder [#12469](https://github.com/pnpm/pnpm/issues/12469).
- fbdc0eb: Fixed `minimumReleaseAgeExclude` and `trustPolicyExclude` so multiple exact-version entries for the same package behave the same as a single `||` disjunction entry. Previously only the first matching rule's versions were honored, so a config like `[form-data@4.0.6, form-data@2.5.6]` could still flag `form-data@2.5.6` as violating `minimumReleaseAge`, while `[form-data@4.0.6 || 2.5.6]` worked as expected [#12463](https://github.com/pnpm/pnpm/issues/12463).
- fa7004b: The in-memory package metadata cache is now populated on the exact-version disk fast path, so repeated resolutions of the same package within one install no longer re-read and re-parse the on-disk metadata. In large monorepos this brings the time for adding a new package down from minutes to seconds. The in-memory cache key now also includes the registry, so a package of the same name served by two different registries in a single install can no longer share a cache slot and resolve the wrong tarball.
- 0a154b1: Fixed `pnpm patch` dropping the package name (and leaking internal option fields) when the patched dependency resolves to a single git-hosted version.
- 4d3fe4b: The pnpr resolver endpoints moved under the reserved `/-/pnpr` namespace: `POST /v1/resolve` is now `POST /-/pnpr/v0/resolve` and `POST /v1/verify-lockfile` is now `POST /-/pnpr/v0/verify-lockfile`. The capability handshake at `GET /-/pnpr` advertises protocol version `0` to match. This keeps every pnpr-proprietary route in npm's reserved namespace, so it can never collide with a package path.
- 0ec878d: Removing a runtime dependency now removes the matching `devEngines.runtime` or `engines.runtime` entry that was materialized from it. Blank runtime selectors are normalized to `latest`.
- 17e7f2c: `pnpm sbom` now emits a CycloneDX `issue-tracker` external reference for components (and the root) whose `package.json` declares a `bugs` URL. Email-only `bugs` entries are skipped, since the reference requires a URL.
- a84d2a1: Add `@pnpm/resolving.tarball-url`, which builds and recognizes the canonical npm tarball URL of a package. It vendors `getNpmTarballUrl` (previously the external `get-npm-tarball-url` package) and adds `isCanonicalRegistryTarballUrl`, the predicate the lockfile writer uses to decide whether a tarball URL is derivable from name+version+registry (and can therefore be omitted from `pnpm-lock.yaml`).

  Exposing `isCanonicalRegistryTarballUrl` lets a custom resolver (pnpmfile `resolvers`) fronting a proxy that serves tarballs on a non-canonical path (e.g. an ephemeral `localhost:<port>`) rewrite the resolved tarball to the canonical form, so nothing host-specific is persisted to the lockfile. Previously this logic was private to `@pnpm/lockfile.utils`.

  Two correctness fixes are included while consolidating the logic: the scoped-package unescape now handles uppercase `%2F` as well as `%2f` (percent-encoding is case-insensitive), and protocol-insensitive comparison strips only a leading `http(s)://` scheme instead of splitting on the first `://` (which could truncate URLs containing a later `://`).

- 852d537: Lockfile verification no longer reports a registry metadata fetch failure (for example a `403`/`401` on a private registry, or a network error) as `ERR_PNPM_TARBALL_URL_MISMATCH`. When the registry can't be reached to verify an entry, the install now aborts with the registry's own fetch error (such as `ERR_PNPM_FETCH_403`, which already explains the authentication situation) instead of mislabeling a transport failure as lockfile tampering. Registry fetch errors no longer leak basic-auth credentials embedded in the registry URL (`https://user:pass@host/`) into their message.


<!-- sponsors -->

## Platinum Sponsors

<table>
  <tbody>
    <tr>
      <td align="center" valign="middle">
        <a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a>
      </td>
    </tr>
    <tr>
      <td align="center" valign="middle">
        <a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer">
          <picture>
            <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/openai_dark.svg" />
            <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/openai_light.svg" />
            <img src="https://pnpm.io/img/users/openai_dark.svg" width="160" alt="OpenAI" />
          </picture>
        </a>
      </td>
    </tr>
  </tbody>
</table>

## Gold Sponsors

<table>
  <tbody>
    <tr>
      <td align="center" valign="middle">
        <a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer">
          <picture>
            <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/sanity.svg" />
            <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/sanity_light.svg" />
            <img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity" />
          </picture>
        </a>
      </td>
      <td align="center" valign="middle">
        <a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer">
          <picture>
            <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/discord.svg" />
            <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/discord_light.svg" />
            <img src="https://pnpm.io/img/users/discord.svg" width="220" alt="Discord" />
          </picture>
        </a>
      </td>
      <td align="center" valign="middle">
        <a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a>
      </td>
    </tr>
    <tr>
      <td align="center" valign="middle">
        <a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer">
          <picture>
            <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/serpapi_dark.svg" />
            <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/serpapi_light.svg" />
            <img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160" alt="SerpApi" />
          </picture>
        </a>
      </td>
      <td align="center" valign="middle">
        <a href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer">
          <picture>
            <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/coderabbit.svg" />
            <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/coderabbit_light.svg" />
            <img src="https://pnpm.io/img/users/coderabbit.svg" width="220" alt="CodeRabbit" />
          </picture>
        </a>
      </td>
      <td align="center" valign="middle">
        <a href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer">
          <picture>
            <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/stackblitz.svg" />
            <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/stackblitz_light.svg" />
            <img src="https://pnpm.io/img/users/stackblitz.svg" width="190" alt="Stackblitz" />
          </picture>
        </a>
      </td>
    </tr>
    <tr>
      <td align="center" valign="middle">
        <a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer">
          <picture>
            <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/workleap.svg" />
            <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/workleap_light.svg" />
            <img src="https://pnpm.io/img/users/workleap.svg" width="190" alt="Workleap" />
          </picture>
        </a>
      </td>
      <td align="center" valign="middle">
        <a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer">
          <picture>
            <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/nx.svg" />
            <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/nx_light.svg" />
            <img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" />
          </picture>
        </a>
      </td>
    </tr>
  </tbody>
</table>

<!-- sponsors end -->
deps: update node version to 26.4.0"

change detected: * key "$.jobs.*.steps[?(@.uses =~ /^actions\\/setup-node/)].with.node-version" updated from "26.3.0" to "26.4.0", in file ".github/workflows/go.yaml" (doc 0)

v26.4.0
### Notable Changes

* \[[`cde0daabcc`](https://github.com/nodejs/node/commit/cde0daabcc)] - **(SEMVER-MINOR)** **doc**: update `blockList` stability status to release candidate (alphaleadership) [#63050](https://github.com/nodejs/node/pull/63050)
* \[[`b78f5a7537`](https://github.com/nodejs/node/commit/b78f5a7537)] - **(SEMVER-MINOR)** **fs**: support caller-supplied `readFile()` buffers (Matteo Collina) [#63634](https://github.com/nodejs/node/pull/63634)
* \[[`417aacbc36`](https://github.com/nodejs/node/commit/417aacbc36)] - **(SEMVER-MINOR)** **http**: close pre-request sockets in `closeIdleConnections` (semimikoh) [#63470](https://github.com/nodejs/node/pull/63470)
* \[[`fbb108be7d`](https://github.com/nodejs/node/commit/fbb108be7d)] - **(SEMVER-MINOR)** **loader**: implement package maps (Maël Nison) [#62239](https://github.com/nodejs/node/pull/62239)
* \[[`45494d5a8a`](https://github.com/nodejs/node/commit/45494d5a8a)] - **(SEMVER-MINOR)** **net**: support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` (Guy Bedford) [#63825](https://github.com/nodejs/node/pull/63825)
* \[[`ee29465e77`](https://github.com/nodejs/node/commit/ee29465e77)] - **(SEMVER-MINOR)** **tls**: add certificateCompression option (Tim Perry) [#62217](https://github.com/nodejs/node/pull/62217)
* \[[`b17817eb2b`](https://github.com/nodejs/node/commit/b17817eb2b)] - **(SEMVER-MINOR)** **vfs**: dispatch `node:fs/promises` to mounted VFS instances (Matteo Collina) [#63537](https://github.com/nodejs/node/pull/63537)
* \[[`7bc93a6ac5`](https://github.com/nodejs/node/commit/7bc93a6ac5)] - **(SEMVER-MINOR)** **vfs**: add minimal `node:vfs` subsystem (Matteo Collina) [#63115](https://github.com/nodejs/node/pull/63115)

### Commits

* \[[`c7eb83b46a`](https://github.com/nodejs/node/commit/c7eb83b46a)] - **benchmark**: add child\_process async path baselines (Yagiz Nizipli) [#63929](https://github.com/nodejs/node/pull/63929)
* \[[`066fff17a5`](https://github.com/nodejs/node/commit/066fff17a5)] - **benchmark**: remove old alias usage in ffi benchmarks (Anna Henningsen) [#63666](https://github.com/nodejs/node/pull/63666)
* \[[`509cd1b94f`](https://github.com/nodejs/node/commit/509cd1b94f)] - **buffer**: optimize Buffer.prototype.copy (Robert Nagy) [#63828](https://github.com/nodejs/node/pull/63828)
* \[[`86e651bbd0`](https://github.com/nodejs/node/commit/86e651bbd0)] - **buffer**: use simdutf for two-byte utf8 byteLength (Mert Can Altin) [#63639](https://github.com/nodejs/node/pull/63639)
* \[[`d3f4ed9015`](https://github.com/nodejs/node/commit/d3f4ed9015)] - **build**: suppress compiler warnings for histogram (Richard Lau) [#63980](https://github.com/nodejs/node/pull/63980)
* \[[`82dd7ddbe6`](https://github.com/nodejs/node/commit/82dd7ddbe6)] - **build**: add QUIC CI job for PRs matching QUIC related paths (Tim Perry) [#63875](https://github.com/nodejs/node/pull/63875)
* \[[`1124c0652d`](https://github.com/nodejs/node/commit/1124c0652d)] - **build**: remove redundant intermediate node\_aix\_shared (Chengzhong Wu) [#63747](https://github.com/nodejs/node/pull/63747)
* \[[`e510ee8087`](https://github.com/nodejs/node/commit/e510ee8087)] - **build**: build codecache and snapshot with libnode (Chengzhong Wu) [#63626](https://github.com/nodejs/node/pull/63626)
* \[[`5b583dace5`](https://github.com/nodejs/node/commit/5b583dace5)] - **build**: enable maglev by default on Linux ppc64le (Richard Lau) [#63474](https://github.com/nodejs/node/pull/63474)
* \[[`a2324246b4`](https://github.com/nodejs/node/commit/a2324246b4)] - **build**: remove duplicated node\_use\_sqlite and node\_use\_ffi conditions (Chengzhong Wu) [#63629](https://github.com/nodejs/node/pull/63629)
* \[[`2a467a5f69`](https://github.com/nodejs/node/commit/2a467a5f69)] - _**Revert**_ "**build, doc**: generate node.1 with doc-kit" (Antoine du Hamel) [#64091](https://github.com/nodejs/node/pull/64091)
* \[[`e01dec45b8`](https://github.com/nodejs/node/commit/e01dec45b8)] - **build, doc**: generate node.1 with doc-kit (Aviv Keller) [#62044](https://github.com/nodejs/node/pull/62044)
* \[[`2ab9848fe4`](https://github.com/nodejs/node/commit/2ab9848fe4)] - **child\_process**: pass spawn options to the binding positionally (Yagiz Nizipli) [#63930](https://github.com/nodejs/node/pull/63930)
* \[[`04c04c8b5c`](https://github.com/nodejs/node/commit/04c04c8b5c)] - **child\_process**: serialize advanced IPC messages natively (Yagiz Nizipli) [#63933](https://github.com/nodejs/node/pull/63933)
* \[[`1eef57293d`](https://github.com/nodejs/node/commit/1eef57293d)] - **crypto**: support non-byte WebCrypto lengths and cSHAKE (Filip Skokan) [#63988](https://github.com/nodejs/node/pull/63988)
* \[[`788a66e147`](https://github.com/nodejs/node/commit/788a66e147)] - **crypto**: share WebCrypto method and usage helpers (Filip Skokan) [#63975](https://github.com/nodejs/node/pull/63975)
* \[[`f9fdce3f46`](https://github.com/nodejs/node/commit/f9fdce3f46)] - **crypto**: use EVP\_MAC for HMAC on OpenSSL >=3 (Filip Skokan) [#63942](https://github.com/nodejs/node/pull/63942)
* \[[`7e9ca87e58`](https://github.com/nodejs/node/commit/7e9ca87e58)] - **crypto**: make webcrypto aliasKeyFormat directional (Filip Skokan) [#63910](https://github.com/nodejs/node/pull/63910)
* \[[`656e57ebbf`](https://github.com/nodejs/node/commit/656e57ebbf)] - **crypto**: fix unhandled error in Hash.\_transform (Haram Jeong) [#63261](https://github.com/nodejs/node/pull/63261)
* \[[`65536f0d98`](https://github.com/nodejs/node/commit/65536f0d98)] - **crypto**: refactor keyObject.toCryptoKey() and SubtleCrypto.getPublicKey() (Filip Skokan) [#63622](https://github.com/nodejs/node/pull/63622)
* \[[`978f1d2bcc`](https://github.com/nodejs/node/commit/978f1d2bcc)] - **crypto**: handle cipher context allocation failures (Tian Teng) [#63542](https://github.com/nodejs/node/pull/63542)
* \[[`5551e8f773`](https://github.com/nodejs/node/commit/5551e8f773)] - **crypto**: deduplicate X509 subject matching logic (Tobias Nießen) [#63644](https://github.com/nodejs/node/pull/63644)
* \[[`57ae87640a`](https://github.com/nodejs/node/commit/57ae87640a)] - **crypto**: fix warnings in test\_node\_crypto.cc (Maya Lekova) [#63490](https://github.com/nodejs/node/pull/63490)
* \[[`9984b05dff`](https://github.com/nodejs/node/commit/9984b05dff)] - **crypto**: coerce -0 to +0 before native calls (Filip Skokan) [#63556](https://github.com/nodejs/node/pull/63556)
* \[[`88011a3689`](https://github.com/nodejs/node/commit/88011a3689)] - **crypto,tls**: do not ignore BN\_get\_word error (Tobias Nießen) [#63895](https://github.com/nodejs/node/pull/63895)
* \[[`9a3393d14f`](https://github.com/nodejs/node/commit/9a3393d14f)] - **debugger**: lazily wait for initial break output (Trivikram Kamat) [#63969](https://github.com/nodejs/node/pull/63969)
* \[[`b0bfcb9c59`](https://github.com/nodejs/node/commit/b0bfcb9c59)] - **debugger**: defer probe pause handling until startup (Trivikram Kamat) [#63608](https://github.com/nodejs/node/pull/63608)
* \[[`8516003953`](https://github.com/nodejs/node/commit/8516003953)] - **debugger**: await initialization after run and restart (Trivikram Kamat) [#63607](https://github.com/nodejs/node/pull/63607)
* \[[`4438cb5284`](https://github.com/nodejs/node/commit/4438cb5284)] - **debugger**: add --max-hit option to probe mode (Joyee Cheung) [#63704](https://github.com/nodejs/node/pull/63704)
* \[[`238b54ed2a`](https://github.com/nodejs/node/commit/238b54ed2a)] - **debugger**: add more logs to probe mode (Joyee Cheung) [#63663](https://github.com/nodejs/node/pull/63663)
* \[[`bbef54b413`](https://github.com/nodejs/node/commit/bbef54b413)] - **deps**: libffi: cherry-pick 9ca53a19833d (Anthony Green) [#64040](https://github.com/nodejs/node/pull/64040)
* \[[`9761385dbd`](https://github.com/nodejs/node/commit/9761385dbd)] - **deps**: update libffi to 3.6.0 (Node.js GitHub Bot) [#64040](https://github.com/nodejs/node/pull/64040)
* \[[`373ec2d092`](https://github.com/nodejs/node/commit/373ec2d092)] - **deps**: update acorn to 8.17.0 (Node.js GitHub Bot) [#63901](https://github.com/nodejs/node/pull/63901)
* \[[`e44b5d487e`](https://github.com/nodejs/node/commit/e44b5d487e)] - **(SEMVER-MINOR)** **deps**: update OpenSSL build config to support compression (Tim Perry) [#62217](https://github.com/nodejs/node/pull/62217)
* \[[`3ed287a2e2`](https://github.com/nodejs/node/commit/3ed287a2e2)] - **deps**: upgrade npm to 11.17.0 (npm team) [#63857](https://github.com/nodejs/node/pull/63857)
* \[[`b1b597c797`](https://github.com/nodejs/node/commit/b1b597c797)] - **deps**: add ngtcp2\_fmt.c to build configuration (ngtcp2.gyp) (沈鸿飞) [#63821](https://github.com/nodejs/node/pull/63821)
* \[[`0bf8e12305`](https://github.com/nodejs/node/commit/0bf8e12305)] - **deps**: V8: add CopyArrayBufferBytes API (Robert Nagy) [#63828](https://github.com/nodejs/node/pull/63828)
* \[[`e49d7301a5`](https://github.com/nodejs/node/commit/e49d7301a5)] - **deps**: update ngtcp2 to 1.23.0 (Node.js GitHub Bot) [#63777](https://github.com/nodejs/node/pull/63777)
* \[[`e5c079004b`](https://github.com/nodejs/node/commit/e5c079004b)] - **deps**: update nghttp3 to 1.16.0 (Node.js GitHub Bot) [#63776](https://github.com/nodejs/node/pull/63776)
* \[[`d599fa2346`](https://github.com/nodejs/node/commit/d599fa2346)] - **deps**: update googletest to 7140cd416cecd7462a8aae488024abeee55598e4 (Node.js GitHub Bot) [#63775](https://github.com/nodejs/node/pull/63775)
* \[[`bc09f1508c`](https://github.com/nodejs/node/commit/bc09f1508c)] - **deps**: update sqlite to 3.53.2 (Node.js GitHub Bot) [#63774](https://github.com/nodejs/node/pull/63774)
* \[[`60787746c4`](https://github.com/nodejs/node/commit/60787746c4)] - **deps**: update zlib to 1.3.2.1-motley-3246f1b (Node.js GitHub Bot) [#63773](https://github.com/nodejs/node/pull/63773)
* \[[`971af104f1`](https://github.com/nodejs/node/commit/971af104f1)] - **deps**: update amaro to 1.1.10 (Node.js GitHub Bot) [#63670](https://github.com/nodejs/node/pull/63670)
* \[[`e17f665444`](https://github.com/nodejs/node/commit/e17f665444)] - **deps**: update googletest to 8736d2cd5c1dcba41170ed2fddca14021d4916c3 (Node.js GitHub Bot) [#63669](https://github.com/nodejs/node/pull/63669)
* \[[`7591949457`](https://github.com/nodejs/node/commit/7591949457)] - **dgram**: add synchronous Socket connectSync() (Guy Bedford) [#63932](https://github.com/nodejs/node/pull/63932)
* \[[`d75222d7cb`](https://github.com/nodejs/node/commit/d75222d7cb)] - **dgram**: add synchronous Socket.prototype.bindSync() (Guy Bedford) [#63838](https://github.com/nodejs/node/pull/63838)
* \[[`0cf8342ae2`](https://github.com/nodejs/node/commit/0cf8342ae2)] - **dns**: coerce -0 to +0 in lookup and resolver inputs (Filip Skokan) [#63556](https://github.com/nodejs/node/pull/63556)
* \[[`e068299320`](https://github.com/nodejs/node/commit/e068299320)] - **doc**: update gcc toolchains to `gcc-13` and `g++-13` (Louie Llaneta) [#64018](https://github.com/nodejs/node/pull/64018)
* \[[`65178bdcf3`](https://github.com/nodejs/node/commit/65178bdcf3)] - **doc**: add aduh95 to last security release steward (Antoine du Hamel) [#63981](https://github.com/nodejs/node/pull/63981)
* \[[`83eedfe85b`](https://github.com/nodejs/node/commit/83eedfe85b)] - **doc**: fix typo in util.md (Daijiro Wachi) [#63961](https://github.com/nodejs/node/pull/63961)
* \[[`54948c78e7`](https://github.com/nodejs/node/commit/54948c78e7)] - **doc**: clarify callback exceptions (Matteo Collina) [#63939](https://github.com/nodejs/node/pull/63939)
* \[[`205d0a57f2`](https://github.com/nodejs/node/commit/205d0a57f2)] - **doc**: fix incorrect test runner mock examples (Kimaswa Emmanuel Yusufu) [#63656](https://github.com/nodejs/node/pull/63656)
* \[[`44809b176c`](https://github.com/nodejs/node/commit/44809b176c)] - **doc**: clarify fromReadable() duck-typed contract (Trivikram Kamat) [#63682](https://github.com/nodejs/node/pull/63682)
* \[[`9cb15fcc85`](https://github.com/nodejs/node/commit/9cb15fcc85)] - **doc**: fix typo in cli.md (Daijiro Wachi) [#63883](https://github.com/nodejs/node/pull/63883)
* \[[`394d0bb928`](https://github.com/nodejs/node/commit/394d0bb928)] - **doc**: fix typo in vm.md (Daijiro Wachi) [#63881](https://github.com/nodejs/node/pull/63881)
* \[[`59b7be8193`](https://github.com/nodejs/node/commit/59b7be8193)] - **doc**: fix typo in packages.md (Daijiro Wachi) [#63882](https://github.com/nodejs/node/pull/63882)
* \[[`33c236cea9`](https://github.com/nodejs/node/commit/33c236cea9)] - **doc**: fix a/an article typos in module, util, and dns (Daijiro Wachi) [#63766](https://github.com/nodejs/node/pull/63766)
* \[[`30595da67b`](https://github.com/nodejs/node/commit/30595da67b)] - **doc**: update npm supported versions link (hojeong park) [#63672](https://github.com/nodejs/node/pull/63672)
* \[[`5919ba7e97`](https://github.com/nodejs/node/commit/5919ba7e97)] - **doc**: fix AES-OCB IV length in SubtleCrypto.supports example (Anshika Jain) [#63717](https://github.com/nodejs/node/pull/63717)
* \[[`51cab5cb72`](https://github.com/nodejs/node/commit/51cab5cb72)] - **doc**: add webstreams to args for `pipeline` from `stream/promises` (David Sanders) [#63628](https://github.com/nodejs/node/pull/63628)
* \[[`ce85b2af88`](https://github.com/nodejs/node/commit/ce85b2af88)] - **doc**: fix "used to sent" → "used to send" in http2 (Daijiro Wachi) [#63700](https://github.com/nodejs/node/pull/63700)
* \[[`298735e8df`](https://github.com/nodejs/node/commit/298735e8df)] - **doc**: mark Node.js 25 as End-of-Life (Antoine du Hamel) [#63692](https://github.com/nodejs/node/pull/63692)
* \[[`56948518b9`](https://github.com/nodejs/node/commit/56948518b9)] - **doc**: clarify tty raw mode applies to input processing only (Muhammad Zeeshan) [#63438](https://github.com/nodejs/node/pull/63438)
* \[[`32ff731248`](https://github.com/nodejs/node/commit/32ff731248)] - **doc**: add worker\_threads history entries (Bob Put) [#63545](https://github.com/nodejs/node/pull/63545)
* \[[`cde0daabcc`](https://github.com/nodejs/node/commit/cde0daabcc)] - **(SEMVER-MINOR)** **doc**: update `blockList` stability status to release candidate (alphaleadership) [#63050](https://github.com/nodejs/node/pull/63050)
* \[[`d29483fc4f`](https://github.com/nodejs/node/commit/d29483fc4f)] - **doc,crypto**: mark argon2 and encap/decap as stable (Filip Skokan) [#63924](https://github.com/nodejs/node/pull/63924)
* \[[`6e668331d9`](https://github.com/nodejs/node/commit/6e668331d9)] - **events**: improve `addAbortListener` perf by caching options object (Raz Luvaton) [#52367](https://github.com/nodejs/node/pull/52367)
* \[[`97aafe2519`](https://github.com/nodejs/node/commit/97aafe2519)] - **ffi**: add fast support for almost all other platforms (Paolo Insogna) [#63941](https://github.com/nodejs/node/pull/63941)
* \[[`f52cf5eeaa`](https://github.com/nodejs/node/commit/f52cf5eeaa)] - **ffi**: add experimental fast FFI call API for AArch64 and x86\_64 (Paolo Insogna) [#63068](https://github.com/nodejs/node/pull/63068)
* \[[`d9461fee05`](https://github.com/nodejs/node/commit/d9461fee05)] - **ffi**: port semi-colon fix for riscv64 (and others) (Stewart X Addison) [#63794](https://github.com/nodejs/node/pull/63794)
* \[[`4c8402e0a8`](https://github.com/nodejs/node/commit/4c8402e0a8)] - **fs**: do not treat EPERM as ENOTEMPTY on Windows (Kirill Saied) [#63709](https://github.com/nodejs/node/pull/63709)
* \[[`b78f5a7537`](https://github.com/nodejs/node/commit/b78f5a7537)] - **(SEMVER-MINOR)** **fs**: support caller-supplied readFile() buffers (Matteo Collina) [#63634](https://github.com/nodejs/node/pull/63634)
* \[[`3d0097d489`](https://github.com/nodejs/node/commit/3d0097d489)] - **fs**: prevent spurious recursive watch events on prefix siblings (Marco) [#63095](https://github.com/nodejs/node/pull/63095)
* \[[`14d829cb3c`](https://github.com/nodejs/node/commit/14d829cb3c)] - **fs**: ignore deleted dirs in recursive watch scan (Trivikram Kamat) [#63686](https://github.com/nodejs/node/pull/63686)
* \[[`ceba08a1ea`](https://github.com/nodejs/node/commit/ceba08a1ea)] - **fs**: coerce -0 to +0 in mode flags and watch intervals (Filip Skokan) [#63556](https://github.com/nodejs/node/pull/63556)
* \[[`6577d3b282`](https://github.com/nodejs/node/commit/6577d3b282)] - **http**: avoid stream listeners on idle agent sockets (Matteo Collina) [#64004](https://github.com/nodejs/node/pull/64004)
* \[[`417aacbc36`](https://github.com/nodejs/node/commit/417aacbc36)] - **(SEMVER-MINOR)** **http**: close pre-request sockets in closeIdleConnections (semimikoh) [#63470](https://github.com/nodejs/node/pull/63470)
* \[[`b7fd13a59a`](https://github.com/nodejs/node/commit/b7fd13a59a)] - **http2**: retain header memory in session accounting (Matteo Collina) [#63752](https://github.com/nodejs/node/pull/63752)
* \[[`e611ccd167`](https://github.com/nodejs/node/commit/e611ccd167)] - **inspector**: fix inspector.close() documented behavior (Chengzhong Wu) [#63837](https://github.com/nodejs/node/pull/63837)
* \[[`a44f51eef3`](https://github.com/nodejs/node/commit/a44f51eef3)] - **lib**: fix missing lazyDOMException import (Filip Skokan) [#64033](https://github.com/nodejs/node/pull/64033)
* \[[`27cc4ec598`](https://github.com/nodejs/node/commit/27cc4ec598)] - **lib**: add lint rule to enforce use of `kEmptyObject` (Antoine du Hamel) [#63790](https://github.com/nodejs/node/pull/63790)
* \[[`7ee31b0bf4`](https://github.com/nodejs/node/commit/7ee31b0bf4)] - **lib**: improve control abstraction coverage in frozen intrinsics (Renegade334) [#63698](https://github.com/nodejs/node/pull/63698)
* \[[`078457839a`](https://github.com/nodejs/node/commit/078457839a)] - **lib**: add Iterator global to primordials (Renegade334) [#63698](https://github.com/nodejs/node/pull/63698)
* \[[`58837dc4dd`](https://github.com/nodejs/node/commit/58837dc4dd)] - **lib**: remove source map deadcode in type stripping (Chengzhong Wu) [#63738](https://github.com/nodejs/node/pull/63738)
* \[[`e7513a8b9e`](https://github.com/nodejs/node/commit/e7513a8b9e)] - **lib**: make `Navigator#language` getter throw on invalid `this` (Mohamed Sayed) [#63601](https://github.com/nodejs/node/pull/63601)
* \[[`fbb108be7d`](https://github.com/nodejs/node/commit/fbb108be7d)] - **(SEMVER-MINOR)** **loader**: implement package maps (Maël Nison) [#62239](https://github.com/nodejs/node/pull/62239)
* \[[`ea0b8e1dc2`](https://github.com/nodejs/node/commit/ea0b8e1dc2)] - **meta**: bump github/codeql-action from 4.35.3 to 4.36.1 (dependabot\[bot]) [#63724](https://github.com/nodejs/node/pull/63724)
* \[[`ac90719532`](https://github.com/nodejs/node/commit/ac90719532)] - **meta**: bump actions/cache from 5.0.4 to 5.0.5 (dependabot\[bot]) [#62847](https://github.com/nodejs/node/pull/62847)
* \[[`3ed3de3062`](https://github.com/nodejs/node/commit/3ed3de3062)] - **meta**: bump actions/checkout from 6.0.2 to 6.0.3 (dependabot\[bot]) [#63726](https://github.com/nodejs/node/pull/63726)
* \[[`d08d57bf70`](https://github.com/nodejs/node/commit/d08d57bf70)] - **meta**: bump codecov/codecov-action from 6.0.0 to 6.0.1 (dependabot\[bot]) [#63725](https://github.com/nodejs/node/pull/63725)
* \[[`e748d192cf`](https://github.com/nodejs/node/commit/e748d192cf)] - **meta**: bump cachix/cachix-action (dependabot\[bot]) [#63729](https://github.com/nodejs/node/pull/63729)
* \[[`10554eb131`](https://github.com/nodejs/node/commit/10554eb131)] - **meta**: bump actions/stale from 10.2.0 to 10.3.0 (dependabot\[bot]) [#63728](https://github.com/nodejs/node/pull/63728)
* \[[`791885f2af`](https://github.com/nodejs/node/commit/791885f2af)] - **meta**: bump step-security/harden-runner from 2.19.0 to 2.19.4 (dependabot\[bot]) [#63727](https://github.com/nodejs/node/pull/63727)
* \[[`32d9a407d9`](https://github.com/nodejs/node/commit/32d9a407d9)] - **meta**: bump cachix/install-nix-action from 31.10.5 to 31.10.6 (dependabot\[bot]) [#63723](https://github.com/nodejs/node/pull/63723)
* \[[`b97c7bed07`](https://github.com/nodejs/node/commit/b97c7bed07)] - **module**: enable existing machinery for deferred import of static modules (Maya Lekova) [#63712](https://github.com/nodejs/node/pull/63712)
* \[[`4becad2117`](https://github.com/nodejs/node/commit/4becad2117)] - **module**: use file: URL as sourceURL for type-stripped CommonJS (Joyee Cheung) [#63705](https://github.com/nodejs/node/pull/63705)
* \[[`c71c85b95f`](https://github.com/nodejs/node/commit/c71c85b95f)] - **net**: early TCP binding via synchronous net.BoundSocket (Guy Bedford) [#63951](https://github.com/nodejs/node/pull/63951)
* \[[`45494d5a8a`](https://github.com/nodejs/node/commit/45494d5a8a)] - **(SEMVER-MINOR)** **net**: support TCP\_KEEPINTVL and TCP\_KEEPCNT in setKeepAlive (Guy Bedford) [#63825](https://github.com/nodejs/node/pull/63825)
* \[[`3988efa1f3`](https://github.com/nodejs/node/commit/3988efa1f3)] - **net**: coerce -0 to +0 in BlockList prefixes (Filip Skokan) [#63556](https://github.com/nodejs/node/pull/63556)
* \[[`484efd1c44`](https://github.com/nodejs/node/commit/484efd1c44)] - **quic**: fix get\_reader bug that dropped data on FIN (Tim Perry) [#63946](https://github.com/nodejs/node/pull/63946)
* \[[`04a17fe6f0`](https://github.com/nodejs/node/commit/04a17fe6f0)] - **quic**: expose QUIC certificates as JS X509Certificate, not raw handles (Tim Perry) [#63191](https://github.com/nodejs/node/pull/63191)
* \[[`b62d5696dc`](https://github.com/nodejs/node/commit/b62d5696dc)] - **quic**: fix reader backpressure deadlock on idle connections (Tim Perry) [#63950](https://github.com/nodejs/node/pull/63950)
* \[[`3f1c8d7453`](https://github.com/nodejs/node/commit/3f1c8d7453)] - **quic**: fix broken listEndpoints export, test callbacks & nghttp3 include (Tim Perry) [#63874](https://github.com/nodejs/node/pull/63874)
* \[[`d8538b9deb`](https://github.com/nodejs/node/commit/d8538b9deb)] - **quic**: impl. cb for http/3 settings/app. options (Marten Richter) [#63558](https://github.com/nodejs/node/pull/63558)
* \[[`643b19716e`](https://github.com/nodejs/node/commit/643b19716e)] - **quic**: add listEndpoints API (James M Snell) [#63536](https://github.com/nodejs/node/pull/63536)
* \[[`2bce35bea4`](https://github.com/nodejs/node/commit/2bce35bea4)] - **sqlite**: do not leave database open after failed open (Yagiz Nizipli) [#63854](https://github.com/nodejs/node/pull/63854)
* \[[`394af52abb`](https://github.com/nodejs/node/commit/394af52abb)] - **sqlite**: fix stack-use-after-scope with function callback (ndossche) [#63640](https://github.com/nodejs/node/pull/63640)
* \[[`10f03e5958`](https://github.com/nodejs/node/commit/10f03e5958)] - **src**: omit unconvertible names in cjs\_lexer::Parse (Yagiz Nizipli) [#63943](https://github.com/nodejs/node/pull/63943)
* \[[`1723773d41`](https://github.com/nodejs/node/commit/1723773d41)] - **src**: keep global list of addon-provided cleanup hooks (Anna Henningsen) [#63985](https://github.com/nodejs/node/pull/63985)
* \[[`ef12e9ea44`](https://github.com/nodejs/node/commit/ef12e9ea44)] - **src**: guard OpenSSL compression header include (Filip Skokan) [#64009](https://github.com/nodejs/node/pull/64009)
* \[[`48af8a6d8d`](https://github.com/nodejs/node/commit/48af8a6d8d)] - **src**: handle empty MaybeLocal in cjs\_lexer::Parse (Yagiz Nizipli) [#63885](https://github.com/nodejs/node/pull/63885)
* \[[`2a672ee9e8`](https://github.com/nodejs/node/commit/2a672ee9e8)] - **src**: fast path empty native immediate drain (Gürgün Dayıoğlu) [#62969](https://github.com/nodejs/node/pull/62969)
* \[[`db6a31d1a1`](https://github.com/nodejs/node/commit/db6a31d1a1)] - **src**: do not track weak `BaseObject`s as childrens of `Realm`s (Anna Henningsen) [#63842](https://github.com/nodejs/node/pull/63842)
* \[[`5fb837ff46`](https://github.com/nodejs/node/commit/5fb837ff46)] - **src**: allow tracking children in `MemoryTracker` with weak edges (Anna Henningsen) [#63842](https://github.com/nodejs/node/pull/63842)
* \[[`6d22d373a9`](https://github.com/nodejs/node/commit/6d22d373a9)] - **src**: use C++14 deprecated attribute for `NODE_DEPRECATED` (Anna Henningsen) [#63755](https://github.com/nodejs/node/pull/63755)
* \[[`7ac3fe1992`](https://github.com/nodejs/node/commit/7ac3fe1992)] - **src**: add cleanup hooks to `node::ObjectWrap` (Anna Henningsen) [#63642](https://github.com/nodejs/node/pull/63642)
* \[[`d82d369155`](https://github.com/nodejs/node/commit/d82d369155)] - **src**: fix edge case when deflateInit2() fails with Z\_VERSION\_ERROR (Nora Dossche) [#63476](https://github.com/nodejs/node/pull/63476)
* \[[`03858d152b`](https://github.com/nodejs/node/commit/03858d152b)] - **src**: remove redundant `handle_` field in ffi (Anna Henningsen) [#63665](https://github.com/nodejs/node/pull/63665)
* \[[`1682264f6b`](https://github.com/nodejs/node/commit/1682264f6b)] - **src**: add Latin1 fast path in StringBytes::Encode utf8 (Mert Can Altin) [#63385](https://github.com/nodejs/node/pull/63385)
* \[[`cc29696acf`](https://github.com/nodejs/node/commit/cc29696acf)] - **stream**: fix Writable.toWeb() desiredSize for non-object-mode (Matteo Collina) [#62986](https://github.com/nodejs/node/pull/62986)
* \[[`d9967a25b2`](https://github.com/nodejs/node/commit/d9967a25b2)] - **stream**: handle falsy push writer fail reasons (Trivikram Kamat) [#63569](https://github.com/nodejs/node/pull/63569)
* \[[`b53f8f75c9`](https://github.com/nodejs/node/commit/b53f8f75c9)] - **stream**: reduce allocations on WHATWG streams hot paths (Matteo Collina) [#63876](https://github.com/nodejs/node/pull/63876)
* \[[`315ca426d8`](https://github.com/nodejs/node/commit/315ca426d8)] - **stream**: handle setEncoding after buffered data (Matteo Collina) [#63973](https://github.com/nodejs/node/pull/63973)
* \[[`06413cd6bd`](https://github.com/nodejs/node/commit/06413cd6bd)] - **stream**: fix Utf8Stream stall after full write of multi-byte data (Daijiro Wachi) [#63964](https://github.com/nodejs/node/pull/63964)
* \[[`a9f9a3dafa`](https://github.com/nodejs/node/commit/a9f9a3dafa)] - **stream**: keep overlapping broadcast reads pending (Trivikram Kamat) [#63500](https://github.com/nodejs/node/pull/63500)
* \[[`009cca11bd`](https://github.com/nodejs/node/commit/009cca11bd)] - **stream**: refine the stream/iter backpressure (James M Snell) [#63697](https://github.com/nodejs/node/pull/63697)
* \[[`3f81dcfc99`](https://github.com/nodejs/node/commit/3f81dcfc99)] - **stream**: only pass the expected number of parameters to callbacks (Antoine du Hamel) [#63909](https://github.com/nodejs/node/pull/63909)
* \[[`9a83b5d1fe`](https://github.com/nodejs/node/commit/9a83b5d1fe)] - **stream**: fix dropped first chunk in Utf8Stream buffer mode (Daijiro Wachi) [#63833](https://github.com/nodejs/node/pull/63833)
* \[[`0bdf5adea9`](https://github.com/nodejs/node/commit/0bdf5adea9)] - **stream**: remove transform-writer handling in pipeTo (Trivikram Kamat) [#63684](https://github.com/nodejs/node/pull/63684)
* \[[`10272a94b6`](https://github.com/nodejs/node/commit/10272a94b6)] - **stream**: check done before backpressure in stream reader (Daijiro Wachi) [#63699](https://github.com/nodejs/node/pull/63699)
* \[[`792c410631`](https://github.com/nodejs/node/commit/792c410631)] - **stream**: fix pipeToSync byte accounting (Trivikram Kamat) [#63564](https://github.com/nodejs/node/pull/63564)
* \[[`3cfafbc54b`](https://github.com/nodejs/node/commit/3cfafbc54b)] - **stream**: reject pull() reads on abort (Trivikram Kamat) [#63498](https://github.com/nodejs/node/pull/63498)
* \[[`640a8cede5`](https://github.com/nodejs/node/commit/640a8cede5)] - **stream**: fast-path stateless transform flush results (Trivikram Kamat) [#63605](https://github.com/nodejs/node/pull/63605)
* \[[`ece4477872`](https://github.com/nodejs/node/commit/ece4477872)] - **stream**: optimize pipeTo promise handling (Matteo Collina) [#63572](https://github.com/nodejs/node/pull/63572)
* \[[`2cb84c2daf`](https://github.com/nodejs/node/commit/2cb84c2daf)] - **stream**: handle sync writev completion in pipeTo (Trivikram Kamat) [#63561](https://github.com/nodejs/node/pull/63561)
* \[[`7d9fdda5fa`](https://github.com/nodejs/node/commit/7d9fdda5fa)] - **stream**: settle pending broadcast reads on return (Trivikram Kamat) [#63603](https://github.com/nodejs/node/pull/63603)
* \[[`e2aea3aac7`](https://github.com/nodejs/node/commit/e2aea3aac7)] - **test**: tolerate duplicate watch change events (Trivikram Kamat) [#63937](https://github.com/nodejs/node/pull/63937)
* \[[`ea6300593a`](https://github.com/nodejs/node/commit/ea6300593a)] - **test**: mark test-debugger-run-after-quit-restart as flaky on macOS (Matteo Collina) [#64006](https://github.com/nodejs/node/pull/64006)
* \[[`be1b204fa4`](https://github.com/nodejs/node/commit/be1b204fa4)] - **test**: update WPT for url to d4598eba09 (Node.js GitHub Bot) [#63899](https://github.com/nodejs/node/pull/63899)
* \[[`b3d0d05b05`](https://github.com/nodejs/node/commit/b3d0d05b05)] - **test**: update WPT for WebCryptoAPI to 03a1476844 (Node.js GitHub Bot) [#63900](https://github.com/nodejs/node/pull/63900)
* \[[`046af2609f`](https://github.com/nodejs/node/commit/046af2609f)] - **test**: update WPT for urlpattern to 23aac92784 (Node.js GitHub Bot) [#63898](https://github.com/nodejs/node/pull/63898)
* \[[`562b831a98`](https://github.com/nodejs/node/commit/562b831a98)] - **test**: add tests for 3 methods in utils (Daijiro Wachi) [#63765](https://github.com/nodejs/node/pull/63765)
* \[[`28e3629dd3`](https://github.com/nodejs/node/commit/28e3629dd3)] - **test**: mark SEA tests flaky on linux arm debug (Trivikram Kamat) [#63743](https://github.com/nodejs/node/pull/63743)
* \[[`243aa846de`](https://github.com/nodejs/node/commit/243aa846de)] - **test**: validate ERR\_INVALID\_THIS for scheduler methods (Daijiro Wachi) [#63764](https://github.com/nodejs/node/pull/63764)
* \[[`6bd07df2bc`](https://github.com/nodejs/node/commit/6bd07df2bc)] - **test**: add coverage outside SEA (Daijiro Wachi) [#63744](https://github.com/nodejs/node/pull/63744)
* \[[`bd67c9d11b`](https://github.com/nodejs/node/commit/bd67c9d11b)] - **test**: update WPT for urlpattern to 2f28df545c (Node.js GitHub Bot) [#63771](https://github.com/nodejs/node/pull/63771)
* \[[`e40bfe7081`](https://github.com/nodejs/node/commit/e40bfe7081)] - **test**: make Brotli 16GB test wait for backpressure (Trivikram Kamat) [#63389](https://github.com/nodejs/node/pull/63389)
* \[[`444c03fd3b`](https://github.com/nodejs/node/commit/444c03fd3b)] - **test**: add regression test for using `ObjectWrap` in worker (Mohamed Akram) [#63642](https://github.com/nodejs/node/pull/63642)
* \[[`771230df78`](https://github.com/nodejs/node/commit/771230df78)] - **test**: accept SIGILL aborts in async-hooks tests (Trivikram Kamat) [#63687](https://github.com/nodejs/node/pull/63687)
* \[[`0b3cd8e5e6`](https://github.com/nodejs/node/commit/0b3cd8e5e6)] - **test**: add more test cases for pathToFileURL (Rafael Gonzaga) [#63293](https://github.com/nodejs/node/pull/63293)
* \[[`0cbc77c60e`](https://github.com/nodejs/node/commit/0cbc77c60e)] - **test**: update test426-fixtures to 2965987bf4c96afa400c9356c8e620cb340aaee (Node.js GitHub Bot) [#63668](https://github.com/nodejs/node/pull/63668)
* \[[`f53dee5fe4`](https://github.com/nodejs/node/commit/f53dee5fe4)] - **test**: update WPT for WebCryptoAPI to 0c413fb56b (Node.js GitHub Bot) [#63647](https://github.com/nodejs/node/pull/63647)
* \[[`3048f8dc1a`](https://github.com/nodejs/node/commit/3048f8dc1a)] - **test,debugger**: add test for type stripping in debugger probe mode (Joyee Cheung) [#63748](https://github.com/nodejs/node/pull/63748)
* \[[`9485caa97e`](https://github.com/nodejs/node/commit/9485caa97e)] - **test\_runner**: remove unused shuffleArrayWithSeed (Daijiro Wachi) [#63847](https://github.com/nodejs/node/pull/63847)
* \[[`34433a4a87`](https://github.com/nodejs/node/commit/34433a4a87)] - **test\_runner**: fix watch cwd with isolation none (Trivikram Kamat) [#63690](https://github.com/nodejs/node/pull/63690)
