Skip to content

Keeping npm up to date in Node.js #9827

Description

@reggi

Keeping npm up to date in Node.js

Hi Node.js team! I (@reggi) opened npm update PRs for the supported Node.js branches.

The Node.js branches are currently out of sync:

Node.js Status Bundled npm Latest release in that npm major
26 Current 11.17.0 11.19.0
25 EOL 11.12.1 11.19.0
24 Active LTS 11.16.0 11.19.0
23 EOL 10.9.2 10.9.9
22 Maintenance LTS 10.9.8 10.9.9
21 EOL 10.5.0 10.9.9
20 EOL 10.8.2 10.9.9
19 EOL 9.6.3 9.9.4
18 EOL 10.8.2 10.9.9

We opened these PRs to update the supported branches:

These are the commands I ran:

gh workflow run create-node-pr.yml -R npm/cli -f spec=latest -f branch=main
gh workflow run create-node-pr.yml -R npm/cli -f spec=next-11 -f branch=26
gh workflow run create-node-pr.yml -R npm/cli -f spec=next-11 -f branch=24
gh workflow run create-node-pr.yml -R npm/cli -f spec=next-10 -f branch=22

I did not create PRs against EOL branches.

  • Should we update those branches as well?

Activity

  1. self-assigned this
    on Jul 31, 2026
  2. MikeMcC399 commented on Aug 1, 2026

    @MikeMcC399
    Contributor

    Should we update those branches as well?

    Node.js EOL branches are frozen and are no longer released. It would be confusing to submit a PR for an EOL branch, and Node.js would probably just reject it.

  3. aliceshi-aaaaaokkk commented on Aug 3, 2026

    @aliceshi-aaaaaokkk

    Could you fix the following CVE issues in node 22?
    ┌────────────────────────────────┬─────────────────────┬──────────┬────────┬───────────────────┬─────────────────────────────┬──────────────────────────────────────────────────────────┐
    │ Library │ Vulnerability │ Severity │ Status │ Installed Version │ Fixed Version │ Title │
    ├────────────────────────────────┼─────────────────────┼──────────┼────────┼───────────────────┼─────────────────────────────┼──────────────────────────────────────────────────────────┤
    │ brace-expansion (package.json) │ CVE-2026-14257 │ HIGH │ fixed │ 5.0.7 │ 5.0.8, 3.0.3, 2.1.3, 1.1.17 │ brace-expansion through 5.0.7 is vulnerable to denial of │
    │ │ │ │ │ │ │ service via m ...... │
    │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-14257 │
    ├────────────────────────────────┼─────────────────────┼──────────┤ ├───────────────────┼─────────────────────────────┼──────────────────────────────────────────────────────────┤
    │ tar (package.json) │ GHSA-r292-9mhp-454m │ MEDIUM │ │ 7.5.19 │ 7.5.21 │ node-tar: Uncontrolled recursion in mapHas/filesFilter │
    │ │ │ │ │ │ │ allows uncatchable stack-overflow DoS via crafted │
    │ │ │ │ │ │ │ long-path... │
    │ │ │ │ │ │ │ GHSA-r292-9mhp-454m │
    └────────────────────────────────┴─────────────────────┴──────────┴────────┴───────────────────┴─────────────────────────────┴──────────────────────────────────────────────────────────┘

  4. MikeMcC399 commented on Aug 4, 2026

    @MikeMcC399
    Contributor

    @reggi

    npm 11.19.0 → Node.js v24.x-staging: deps: upgrade npm to 11.19.0 nodejs/node#64885

    There are some comments in nodejs/node#64885 regarding the above PR.

    The Node.js backporting policy specifies a minimum of 2 weeks' availability in the current release line (26.x) before a commit is backported to the Active LTS (24.x) release line.

    Pushing npm 11.19.0 directly to v24.x-staging would violate that policy, since

    npm 11.19.0 → Node.js v26.x-staging: nodejs/node#64883

    has not landed and been released with availability for >= 2 weeks.

    I don't know if you need to be active in making any changes. You should probably at least monitor your PRs and see what the Node.js Releasers / Backporters teams are saying and doing.

  5. aduh95 commented on Aug 4, 2026

    @aduh95
    Contributor

    It would make Node.js backporters/releasers' life easier to target main for this kind of update rather than the staging branches (except for Node.js 22, given it's on a different release line than main). Would it be OK to change the base branch of nodejs/node#64883 so it can land on main? EDIT: I went ahead and did just that

  6. MikeMcC399 commented on Aug 5, 2026

    @MikeMcC399
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions