Skip to content

2026-09-01, Version 22.23.3 'Jod' (LTS) - #65448

Open
github-actions[bot] wants to merge 28 commits into
v22.xfrom
v22.23.3-proposal
Open

2026-09-01, Version 22.23.3 'Jod' (LTS)#65448
github-actions[bot] wants to merge 28 commits into
v22.xfrom
v22.23.3-proposal

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

2026-09-01, Version 22.23.3 'Jod' (LTS), @juanarbol

Notable Changes

  • [fe2a6b2be8] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746
  • [71feba6b69] - crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527

Commits

  • [44cf27b8fa] - build: update binary-upload to use correct tarball name (Stewart X Addison) #65282
  • [fe2a6b2be8] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746
  • [71feba6b69] - crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527
  • [3376e27de2] - deps: V8: cherry-pick a6eaf7574109 (Camillo Bruni) #65402
  • [b816fc8958] - deps: upgrade npm to 10.9.9 (npm team) #64884
  • [4e4bd1b104] - deps: update timezone to 2026c (Node.js GitHub Bot) #64588
  • [7d82841b4e] - deps: update c-ares to 1.34.8 (Node.js GitHub Bot) #64330
  • [01855a19d3] - deps: c-ares: cherry-pick 8ba37af8e3fb (René) #64110
  • [23fb398c3d] - deps: update corepack to 0.35.0 (Node.js GitHub Bot) #63375
  • [5286330365] - deps: update corepack to 0.34.7 (Node.js GitHub Bot) #62810
  • [6d6c3c98b1] - deps: update timezone to 2026b (Node.js GitHub Bot) #62962
  • [e306521444] - deps: update icu to 78.3 (Node.js GitHub Bot) #62324
  • [d9cb8468a3] - doc: clarify filter option of sqlite.database.applyChangeset (Antoine du Hamel) #63515
  • [c9c5662d91] - doc: add sxa GPG key (ed25519) (Stewart X Addison) #64193
  • [7c2df5dd96] - http2: avoid uaf while receiving and sending rst_stream (esgor) #64166
  • [3909ff2c4a] - node-api: support SharedArrayBuffer in napi_create_typedarray (Yilong Li) #62710
  • [66de6349ad] - node-api: add napi_create_external_sharedarraybuffer (Ben Noordhuis) #62623
  • [ce9139107f] - src: escape Windows environment variables in task runner (Antoine du Hamel) #65217
  • [02cafc479f] - tools: fix commit linter for semver-major release proposals (Antoine du Hamel) #62993
  • [6f6cd3768d] - tools: sync mk-ca-bundle.pl with curl (Archkon) #64753
  • [bc5753d438] - tools: remove envinfo from our workflows (Antoine du Hamel) #64259
  • [d68ee9f8a5] - tools: validate version number in release proposal commit message lint (Antoine du Hamel) #64070
  • [38ee2e895f] - tools: avoid test/fixtures/wpt/README.md conflicts (Filip Skokan) #63938
  • [fdc65e489f] - tools: use different branch for tool updates on staging branches (Antoine du Hamel) #63110
  • [e5a6fde002] - tools: update gyp-next to 0.22.1 (Node.js GitHub Bot) #62961
  • [5fbbad6e82] - url: handle unparsable serialized URLs in setters (Matteo Collina) #64651
  • [ed019e4854] - util: preserve function names without source map names (Hiroki Osame) #65108

nodejs-github-bot added a commit that referenced this pull request Aug 20, 2026
Notable changes:

crypto:
  * update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746
  * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527

PR-URL: #65448
@github-actions github-actions Bot added the release Issues and PRs related to Node.js releases. label Aug 20, 2026
@github-actions github-actions Bot added the v22.x Issues that can be reproduced on v22.x or PRs targeting the v22.x-staging branch. label Aug 20, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/actions
  • @nodejs/net
  • @nodejs/security-wg

@juanarbol
juanarbol requested a review from a team August 21, 2026 13:45
@juanarbol
juanarbol marked this pull request as ready for review August 21, 2026 13:46
@MikeMcC399

Copy link
Copy Markdown
Contributor

Please include [email protected] from #64884 if possible, as it resolves a critical severity vulnerability reported for tar as a dependency of npm. See issue npm/cli#9801.

@juanarbol

juanarbol commented Aug 21, 2026

Copy link
Copy Markdown
Member

#64166 needs manual backport. The #65264 PR works also in v22.x

Can anyone review #65402, seems to solve a real issue.

sxa and others added 21 commits August 21, 2026 12:53
Signed-off-by: Stewart X Addison <[email protected]>
PR-URL: #64193
Reviewed-By: Antoine du Hamel <[email protected]>
Reviewed-By: Richard Lau <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
the binary-upload target uses $(TARNAME)-$(OSTYPE)-$(ARCH).tar.xz as the
name to upload whereas it is created by the $(BINARYTAR) target as
$(BINARYNAME). Since BINARYNAME includes the optional VARIATION when
present this gets missed out int he binary-upload target, for example
during a release build for Alpine/musl. This commit changes the
binary-upload target to use the same variable for the tarball that is
used when the file is created.

Signed-off-by: Stewart X Addison <[email protected]>
PR-URL: #65282
Reviewed-By: Richard Lau <[email protected]>
Reviewed-By: Luigi Pinca <[email protected]>
Reviewed-By: Gürgün Dayıoğlu <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #62324
Reviewed-By: Richard Lau <[email protected]>
Reviewed-By: Marco Ippolito <[email protected]>
Reviewed-By: Luigi Pinca <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
Creates a SharedArrayBuffer from externally managed memory.

Fixes: #62259
PR-URL: #62623
Reviewed-By: Matteo Collina <[email protected]>
Reviewed-By: Chengzhong Wu <[email protected]>
Reviewed-By: Vladimir Morozov <[email protected]>
Reviewed-By: Robert Nagy <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #62961
Reviewed-By: Colin Ihrig <[email protected]>
Reviewed-By: Luigi Pinca <[email protected]>
Reviewed-By: Chengzhong Wu <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #62962
Reviewed-By: Luigi Pinca <[email protected]>
Reviewed-By: Antoine du Hamel <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #62810
Reviewed-By: Antoine du Hamel <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Antoine du Hamel <[email protected]>
PR-URL: #63110
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: Richard Lau <[email protected]>
Reviewed-By: Marco Ippolito <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: umuoy1 <[email protected]>
PR-URL: #62710
Reviewed-By: Chengzhong Wu <[email protected]>
Reviewed-By: Vladimir Morozov <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #63375
Reviewed-By: Antoine du Hamel <[email protected]>
Reviewed-By: Trivikram Kamat <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
This is the [`certdata.txt`][0] from NSS 3.123.1.

This is the version of NSS that shipped in Firefox 151.0.1 on 2026-05-21

Certificates removed:
- QuoVadis Root CA 2
- QuoVadis Root CA 3
- DigiCert Assured ID Root CA
- DigiCert Global Root CA
- DigiCert High Assurance EV Root CA
- SwissSign Gold CA - G2
- SecureTrust CA
- Secure Global CA
- COMODO Certification Authority
- Certigna
- certSIGN ROOT CA
- Izenpe.com
- AffirmTrust Commercial
- AffirmTrust Networking
- AffirmTrust Premium
- AffirmTrust Premium ECC
- TeliaSonera Root CA v1
- Entrust Root Certification Authority - G2
- Entrust Root Certification Authority - EC1
- Trustwave Global Certification Authority
- Trustwave Global ECC P256 Certification Authority
- Trustwave Global ECC P384 Certification Authority
- GLOBALTRUST 2020
- GTS Root R2
- FIRMAPROFESIONAL CA ROOT-A WEB

[0]: https://raw.githubusercontent.com/nss-dev/nss/refs/tags/NSS_3_123_1_RTM/lib/ckfw/builtins/certdata.txt

PR-URL: #63527
Reviewed-By: Luigi Pinca <[email protected]>
Reviewed-By: Gürgün Dayıoğlu <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Antoine du Hamel <[email protected]>
PR-URL: #63515
Reviewed-By: Colin Ihrig <[email protected]>
Reviewed-By: Edy Silva <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Filip Skokan <[email protected]>
PR-URL: #63938
Refs: nodejs/node-core-utils#1094
Reviewed-By: Antoine du Hamel <[email protected]>
Reviewed-By: Mattias Buelens <[email protected]>
Reviewed-By: Yagiz Nizipli <[email protected]>
Reviewed-By: Daijiro Wachi <[email protected]>
Reviewed-By: Luigi Pinca <[email protected]>
Reviewed-By: Ethan Arrowood <[email protected]>
Reviewed-By: Daeyeon Jeong <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
Original commit message:

    Fixes #1056

    The commit
    c-ares/c-ares@1d1b3d4
    refactored the function to use wide strings, but didn't touch this
    check. Because an empty wide string would now be size 2 and not 1, the
    empty string would go on and cause the DNS domain list to be replaced
    with nothing.

    Signed-off-by: @dankmeme01

Refs: c-ares/c-ares@8ba37af
PR-URL: #64110
Fixes: #62347
Reviewed-By: Luigi Pinca <[email protected]>
Reviewed-By: Tim Perry <[email protected]>
Reviewed-By: Colin Ihrig <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Antoine du Hamel <[email protected]>
PR-URL: #64070
Reviewed-By: Marco Ippolito <[email protected]>
Reviewed-By: Richard Lau <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Antoine du Hamel <[email protected]>
PR-URL: #64259
Reviewed-By: Richard Lau <[email protected]>
Reviewed-By: Joyee Cheung <[email protected]>
Reviewed-By: Marco Ippolito <[email protected]>
Reviewed-By: Filip Skokan <[email protected]>
Reviewed-By: Luigi Pinca <[email protected]>
Reviewed-By: René <[email protected]>
Reviewed-By: Colin Ihrig <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #64330
Reviewed-By: Antoine du Hamel <[email protected]>
Reviewed-By: Richard Lau <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #64588
Reviewed-By: René <[email protected]>
Reviewed-By: Colin Ihrig <[email protected]>
Reviewed-By: Luigi Pinca <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
This is the certdata.txt[0] from NSS 3.125.

This is the version of NSS that shipped in Firefox 153.0 on 2026-07-21.

Certificates removed:
- Entrust Root Certification Authority
- SecureSign Root CA12

[0] https://raw.githubusercontent.com/nss-dev/nss/refs/tags/NSS_3_125_RTM/lib/ckfw/builtins/certdata.txt

PR-URL: #64746
Reviewed-By: Antoine du Hamel <[email protected]>
Reviewed-By: Luigi Pinca <[email protected]>
Reviewed-By: Yagiz Nizipli <[email protected]>
Reviewed-By: Colin Ihrig <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
Synchronize mk-ca-bundle.pl with curl 1.33. This brings in curl's
corrected handling of NSS distrust-after metadata.

Refs: https://github.com/curl/curl/blob/0ada20387c31c638cfd7f6b4ae7e5cab5b318caf/scripts/mk-ca-bundle.pl
Signed-off-by: Archkon <[email protected]>
PR-URL: #64753
Fixes: #64752
Reviewed-By: Tim Perry <[email protected]>
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: René <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Matteo Collina <[email protected]>
PR-URL: #64651
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: Yagiz Nizipli <[email protected]>
Reviewed-By: Filip Skokan <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
privatenumber and others added 7 commits August 21, 2026 12:53
Signed-off-by: Hiroki Osame <[email protected]>
PR-URL: #65108
Fixes: #65104
Reviewed-By: Chengzhong Wu <[email protected]>
Reviewed-By: Aviv Keller <[email protected]>
Reviewed-By: Marco Ippolito <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
Signed-off-by: Antoine du Hamel <[email protected]>
PR-URL: #65217
Reviewed-By: Yagiz Nizipli <[email protected]>
Reviewed-By: Tierney Cyren <[email protected]>
Signed-off-by: Juan José Arboleda <[email protected]>
PR-URL: #62993
Reviewed-By: Richard Lau <[email protected]>
Reviewed-By: Rafael Gonzaga <[email protected]>
Reviewed-By: Jacob Smith <[email protected]>
Signed-off-by: Antoine du Hamel <[email protected]>
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().

Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <[email protected]>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <[email protected]>
PR-URL: #64884
Reviewed-By: Jordan Harband <[email protected]>
Reviewed-By: Aviv Keller <[email protected]>
Reviewed-By: Luigi Pinca <[email protected]>
Reviewed-By: Mike McCready <[email protected]>
Reviewed-By: Trivikram Kamat <[email protected]>
Reviewed-By: Juan José Arboleda <[email protected]>
Original commit message:

    [logging] Use RecursiveMutex for Logger

    Logger::allows_code_compaction might be called from within a
    CodeCreateEvent where initializing line script line ends might trigger
    a GC. During compaction we check if code compaction is allowed which
    calls back into the above Logger method.

    Bug: 41497149
    Change-Id: Ifd1b740df8600584780341d8214e995832e663b4
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/5572952
    Reviewed-by: Victor Gomes <[email protected]>
    Commit-Queue: Camillo Bruni <[email protected]>
    Cr-Commit-Position: refs/heads/main@{#94140}

Refs: v8/v8@a6eaf75
PR-URL: #65402
Fixes: #65140
Reviewed-By: Richard Lau <[email protected]>
Notable changes:

crypto:
  * update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746
  * update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527

PR-URL: #65448
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release Issues and PRs related to Node.js releases. v22.x Issues that can be reproduced on v22.x or PRs targeting the v22.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.