Repository navigation
Keeping npm up to date in Node.js #9827
Description
Activity
Should we update those branches as well?
Node.js EOL branches are frozen and are no longer released. It would be confusing to submit a PR for an EOL branch, and Node.js would probably just reject it.
Reacted by RenéCould you fix the following CVE issues in node 22?
┌────────────────────────────────┬─────────────────────┬──────────┬────────┬───────────────────┬─────────────────────────────┬──────────────────────────────────────────────────────────┐
│ Library │ Vulnerability │ Severity │ Status │ Installed Version │ Fixed Version │ Title │
├────────────────────────────────┼─────────────────────┼──────────┼────────┼───────────────────┼─────────────────────────────┼──────────────────────────────────────────────────────────┤
│ brace-expansion (package.json) │ CVE-2026-14257 │ HIGH │ fixed │ 5.0.7 │ 5.0.8, 3.0.3, 2.1.3, 1.1.17 │ brace-expansion through 5.0.7 is vulnerable to denial of │
│ │ │ │ │ │ │ service via m ...... │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-14257 │
├────────────────────────────────┼─────────────────────┼──────────┤ ├───────────────────┼─────────────────────────────┼──────────────────────────────────────────────────────────┤
│ tar (package.json) │ GHSA-r292-9mhp-454m │ MEDIUM │ │ 7.5.19 │ 7.5.21 │ node-tar: Uncontrolled recursion in mapHas/filesFilter │
│ │ │ │ │ │ │ allows uncatchable stack-overflow DoS via crafted │
│ │ │ │ │ │ │ long-path... │
│ │ │ │ │ │ │ GHSA-r292-9mhp-454m │
└────────────────────────────────┴─────────────────────┴──────────┴────────┴───────────────────┴─────────────────────────────┴──────────────────────────────────────────────────────────┘npm 11.19.0 → Node.js
v24.x-staging: deps: upgrade npm to 11.19.0 nodejs/node#64885There are some comments in nodejs/node#64885 regarding the above PR.
The Node.js backporting policy specifies a minimum of 2 weeks' availability in the current release line (26.x) before a commit is backported to the Active LTS (24.x) release line.
Pushing npm 11.19.0 directly to v24.x-staging would violate that policy, since
npm 11.19.0 → Node.js v26.x-staging: nodejs/node#64883
has not landed and been released with availability for >= 2 weeks.
I don't know if you need to be active in making any changes. You should probably at least monitor your PRs and see what the Node.js Releasers / Backporters teams are saying and doing.
It would make Node.js backporters/releasers' life easier to target
mainfor this kind of update rather than the staging branches (except for Node.js 22, given it's on a different release line thanmain). Would it be OK to change the base branch of nodejs/node#64883 so it can land onmain? EDIT: I went ahead and did just that
Keeping npm up to date in Node.js
Hi Node.js team! I (@reggi) opened npm update PRs for the supported Node.js branches.
The Node.js branches are currently out of sync:
We opened these PRs to update the supported branches:
main: deps: upgrade npm to 12.0.2 nodejs/node#64882v26.x-staging: deps: upgrade npm to 11.19.0 nodejs/node#64883v22.x-staging: [v22.x] deps: upgrade npm to 10.9.9 nodejs/node#64884v24.x-staging: deps: upgrade npm to 11.19.0 nodejs/node#64885These are the commands I ran:
I did not create PRs against EOL branches.