* \[[`2e7da29b7c`](https://github.com/nodejs/node/commit/2e7da29b7c)] - **test\_runner**: avoid recompiling coverage globs for every file (sangwook) [#63675](https://github.com/nodejs/node/pull/63675)
* \[[`205295a31e`](https://github.com/nodejs/node/commit/205295a31e)] - **test\_runner**: cache `shouldSkipFileCoverage` result per URL (sangwook) [#63675](https://github.com/nodejs/node/pull/63675)
* \[[`ee29465e77`](https://github.com/nodejs/node/commit/ee29465e77)] - **(SEMVER-MINOR)** **tls**: add certificateCompression option (Tim Perry) [#62217](https://github.com/nodejs/node/pull/62217)
* \[[`57d060ed2b`](https://github.com/nodejs/node/commit/57d060ed2b)] - **tls**: route event listener exceptions through error handlers (Antoine du Hamel) [#63822](https://github.com/nodejs/node/pull/63822)
* \[[`d2dc6f8506`](https://github.com/nodejs/node/commit/d2dc6f8506)] - **tools**: bump piscina from 5.1.4 to 5.2.0 in /tools/doc (dependabot\[bot]) [#64002](https://github.com/nodejs/node/pull/64002)
* \[[`b0c418f605`](https://github.com/nodejs/node/commit/b0c418f605)] - **tools**: update sccache to v0.16.0 (Michaël Zasso) [#63078](https://github.com/nodejs/node/pull/63078)
* \[[`2af8433bef`](https://github.com/nodejs/node/commit/2af8433bef)] - **tools**: bump js-yaml from 4.1.1 to 4.2.0 in /tools/lint-md (dependabot\[bot]) [#63948](https://github.com/nodejs/node/pull/63948)
* \[[`8ba5b8574b`](https://github.com/nodejs/node/commit/8ba5b8574b)] - **tools**: bump js-yaml from 4.1.1 to 4.2.0 in /tools/eslint (dependabot\[bot]) [#63947](https://github.com/nodejs/node/pull/63947)
* \[[`325087be5b`](https://github.com/nodejs/node/commit/325087be5b)] - **tools**: enforce iterator result property order (Trivikram Kamat) [#63526](https://github.com/nodejs/node/pull/63526)
* \[[`314f417db7`](https://github.com/nodejs/node/commit/314f417db7)] - **tools**: update the llhttp updater script (Antoine du Hamel) [#63819](https://github.com/nodejs/node/pull/63819)
* \[[`c6e4f5a4fe`](https://github.com/nodejs/node/commit/c6e4f5a4fe)] - **tools**: avoid test/fixtures/wpt/README.md conflicts (Filip Skokan) [#63938](https://github.com/nodejs/node/pull/63938)
* \[[`363912acc3`](https://github.com/nodejs/node/commit/363912acc3)] - **tools**: align Bash snippets in GHA with `lint-sh` conventions (Antoine du Hamel) [#63829](https://github.com/nodejs/node/pull/63829)
* \[[`cfd16e973c`](https://github.com/nodejs/node/commit/cfd16e973c)] - **tools**: bump @node-core/doc-kit in /tools/doc in the doc group (dependabot\[bot]) [#63760](https://github.com/nodejs/node/pull/63760)
* \[[`1566872706`](https://github.com/nodejs/node/commit/1566872706)] - **tools**: bump the eslint group in /tools/eslint with 7 updates (dependabot\[bot]) [#63730](https://github.com/nodejs/node/pull/63730)
* \[[`08437a3a5b`](https://github.com/nodejs/node/commit/08437a3a5b)] - **tools**: fix zlib updater script (Antoine du Hamel) [#63707](https://github.com/nodejs/node/pull/63707)
* \[[`e883366172`](https://github.com/nodejs/node/commit/e883366172)] - **url**: fix URLSearchParams(null) to prudce null= per spec (Marco) [#63782](https://github.com/nodejs/node/pull/63782)
* \[[`60e83d9bfd`](https://github.com/nodejs/node/commit/60e83d9bfd)] - **util**: fix scientific notation formatting (Daijiro Wachi) [#63823](https://github.com/nodejs/node/pull/63823)
* \[[`5f7f60ac36`](https://github.com/nodejs/node/commit/5f7f60ac36)] - **util**: fix -0 formatting when numericSeparator is enabled (Daijiro Wachi) [#63815](https://github.com/nodejs/node/pull/63815)
* \[[`af1a11e0dd`](https://github.com/nodejs/node/commit/af1a11e0dd)] - **util**: remove style caches from styleText slow path (Guilherme Araújo) [#63706](https://github.com/nodejs/node/pull/63706)
* \[[`b17817eb2b`](https://github.com/nodejs/node/commit/b17817eb2b)] - **(SEMVER-MINOR)** **vfs**: dispatch fs/promises to mounted VFS instances (Matteo Collina) [#63537](https://github.com/nodejs/node/pull/63537)
* \[[`7bc93a6ac5`](https://github.com/nodejs/node/commit/7bc93a6ac5)] - **(SEMVER-MINOR)** **vfs**: add minimal node:vfs subsystem (Matteo Collina) [#63115](https://github.com/nodejs/node/pull/63115)
* \[[`584e7527c4`](https://github.com/nodejs/node/commit/584e7527c4)] - **vm**: fix property queries for proxy sandboxes (Brian Meek) [#63742](https://github.com/nodejs/node/pull/63742)
* \[[`a926e72eaf`](https://github.com/nodejs/node/commit/a926e72eaf)] - **watch**: print name of changed file that triggers restart (Marco) [#63781](https://github.com/nodejs/node/pull/63781)
* \[[`32a2621ca4`](https://github.com/nodejs/node/commit/32a2621ca4)] - **watch**: cancel pending restart on shutdown (Trivikram Kamat) [#63383](https://github.com/nodejs/node/pull/63383)
* \[[`692215d1b1`](https://github.com/nodejs/node/commit/692215d1b1)] - **zlib**: coerce -0 to +0 for crc32 seeds (Filip Skokan) [#63556](https://github.com/nodejs/node/pull/63556)

GitHub Action workflow link
Updatecli logo

Created automatically by Updatecli

Options:

Most of Updatecli configuration is done via its manifest(s).

  • If you close this pull request, Updatecli will automatically reopen it, the next time it runs.
  • If you close this pull request and delete the base branch, Updatecli will automatically recreate it, erasing all previous commits made.

Feel free to report any issues at github.com/updatecli/updatecli.
If you find this tool useful, do not hesitate to star our GitHub repository as a sign of appreciation, and/or to tell us directly on our chat!

updateclibot Bot added 2 commits June 29, 2026 15:38
Made with ❤️️ by updatecli
Made with ❤️️ by updatecli
@updateclibot updateclibot Bot added dependencies Pull requests that update a dependency file chore labels Jun 29, 2026
@updateclibot
updateclibot Bot enabled auto-merge June 29, 2026 16:03
@updateclibot
updateclibot Bot merged commit 2b197c4 into main Jun 29, 2026
8 checks passed
@updateclibot
updateclibot Bot deleted the updatecli_main_node_version branch June 29, 2026 16:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants