Skip to content

[JavaScript] Bump Node.js from v26.7.0 to v26.8.1 - #483

Merged
hayat01sh1da merged 1 commit into
masterfrom
hayat01sh1da/no-issue-number/javascript/bump-nodejs-from-v26.7.0-to-v26.8.1
Sep 6, 2026
Merged

hayat01sh1da merged 1 commit into
masterfrom
hayat01sh1da/no-issue-number/javascript/bump-nodejs-from-v26.7.0-to-v26.8.1

Conversation

@hayat01sh1da

Copy link
Copy Markdown
Owner

1. Overview

This pull request bumps the pinned Node.js runtime from v26.7.0 to v26.8.1.

Two upstream releases land with this single bump: v26.8.0 (2026-08-26), a feature release of 355 commits with 9 semver-minor additions and no semver-major change, and v26.8.1 (2026-08-26), a two-commit out-of-band release.
Neither is a security release and no CVE is referenced in the range, so unlike the previous bump this one is routine maintenance rather than a patch that has to land.

v26.8.1 is the reason not to stop at v26.8.0: that release shipped with an accidental alpha designation compiled into the version string, so node --version reported an alpha.
v26.8.1 reverts exactly that, which matters here because .node-version feeds actions/setup-node on every CI run.

The runtime's own foundations do not move: V8 stays on 14.6.202.34, the ABI module version stays at 147 so no native add-on needs rebuilding, npm stays at 11.19.0, OpenSSL stays at 3.5.7 and libuv stays at 1.52.1.
What does change is breadth of small work — 13 fs commits (recursive readdir no longer stat()s every entry, small files read in one thread-pool round trip), 17 stream commits, 29 sqlite commits, refreshed root certificates at NSS 3.126 and undici at 8.10.0.

The fs work is the part this repository is most likely to feel: jest's file crawling walks the whole project on every run in the javascript, typescript, reactjs and vuejs tracks.
No benchmark was taken here, so treat that as the direction of travel rather than a measured gain.

2. Key Changes & Differences

2-1. Node.js Runtime — v26.7.0 → v26.8.1

Component Before (v26.7.0, 2026-08-05) After (v26.8.1, 2026-08-26) Changes & Differences
Node.js v26.7.0 v26.8.1 Two upstream releases fold into this bump: v26.8.0 (2026-08-26), a feature release of 355 commits, and v26.8.1 (same day), a two-commit out-of-band release. Both are on the Current line; neither is flagged as a security release ("security": false in https://nodejs.org/dist/index.json), and no CVE is referenced in the range.
Why v26.8.1 and not v26.8.0 — node --version reports the release version again v26.8.0 shipped with an accidental alpha designation compiled in, so node --version reported an alpha string. v26.8.1 exists only to revert it (#65568), plus a tools/nix/list-requisites.sh fix. Anything that parses node --version — .node-version tooling, engines checks, actions/setup-node — is the reason to land on v26.8.1 directly and never on v26.8.0.
New APIs (semver-minor) — 9 additions, 0 semver-major crypto: SIV and GCM-SIV modes in the Cipher/Decipher APIs. zlib: ZipEntry, ZipFile and ZipBuffer. sqlite: StatementSync.prototype.close() and StatementSync.prototype[Symbol.dispose](). util: a non-throwing MIMEType.parse. net: faster net.BlockList. lib,src and perf_hooks: a reworked histogram implementation with statistical hypothesis testing. benchmark: an --analyze mode for compare.js. Everything is additive; nothing is deprecated or removed.
Stability changes TracingChannel experimental TracingChannel stable diagnostics_channel marks TracingChannel stable (#64525), and channel activation now validates its input first.
V8 14.6.202.34 14.6.202.34 Unchanged — v26.8.0 carries no V8 update at all, unlike v26.7.0 which moved the Rust crates and took three backports.
ABI (process.versions.modules) 147 147 Unchanged, so no native add-on needs rebuilding.
npm (bundled) 11.19.0 11.19.0 Unchanged. Not used by these tracks anyway — they run on pnpm — but it ships with the runtime.
OpenSSL 3.5.7 3.5.7 Version unchanged. The bundled root certificate store moves NSS 3.125 → NSS 3.126, FIPS mode gains fixes (disabling FIPS, non-FIPS WebCrypto paths now refused in FIPS mode), mgf1Hash is accepted for RSA-OAEP, and SubtleCrypto.supports() reports more accurately.
libuv 1.52.1 1.52.1 Version unchanged; one upstream cherry-pick (libuv@e640dc9).
Other bundled deps undici 8.9.0, simdjson 4.6.6, libffi 3.7.1, zlib 1.3.2.1-motley-42c2f19 undici 8.10.0, simdjson 4.6.7, libffi 3.8.0, zlib 1.3.2.1-motley-8002e91 Plus perfetto 57.2, an ICU-23262 patch floated for icu78, googletest refreshes, and AVX-512 OpenSSL assembly enabled under clang.
Filesystem performance — 13 fs commits Recursive readdir no longer stat()s every entry, readFileUtf8 uses sized reads for large files, small files are read in a single thread-pool round trip, and FSReqPromise stat arrays are allocated lazily. Correctness alongside: a glob early return that skipped sibling entries, an out-of-bounds write in mkdtemp for long prefixes, realpath of namespaced drive paths, and EPERM mapping for permission_denied.
Streams and modules — 17 stream, 5 module commits Web-stream hot paths lose promise churn, async iteration of Readable is faster, and several abort/backpressure edge cases are fixed. module adds a read-only mode for the compile cache, caches the nearest parent package.json per directory, stops splitting a portable compile cache by uid, and fixes --check on ambiguous ESM files.
Tightened runtime behaviour — Input validation and edge cases dgram no longer swallows bind errors when a callback is provided; dns validates the address type in lookupService() and the port range in setServers(), and no longer crashes on port 0; buffer treats detached ArrayBuffers as empty and prevents a string write offset overflow; on Windows, SIGWINCH no longer kills a child process. These are the changes most likely to surface an existing latent bug, though none applies to code in this repository.
Release artifacts No musl build node-v26.8.1-linux-x64-musl.tar.{gz,xz} The dist directory for v26.8.1 carries official musl (Alpine) tarballs that v26.7.0's does not. The changelog does not call this out; it is visible by comparing https://nodejs.org/dist/v26.7.0/ with https://nodejs.org/dist/v26.8.1/.
REPL — Basic syntax highlighting repl gains syntax highlighting (#64591) and keeps entries added while the history file is still loading.

2-2. Files Updated in This Repository

Files Before After Changes & Differences
.node-version v26.7.0 v26.8.1 The repository-wide Node.js pin that actions/setup-node reads on every CI run.
SECURITY.md Node v26.7.0 Node v26.8.1 The supported-versions table, so the documented runtime matches .node-version.
javascript/README.md - Node v26.7.0 - Node v26.8.1 The Environment section of this track; pnpm stays at 12.3.4.
javascript/package.json Node.js v26.7.0 in description Node.js v26.8.1 in description Environment description only; no dependency or script change.
ruby-on-rails/perfect-ruby-on-rails/.node-version v26.7.0 v26.8.1 The application-level pin for the Rails app, kept in step with the repository-wide one.
ruby-on-rails/perfect-ruby-on-rails/Dockerfile FROM node:26.7.0 FROM node:26.8.1 The development image that builds the Rails app's assets. The tag exists on Docker Hub.
ruby-on-rails/perfect-ruby-on-rails/Dockerfile.production FROM docker.io/library/node:26.7.0-slim FROM docker.io/library/node:26.8.1-slim The production image Kamal builds and deploys. The -slim tag exists on Docker Hub.
ruby-on-rails/perfect-ruby-on-rails/README.md - Node v26.7.0 - Node v26.8.1 The Environment section of this track; pnpm stays at 12.3.4.
ruby-on-rails/perfect-ruby-on-rails/package.json Node.js v26.7.0 in description Node.js v26.8.1 in description Environment description only; no dependency or script change.
typescript/README.md - Node v26.7.0 - Node v26.8.1 The Environment section of this track; pnpm stays at 12.3.4.
typescript/package.json Node.js v26.7.0 in description Node.js v26.8.1 in description Environment description only; no dependency or script change.
vuejs/README.md - Node v26.7.0 - Node v26.8.1 The Environment section of this track; pnpm stays at 12.3.4.

3. Summary

  • Bumped the Node.js pin from v26.7.0 to v26.8.1 across 12 files (+12 / -12); every place that documents the runtime is back in sync with .node-version, and git grep 26.7 finds nothing left behind.
  • No source, dependency-manifest or lockfile change: version pins and documentation only. pnpm stays at 12.3.4.
  • Availability was checked rather than assumed: v26.8.1 is in the actions/node-versions manifest that actions/setup-node resolves, https://nodejs.org/dist/v26.8.1/ serves it, and the 26.8.1 and 26.8.1-slim tags both exist on Docker Hub.
  • Low upgrade risk: V8, the ABI module version (147), npm, OpenSSL and libuv are all unchanged, and the 9 new APIs are additive with nothing deprecated or removed.
  • The one class of change that could surface an existing latent bug is the tightened input validation — dgram bind errors no longer swallowed, dns port/address validation, buffer detached-ArrayBuffer handling — none of which this repository's code touches.

4. References

v26.8.0 (2026-08-26) carries 355 commits, 9 semver-minor additions and no
semver-major change, and v26.8.1 (same day) is a two-commit out-of-band
release that fixes `node --version` reporting an alpha version, which is why
this goes straight to v26.8.1 rather than to v26.8.0.

The V8 line and the bundled npm are untouched since v26.7.0; root certificates
move to NSS 3.126 and undici to 8.10.0.
@hayat01sh1da hayat01sh1da self-assigned this Sep 6, 2026

@hayat01sh1da hayat01sh1da left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@hayat01sh1da
hayat01sh1da merged commit 15c1f32 into master Sep 6, 2026
18 checks passed
@hayat01sh1da
hayat01sh1da deleted the hayat01sh1da/no-issue-number/javascript/bump-nodejs-from-v26.7.0-to-v26.8.1 branch September 6, 2026 16:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant