v26.8.2

nodejs/nodev26.8.2Sep 9, 2026by aduh95

AI Summary

This release updates core dependencies like Undici and OpenSSL to 3.5.8, alongside npm and Corepack. It includes build improvements for RISC-V architectures and updates to various security tooling. Documentation updates include clarifying return types, deprecating internal methods, and refining AI guidelines.

Key Highlights

  • Update Undici to version 8.10.2
  • Upgrade OpenSSL to version 3.5.8
  • Deprecate `Server.prototype._listen2` in `node:net`
  • Update npm to version 11.19.1 and Corepack to version 0.36.0
  • Improve build configurations for RISC-V (riscv64) architectures

Full Release Notes




### Notable Changes

* \[[`616bd3fa26`](https://github.com/nodejs/node/commit/616bd3fa26)] - **doc**: deprecate `Server.prototype._listen2` in `node:net` (Antoine du Hamel) [#65593](https://github.com/nodejs/node/pull/65593)
* \[[`ae1801eb55`](https://github.com/nodejs/node/commit/ae1801eb55)] - **meta**: refine the security vuln posture for experimental features (James M Snell) [#65438](https://github.com/nodejs/node/pull/65438)
* \[[`09feba74c8`](https://github.com/nodejs/node/commit/09feba74c8)] - **deps**: update Undici to 8.10.2 (Node.js GitHub Bot) [#65788](https://github.com/nodejs/node/pull/65788)
* \[[`7efdbe3eb9`](https://github.com/nodejs/node/commit/7efdbe3eb9)] - **deps**: update OpenSSL to 3.5.8 (Node.js GitHub Bot) [#65542](https://github.com/nodejs/node/pull/65542)

### Commits

* \[[`d8aedd6584`](https://github.com/nodejs/node/commit/d8aedd6584)] - **build**: skip dockit on riscv64 (Stewart X Addison) [#62251](https://github.com/nodejs/node/pull/62251)
* \[[`1899c274eb`](https://github.com/nodejs/node/commit/1899c274eb)] - **build**: activate correct default flags for riscv64 (Stewart X Addison) [#65708](https://github.com/nodejs/node/pull/65708)
* \[[`ec8a3be996`](https://github.com/nodejs/node/commit/ec8a3be996)] - **build**: derive NODE\_ARCH from target\_cpu in the GN build (Shelley Vohr) [#65491](https://github.com/nodejs/node/pull/65491)
* \[[`b73118a507`](https://github.com/nodejs/node/commit/b73118a507)] - **build,win**: remove LTO parallelisation limit (Stefan Stojanovic) [#65535](https://github.com/nodejs/node/pull/65535)
* \[[`09feba74c8`](https://github.com/nodejs/node/commit/09feba74c8)] - **deps**: update undici to 8.10.2 (Node.js GitHub Bot) [#65788](https://github.com/nodejs/node/pull/65788)
* \[[`e47c432dd6`](https://github.com/nodejs/node/commit/e47c432dd6)] - **deps**: upgrade npm to 11.19.1 (npm team) [#65573](https://github.com/nodejs/node/pull/65573)
* \[[`2fd6ce36a9`](https://github.com/nodejs/node/commit/2fd6ce36a9)] - **deps**: update corepack to 0.36.0 (Node.js GitHub Bot) [#65653](https://github.com/nodejs/node/pull/65653)
* \[[`49dec2767a`](https://github.com/nodejs/node/commit/49dec2767a)] - **deps**: update googletest to 36ba75f0ad5383a9759f17f3f72fd4661c72cb6d (Node.js GitHub Bot) [#65654](https://github.com/nodejs/node/pull/65654)
* \[[`676174a071`](https://github.com/nodejs/node/commit/676174a071)] - **deps**: update simdjson to 4.6.9 (Node.js GitHub Bot) [#65655](https://github.com/nodejs/node/pull/65655)
* \[[`2f1b7fa0bb`](https://github.com/nodejs/node/commit/2f1b7fa0bb)] - **deps**: update perfetto to 58.2 (Node.js GitHub Bot) [#65656](https://github.com/nodejs/node/pull/65656)
* \[[`12acd0ad15`](https://github.com/nodejs/node/commit/12acd0ad15)] - **deps**: update zlib to 1.3.2.1-motley-5eb4d7e (Node.js GitHub Bot) [#65494](https://github.com/nodejs/node/pull/65494)
* \[[`48631c80fb`](https://github.com/nodejs/node/commit/48631c80fb)] - **deps**: update archs files for openssl-3.5.8 (Node.js GitHub Bot) [#65542](https://github.com/nodejs/node/pull/65542)
* \[[`7efdbe3eb9`](https://github.com/nodejs/node/commit/7efdbe3eb9)] - **deps**: upgrade openssl sources to openssl-3.5.8 (Node.js GitHub Bot) [#65542](https://github.com/nodejs/node/pull/65542)
* \[[`bdc75900ee`](https://github.com/nodejs/node/commit/bdc75900ee)] - **doc**: replace `node:modules` documentation header (René) [#65800](https://github.com/nodejs/node/pull/65800)
* \[[`44c8a499ba`](https://github.com/nodejs/node/commit/44c8a499ba)] - **doc**: clarify return type of `fs.mkdtemp*` (Antoine du Hamel) [#65743](https://github.com/nodejs/node/pull/65743)
* \[[`025fb5eeb0`](https://github.com/nodejs/node/commit/025fb5eeb0)] - **doc**: update `changelog-maker` instructions for releasing (Juan José) [#65707](https://github.com/nodejs/node/pull/65707)
* \[[`5f64847afa`](https://github.com/nodejs/node/commit/5f64847afa)] - **doc**: add stability status to `crypto.setEngine` (Antoine du Hamel) [#65746](https://github.com/nodejs/node/pull/65746)
* \[[`299dee0cb9`](https://github.com/nodejs/node/commit/299dee0cb9)] - **doc**: remove outdated TLS authorized warning (Tim Perry) [#65597](https://github.com/nodejs/node/pull/65597)
* \[[`e97dcc0278`](https://github.com/nodejs/node/commit/e97dcc0278)] - **doc**: fix broken `using` link in ffi.md (Soul Lee) [#65632](https://github.com/nodejs/node/pull/65632)
* \[[`2c9cc7d237`](https://github.com/nodejs/node/commit/2c9cc7d237)] - **doc**: fix some broken links (Antoine du Hamel) [#65583](https://github.com/nodejs/node/pull/65583)
* \[[`0c330ec329`](https://github.com/nodejs/node/commit/0c330ec329)] - **doc**: fix stale TOC in maintaining-dependencies (greenhead) [#65523](https://github.com/nodejs/node/pull/65523)
* \[[`9c522a3a69`](https://github.com/nodejs/node/commit/9c522a3a69)] - **doc**: refactor the AI guidelines (Joyee Cheung) [#65269](https://github.com/nodejs/node/pull/65269)
* \[[`46cbf1bf8c`](https://github.com/nodejs/node/commit/46cbf1bf8c)] - **doc**: fix triggerAsyncId() comment in async\_hooks example (soreavis) [#64583](https://github.com/nodejs/node/pull/64583)
* \[[`788904ff78`](https://github.com/nodejs/node/commit/788904ff78)] - **doc**: fix fsPromises.watch overflow value (Matt Radbourne) [#64605](https://github.com/nodejs/node/pull/64605)
* \[[`3d06ff19e8`](https://github.com/nodejs/node/commit/3d06ff19e8)] - **doc**: clarify stream direction in options.stdio note (Avocado) [#65236](https://github.com/nodejs/node/pull/65236)
* \[[`d334838379`](https://github.com/nodejs/node/commit/d334838379)] - **doc**: clarify signal listener behavior (Som Samantray) [#65243](https://github.com/nodejs/node/pull/65243)
* \[[`d55a2bd56a`](https://github.com/nodejs/node/commit/d55a2bd56a)] - **doc**: add test reporter event lifecycle diagram (sangwook) [#63780](https://github.com/nodejs/node/pull/63780)
* \[[`c17dfc87de`](https://github.com/nodejs/node/commit/c17dfc87de)] - **doc**: discourage AbortSignal cleanup for long-lived resources (Efe Karasakal) [#64342](https://github.com/nodejs/node/pull/64342)
* \[[`616bd3fa26`](https://github.com/nodejs/node/commit/616bd3fa26)] - **doc**: deprecate `Server.prototype._listen2` in `node:net` (Antoine du Hamel) [#65593](https://github.com/nodejs/node/pull/65593)
* \[[`4e6d7e0ca6`](https://github.com/nodejs/node/commit/4e6d7e0ca6)] - **meta**: cleanup targos emeritus changes (Antoine du Hamel) [#65738](https://github.com/nodejs/node/pull/65738)
* \[[`a70cfe1747`](https://github.com/nodejs/node/commit/a70cfe1747)] - **meta**: bump github/codeql-action/init from 4.37.3 to 4.37.9 (dependabot\[bot]) [#65714](https://github.com/nodejs/node/pull/65714)
* \[[`e43a0ad4ce`](https://github.com/nodejs/node/commit/e43a0ad4ce)] - **meta**: bump github/codeql-action/autobuild from 4.37.3 to 4.37.9 (dependabot\[bot]) [#65717](https://github.com/nodejs/node/pull/65717)
* \[[`99e06288f1`](https://github.com/nodejs/node/commit/99e06288f1)] - **meta**: bump actions/checkout from 7.0.0 to 7.0.1 (dependabot\[bot]) [#65718](https://github.com/nodejs/node/pull/65718)
* \[[`89662762b3`](https://github.com/nodejs/node/commit/89662762b3)] - **meta**: bump cachix/install-nix-action from 31.11.0 to 31.11.1 (dependabot\[bot]) [#65719](https://github.com/nodejs/node/pull/65719)
* \[[`6b8f078672`](https://github.com/nodejs/node/commit/6b8f078672)] - **meta**: bump actions/setup-node from 6.4.0 to 7.0.0 (dependabot\[bot]) [#65720](https://github.com/nodejs/node/pull/65720)
* \[[`6c6fb18e63`](https://github.com/nodejs/node/commit/6c6fb18e63)] - **meta**: bump step-security/harden-runner from 2.20.0 to 2.21.0 (dependabot\[bot]) [#65721](https://github.com/nodejs/node/pull/65721)
* \[[`0e002e859f`](https://github.com/nodejs/node/commit/0e002e859f)] - **meta**: bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.9 (dependabot\[bot]) [#65722](https://github.com/nodejs/node/pull/65722)
* \[[`98aaffe4b9`](https://github.com/nodejs/node/commit/98aaffe4b9)] - **meta**: bump github/codeql-action/analyze from 4.37.3 to 4.37.9 (dependabot\[bot]) [#65723](https://github.com/nodejs/node/pull/65723)
* \[[`d247cb2975`](https://github.com/nodejs/node/commit/d247cb2975)] - **meta**: document collaborator automation (Filip Skokan) [#65671](https://github.com/nodejs/node/pull/65671)
* \[[`ae1801eb55`](https://github.com/nodejs/node/commit/ae1801eb55)] - **meta**: refine the security vuln posture for experimental features (James M Snell) [#65438](https://github.com/nodejs/node/pull/65438)
* \[[`fab81d15c3`](https://github.com/nodejs/node/commit/fab81d15c3)] - **test**: widen the gap in the resolver maxTimeout comparison (Shelley Vohr) [#65780](https://github.com/nodejs/node/pull/65780)
* \[[`62e2a6265c`](https://github.com/nodejs/node/commit/62e2a6265c)] - **test**: fix the thread-spawn handshake in the WASI threads fixture (Shelley Vohr) [#65780](https://github.com/nodejs/node/pull/65780)
* \[[`7eb20b1810`](https://github.com/nodejs/node/commit/7eb20b1810)] - **test**: only count restarts after the write in watch emit-restarted test (Shelley Vohr) [#65780](https://github.com/nodejs/node/pull/65780)
* \[[`14c3a77bc5`](https://github.com/nodejs/node/commit/14c3a77bc5)] - **test**: ignore tunnel resets in proxy invalid-char-in-url test (Shelley Vohr) [#65780](https://github.com/nodejs/node/pull/65780)
* \[[`ebc99e0560`](https://github.com/nodejs/node/commit/ebc99e0560)] - **test**: handle EPIPE in closed channel test (Christian Aurich) [#65770](https://github.com/nodejs/node/pull/65770)
* \[[`5e73a2ca79`](https://github.com/nodejs/node/commit/5e73a2ca79)] - **test**: deflake test-permission-net-udp-handle (Christian Aurich) [#65767](https://github.com/nodejs/node/pull/65767)
* \[[`beb669f7de`](https://github.com/nodejs/node/commit/beb669f7de)] - **test**: deflake test-runner-coverage (Christian Aurich) [#65728](https://github.com/nodejs/node/pull/65728)
* \[[`ef4b6bfa62`](https://github.com/nodejs/node/commit/ef4b6bfa62)] - **test**: set type=none on IBM i for empty source (Abdirahim Musse) [#65545](https://github.com/nodejs/node/pull/65545)
* \[[`027eef0691`](https://github.com/nodejs/node/commit/027eef0691)] - **test**: deflake WASI poll timing checks (Filip Skokan) [#65672](https://github.com/nodejs/node/pull/65672)
* \[[`a352b0e2fe`](https://github.com/nodejs/node/commit/a352b0e2fe)] - **test**: skip `fs-watch-recursive-delete-race` on AIX (Antoine du Hamel) [#65698](https://github.com/nodejs/node/pull/65698)
* \[[`f9ce35aa43`](https://github.com/nodejs/node/commit/f9ce35aa43)] - **test**: deflake test-inspect-async-hook-setup-at-inspect (Christian Aurich) [#65584](https://github.com/nodejs/node/pull/65584)
* \[[`32281cec7b`](https://github.com/nodejs/node/commit/32281cec7b)] - **test**: deflake test-watch-mode-restart-esm-loading-error (Christian Aurich) [#65623](https://github.com/nodejs/node/pull/65623)
* \[[`79be5d61be`](https://github.com/nodejs/node/commit/79be5d61be)] - **test**: avoid orphaned child on Windows abort test (Kirill Saied) [#65451](https://github.com/nodejs/node/pull/65451)
* \[[`8972b8540b`](https://github.com/nodejs/node/commit/8972b8540b)] - **test**: fix link-local dgram scope assertion (Filip Skokan) [#65629](https://github.com/nodejs/node/pull/65629)
* \[[`b7cd1d96de`](https://github.com/nodejs/node/commit/b7cd1d96de)] - **test**: riscv64: skip node-api sea test (Stewart X Addison) [#65569](https://github.com/nodejs/node/pull/65569)
* \[[`7eeb9d0e57`](https://github.com/nodejs/node/commit/7eeb9d0e57)] - **test**: mark platform-specific tests as flaky (Filip Skokan) [#65562](https://github.com/nodejs/node/pull/65562)
* \[[`649ac82bda`](https://github.com/nodejs/node/commit/649ac82bda)] - **test**: account for varied OpenSSL CCM final behaviours (Filip Skokan) [#65542](https://github.com/nodejs/node/pull/65542)
* \[[`050fb1a15d`](https://github.com/nodejs/node/commit/050fb1a15d)] - **tools**: bump @humanfs/node from 0.16.7 to 0.16.8 in /tools/eslint (dependabot\[bot]) [#65757](https://github.com/nodejs/node/pull/65757)
* \[[`5314dda396`](https://github.com/nodejs/node/commit/5314dda396)] - **tools**: bump browserslist from 4.28.4 to 4.28.8 in /tools/eslint (dependabot\[bot]) [#65758](https://github.com/nodejs/node/pull/65758)
* \[[`5938a08929`](https://github.com/nodejs/node/commit/5938a08929)] - **tools**: do not hardcode `yamllint` path (Antoine du Hamel) [#65747](https://github.com/nodejs/node/pull/65747)
* \[[`d8408f7415`](https://github.com/nodejs/node/commit/d8408f7415)] - **tools**: refine contributor guidance workflow (Filip Skokan) [#65745](https://github.com/nodejs/node/pull/65745)
* \[[`196e372b69`](https://github.com/nodejs/node/commit/196e372b69)] - **tools**: bump the eslint group in /tools/eslint with 4 updates (dependabot\[bot]) [#65716](https://github.com/nodejs/node/pull/65716)
* \[[`7e986b09f6`](https://github.com/nodejs/node/commit/7e986b09f6)] - **tools**: do not flag force push as invalid message (Antoine du Hamel) [#65700](https://github.com/nodejs/node/pull/65700)
* \[[`837ce2ccef`](https://github.com/nodejs/node/commit/837ce2ccef)] - **tools**: do not hardcode path to Ruff (Antoine du Hamel) [#65681](https://github.com/nodejs/node/pull/65681)
* \[[`1c7149a96a`](https://github.com/nodejs/node/commit/1c7149a96a)] - **tools**: retry first-time contributor query (Filip Skokan) [#65648](https://github.com/nodejs/node/pull/65648)
* \[[`bd310a2bea`](https://github.com/nodejs/node/commit/bd310a2bea)] - **tools**: query first-time contributor status (Filip Skokan) [#65592](https://github.com/nodejs/node/pull/65592)
* \[[`ab7b57e547`](https://github.com/nodejs/node/commit/ab7b57e547)] - **tools**: offset GitHub crons by 3 minutes (Michaël Zasso) [#65612](https://github.com/nodejs/node/pull/65612)
* \[[`62ece28eae`](https://github.com/nodejs/node/commit/62ece28eae)] - **tools**: label PRs lacking second approval (Filip Skokan) [#65538](https://github.com/nodejs/node/pull/65538)
* \[[`68227b4029`](https://github.com/nodejs/node/commit/68227b4029)] - **tools**: welcome first-time contributors (Filip Skokan) [#65533](https://github.com/nodejs/node/pull/65533)
* \[[`490dc93e37`](https://github.com/nodejs/node/commit/490dc93e37)] - **tools**: enable concurrency for eslint (Huáng Jùnliàng) [#62352](https://github.com/nodejs/node/pull/62352)
* \[[`d794676217`](https://github.com/nodejs/node/commit/d794676217)] - **typings**: fix fs\_event\_wrap start filename type (leah-1ee) [#65661](https://github.com/nodejs/node/pull/65661)
* \[[`29e2b5a325`](https://github.com/nodejs/node/commit/29e2b5a325)] - **typings**: add fs\_event\_wrap internal binding types (leah-1ee) [#65661](https://github.com/nodejs/node/pull/65661)
* \[[`6357c8f56e`](https://github.com/nodejs/node/commit/6357c8f56e)] - **typings**: add stream\_pipe internal binding types (Seongeun Lee) [#65664](https://github.com/nodejs/node/pull/65664)
* \[[`569720ac7f`](https://github.com/nodejs/node/commit/569720ac7f)] - **typings**: add profiler internal binding types (Seongeun Lee) [#65660](https://github.com/nodejs/node/pull/65660)
* \[[`52ae89c69d`](https://github.com/nodejs/node/commit/52ae89c69d)] - **typings**: add ffi internal binding types (Donghoon Kang) [#65734](https://github.com/nodejs/node/pull/65734)
* \[[`22c7469062`](https://github.com/nodejs/node/commit/22c7469062)] - **typings**: update zlib binding declarations (이혜미) [#65639](https://github.com/nodejs/node/pull/65639)