PageSourceSearch

https://nodesource.com/blog

html nodesource.com collected 2026-09-24 08:26:53 UTC 270,272 bytes, 1 lines download raw bytes

1<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="stylesheet" href="/_next/static/css/2ee0f2d58117d372.css" data-precedence="next"/><link rel="stylesheet" href="/_next/static/css/f4685ab6d7bf154a.css" data-precedence="next"/><link rel="stylesheet" href="/_next/static/css/a1bf9c83425553a7.css" data-precedence="next"/><link rel="stylesheet" href="/_next/static/css/2dc06cae63eb0e1c.css" data-precedence="next"/><link rel="stylesheet" href="/_next/static/css/8eb4dcc5e54bc624.css" data-precedence="next"/><link rel="stylesheet" href="/_next/static/css/1d9172112cbb9e73.css" data-precedence="next"/><link rel="stylesheet" href="/_next/static/css/0d6c56b467870d9b.css" data-precedence="next"/><link rel="stylesheet" href="/_next/static/css/c7bbeaf23a8f46b6.css" data-precedence="next"/><link rel="stylesheet" href="/_next/static/css/20163c4a24f1ba94.css" data-precedence="next"/><link rel="preload" as="script" fetchPriority="low" href="/_next/static/chunks/webpack-972a2bc86895fbee.js"/>
1<script src="/_next/static/chunks/4bd1b696-f785427dddbba9fb.js" async=""></script>
1<script src="/_next/static/chunks/1255-5c680abb9db89955.js" async=""></script>
1<script src="/_next/static/chunks/main-app-9030513b2ea7c6ba.js" async=""></script>
1<script src="/_next/static/chunks/13b76428-8a44d6718d54fa7a.js" async=""></script>
1<script src="/_next/static/chunks/1356-05a24602620546b0.js" async=""></script>
1<script src="/_next/static/chunks/2619-38012e79151e370a.js" async=""></script>
1<script src="/_next/static/chunks/6581-5a59c9fda9fdaf5d.js" async=""></script>
1<script src="/_next/static/chunks/7965-bf824f1784f24116.js" async=""></script>
1<script src="/_next/static/chunks/3115-89bdcd254bfb768d.js" async=""></script>
1<script src="/_next/static/chunks/app/blog/page-fdd9771c982bc6d0.js" async=""></script>
1<script src="/_next/static/chunks/app/not-found-38ca58a98a2e4b4e.js" async=""></script>
1<script src="/_next/static/chunks/3718-f0bdafb5610c83c6.js" async=""></script>
1<script src="/_next/static/chunks/app/layout-98c333f932313141.js" async=""></script>
1<link rel="preload" href="https://www.chatbase.co/embed.min.js" as="script"/><link rel="preload" href="https://js-na2.hs-scripts.com/242134877.js" as="script"/><link rel="preload" href="https://www.googletagmanager.com/gtag/js?id=G-SB8GG8SJ5E" as="script"/><link rel="preconnect" href="https://turboeagle.co"/><link rel="preconnect" href="https://www.chatbase.co"/><link rel="preconnect" href="https://static.reo.dev"/><link rel="preconnect" href="https://www.googletagmanager.com"/><link rel="preconnect" href="https://www.clarity.ms"/><link rel="preload" as="image" fetchPriority="high" href="https://assets.nodesource.com/website/hero-home-medium.webp"/><meta name="next-size-adjust" content=""/><title>The NodeSource Blog </title><meta name="description" content="Articles about the Node.js Community, How-tos, and Products from NodeSource - The Node.js Company"/><meta name="keywords" content="node.js,nodejs,node,support,training,consulting,hardware,API"/><meta name="google-site-verification" content="GVuZldEHTZHcYj1H2G34YfYv2OHPxfrEXSDMmsEtN38"/><meta property="og:title" content="The NodeSource Blog "/><meta property="og:description" content="Articles about the Node.js Community, How-tos, and Products from NodeSource - The Node.js Company"/><meta property="og:site_name" content="NodeSource"/><meta property="og:image" content="https://nodesource.com/assets/icons/nodesource-1200x630.png"/><meta property="og:image:width" content="600"/><meta property="og:image:height" content="315"/><meta property="og:image:type" content="image/png"/><meta name="twitter:card" content="summary_large_image"/><meta name="twitter:site" content="@nodesource"/><meta name="twitter:creator" content="@nodesource"/><meta name="twitter:title" content="The NodeSource Blog "/><meta name="twitter:description" content="Articles about the Node.js Community, How-tos, and Products from NodeSource - The Node.js Company"/><meta name="twitter:image" content="https://nodesource.com/assets/icons/nodesource-1024x512.png"/><link rel="icon" href="/icon.ico?b781f1b1ea0422ee" type="image/x-icon" sizes="256x256"/>
1<script src="/_next/static/chunks/polyfills-42372ed130431b0a.js" noModule=""></script>
1</head><body class="__className_5f8b59 "><div hidden=""><!--$--><!--/$--></div><nav class="main-navigation  nav-wrapper"><div class="body-width"><a aria-label="logo-nodesource" class="logo" href="/"><svg width="231" height="39" viewBox="0 0 231 39" fill="none" xmlns="http://www.w3.org/2000/svg"><path fill-rule="evenodd" clip-rule="evenodd" d="m26.644 5.872-6.01-3.47h-.002a3.856 3.856 0 0 0-1.934-.532c-.66 0-1.32.178-1.934.533L10.75 5.872l.001.001-6.008 3.468a3.858 3.858 0 0 0-1.429 1.413 3.854 3.854 0 0 0-.51 1.94v13.878c0 .704.178 1.363.51 1.94a3.858 3.858 0 0 0 1.43 1.412l6.007 3.468v.002l6.012 3.469a3.857 3.857 0 0 0 1.934.533c.66 0 1.319-.178 1.934-.533l6.012-3.47 6.007-3.469a3.859 3.859 0 0 0 1.43-1.412c.332-.577.51-1.236.51-1.94V12.694c0-.704-.178-1.364-.51-1.94a3.858 3.858 0 0 0-1.43-1.413l-6.008-3.468.001-.001zm-6.686-2.301 6.01 3.47 6.012 3.468c.232.135.436.296.607.479l-7.144 4.09c-.294-.44-.63-.85-1.001-1.223a8.073 8.073 0 0 0-5.744-2.393 8.074 8.074 0 0 0-5.744 2.393 8.198 8.198 0 0 0-.983 1.196l-7.114-4.114c.16-.162.348-.306.559-.428l12.022-6.938-.001-.002c.18-.103.365-.183.554-.24V9.348a.697.697 0 0 0 .207.486.71.71 0 0 0 1 0 .699.699 0 0 0 .206-.486V3.328c.19.057.375.138.555.241l-.001.002zm-15.74 8.552c-.04.182-.06.373-.06.57v13.879c0 .223.026.438.075.64l5.25-3.048.008-.005a.69.69 0 0 1 .522-.063.72.72 0 0 1 .5.87.695.695 0 0 1-.316.424l-.007.004-5.227 3.035c.136.122.287.231.453.327l12.022 6.939-.001.001c.184.106.373.188.567.245l.006-8.166a8.076 8.076 0 0 1-5.056-2.365 8.17 8.17 0 0 1-2.38-5.777c0-1.216.265-2.37.738-3.407l-7.095-4.103zm15.146 23.826c.203-.058.402-.142.595-.253l-.001-.001 12.022-6.94c.166-.095.317-.204.452-.326l-5.226-3.035-.008-.004a.697.697 0 0 1-.315-.423.719.719 0 0 1 .5-.87.688.688 0 0 1 .522.062l.007.005 5.25 3.048c.05-.203.075-.417.075-.64V12.694c0-.173-.015-.34-.045-.502l-7.095 4.064a8.181 8.181 0 0 1 .724 3.377c0 2.256-.91 4.299-2.38 5.777a8.077 8.077 0 0 1-5.07 2.366l-.006 8.173zm-6.847-19.027 5.5 3.181-.005 6.276a6.705 6.705 0 0 1-4.08-1.952 6.78 6.78 0 0 1-1.975-4.794c0-.964.2-1.88.56-2.71zm.656-1.176c.226-.324.48-.628.758-.908a6.7 6.7 0 0 1 4.767-1.986 6.7 6.7 0 0 1 4.766 1.986c.285.286.544.598.774.93l-5.54 3.173-5.525-3.195zm11.716 1.201-5.511 3.156-.006 6.277a6.704 6.704 0 0 0 4.092-1.953 6.78 6.78 0 0 0 1.975-4.794c0-.954-.196-1.863-.55-2.686z" fill="#5AC878"></path><path d="M56.99 11.537v15.925a1.046 1.046 0 0 1-.693.98 1.024 1.024 0 0 1-1.147-.335L44.513 14.533v12.93c0 .275-.109.54-.302.735a1.028 1.028 0 0 1-1.46 0 1.045 1.045 0 0 1-.302-.736V11.537a1.033 1.033 0 0 1 1.321-1c.206.061.388.185.521.355l10.635 13.574V11.537c0-.276.109-.54.303-.736a1.027 1.027 0 0 1 1.46 0c.193.195.301.46.301.736zm21.176 7.962c0 5.155-3.944 9.35-8.79 9.35-4.847 0-8.791-4.195-8.791-9.35 0-5.155 3.944-9.349 8.79-9.349 4.847 0 8.79 4.195 8.79 9.35zm-2.064 0c0-4.007-3.018-7.268-6.727-7.268-3.71 0-6.727 3.26-6.727 7.268s3.017 7.268 6.727 7.268c3.71 0 6.727-3.26 6.727-7.268zm72.696 0c0 5.155-3.945 9.35-8.791 9.35s-8.79-4.195-8.79-9.35c0-5.155 3.943-9.349 8.79-9.349 4.847 0 8.791 4.195 8.791 9.35zm-2.065 0c0-4.007-3.017-7.268-6.727-7.268-3.71 0-6.727 3.26-6.727 7.268s3.018 7.268 6.727 7.268c3.709 0 6.727-3.26 6.727-7.268zm18.961-9.002c-.274 0-.536.11-.73.304-.193.195-.302.46-.302.736v9.729a5.343 5.343 0 0 1-1.472 3.879 5.258 5.258 0 0 1-3.792 1.624 5.234 5.234 0 0 1-3.791-1.624 5.306 5.306 0 0 1-1.128-1.789 5.362 5.362 0 0 1-.345-2.09v-9.729c0-.276-.108-.54-.302-.736a1.027 1.027 0 0 0-1.459 0c-.194.195-.303.46-.303.736v9.729a7.435 7.435 0 0 0 2.082 5.342 7.33 7.33 0 0 0 2.4 1.65 7.275 7.275 0 0 0 5.693 0 7.33 7.33 0 0 0 2.4-1.65 7.386 7.386 0 0 0 1.576-2.459 7.452 7.452 0 0 0 .505-2.883v-9.729c0-.276-.109-.54-.302-.736a1.028 1.028 0 0 0-.73-.305zm-37.248 11.912a4.677 4.677 0 0 0-1.387-2.03 7.557 7.557 0 0 0-1.921-1.19c-.659-.29-1.341-.522-2.039-.692-.37-.101-.637-.145-1-.228-.306-.064-.61-.128-.905-.207a9.705 9.705 0 0 1-1.663-.574 3.812 3.812 0 0 1-1.226-.855 2.06 2.06 0 0 1-.338-.531 2.096 2.096 0 0 1-.163-.57 2.46 2.46 0 0 1 .111-1.275c.149-.408.403-.768.737-1.043a4.463 4.463 0 0 1 2.36-.929 7.124 7.124 0 0 1 2.337.095c.596.13 1.174.33 1.725.593.362.173.714.367 1.053.581.11.064.218.142.282.184l.1.068.01.006a.924.924 0 0 0 1.296-.223.944.944 0 0 0-.221-1.307l-.39-.296a9.772 9.772 0 0 0-1.244-.787 8.626 8.626 0 0 0-5.177-.983 6.467 6.467 0 0 0-3.468 1.412 4.58 4.58 0 0 0-1.301 1.82c-.072.18-.119.372-.176.56a8.65 8.65 0 0 0-.099.58l-.018.292-.007.147-.004.073.004.114.012.231c.002.09.01.18.023.27a4.194 4.194 0 0 0 1.012 2.294 5.817 5.817 0 0 0 1.898 1.36 11.65 11.65 0 0 0 2.023.705c.339.09.676.162 1.012.232.276.064.658.134.921.21a7.682 7.682 0 0 1 3.087 1.428c.364.28.635.664.779 1.102.143.438.152.909.026 1.352a2.35 2.35 0 0 1-.222.548 1.427 1.427 0 0 1-.172.268c-.061.088-.13.171-.206.247a3.517 3.517 0 0 1-1.101.765 6.599 6.599 0 0 1-2.676.538 5.811 5.811 0 0 1-1.193-.106 7.165 7.165 0 0 1-1.079-.3 9.676 9.676 0 0 1-1.708-.792 10.778 10.778 0 0 1-1.361-.922.923.923 0 0 0-1.296.079.938.938 0 0 0 .05 1.308l.025.024s.135.128.397.345a11.35 11.35 0 0 0 3.197 1.879c.446.169.905.303 1.372.402a7.808 7.808 0 0 0 1.615.168 8.617 8.617 0 0 0 3.517-.726 4.872 4.872 0 0 0 1.822-1.319 4.928 4.928 0 0 0 1.045-2.002l.037-.16.
1017-.116.033-.231.009-.058.01-.095v-.038l.005-.15.007-.304c0-.204-.034-.413-.055-.62a6.127 6.127 0 0 0-.15-.621zm-32.016-2.91c0 5.722-3.668 9.004-10.056 9.004h-3.662c-.274 0-.536-.11-.73-.305a1.045 1.045 0 0 1-.302-.736V11.537c0-.276.109-.54.302-.736.194-.195.456-.305.73-.305h3.662c6.945 0 10.056 4.522 10.056 9.003zm-2.065 0c0-4.204-3.137-6.922-7.992-6.922h-2.63v13.845h2.63c6.606 0 7.992-3.765 7.992-6.923zm17.182-6.922c.273 0 .536-.11.729-.304a1.044 1.044 0 0 0 0-1.472 1.026 1.026 0 0 0-.729-.305h-10.548a1.03 1.03 0 0 0-.953.643 1.043 1.043 0 0 0-.079.398v15.925c0 .276.109.54.303.736.193.195.456.305.729.305h10.55c.274 0 .536-.11.73-.305a1.047 1.047 0 0 0 0-1.472 1.028 1.028 0 0 0-.73-.304h-9.518V20.5h6.684c.273 0 .536-.11.729-.305a1.043 1.043 0 0 0-.729-1.776h-6.686v-5.843h9.518zm106.806 0c.274 0 .536-.11.73-.304a1.047 1.047 0 0 0 0-1.472 1.028 1.028 0 0 0-.73-.305h-10.55a1.022 1.022 0 0 0-.73.305 1.041 1.041 0 0 0-.302.736v15.925c0 .276.108.54.302.736.193.195.456.305.73.305h10.55c.274 0 .536-.11.73-.305a1.047 1.047 0 0 0 0-1.472 1.028 1.028 0 0 0-.73-.304h-9.518V20.5h6.687c.274 0 .537-.11.73-.305.194-.195.302-.46.302-.736 0-.276-.108-.54-.302-.735a1.027 1.027 0 0 0-.73-.305h-6.687v-5.843h9.518zm-34.066 14.285a1.046 1.046 0 0 1-.248 1.45 1.032 1.032 0 0 1-.771.175 1.027 1.027 0 0 1-.668-.425l-5.299-7.568h-4.581v6.968c0 .276-.109.54-.302.736a1.029 1.029 0 0 1-1.46 0 1.047 1.047 0 0 1-.302-.736V11.537c0-.276.109-.54.302-.736.194-.195.456-.305.73-.305h7.326c3.119 0 5.382 2.104 5.382 4.999 0 2.648-1.897 4.627-4.602 4.948l4.493 6.42zm-5.274-8.45c1.954 0 3.318-1.199 3.318-2.917 0-1.718-1.364-2.918-3.318-2.918h-6.293v5.836h6.293zm10.164.244c.048-.244.063-.478.126-.732.115-.511.284-1.01.506-1.484a7.336 7.336 0 0 1 1.814-2.428 7.12 7.12 0 0 1 2.45-1.408 7.64 7.64 0 0 1 2.513-.368 7.43 7.43 0 0 1 3.62 1.063c.309.184.605.39.886.616l.292.25.048.04a.922.922 0 0 0 1.282-.1.938.938 0 0 0-.047-1.296l-.349-.334a9.389 9.389 0 0 0-1.075-.842 8.897 8.897 0 0 0-4.61-1.473 9.52 9.52 0 0 0-3.214.47 9.184 9.184 0 0 0-3.152 1.811 9.426 9.426 0 0 0-2.98 5.033c-.079.332-.117.701-.171 1.054-.02.171-.018.308-.029.463l-.024.506a9.419 9.419 0 0 0 1.761 5.468 9.3 9.3 0 0 0 4.595 3.403c.547.181 1.11.31 1.681.383.254.04.51.064.767.07l.348.017.14.005.096-.003.19-.006a8.862 8.862 0 0 0 4.602-1.474 9.499 9.499 0 0 0 1.088-.854l.316-.307a.941.941 0 0 0 .046-1.301.923.923 0 0 0-1.288-.09l-.009.007-.323.276c-.277.22-.569.422-.873.604a7.39 7.39 0 0 1-3.628 1.063h-.256l-.347-.018a3.932 3.932 0 0 1-.658-.063 7.195 7.195 0 0 1-1.245-.292 7.118 7.118 0 0 1-2.449-1.409 7.289 7.289 0 0 1-1.835-2.471 7.34 7.34 0 0 1-.657-3.015l.021-.401c.014-.137.014-.304.032-.433h-.001zM226.709 12.706a4.451 4.451 0 0 1-1.668-.311 4.569 4.569 0 0 1-1.379-.912 4.484 4.484 0 0 1-.911-1.4 4.737 4.737 0 0 1-.334-1.802c0-.652.111-1.252.334-1.8a4.076 4.076 0 0 1 2.29-2.312 4.19 4.19 0 0 1 1.668-.335c.593 0 1.148.111 1.667.334.519.207.971.511 1.357.911.4.386.711.853.933 1.401.223.549.334 1.15.334 1.801 0 .653-.111 1.253-.334 1.801-.222.534-.533 1.001-.933 1.401-.386.386-.838.69-1.357.912a4.446 4.446 0 0 1-1.667.311zm0-.956c.459 0 .889-.082 1.289-.245.4-.177.741-.415 1.023-.711.297-.311.526-.675.689-1.09.163-.43.245-.904.245-1.423 0-.518-.082-.993-.245-1.423-.163-.43-.392-.8-.689-1.111a2.773 2.773 0 0 0-1.023-.712c-.4-.178-.83-.267-1.289-.267-.475 0-.912.09-1.312.267-.386.163-.727.4-1.023.712a3.465 3.465 0 0 0-.667 1.111c-.163.43-.245.905-.245 1.423 0 .52.082.994.245 1.423.163.415.385.779.667 1.09.296.296.637.534 1.023.711.4.163.837.245 1.312.245zm-1.713-1.312V6.013h1.846c.489 0 .904.112 1.245.334.356.222.534.593.534 1.112 0 .252-.074.489-.223.711a1.279 1.279 0 0 1-.6.512l.978 1.756h-1.178l-.734-1.445h-.756v1.445h-1.112zm1.112-2.246h.512c.252 0 .452-.059.6-.177a.593.593 0 0 0 .222-.49.593.593 0 0 0-.2-.467c-.118-.133-.318-.2-.6-.2h-.534v1.334z" fill="#F5F7F7"></path></svg></a><ul class="primary-nav"><li class="subnav nav-learn"><a id="nav-nsolid">N|Solid <svg width="13" height="13" viewBox="0 0 13 13" fill="none" xmlns="http://www.w3.org/2000/svg"><path fill-rule="evenodd" clip-rule="evenodd" d="M6.559 10.75a.502.502 0 0 1-.354-.146l-5.5-5.5a.502.502 0 0 1 .708-.708l5.146 5.147 5.146-5.147a.502.502 0 0 1 .708.708l-5.5 5.5a.502.502 0 0 1-.354.146" fill="#A3E0B4"></path></svg> <div class="border"></div></a><ul><li><a id="nav-nsolid-overview" href="/products/nsolid/overview">Overview</a><div class="second-border"></div></li><li><a id="nav-nsolid-observability" href="/products/nsolid/keyfeatures#performance-observability">Observability</a><div class="second-border"></div></li><li><a id="nav-nsolid-security" href="/products/nsolid/keyfeatures#security-observability">Security</a><div class="second-border"></div></li><li class="nav-submenu-separator" aria-hidden="true"><span></span></li><li><a id="nav-nsolid-ai" href="/products/copilot">AI</a><div class="second-border"></div></li><li><a id="nav-nsolid-oss-runtime" href="/products/runtime">
1OSS Runtime</a><div class="second-border"></div></li><li><a id="nav-nsolid-ide" href="/products/nsolid/devtools">DevTools</a><div class="second-border"></div></li></ul></li><li class="subnav nav-services"><a id="nav-nodejs">Node.js <svg width="13" height="13" viewBox="0 0 13 13" fill="none" xmlns="http://www.w3.org/2000/svg"><path fill-rule="evenodd" clip-rule="evenodd" d="M6.559 10.75a.502.502 0 0 1-.354-.146l-5.5-5.5a.502.502 0 0 1 .708-.708l5.146 5.147 5.146-5.147a.502.502 0 0 1 .708.708l-5.5 5.5a.502.502 0 0 1-.354.146" fill="#A3E0B4"></path></svg> <div class="border"></div></a><ul><li><a id="nav-nodejs-services" href="/services">Services</a><div class="second-border"></div></li><li class="nav-submenu-separator" aria-hidden="true"><span></span></li><li><a id="nav-nodejs-support" href="/services/support">Support</a><div class="second-border"></div></li><li><a id="nav-nodejs-training" href="/services/training">Training</a><div class="second-border"></div></li><li class="nav-submenu-separator" aria-hidden="true"><span></span></li><li><a id="nav-nodejs-upgrade" href="/products/nodejs-upgrade">Upgrade</a><div class="second-border"></div></li><li><a id="nav-nodejs-distributions" href="/products/distributions">Distributions</a><div class="second-border"></div></li></ul></li><li class="subnav nav-learn"><a id="nav-learn">Solutions <svg width="13" height="13" viewBox="0 0 13 13" fill="none" xmlns="http://www.w3.org/2000/svg"><path fill-rule="evenodd" clip-rule="evenodd" d="M6.559 10.75a.502.502 0 0 1-.354-.146l-5.5-5.5a.502.502 0 0 1 .708-.708l5.146 5.147 5.146-5.147a.502.502 0 0 1 .708.708l-5.5 5.5a.502.502 0 0 1-.354.146" fill="#A3E0B4"></path></svg> <div class="border"></div></a><ul><li><a id="nav-api" href="/solutions/api-integration-microservices">API Integration / Microservices</a><div class="second-border"></div></li><li><a id="nav-performance" href="/solutions/high-performance-applications">High Performance Applications</a><div class="second-border"></div></li><li><a id="nav-legacy" href="/solutions/legacy-application-migration">Legacy Application Migration</a><div class="second-border"></div></li><li><a id="nav-iot" href="/solutions/iot">Internet of Things</a><div class="second-border"></div></li></ul></li><li class="subnav nav-learn"><a id="nav-resource">Resources <svg width="13" height="13" viewBox="0 0 13 13" fill="none" xmlns="http://www.w3.org/2000/svg"><path fill-rule="evenodd" clip-rule="evenodd" d="M6.559 10.75a.502.502 0 0 1-.354-.146l-5.5-5.5a.502.502 0 0 1 .708-.708l5.146 5.147 5.146-5.147a.502.502 0 0 1 .708.708l-5.5 5.5a.502.502 0 0 1-.354.146" fill="#A3E0B4"></path></svg> <div class="border"></div></a><ul><li><a id="nav-blog" href="/blog">Blog</a><div class="second-border"></div></li><li><a href="https://docs.nodesource.com" target="_blank" rel="noreferrer" id="nav-docs">N|Solid Docs</a><div class="second-border"></div></li><li><a id="nav-resources" href="/resources">Knowledge Center</a><div class="second-border"></div></li><li><a href="/pages/approved-partner-program.html">Partner Program</a><div class="second-border"></div></li><li><a href="/infrastructure-cost">
1Infrastructure Cost</a><div class="second-border"></div></li></ul></li><li class="subnav nav-company"><a id="nav-company">Company <svg width="13" height="13" viewBox="0 0 13 13" fill="none" xmlns="http://www.w3.org/2000/svg"><path fill-rule="evenodd" clip-rule="evenodd" d="M6.559 10.75a.502.502 0 0 1-.354-.146l-5.5-5.5a.502.502 0 0 1 .708-.708l5.146 5.147 5.146-5.147a.502.502 0 0 1 .708.708l-5.5 5.5a.502.502 0 0 1-.354.146" fill="#A3E0B4"></path></svg> <div class="border"></div></a><ul><li><a href="https://pages.nodesource.com/contact-us.html" target="_blank" rel="noreferrer" data-event-category="contact" data-event-action="view-contact-form" data-event-label="company-subnav-" class="track-link crosspage-link" id="nav-contact">Contact Us</a><div class="second-border"></div></li><li><a id="nav-about" href="/about">About</a><div class="second-border"></div></li><li><a id="nav-press" href="/press">Press</a><div class="second-border"></div></li></ul></li></ul><div class="buttons-cta"><div class="cta-area"><div><a class="black button track-link crosspage-link button-demo size-button">BOOK A DEMO</a></div><a href="https://accounts.nodesource.com/sign-in" target="_blank" rel="noreferrer" data-event-category="accounts" data-event-action="view-signin-form" data-event-label="nav-signin-cta" class="black button track-link crosspage-link" id="signinNav">SIGN IN/SIGN UP</a><a href="https://nodesource.com/pages/contact-us.html" target="_blank" rel="noreferrer" data-event-category="accounts" data-event-action="view-accounts-form" data-event-label="nav-accounts-cta" class="track-link crosspage-link" id="supportContactNav">CONTACT US</a></div></div></div></nav><nav class="mobile-navigation"><menu class="mobile-menu "><ul class="mobile-menu-primary"><li class="subnav nav-learn"><a id="nav-nsolid" class="main-option">N|Solid <svg width="13" height="13" viewBox="0 0 13 13" fill="none" xmlns="http://www.w3.org/2000/svg"><path fill-rule="evenodd" clip-rule="evenodd" d="M6.559 10.75a.502.502 0 0 1-.354-.146l-5.5-5.5a.502.502 0 0 1 .708-.708l5.146 5.147 5.146-5.147a.502.502 0 0 1 .708.708l-5.5 5.5a.502.502 0 0 1-.354.146" fill="#A3E0B4"></path></svg></a><ul><li><a id="nav-nsolid-overview" href="/products/nsolid/overview">Overview</a></li><li><a id="nav-nsolid-observability" href="/products/nsolid/keyfeatures#performance-observability">Observability</a></li><li><a id="nav-nsolid-security" href="/products/nsolid/keyfeatures#security-observability">Security</a></li><li class="nav-submenu-separator" aria-hidden="true"><span></span></li><li><a id="nav-nsolid-ai" href="/products/copilot">AI</a></li><li><a id="nav-nsolid-oss-runtime" href="/products/runtime">OSS Runtime</a></li><li><a id="nav-nsolid-ide" href="/products/nsolid/devtools">DevTools</a></li></ul></li><li class="subnav nav-services"><a id="nav-nodejs" class="main-option">Node.js <svg width="13" height="13" viewBox="0 0 13 13" fill="none" xmlns="http://www.w3.org/2000/svg"><path fill-rule="evenodd" clip-rule="evenodd" d="M6.559 10.75a.502.502 0 0 1-.354-.146l-5.5-5.5a.502.502 0 0 1 .708-.708l5.146 5.147 5.146-5.147a.502.502 0 0 1 .708.708l-5.5 5.5a.502.502 0 0 1-.354.146" fill="#A3E0B4"></path></svg></a><ul><li><a id="nav-nodejs-services" href="/services">Services</a></li><li class="nav-submenu-separator" aria-hidden="true"><span></span></li><li><a id="nav-nodejs-support" href="/services/support">Support</a></li><li><a id="nav-nodejs-training" href="/services/training">Training</a></li><li class="nav-submenu-separator" aria-hidden="true"><span></span></li><li><a id="nav-nodejs-upgrade" href="/products/nodejs-upgrade">Upgrade</a></li><li><a id="nav-nodejs-distributions" href="/products/distributions">Distributions</a></li></ul></li><li class="subnav nav-learn"><a id="nav-learn" class="main-option">Solutions <svg width="13" height="13" viewBox="0 0 13 13" fill="none" xmlns="http://www.w3.org/2000/svg"><path fill-rule="evenodd" clip-rule="evenodd" d="M6.559 10.75a.502.502 0 0 1-.354-.146l-5.5-5.5a.502.502 0 0 1 .708-.708l5.146 5.147 5.146-5.147a.502.502 0 0 1 .708.708l-5.5 5.5a.502.502 0 0 1-.354.146" fill="#A3E0B4"></path></svg></a><ul><li><a id="nav-api" href="/solutions/api-integration-microservices">API Integration / Microservices</a></li><li><a id="nav-performance" href="/solutions/high-performance-applications">High Performance Applications</a></li><li><a id="nav-legacy" href="/solutions/legacy-application-migration">Legacy Application Migration</a></li><li><a id="nav-iot" href="/solutions/iot">Internet of Things</a></li></ul></li><li class="subnav nav-learn"><a id="nav-resource" class="main-option">Resources <svg width="13" height="13" viewBox="0 0 13 13" fill="none" xmlns="http://www.w3.org/2000/svg"><path fill-rule="evenodd" clip-rule="evenodd" d="M6.559 10.75a.502.502 0 0 1-.354-.146l-5.5-5.5a.502.502 0 0 1 .708-.708l5.146 5.147 5.146-5.147a.502.502 0 0 1 .708.708l-5.5 5.5a.502.502 0 0 1-.354.146" fill="#A3E0B4"></path></svg></a><ul><li><a id="nav-blog" href="/blog">Blog</a></li><li><a href="https://docs.nodesource.com" target="_blank" rel="noreferrer" id="nav-docs">N|Solid Docs</a></li><li><a href="/resources">Knowledge Center</a></li><li><a href="/pages/approved-partner-program.html">Partner Program</a></li><li>
1<a href="/infrastructure-cost">Infrastructure Cost</a></li></ul></li><li class="subnav nav-company"><a id="nav-company" class="main-option">Company <svg width="13" height="13" viewBox="0 0 13 13" fill="none" xmlns="http://www.w3.org/2000/svg"><path fill-rule="evenodd" clip-rule="evenodd" d="M6.559 10.75a.502.502 0 0 1-.354-.146l-5.5-5.5a.502.502 0 0 1 .708-.708l5.146 5.147 5.146-5.147a.502.502 0 0 1 .708.708l-5.5 5.5a.502.502 0 0 1-.354.146" fill="#A3E0B4"></path></svg></a><ul><li><a href="https://pages.nodesource.com/contact-us.html" target="_blank" rel="noreferrer" data-event-category="contact" data-event-action="view-contact-form" data-event-label="company-subnav-" class="track-link crosspage-link" id="nav-contact">Contact Us</a></li><li><a id="nav-about" href="/about">About</a></li><li><a id="nav-press" href="/press">Press</a></li></ul></li></ul><div><div><a class="black button track-link crosspage-link signin-button size-button">BOOK A DEMO</a></div><a href="https://accounts.nodesource.com/sign-in" target="_blank" rel="noreferrer" data-event-category="accounts" data-event-action="view-signin-form" data-event-label="nav-signin-cta" class="black button track-link crosspage-link signin-button" id="signinNav">SIGN IN/SIGN UP</a><div class="nav-icons"><a href="http://github.com/nodesource" target="_blank" rel="noreferrer" class="icon" aria-label="icon-github"><span class="icon-github"></span></a><a href="http://twitter.com/nodesource" target="_blank" rel="noreferrer" class="icon" aria-label="icon-twitter"><svg xmlns="http://www.w3.org/2000/svg" width="16" height="14" fill="none"><path fill="#89A19D" d="M12.13 0h2.36L9.33 5.93 15.4 14h-4.75L6.93 9.1 2.67 14H.3l5.52-6.34L0 0h4.87l3.37 4.47L12.13 0Zm-.83 12.58h1.3L4.17 1.35h-1.4l8.54 11.23Z"></path></svg></a><a href="https://www.youtube.com/@NodeSourceHQ" target="_blank" rel="noreferrer" class="icon" aria-label="icon-youtube"><span class="icon-youtube"></span></a><a href="https://www.linkedin.com/company/nodesource" target="_blank" rel="noreferrer" class="icon class-x" aria-label="icon-linkedin"><svg width="17" height="17" viewBox="0 0 17 17" fill="none" xmlns="http://www.w3.org/2000/svg"><g clip-path="url(#t5hvczzbja)"><path d="M15.1.56H1.467c-.653 0-1.18.515-1.18 1.152v13.69a1.17 1.17 0 0 0 1.18 1.157h13.635c.653 0 1.184-.519 1.184-1.153V1.712c0-.637-.531-1.153-1.184-1.153zM5.033 14.192H2.657V6.557h2.375v7.638zM3.845 5.515a1.376 1.376 0 1 1-.005-2.751 1.376 1.376 0 0 1 .005 2.751zm10.075 8.678h-2.372v-3.712c0-.884-.016-2.025-1.235-2.025-1.234 0-1.422.966-1.422 1.963v3.774H6.523V6.557h2.275V7.6h.03c.317-.6 1.092-1.235 2.245-1.235 2.403 0 2.846 1.582 2.846 3.638v4.19z" fill="#89A19D"></path></g><defs><clipPath id="t5hvczzbja"><path fill="#fff" transform="translate(.285 .56)" d="M0 0h16v16H0z"></path></clipPath></defs></svg></a></div></div></menu><a class="nav-toggle " aria-label="toogle-menu" href="#"><div class="hamburger"><svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg"><path fill="#353D3E" d="M0 0h40v40H0z"></path><path fill="#A3E0B4" d="M8 13h24v2H8z"></path><path fill="#85D69A" d="M8 19h24v2H8z"></path><path fill="#5AC878" d="M8 25h24v2H8z"></path></svg></div><div class="close"><svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg"><rect width="40" height="40" fill="#4C5859"></rect><rect x="12.2218" y="11" width="24" height="2" transform="rotate(45 12.2218 11)" fill="#5AC878"></rect><rect x="10.8076" y="28" width="24" height="2" transform="rotate(-45 10.8076 28)" fill="#5AC878"></rect></svg></div></a><a aria-label="logo-nodesource" class="logo" href="/"><svg width="231" height="39" viewBox="0 0 231 39" fill="none" xmlns="http://www.w3.org/2000/svg"><path fill-rule="evenodd" clip-rule="evenodd" d="m26.644 5.872-6.01-3.47h-.002a3.856 3.856 0 0 0-1.934-.532c-.66 0-1.32.178-1.934.533L10.75 5.872l.001.001-6.008 3.468a3.858 3.858 0 0 0-1.429 1.413 3.854 3.854 0 0 0-.51 1.94v13.878c0 .704.178 1.363.51 1.94a3.858 3.858 0 0 0 1.43 1.412l6.007 3.468v.002l6.012 3.469a3.857 3.857 0 0 0 1.934.533c.66 0 1.319-.178 1.934-.533l6.012-3.47 6.00
17-3.469a3.859 3.859 0 0 0 1.43-1.412c.332-.577.51-1.236.51-1.94V12.694c0-.704-.178-1.364-.51-1.94a3.858 3.858 0 0 0-1.43-1.413l-6.008-3.468.001-.001zm-6.686-2.301 6.01 3.47 6.012 3.468c.232.135.436.296.607.479l-7.144 4.09c-.294-.44-.63-.85-1.001-1.223a8.073 8.073 0 0 0-5.744-2.393 8.074 8.074 0 0 0-5.744 2.393 8.198 8.198 0 0 0-.983 1.196l-7.114-4.114c.16-.162.348-.306.559-.428l12.022-6.938-.001-.002c.18-.103.365-.183.554-.24V9.348a.697.697 0 0 0 .207.486.71.71 0 0 0 1 0 .699.699 0 0 0 .206-.486V3.328c.19.057.375.138.555.241l-.001.002zm-15.74 8.552c-.04.182-.06.373-.06.57v13.879c0 .223.026.438.075.64l5.25-3.048.008-.005a.69.69 0 0 1 .522-.063.72.72 0 0 1 .5.87.695.695 0 0 1-.316.424l-.007.004-5.227 3.035c.136.122.287.231.453.327l12.022 6.939-.001.001c.184.106.373.188.567.245l.006-8.166a8.076 8.076 0 0 1-5.056-2.365 8.17 8.17 0 0 1-2.38-5.777c0-1.216.265-2.37.738-3.407l-7.095-4.103zm15.146 23.826c.203-.058.402-.142.595-.253l-.001-.001 12.022-6.94c.166-.095.317-.204.452-.326l-5.226-3.035-.008-.004a.697.697 0 0 1-.315-.423.719.719 0 0 1 .5-.87.688.688 0 0 1 .522.062l.007.005 5.25 3.048c.05-.203.075-.417.075-.64V12.694c0-.173-.015-.34-.045-.502l-7.095 4.064a8.181 8.181 0 0 1 .724 3.377c0 2.256-.91 4.299-2.38 5.777a8.077 8.077 0 0 1-5.07 2.366l-.006 8.173zm-6.847-19.027 5.5 3.181-.005 6.276a6.705 6.705 0 0 1-4.08-1.952 6.78 6.78 0 0 1-1.975-4.794c0-.964.2-1.88.56-2.71zm.656-1.176c.226-.324.48-.628.758-.908a6.7 6.7 0 0 1 4.767-1.986 6.7 6.7 0 0 1 4.766 1.986c.285.286.544.598.774.93l-5.54 3.173-5.525-3.195zm11.716 1.201-5.511 3.156-.006 6.277a6.704 6.704 0 0 0 4.092-1.953 6.78 6.78 0 0 0 1.975-4.794c0-.954-.196-1.863-.55-2.686z" fill="#5AC878"></path><path d="M56.99 11.537v15.925a1.046 1.046 0 0 1-.693.98 1.024 1.024 0 0 1-1.147-.335L44.513 14.533v12.93c0 .275-.109.54-.302.735a1.028 1.028 0 0 1-1.46 0 1.045 1.045 0 0 1-.302-.736V11.537a1.033 1.033 0 0 1 1.321-1c.206.061.388.185.521.355l10.635 13.574V11.537c0-.276.109-.54.303-.736a1.027 1.027 0 0 1 1.46 0c.193.195.301.46.301.736zm21.176 7.962c0 5.155-3.944 9.35-8.79 9.35-4.847 0-8.791-4.195-8.791-9.35 0-5.155 3.944-9.349 8.79-9.349 4.847 0 8.79 4.195 8.79 9.35zm-2.064 0c0-4.007-3.018-7.268-6.727-7.268-3.71 0-6.727 3.26-6.727 7.268s3.017 7.268 6.727 7.268c3.71 0 6.727-3.26 6.727-7.268zm72.696 0c0 5.155-3.945 9.35-8.791 9.35s-8.79-4.195-8.79-9.35c0-5.155 3.943-9.349 8.79-9.349 4.847 0 8.791 4.195 8.791 9.35zm-2.065 0c0-4.007-3.017-7.268-6.727-7.268-3.71 0-6.727 3.26-6.727 7.268s3.018 7.268 6.727 7.268c3.709 0 6.727-3.26 6.727-7.268zm18.961-9.002c-.274 0-.536.11-.73.304-.193.195-.302.46-.302.736v9.729a5.343 5.343 0 0 1-1.472 3.879 5.258 5.258 0 0 1-3.792 1.624 5.234 5.234 0 0 1-3.791-1.624 5.306 5.306 0 0 1-1.128-1.789 5.362 5.362 0 0 1-.345-2.09v-9.729c0-.276-.108-.54-.302-.736a1.027 1.027 0 0 0-1.459 0c-.194.195-.303.46-.303.736v9.729a7.435 7.435 0 0 0 2.082 5.342 7.33 7.33 0 0 0 2.4 1.65 7.275 7.275 0 0 0 5.693 0 7.33 7.33 0 0 0 2.4-1.65 7.386 7.386 0 0 0 1.576-2.459 7.452 7.452 0 0 0 .505-2.883v-9.729c0-.276-.109-.54-.302-.736a1.028 1.028 0 0 0-.73-.305zm-37.248 11.912a4.677 4.677 0 0 0-1.387-2.03 7.557 7.557 0 0 0-1.921-1.19c-.659-.29-1.341-.522-2.039-.692-.37-.101-.637-.145-1-.228-.306-.064-.61-.128-.905-.207a9.705 9.705 0 0 1-1.663-.574 3.812 3.812 0 0 1-1.226-.855 2.06 2.06 0 0 1-.338-.531 2.096 2.096 0 0 1-.163-.57 2.46 2.46 0 0 1 .111-1.275c.149-.408.403-.768.737-1.043a4.463 4.463 0 0 1 2.36-.929 7.124 7.124 0 0 1 2.337.095c.596.13 1.174.33 1.725.593.362.173.714.367 1.053.581.11.064.218.142.282.184l.1.068.01.006a.924.924 0 0 0 1.296-.223.944.944 0 0 0-.221-1.307l-.39-.296a9.772 9.772 0 0 0-1.244-.787 8.626 8.626 0 0 0-5.177-.983 6.467 6.467 0 0 0-3.468 1.412 4.58 4.58 0 0 0-1.301 1.82c-.072.18-.119.372-.176.56a8.65 8.65 0 0 0-.099.58l-.018.292-.007.147-.004.073.004.114.012.231c.002.09.01.18.023.27a4.194 4.194 0 0 0 1.012 2.294 5.817 5.817 0 0 0 1.898 1.36 11.65 11.65 0 0 0 2.023.705c.339.09.676.162 1.012.232.276.064.658.134.921.21a7.682 7.682 0 0 1 3.087 1.428c.364.28.635.664.779 1.102.143.438.152.909.026 1.352a2.35 2.35 0 0 1-.222.548 1.427 1.427 0 0 1-.172.268c-.061.088-.13.171-.206.247a3.517 3.517 0 0 1-1.101.765 6.599 6.599 0 0 1-2.676.538 5.811 5.811 0 0 1-1.193-.106 7.165 7.165 0 0 1-1.079-.3 9.676 9.676 0 0 1-1.708-.792 10.778 10.778 0 0 1-1.361-.922.923.923 0 0 0-1.296.079.938.938 0 0 0 .05 1.308l.025.024s.135.128.397.345a11.35 11.35 0 0 0 3.197 1.879c.446.169.905.303 1.372.402a7.808 7.808 0 0 0 1.615.168 8.617 8.617 0 0 0 3.517-.726 4.872 4.872 0 0 0 1.822-1.319 4.928 4.928 0 0 0 1.045-2.002l.037-.16.
1017-.116.033-.231.009-.058.01-.095v-.038l.005-.15.007-.304c0-.204-.034-.413-.055-.62a6.127 6.127 0 0 0-.15-.621zm-32.016-2.91c0 5.722-3.668 9.004-10.056 9.004h-3.662c-.274 0-.536-.11-.73-.305a1.045 1.045 0 0 1-.302-.736V11.537c0-.276.109-.54.302-.736.194-.195.456-.305.73-.305h3.662c6.945 0 10.056 4.522 10.056 9.003zm-2.065 0c0-4.204-3.137-6.922-7.992-6.922h-2.63v13.845h2.63c6.606 0 7.992-3.765 7.992-6.923zm17.182-6.922c.273 0 .536-.11.729-.304a1.044 1.044 0 0 0 0-1.472 1.026 1.026 0 0 0-.729-.305h-10.548a1.03 1.03 0 0 0-.953.643 1.043 1.043 0 0 0-.079.398v15.925c0 .276.109.54.303.736.193.195.456.305.729.305h10.55c.274 0 .536-.11.73-.305a1.047 1.047 0 0 0 0-1.472 1.028 1.028 0 0 0-.73-.304h-9.518V20.5h6.684c.273 0 .536-.11.729-.305a1.043 1.043 0 0 0-.729-1.776h-6.686v-5.843h9.518zm106.806 0c.274 0 .536-.11.73-.304a1.047 1.047 0 0 0 0-1.472 1.028 1.028 0 0 0-.73-.305h-10.55a1.022 1.022 0 0 0-.73.305 1.041 1.041 0 0 0-.302.736v15.925c0 .276.108.54.302.736.193.195.456.305.73.305h10.55c.274 0 .536-.11.73-.305a1.047 1.047 0 0 0 0-1.472 1.028 1.028 0 0 0-.73-.304h-9.518V20.5h6.687c.274 0 .537-.11.73-.305.194-.195.302-.46.302-.736 0-.276-.108-.54-.302-.735a1.027 1.027 0 0 0-.73-.305h-6.687v-5.843h9.518zm-34.066 14.285a1.046 1.046 0 0 1-.248 1.45 1.032 1.032 0 0 1-.771.175 1.027 1.027 0 0 1-.668-.425l-5.299-7.568h-4.581v6.968c0 .276-.109.54-.302.736a1.029 1.029 0 0 1-1.46 0 1.047 1.047 0 0 1-.302-.736V11.537c0-.276.109-.54.302-.736.194-.195.456-.305.73-.305h7.326c3.119 0 5.382 2.104 5.382 4.999 0 2.648-1.897 4.627-4.602 4.948l4.493 6.42zm-5.274-8.45c1.954 0 3.318-1.199 3.318-2.917 0-1.718-1.364-2.918-3.318-2.918h-6.293v5.836h6.293zm10.164.244c.048-.244.063-.478.126-.732.115-.511.284-1.01.506-1.484a7.336 7.336 0 0 1 1.814-2.428 7.12 7.12 0 0 1 2.45-1.408 7.64 7.64 0 0 1 2.513-.368 7.43 7.43 0 0 1 3.62 1.063c.309.184.605.39.886.616l.292.25.048.04a.922.922 0 0 0 1.282-.1.938.938 0 0 0-.047-1.296l-.349-.334a9.389 9.389 0 0 0-1.075-.842 8.897 8.897 0 0 0-4.61-1.473 9.52 9.52 0 0 0-3.214.47 9.184 9.184 0 0 0-3.152 1.811 9.426 9.426 0 0 0-2.98 5.033c-.079.332-.117.701-.171 1.054-.02.171-.018.308-.029.463l-.024.506a9.419 9.419 0 0 0 1.761 5.468 9.3 9.3 0 0 0 4.595 3.403c.547.181 1.11.31 1.681.383.254.04.51.064.767.07l.348.017.14.005.096-.003.19-.006a8.862 8.862 0 0 0 4.602-1.474 9.499 9.499 0 0 0 1.088-.854l.316-.307a.941.941 0 0 0 .046-1.301.923.923 0 0 0-1.288-.09l-.009.007-.323.276c-.277.22-.569.422-.873.604a7.39 7.39 0 0 1-3.628 1.063h-.256l-.347-.018a3.932 3.932 0 0 1-.658-.063 7.195 7.195 0 0 1-1.245-.292 7.118 7.118 0 0 1-2.449-1.409 7.289 7.289 0 0 1-1.835-2.471 7.34 7.34 0 0 1-.657-3.015l.021-.401c.014-.137.014-.304.032-.433h-.001zM226.709 12.706a4.451 4.451 0 0 1-1.668-.311 4.569 4.569 0 0 1-1.379-.912 4.484 4.484 0 0 1-.911-1.4 4.737 4.737 0 0 1-.334-1.802c0-.652.111-1.252.334-1.8a4.076 4.076 0 0 1 2.29-2.312 4.19 4.19 0 0 1 1.668-.335c.593 0 1.148.111 1.667.334.519.207.971.511 1.357.911.4.386.711.853.933 1.401.223.549.334 1.15.334 1.801 0 .653-.111 1.253-.334 1.801-.222.534-.533 1.001-.933 1.401-.386.386-.838.69-1.357.912a4.446 4.446 0 0 1-1.667.311zm0-.956c.459 0 .889-.082 1.289-.245.4-.177.741-.415 1.023-.711.297-.311.526-.675.689-1.09.163-.43.245-.904.245-1.423 0-.518-.082-.993-.245-1.423-.163-.43-.392-.8-.689-1.111a2.773 2.773 0 0 0-1.023-.712c-.4-.178-.83-.267-1.289-.267-.475 0-.912.09-1.312.267-.386.163-.727.4-1.023.712a3.465 3.465 0 0 0-.667 1.111c-.163.43-.245.905-.245 1.423 0 .52.082.994.245 1.423.163.415.385.779.667 1.09.296.296.637.534 1.023.711.4.163.837.245 1.312.245zm-1.713-1.312V6.013h1.846c.489 0 .904.112 1.245.334.356.222.534.593.534 1.112 0 .252-.074.489-.223.711a1.279 1.279 0 0 1-.6.512l.978 1.756h-1.178l-.734-1.445h-.756v1.445h-1.112zm1.112-2.246h.512c.252 0 .452-.059.6-.177a.593.593 0 0 0 .222-.49.593.593 0 0 0-.2-.467c-.118-.133-.318-.2-.6-.2h-.534v1.334z" fill="#F5F7F7"></path></svg></a></nav><main><div><header id="blog-header"><div class="content-container"><div><h1 class="hero-title"><a href="/blog">The NodeSource Blog</a></h1><a id="rss-link" href="/blog/rss"><svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 60 60"><path d="M7.826 56.087c0 2.16-1.752 3.913-3.913 3.913S0 58.248 0 56.087s1.752-3.913 3.913-3.913 3.913 1.752 3.913 3.913zM3.913 0C3.193 0 2.61.583 2.61 1.304s.582 1.304 1.303 1.304c29.488 0 53.478 23.99 53.478 53.477 0 .72.587 1.304 1.308 1.304S60 56.803 60 56.082C60 25.16 34.84 0 3.913 0zm0 18.26c-.72 0-1.304.584-1.304 1.305 0 .72.58 1.304 1.3 1.304 19.42 0 35.217 15.793 35.217 35.212 0 .72.582 1.304 1.303 1.304.72 0 1.305-.584 1.305-1.305 0-20.855-16.968-37.823-37.825-37.823zm0 18.262c-.72 0-1.304.583-1.304 1.304s.58 1.304 1.3 1.304c9.35 0 16.957 7.606 16.95
17 16.955 0 .72.582 1.304 1.303 1.304.72 0 1.305-.587 1.305-1.308 0-10.786-8.776-19.563-19.565-19.563z"></path></svg></a></div><div id="search-box"><div id="search-link"><svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><g id="exportable"><path d="M9.42 18.838a9.42 9.42 0 1 1 6.662-2.756 9.4 9.4 0 0 1-6.663 2.756zm0-17.792A8.373 8.373 0 1 0 15.34 3.5a8.35 8.35 0 0 0-5.92-2.454z" class="search-1"></path><path d="M16.082 15.342l7.572 6.832a1.048 1.048 0 0 1-1.4 1.557c-.027-.022-.053-.05-.076-.074l-6.832-7.572a.524.524 0 0 1 .74-.74z" class="search-1"></path></g></svg></div><input type="search" id="search-input" placeholder="Search"/></div></div></header><section class="two-column blog"><div class="body-width two-column-layout"><div class="two-column-left blog-content"><div class="breadcrumbs"><h1 class="category">All Posts</h1></div><div class="post-list"><article id="nodesource-weekly-sept-22-2026-nodejs-26-10-ai-security-nodeconf-eu" class="post-list-item"><div class="post-header"><a href="/blog/nodesource-weekly-sept-22-2026-nodejs-26-10-ai-security-nodeconf-eu"><img alt="nodesource-weekly-sept-22-2026-nodejs-26-10-ai-security-nodeconf-eu" loading="lazy" width="314" height="177" decoding="async" data-nimg="1" style="color:transparent" srcSet="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_12_6b29b70a88.png 1x, https://assets.nodesource.com/strapi-uploads/Linked_In_Article_12_6b29b70a88.png 2x" src="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_12_6b29b70a88.png"/></a></div><div class="post-preview"><h3 class="post-title"><a href="/blog/nodesource-weekly-sept-22-2026-nodejs-26-10-ai-security-nodeconf-eu">NodeSource Weekly — Sept 22, 2026: Node.js 26.10.0, AI Security &amp; NodeConf EU</a></h3><p class="post-meta">In <a href="/blog/category/Newsletter">newsletter</a>  on <span class="post-date" data-date="2026-09-22T17:14:45.291Z">Sep 22 2026</span></p><p class="post-description">NodeSource Weekly covers Node.js 26.9.0 and 26.10.0, AI-assisted development security, NodeConf EU 2026, and the Node.js Upgrade Program.</p><p class="blog-read-more"><a class="small button more" href="/blog/nodesource-weekly-sept-22-2026-nodejs-26-10-ai-security-nodeconf-eu">Read More</a></p></div></article><article id="correct-code-wrong-baseline-ai-assisted-nodejs-security" class="post-list-item"><div class="post-header"><a href="/blog/correct-code-wrong-baseline-ai-assisted-nodejs-security"><img alt="correct-code-wrong-baseline-ai-assisted-nodejs-security" loading="lazy" width="314" height="177" decoding="async" data-nimg="1" style="color:transparent" srcSet="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_11_8ff32fa814.png 1x, https://assets.nodesource.com/strapi-uploads/Linked_In_Article_11_8ff32fa814.png 2x" src="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_11_8ff32fa814.png"/></a></div><div class="post-preview"><h3 class="post-title"><a href="/blog/correct-code-wrong-baseline-ai-assisted-nodejs-security">Correct Code, Wrong Baseline: The Hidden Security Risk of AI-Assisted Node.js Development</a></h3><p class="post-meta">In <a href="/blog/category/ai">ai</a>  on <span class="post-date" data-date="2026-09-17T18:29:41.704Z">Sep 17 2026</span></p><p class="post-description">AI can generate correct Node.js code while choosing outdated runtimes or vulnerable dependencies. Learn why current baselines matter for security.</p><p class="blog-read-more"><a class="small button more" href="/blog/correct-code-wrong-baseline-ai-assisted-nodejs-security">Read More</a></p></div></article><article id="nodesource-weekly-nodejs-24-21-0-nsolid-growth-ai-agents" class="post-list-item"><div class="post-header"><a href="/blog/nodesource-weekly-nodejs-24-21-0-nsolid-growth-ai-agents"><img alt="nodesource-weekly-nodejs-24-21-0-nsolid-growth-ai-agents" loading="lazy" width="314" height="177" decoding="async" data-nimg="1" style="color:transparent" srcSet="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_9_8d9427dd47.png 1x, https://assets.nodesource.com/strapi-uploads/Linked_In_Article_9_8d9427dd47.png 2x" src="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_9_8d9427dd47.png"/></a></div><div class="post-preview"><h3 class="post-title"><a href="/blog/nodesource-weekly-nodejs-24-21-0-nsolid-growth-ai-agents">NodeSource Weekly — Sept 15, 2026: Node.js 24.21.0, N|Solid Growth &amp; AI Agents</a></h3><p class="post-meta">
1In <a href="/blog/category/Newsletter">newsletter</a>  on <span class="post-date" data-date="2026-09-15T17:29:29.778Z">Sep 15 2026</span></p><p class="post-description">Catch up on Node.js 24.21.0 and 26.8.2, N|Solid&#x27;s 98% August growth, 2.5K DevTools downloads, NodeConf EU, and the latest AI agent updates.</p><p class="blog-read-more"><a class="small button more" href="/blog/nodesource-weekly-nodejs-24-21-0-nsolid-growth-ai-agents">Read More</a></p></div></article><article id="nsolid-downloads-98-percent-growth-nodejs-runtime-adoption" class="post-list-item"><div class="post-header"><a href="/blog/nsolid-downloads-98-percent-growth-nodejs-runtime-adoption"><img alt="nsolid-downloads-98-percent-growth-nodejs-runtime-adoption" loading="lazy" width="314" height="177" decoding="async" data-nimg="1" style="color:transparent" srcSet="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_7_0bc438f52a.png 1x, https://assets.nodesource.com/strapi-uploads/Linked_In_Article_7_0bc438f52a.png 2x" src="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_7_0bc438f52a.png"/></a></div><div class="post-preview"><h3 class="post-title"><a href="/blog/nsolid-downloads-98-percent-growth-nodejs-runtime-adoption">N|Solid Downloads Surged 98% in August 2026 — What It Says About Node.js Runtime Adoption</a></h3><p class="post-meta">In <a href="/blog/category/product">Product</a>  on <span class="post-date" data-date="2026-09-10T15:52:32.479Z">Sep 10 2026</span></p><p class="post-description">N|Solid reached 1.15M+ downloads in 2026, with 98% growth in August. See what the latest data shows about Node.js runtime adoption and version trends.</p><p class="blog-read-more"><a class="small button more" href="/blog/nsolid-downloads-98-percent-growth-nodejs-runtime-adoption">Read More</a></p></div></article><article id="risk-behind-103m-eol-nodejs-downloads" class="post-list-item"><div class="post-header"><a href="/blog/risk-behind-103m-eol-nodejs-downloads"><img alt="risk-behind-103m-eol-nodejs-downloads" loading="lazy" width="314" height="177" decoding="async" data-nimg="1" style="color:transparent" srcSet="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_6_6dd95f8ce2.png 1x, https://assets.nodesource.com/strapi-uploads/Linked_In_Article_6_6dd95f8ce2.png 2x" src="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_6_6dd95f8ce2.png"/></a></div><div class="post-preview"><h3 class="post-title"><a href="/blog/risk-behind-103m-eol-nodejs-downloads">The Risk Behind 103M EOL Node.js Downloads</a></h3><p class="post-meta">In <a href="/blog/category/node-js">Node.js</a>  on <span class="post-date" data-date="2026-09-08T20:26:17.406Z">Sep 08 2026</span></p><p class="post-description">103M Node.js 20 downloads in July 2026 show EOL adoption is still widespread. Explore why teams stay on unsupported versions and the risks involved.</p><p class="blog-read-more"><a class="small button more" href="/blog/risk-behind-103m-eol-nodejs-downloads">Read More</a></p></div></article><article id="nodesource-weekly-sept-8-2026-eol-nodejs-risk-undici-security-nsolid-downloads" class="post-list-item"><div class="post-header"><a href="/blog/nodesource-weekly-sept-8-2026-eol-nodejs-risk-undici-security-nsolid-downloads"><img alt="nodesource-weekly-sept-8-2026-eol-nodejs-risk-undici-security-nsolid-downloads" loading="lazy" width="314" height="177" decoding="async" data-nimg="1" style="color:transparent" srcSet="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_5_a9ca3329df.png 1x, https://assets.nodesource.com/strapi-uploads/Linked_In_Article_5_a9ca3329df.png 2x" src="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_5_a9ca3329df.png"/></a></div><div class="post-preview"><h3 class="post-title"><a href="/blog/nodesource-weekly-sept-8-2026-eol-nodejs-risk-undici-security-nsolid-downloads">NodeSource Weekly — Sept 8, 2026: The Risk Behind 103M EOL Node.js Downloads, Undici Security Fixes &amp; 1.15M N|Solid Downloads</a></h3><p class="post-meta">In <a href="/blog/category/Newsletter">newsletter</a>  on <span class="post-date" data-date="2026-09-08T18:56:56.108Z">Sep 08 2026</span></p><p class="post-description">Explore the risk behind 103M EOL Node.js 20 downloads, new Undici security fixes, N|Solid’s 1.15M download milestone, AI updates, and Node.js community news.</p><p class="blog-read-more"><a class="small button more" href="/blog/nodesource-weekly-sept-8-2026-eol-nodejs-risk-undici-security-nsolid-downloads">Read More</a></p></div></article><article id="nodesource-weekly-sept-1-2026-ai-agents-nodejs-devtools-community" class="post-list-item"><div class="post-header"><a href="/blog/nodesource-weekly-sept-1-2026-ai-agents-nodejs-devtools-community"><img alt="nodesource-weekly-sept-1-2026-ai-agents-nodejs-devtools-community" loading="lazy" width="314" height="177" decoding="async" data-nimg="1" style="color:transparent" srcSet="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_3_1bc55aff4a.png 1x, https://assets.nodesource.com/strapi-uploads/Linked_In_Article_3_1bc55aff4a.png 2x" src="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_3_1bc55aff4a.png"/></a></div><div class="post-preview"><h3 class="post-title"><a href="/blog/nodesource-weekly-sept-1-2026-ai-agents-nodejs-devtools-community">NodeSource Weekly — Sept 1, 2026: New Node.js releases, N|Solid Plugin v1.0.3 &amp; the road to Node.js 26 LTS</a></h3><p class="post-meta">
1In <a href="/blog/category/Newsletter">newsletter</a>  on <span class="post-date" data-date="2026-09-01T17:36:46.816Z">Sep 01 2026</span></p><p class="post-description">Explore this week’s Node.js updates, N|Solid DevTools, AI coding agent workflows, NodeConf EU 2026, and the Node.js Upgrade Program.</p><p class="blog-read-more"><a class="small button more" href="/blog/nodesource-weekly-sept-1-2026-ai-agents-nodejs-devtools-community">Read More</a></p></div></article><article id="nodejs-downloads-2026-node-24-adoption" class="post-list-item"><div class="post-header"><a href="/blog/nodejs-downloads-2026-node-24-adoption"><img alt="nodejs-downloads-2026-node-24-adoption" loading="lazy" width="314" height="177" decoding="async" data-nimg="1" style="color:transparent" srcSet="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_2_29d5649ff8.png 1x, https://assets.nodesource.com/strapi-uploads/Linked_In_Article_2_29d5649ff8.png 2x" src="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_2_29d5649ff8.png"/></a></div><div class="post-preview"><h3 class="post-title"><a href="/blog/nodejs-downloads-2026-node-24-adoption">Node.js Downloads Surge in 2026 as Node.js 24 Takes the Lead</a></h3><p class="post-meta">In <a href="/blog/category/node-js">Node.js</a>  on <span class="post-date" data-date="2026-08-27T19:30:13.090Z">Aug 27 2026</span></p><p class="post-description">Official Node.js download data shows 2026 has already surpassed 2025 totals, while Node.js 24 leads for the first time. See what the data means for LTS adoption, EOL risk, and modernization. </p><p class="blog-read-more"><a class="small button more" href="/blog/nodejs-downloads-2026-node-24-adoption">Read More</a></p></div></article><article id="nodesource-weekly-august-25-2026-ai-agents-nodejs-devtools-community" class="post-list-item"><div class="post-header"><a href="/blog/nodesource-weekly-august-25-2026-ai-agents-nodejs-devtools-community"><img alt="nodesource-weekly-august-25-2026-ai-agents-nodejs-devtools-community" loading="lazy" width="314" height="177" decoding="async" data-nimg="1" style="color:transparent" srcSet="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_1_e6064c0ec4.png 1x, https://assets.nodesource.com/strapi-uploads/Linked_In_Article_1_e6064c0ec4.png 2x" src="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_1_e6064c0ec4.png"/></a></div><div class="post-preview"><h3 class="post-title"><a href="/blog/nodesource-weekly-august-25-2026-ai-agents-nodejs-devtools-community">NodeSource Weekly — Aug 25, 2026: AI Agents, Node.js DevTools &amp; Community</a></h3><p class="post-meta">In <a href="/blog/category/Newsletter">newsletter</a>  on <span class="post-date" data-date="2026-08-25T20:12:41.907Z">Aug 25 2026</span></p><p class="post-description">Explore this week’s NodeSource updates on AI coding agents, N|Solid DevTools, Node.js community events, dependency security, and the Node.js Upgrade Program.</p><p class="blog-read-more"><a class="small button more" href="/blog/nodesource-weekly-august-25-2026-ai-agents-nodejs-devtools-community">Read More</a></p></div></article><article id="nodejs-upgrade-things-that-can-break-before-you-migrate" class="post-list-item"><div class="post-header"><a href="/blog/nodejs-upgrade-things-that-can-break-before-you-migrate"><img alt="nodejs-upgrade-things-that-can-break-before-you-migrate" loading="lazy" width="314" height="177" decoding="async" data-nimg="1" style="color:transparent" srcSet="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_31aa3b9095.png 1x, https://assets.nodesource.com/strapi-uploads/Linked_In_Article_31aa3b9095.png 2x" src="https://assets.nodesource.com/strapi-uploads/Linked_In_Article_31aa3b9095.png"/></a></div><div class="post-preview"><h3 class="post-title"><a href="/blog/nodejs-upgrade-things-that-can-break-before-you-migrate">Node.js Upgrade: 5 Things That Can Break Before You Migrate</a></h3><p class="post-meta">In <a href="/blog/category/upgrade-program">Upgrade Program</a>  on <span class="post-date" data-date="2026-08-20T22:17:44.815Z">Aug 20 2026</span></p><p class="post-description">Planning a Node.js upgrade? Learn the 5 areas that can break during migration, from native addons and dependencies to OpenSSL, APIs, CI, and OS compatibility.</p><p class="blog-read-more"><a class="small button more" href="/blog/nodejs-upgrade-things-that-can-break-before-you-migrate">Read More</a></p></div></article><article id="Update-Node.js-versions-on-linux" class="post-list-item"><div class="post-header"><a href="/blog/Update-Node.js-versions-on-linux"><img alt="Update-Node.js-versions-on-linux" loading="lazy" width="314" height="177" decoding="async" data-nimg="1" style="color:transparent" srcSet="https://assets.nodesource.com/strapi-uploads/twitter-Update-Node.js-versions-on-linux_98ebf54158.png 1x, https://assets.nodesource.com/strapi-uploads/twitter-Update-Node.js-versions-on-linux_98ebf54158.png 2x" src="https://assets.nodesource.com/strapi-uploads/twitter-Update-Node.js-versions-on-linux_98ebf54158.png"/></a></div><div class="post-preview"><h3 class="post-title"><a href="/blog/Update-Node.js-versions-on-linux">How to Update Node.js Versions on Linux</a></h3><p class="post-meta">  on <span class="post-date" data-date="2026-08-19T21:18:10.543Z">Aug 19 2026</span></p><p class="post-description">
1 This guide will walk you through multiple methods: using a package manager, nvm, NodeSource distribution binaries, and manually downloading </p><p class="blog-read-more"><a class="small button more" href="/blog/Update-Node.js-versions-on-linux">Read More</a></p></div></article><article id="update-Node.js-versions-on-MacOS" class="post-list-item"><div class="post-header"><a href="/blog/update-Node.js-versions-on-MacOS"><img alt="update-Node.js-versions-on-MacOS" loading="lazy" width="314" height="177" decoding="async" data-nimg="1" style="color:transparent" srcSet="https://assets.nodesource.com/strapi-uploads/twitter-update-Node.js-versions-on-MacOS_7711428d33.png 1x, https://assets.nodesource.com/strapi-uploads/twitter-update-Node.js-versions-on-MacOS_7711428d33.png 2x" src="https://assets.nodesource.com/strapi-uploads/twitter-update-Node.js-versions-on-MacOS_7711428d33.png"/></a></div><div class="post-preview"><h3 class="post-title"><a href="/blog/update-Node.js-versions-on-MacOS">How to Update Node.js Versions on MacOS</a></h3><p class="post-meta">In <a href="/blog/category/node-js-1">Node.js</a>  on <span class="post-date" data-date="2026-08-19T21:18:00.281Z">Aug 19 2026</span></p><p class="post-description">In this guide, we’ll walk through different methods to updated Node.js in MacOS, including Homebrew, Node Version Manager (nvm), and manual installation.</p><p class="blog-read-more"><a class="small button more" href="/blog/update-Node.js-versions-on-MacOS">Read More</a></p></div></article></div><nav class="pagination" role="navigation"><div class="previous"><button class="active newer-posts" disabled="">PREV</button></div><div class="page-number">1<!-- --> / <!-- -->57</div><div class="next"><button class="active older-posts">NEXT</button></div></nav></div><div class="two-column-right"><div class="sidebar"><div class="featured-posts"><h4>Featured Articles</h4><ul><li><a href="/blog/owning-agentic-sdlc-ai-development-orchestration">Owning the Agentic SDLC: How NodeSource Reclaimed Control of AI Development</a><p class="post-meta">In  <a href="/blog/category/ai">ai</a>  on <!-- -->Aug 12 2026</p></li><li><a href="/blog/2-million-runtime-downloads-nsolid">2 Million Runtime Downloads: Thank You for Trusting N|Solid</a><p class="post-meta">In  <a href="/blog/category/nodesource">NodeSource</a>  on <!-- -->Jul 16 2026</p></li><li><a href="/blog/introducing-nsolid-plugin-ai-coding-agents">Introducing the N|Solid Plugin for AI Coding Agents</a><p class="post-meta">In  <a href="/blog/category/ai">ai</a>  on <!-- -->Jul 08 2026</p></li></ul></div><div class="categories"><h4>Categories</h4><ul><li><a title="ai" class="category-ai}" href="/blog/category/ai">ai</a></li><li><a title="Community" class="category-Community}" href="/blog/category/community">Community</a></li><li><a title="Debugging" class="category-Debugging}" href="/blog/category/debugging">Debugging</a></li><li><a title="How To" class="category-How To}" href="/blog/category/how-to">How To</a></li><li><a title="newsletter" class="category-newsletter}" href="/blog/category/Newsletter">newsletter</a></li><li><a title="Node.js" class="category-Node.js}" href="/blog/category/node-js-1">Node.js</a></li><li><a title="Node.js" class="category-Node.js}" href="/blog/category/node-js">Node.js</a></li><li><a title="NodeSource" class="category-NodeSource}" href="/blog/category/nodesource">NodeSource</a></li><li><a title="Observability" class="category-Observability}" href="/blog/category/observability">Observability</a></li><li><a title="Product" class="category-Product}" href="/blog/category/product">Product</a></li><li><a title="Security" class="category-Security}" href="/blog/category/security">Security</a></li><li><a title="Upgrade Program" class="category-Upgrade Program}" href="/blog/category/upgrade-program">Upgrade Program</a></li></ul></div></div></div></div></section></div><!--$--><!--/$--></main><footer class="main-footer-wrap"><div class="main-footer content-container"><div id="footer-logo"><a href="/" aria-label="icon-nodesource"><svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 100 100"><path d="M89.243 20.864L55.642 1.5a11.21 11.21 0 0 0-11.2 0L10.778 20.937a11.208 11.208 0 0 0-5.6 9.7l-.032 38.781a11.2 11.2 0 0 0 5.611 9.718L44.359 98.5a11.208 11.208 0 0 0 11.2 0l33.663-19.437a11.206 11.206 0 0 0 5.6-9.7l.028-38.784a11.2 11.2 0 0 0-5.607-9.715zM46.36 4.823a7.338 7.338 0 0 1 1.723-.718v16.552a1.917 1.917 0 0 0 3.834 0V4.079a7.369 7.369 0 0 1 1.81.741l33.6 19.366a7.322 7.322 0 0 1 1.522 1.169L68.486 37.113a22.518 22.518 0 0 0-36.983.014L11.186 25.418a7.329 7.329 0 0 1 1.51-1.16zM68.713 50a18.74 18.74 0 0 1-16.8 18.616V51.107l15.149-8.746A18.579 18.579 0 0 1 68.713 50zm-35.785-7.626l15.155 8.734v17.508a18.679 18.679 0 0 1-15.155-26.242zM50 47.786l-15.149-8.729a18.651 18.651 0 0 1 30.288-.012zM12.672 75.813a7.284 7.284 0 0 1-1.522-1.168l13.117-7.574a1.918 1.918 0 0 0-1.918-3.321L9.232 71.323a7.316 7.316 0 0 1-.251-1.9l.029-38.786a7.274 7.274 0 0 1 .254-1.9l20.318 11.71a22.53 22.53 0 0 0 18.5 32.015v22.945a1.9 1.9 0 0 0 .083.53 7.351 7.351 0 0 1-1.892-.757zm40.969 19.364a7.362 7.362 0 0 1-1.8.741 1.919 1.919 0 0 0 .077-.511V72.461A22.533 22.533 0 0 0 70.411 40.43l20.357-11.754a7.329 7.329 0 0 1 .251 1.9l-.028 38.784a7.33 7.33 0 0 1-.264 1.937L77.651 63.75a1.918 1.918 0 0 0-1.918 3.321l13.053 7.536a7.3 7.3 0 0 1-1.481 1.135z" fill="#89a19d"></path></svg></a><div class="social-links"><a class="icon" href="http://github.com/nodesource" aria-label="icon-github"><span class="icon-github"></span></a><a class="icon class-x" href="http://twitter.com/nodesource" aria-label="icon-twitter"><svg xmlns="http://www.w3.org/2000/svg" width="16" height="14" fill="none"><path fill="#89A19D" d="M12.13 0h2.36L9.33 5.93 15.4 14h-4.75L6.93 9.1 2.67 14H.3l5.52-6.34L0 0h4.87l3.37 4.47L12.13 0Zm-.83 12.58h1.3L4.17 1.35h-1.4l8.54 11.23Z"></path></svg></a><a class="icon" href="https://www.youtube.com/@NodeSourceHQ" aria-label="icon-youtube"><span class="icon-youtube"></span></a><a class="icon class-x" href="https://www.linkedin.com/company/nodesource" aria-label="icon-linkedin"><svg width="17" height="17" viewBox="0 0 17 17" fill="none" xmlns="http://www.w3.org/2000/svg"><g clip-path="url(#t5hvczzbja)"><path d="M15.1.56H1.467c-.653 0-1.18.515-1.18 1.152v13.69a1.17 1.17 0 0 0 1.18 1.157h13.635c.653 
10 1.184-.519 1.184-1.153V1.712c0-.637-.531-1.153-1.184-1.153zM5.033 14.192H2.657V6.557h2.375v7.638zM3.845 5.515a1.376 1.376 0 1 1-.005-2.751 1.376 1.376 0 0 1 .005 2.751zm10.075 8.678h-2.372v-3.712c0-.884-.016-2.025-1.235-2.025-1.234 0-1.422.966-1.422 1.963v3.774H6.523V6.557h2.275V7.6h.03c.317-.6 1.092-1.235 2.245-1.235 2.403 0 2.846 1.582 2.846 3.638v4.19z" fill="#89A19D"></path></g><defs><clipPath id="t5hvczzbja"><path fill="#fff" transform="translate(.285 .56)" d="M0 0h16v16H0z"></path></clipPath></defs></svg></a></div><p class="main-footer-fine-print">© <!-- -->2026<!-- --> NodeSource</p></div><div id="footer-links"><ul class="main-footer-links"><li class="section">What We Do</li><li><a href="/products/nsolid">N|Solid</a></li><li><a href="/products/pricing">Product Pricing</a></li><li><a href="/services">NodeSource Services</a></li></ul><ul class="main-footer-links"><li class="section">Solutions</li><li><a href="/solutions/api-integration-microservices">Microservices</a></li><li><a href="/solutions/high-traffic-applications">High Traffic</a></li><li><a href="/solutions/legacy-application-migration">Legacy Applications</a></li><li><a href="/solutions/iot">Internet of Things</a></li></ul><ul class="main-footer-links"><li class="section">Learn</li><li><a href="/blog">Blog</a></li><li><a href="/resources">Resources</a></li><li><a href="https://support.nodesource.com">Support Portal</a></li><li><a href="https://docs.nodesource.com" target="_blank" rel="noreferrer">Documentation</a></li></ul><ul class="main-footer-links"><li class="section">Company</li><li><a href="https://pages.nodesource.com/contact-us.html" target="_blank" rel="noreferrer">Contact Us</a></li><li><a href="/about">About NodeSource</a></li><li><a href="/press">Press</a></li><li><a href="/legal">Legal</a></li><li><a href="/privacy">Privacy Policy</a></li></ul></div></div></footer>
1<script src="/_next/static/chunks/webpack-972a2bc86895fbee.js" id="_R_" async=""></script>
1<script>(self.__next_f=self.__next_f||[]).push([0])</script>
1<script>self.__next_f.push([1,"1:\"$Sreact.fragment\"\n2:I[2285,[\"586\",\"static/chunks/13b76428-8a44d6718d54fa7a.js\",\"1356\",\"static/chunks/1356-05a24602620546b0.js\",\"2619\",\"static/chunks/2619-38012e79151e370a.js\",\"6581\",\"static/chunks/6581-5a59c9fda9fdaf5d.js\",\"7965\",\"static/chunks/7965-bf824f1784f24116.js\",\"3115\",\"static/chunks/3115-89bdcd254bfb768d.js\",\"3831\",\"static/chunks/app/blog/page-fdd9771c982bc6d0.js\"],\"Template\"]\n3:I[9766,[],\"\"]\n4:I[8924,[],\"\"]\n5:I[2988,[\"1356\",\"static/chunks/1356-05a24602620546b0.js\",\"2619\",\"static/chunks/2619-38012e79151e370a.js\",\"4345\",\"static/chunks/app/not-found-38ca58a98a2e4b4e.js\"],\"default\"]\n6:I[5281,[\"586\",\"static/chunks/13b76428-8a44d6718d54fa7a.js\",\"1356\",\"static/chunks/1356-05a24602620546b0.js\",\"2619\",\"static/chunks/2619-38012e79151e370a.js\",\"6581\",\"static/chunks/6581-5a59c9fda9fdaf5d.js\",\"3718\",\"static/chunks/3718-f0bdafb5610c83c6.js\",\"7965\",\"static/chunks/7965-bf824f1784f24116.js\",\"3115\",\"static/chunks/3115-89bdcd254bfb768d.js\",\"7177\",\"static/chunks/app/layout-98c333f932313141.js\"],\"CookieBanner\"]\n7:I[1402,[\"586\",\"static/chunks/13b76428-8a44d6718d54fa7a.js\",\"1356\",\"static/chunks/1356-05a24602620546b0.js\",\"2619\",\"static/chunks/2619-38012e79151e370a.js\",\"6581\",\"static/chunks/6581-5a59c9fda9fdaf5d.js\",\"3718\",\"static/chunks/3718-f0bdafb5610c83c6.js\",\"7965\",\"static/chunks/7965-bf824f1784f24116.js\",\"3115\",\"static/chunks/3115-89bdcd254bfb768d.js\",\"7177\",\"static/chunks/app/layout-98c333f932313141.js\"],\"\"]\n10:I[7150,[],\"\"]\n11:I[8332,[\"586\",\"static/chunks/13b76428-8a44d6718d54fa7a.js\",\"1356\",\"static/chunks/1356-05a24602620546b0.js\",\"2619\",\"static/chunks/2619-38012e79151e370a.js\",\"6581\",\"static/chunks/6581-5a59c9fda9fdaf5d.js\",\"3718\",\"static/chunks/3718-f0bdafb5610c83c6.js\",\"7965\",\"static/chunks/7965-bf824f1784f24116.js\",\"3115\",\"static/chunks/3115-89bdcd254bfb768d.js\",\"7177\",\"static/chunks/app/layout-98c333f932313141.js\"],\"GoogleAnalytics\"]\n13:I[4431,[],\"OutletBoundary\"]\n15:I[5278,[],\"AsyncMetadataOutlet\"]\n17:I[4431,[],\"ViewportBoundary\"]\n19:I[4431,[],\"MetadataBoundary\"]\n1a:\"$Sreact.suspense\"\n1c:I[622,[],\"IconMark\"]\n:"])</script>
1<script>self.__next_f.push([1,"HL[\"/_next/static/media/443896d591e4f761-s.p.woff2\",\"font\",{\"crossOrigin\":\"\",\"type\":\"font/woff2\"}]\n:HL[\"/_next/static/media/9cf9c6e84ed13b5e-s.p.woff2\",\"font\",{\"crossOrigin\":\"\",\"type\":\"font/woff2\"}]\n:HL[\"/_next/static/css/2ee0f2d58117d372.css\",\"style\"]\n:HL[\"/_next/static/css/f4685ab6d7bf154a.css\",\"style\"]\n:HL[\"/_next/static/css/a1bf9c83425553a7.css\",\"style\"]\n:HL[\"/_next/static/css/2dc06cae63eb0e1c.css\",\"style\"]\n:HL[\"/_next/static/css/8eb4dcc5e54bc624.css\",\"style\"]\n:HL[\"/_next/static/css/1d9172112cbb9e73.css\",\"style\"]\n:HL[\"/_next/static/css/0d6c56b467870d9b.css\",\"style\"]\n:HL[\"/_next/static/css/c7bbeaf23a8f46b6.css\",\"style\"]\n:HL[\"/_next/static/css/20163c4a24f1ba94.css\",\"style\"]\n8:T992,"])</script>
1<script>self.__next_f.push([1,"\n            (function() {\n              try {\n                // List of paths where Autopilot SHOULD run\n                const allowedPaths = [\n                  '/pages/contact-us',\n                  '/blog',\n                  '/about',\n                  '/' // homepage\n                ];\n                \n                // Check if current path is allowed\n                const currentPath = window.location.pathname;\n                const isAllowed = allowedPaths.some(path =\u003e \n                  currentPath === path || // exact match\n                  (path !== '/' \u0026\u0026 currentPath.startsWith(path)) // prefix match, but not for homepage\n                );\n                \n                if (!isAllowed) {\n                  console.debug('Autopilot: Path not configured for Autopilot:', currentPath);\n                  return;\n                }\n\n                // Original Autopilot code\n                (function(o){\n                  var b=\"https://turboeagle.co/anywhere/\",\n                      t=\"e890757b77294cb0ae1c1079cc3cca1767c81f1c14f9463988ff2e06b09796ab\",\n                      a=window.AutopilotAnywhere={_runQueue:[],run:function(){this._runQueue.push(arguments);}},\n                      c=encodeURIComponent,\n                      s=\"SCRIPT\",\n                      d=document,\n                      l=d.getElementsByTagName(s)[0],\n                      p=\"t=\"+c(d.title||\"\")+\"\u0026u=\"+c(d.location.href||\"\")+\"\u0026r=\"+c(d.referrer||\"\"),\n                      j=\"text/javascript\";\n                  \n                  if(!window.Autopilot) window.Autopilot=a;\n                  if(o.app) p=\"devmode=true\u0026\"+p;\n                  \n                  var z=function(src,asy){\n                    try {\n                      var e=d.createElement(s);\n                      e.src=src;\n                      e.type=j;\n                      e.async=asy;\n                      if(l \u0026\u0026 l.parentNode) {\n                        l.parentNode.insertBefore(e,l);\n                      }\n                    } catch(err) {\n                      console.warn('Autopilot: Error inserting script:', err);\n                    }\n                  };\n                  \n                  window.addEventListener('load', function() {\n                    z(b+t+'?'+p,true);\n                  });\n                })({});\n              } catch(error) {\n                console.warn('Autopilot: Failed to initialize:', error);\n              }\n            })();"])</script>
1<script>self.__next_f.push([1,"0:{\"P\":null,\"b\":\"m9Oz7vpzBOlkvJ-P_PL2i\",\"p\":\"\",\"c\":[\"\",\"blog\"],\"i\":false,\"f\":[[[\"\",{\"children\":[\"blog\",{\"children\":[\"__PAGE__\",{}]}]},\"$undefined\",\"$undefined\",true],[\"\",[\"$\",\"$1\",\"c\",{\"children\":[[[\"$\",\"link\",\"0\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/2ee0f2d58117d372.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\",\"nonce\":\"$undefined\"}],[\"$\",\"link\",\"1\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/f4685ab6d7bf154a.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\",\"nonce\":\"$undefined\"}],[\"$\",\"link\",\"2\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/a1bf9c83425553a7.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\",\"nonce\":\"$undefined\"}],[\"$\",\"link\",\"3\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/2dc06cae63eb0e1c.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\",\"nonce\":\"$undefined\"}],[\"$\",\"link\",\"4\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/8eb4dcc5e54bc624.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\",\"nonce\":\"$undefined\"}],[\"$\",\"link\",\"5\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/1d9172112cbb9e73.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\",\"nonce\":\"$undefined\"}],[\"$\",\"link\",\"6\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/0d6c56b467870d9b.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\",\"nonce\":\"$undefined\"}],[\"$\",\"link\",\"7\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/c7bbeaf23a8f46b6.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\",\"nonce\":\"$undefined\"}]],[\"$\",\"html\",null,{\"lang\":\"en\",\"suppressHydrationWarning\":true,\"children\":[[\"$\",\"head\",null,{\"children\":[[\"$\",\"link\",null,{\"rel\":\"preconnect\",\"href\":\"https://turboeagle.co\"}],[\"$\",\"link\",null,{\"rel\":\"preconnect\",\"href\":\"https://www.chatbase.co\"}],[\"$\",\"link\",null,{\"rel\":\"preconnect\",\"href\":\"https://static.reo.dev\"}],[\"$\",\"link\",null,{\"rel\":\"preconnect\",\"href\":\"https://www.googletagmanager.com\"}],[\"$\",\"link\",null,{\"rel\":\"preconnect\",\"href\":\"https://www.clarity.ms\"}],[\"$\",\"link\",null,{\"rel\":\"preload\",\"as\":\"image\",\"fetchPriority\":\"high\",\"href\":\"https://assets.nodesource.com/website/hero-home-medium.webp\"}]]}],[\"$\",\"body\",null,{\"className\":\"__className_5f8b59 \",\"suppressHydrationWarning\":true,\"children\":[[\"$\",\"$L2\",null,{\"children\":[\"$\",\"$L3\",null,{\"parallelRouterKey\":\"children\",\"error\":\"$undefined\",\"errorStyles\":\"$undefined\",\"errorScripts\":\"$undefined\",\"template\":[\"$\",\"$L4\",null,{}],\"templateStyles\":\"$undefined\",\"templateScripts\":\"$undefined\",\"notFound\":[[\"$\",\"$L5\",null,{}],[[\"$\",\"link\",\"0\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/27bf97a5fe0bf147.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\",\"nonce\":\"$undefined\"}]]],\"forbidden\":\"$undefined\",\"unauthorized\":\"$undefined\"}]}],[\"$\",\"$L6\",null,{}],[\"$\",\"$L7\",null,{\"id\":\"autopilot\",\"strategy\":\"afterInteractive\",\"defer\":true,\"dangerouslySetInnerHTML\":{\"__html\":\"$8\"}}],\"$L9\",\"$La\",\"$Lb\",\"$Lc\"]}]]}]]}],{\"children\":[\"blog\",\"$Ld\",{\"children\":[\"__PAGE__\",\"$Le\",{},null,false]},null,false]},null,false],\"$Lf\",false]],\"m\":\"$undefined\",\"G\":[\"$10\",[]],\"s\":false,\"S\":false}\n"])</script>
1<script>self.__next_f.push([1,"9:[\"$\",\"$L7\",null,{\"id\":\"chatbot-config\",\"strategy\":\"afterInteractive\",\"dangerouslySetInnerHTML\":{\"__html\":\"window.embeddedChatbotConfig = {\\n              chatbotId: \\\"g3oqFIq-zvqpF9WL3YcQ0\\\",\\n              domain: \\\"www.chatbase.co\\\"\\n            }\"}}]\na:[\"$\",\"$L7\",null,{\"id\":\"chatbot-script\",\"src\":\"https://www.chatbase.co/embed.min.js\",\"strategy\":\"afterInteractive\",\"defer\":true}]\nb:[\"$\",\"$L7\",null,{\"type\":\"text/javascript\",\"id\":\"hs-script-loader\",\"src\":\"https://js-na2.hs-scripts.com/242134877.js\",\"strategy\":\"afterInteractive\",\"async\":true,\"defer\":true}]\nc:[\"$\",\"$L11\",null,{\"gaId\":\"G-SB8GG8SJ5E\"}]\nd:[\"$\",\"$1\",\"c\",{\"children\":[null,[\"$\",\"$L3\",null,{\"parallelRouterKey\":\"children\",\"error\":\"$undefined\",\"errorStyles\":\"$undefined\",\"errorScripts\":\"$undefined\",\"template\":[\"$\",\"$L4\",null,{}],\"templateStyles\":\"$undefined\",\"templateScripts\":\"$undefined\",\"notFound\":\"$undefined\",\"forbidden\":\"$undefined\",\"unauthorized\":\"$undefined\"}]]}]\ne:[\"$\",\"$1\",\"c\",{\"children\":[\"$L12\",[[\"$\",\"link\",\"0\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/20163c4a24f1ba94.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\",\"nonce\":\"$undefined\"}]],[\"$\",\"$L13\",null,{\"children\":[\"$L14\",[\"$\",\"$L15\",null,{\"promise\":\"$@16\"}]]}]]}]\nf:[\"$\",\"$1\",\"h\",{\"children\":[null,[[\"$\",\"$L17\",null,{\"children\":\"$L18\"}],[\"$\",\"meta\",null,{\"name\":\"next-size-adjust\",\"content\":\"\"}]],[\"$\",\"$L19\",null,{\"children\":[\"$\",\"div\",null,{\"hidden\":true,\"children\":[\"$\",\"$1a\",null,{\"fallback\":null,\"children\":\"$L1b\"}]}]}]]}]\n18:[[\"$\",\"meta\",\"0\",{\"charSet\":\"utf-8\"}],[\"$\",\"meta\",\"1\",{\"name\":\"viewport\",\"content\":\"width=device-width, initial-scale=1\"}]]\n14:null\n"])</script>
1<script>self.__next_f.push([1,"16:{\"metadata\":[[\"$\",\"title\",\"0\",{\"children\":\"The NodeSource Blog \"}],[\"$\",\"meta\",\"1\",{\"name\":\"description\",\"content\":\"Articles about the Node.js Community, How-tos, and Products from NodeSource - The Node.js Company\"}],[\"$\",\"meta\",\"2\",{\"name\":\"keywords\",\"content\":\"node.js,nodejs,node,support,training,consulting,hardware,API\"}],[\"$\",\"meta\",\"3\",{\"name\":\"google-site-verification\",\"content\":\"GVuZldEHTZHcYj1H2G34YfYv2OHPxfrEXSDMmsEtN38\"}],[\"$\",\"meta\",\"4\",{\"property\":\"og:title\",\"content\":\"The NodeSource Blog \"}],[\"$\",\"meta\",\"5\",{\"property\":\"og:description\",\"content\":\"Articles about the Node.js Community, How-tos, and Products from NodeSource - The Node.js Company\"}],[\"$\",\"meta\",\"6\",{\"property\":\"og:site_name\",\"content\":\"NodeSource\"}],[\"$\",\"meta\",\"7\",{\"property\":\"og:image\",\"content\":\"https://nodesource.com/assets/icons/nodesource-1200x630.png\"}],[\"$\",\"meta\",\"8\",{\"property\":\"og:image:width\",\"content\":\"600\"}],[\"$\",\"meta\",\"9\",{\"property\":\"og:image:height\",\"content\":\"315\"}],[\"$\",\"meta\",\"10\",{\"property\":\"og:image:type\",\"content\":\"image/png\"}],[\"$\",\"meta\",\"11\",{\"name\":\"twitter:card\",\"content\":\"summary_large_image\"}],[\"$\",\"meta\",\"12\",{\"name\":\"twitter:site\",\"content\":\"@nodesource\"}],[\"$\",\"meta\",\"13\",{\"name\":\"twitter:creator\",\"content\":\"@nodesource\"}],[\"$\",\"meta\",\"14\",{\"name\":\"twitter:title\",\"content\":\"The NodeSource Blog \"}],[\"$\",\"meta\",\"15\",{\"name\":\"twitter:description\",\"content\":\"Articles about the Node.js Community, How-tos, and Products from NodeSource - The Node.js Company\"}],[\"$\",\"meta\",\"16\",{\"name\":\"twitter:image\",\"content\":\"https://nodesource.com/assets/icons/nodesource-1024x512.png\"}],[\"$\",\"link\",\"17\",{\"rel\":\"icon\",\"href\":\"/icon.ico?b781f1b1ea0422ee\",\"type\":\"image/x-icon\",\"sizes\":\"256x256\"}],[\"$\",\"$L1c\",\"18\",{}]],\"error\":null,\"digest\":\"$undefined\"}\n"])</script>
1<script>self.__next_f.push([1,"1b:\"$16:metadata\"\n"])</script>
1<script>self.__next_f.push([1,"1d:I[8481,[\"586\",\"static/chunks/13b76428-8a44d6718d54fa7a.js\",\"1356\",\"static/chunks/1356-05a24602620546b0.js\",\"2619\",\"static/chunks/2619-38012e79151e370a.js\",\"6581\",\"static/chunks/6581-5a59c9fda9fdaf5d.js\",\"7965\",\"static/chunks/7965-bf824f1784f24116.js\",\"3115\",\"static/chunks/3115-89bdcd254bfb768d.js\",\"3831\",\"static/chunks/app/blog/page-fdd9771c982bc6d0.js\"],\"BlogHeader\"]\n1e:I[9350,[\"586\",\"static/chunks/13b76428-8a44d6718d54fa7a.js\",\"1356\",\"static/chunks/1356-05a24602620546b0.js\",\"2619\",\"static/chunks/2619-38012e79151e370a.js\",\"6581\",\"static/chunks/6581-5a59c9fda9fdaf5d.js\",\"7965\",\"static/chunks/7965-bf824f1784f24116.js\",\"3115\",\"static/chunks/3115-89bdcd254bfb768d.js\",\"3831\",\"static/chunks/app/blog/page-fdd9771c982bc6d0.js\"],\"Article\"]\n1f:T2300,"])</script>
1<script>self.__next_f.push([1,"## 👋 Welcome to This Week’s Edition!\n\nHere’s what’s inside:\n\n- 🟢 **Node.js Releases:** A look at **Node.js 26.9.0** and the newly released **Node.js 26.10.0**, with updates across FFI, benchmarking, Web Workers, crypto, filesystem APIs, and performance tooling.\n- 🚀 **Featured from NodeSource:** Why **AI-assisted Node.js development** can still introduce security risk when applications are built on outdated runtimes, vulnerable dependencies, or the wrong production baseline.\n- 🌎 **Community \u0026 Events:** **NodeConf EU 2026 is next week**, with Rafael Gonzaga joining Antoine du Hamel to discuss the future of the Node.js release model, plus upcoming Node.js community meetings.\n- 🤖 **AI Corner:** New developments in **coding agents, real-time AI applications, and AI-powered security workflows** from GitHub and Google.\n- 🛠️ **Node.js Upgrade Program:** Resources and expert support for teams moving from **End-of-Life Node.js versions** to supported releases.\n\nHappy reading! 🚀\n\n---\n\n## 🟢 Last Week in Node.js\n\nNode.js 26 continues moving quickly, with **two Current releases landing within a week** and bringing new capabilities across crypto, benchmarking, FFI, workers, performance monitoring, and core utilities.\n\n### Node.js 26.9.0 — FFI, `node:bench`, Web Workers, and more\n\n[Node.js 26.9.0](https://nodejs.org/en/blog/release/v26.9.0) landed on September 16 with several notable additions:\n\n- 🔐 A new **generic MAC API**, plus discovery of ciphers and hashes from OpenSSL providers\n- 🔌 The `node:ffi` module is now **enabled by default**\n- 📊 A new built-in **`node:bench` benchmarking API**\n- 📈 New `perf_hooks` histogram capabilities, including `meanCI`\n- 🌐 An **experimental DTLS API**\n- 📦 Virtual File System integration with both **CommonJS and ESM module loaders**\n- 🧵 Support for **Web Workers**\n\nThis is a particularly feature-heavy Current release, with improvements spanning native interoperability, diagnostics, networking, and performance tooling.\n\n### Node.js 26.10.0 — New crypto, filesystem, and performance APIs\n\nAnd just today, [Node.js 26.10.0](https://nodejs.org/en/blog/release/v26.10.0) arrived with another set of additions:\n\n- 🔐 New **`crypto.parsePKCS12()`** support\n- 📁 New **`fs.openAsBlobSync()`** API\n- 🔌 FFI can now load libraries directly from a **mounted VFS**\n- 🧵 `net.BoundSocket` can be sent to **worker threads and child processes**\n- 📊 New **`SlidingWindowHistogram`** and histogram analysis capabilities in `perf_hooks`\n- 🗃️ SQLite now binds JavaScript `undefined` values to SQL `NULL`\n- ⚡ New **`util.throttle()` and `util.debounce()`** utilities\n\nNode.js 26 remains the **Current** release line, while Node.js 24 (Krypton) remains the latest **LTS** line for production workloads.\n\n---\n\n## 🚀 Featured from NodeSource\n\n### 🤖 Correct Code, Wrong Baseline: The Hidden Security Risk of AI-Assisted Node.js Development\n\nAI can generate Node.js code that works — while still choosing an **outdated runtime, vulnerable dependency, or unsafe production baseline**.\n\nOur latest article explores why AI-assisted development needs more than correct code. The runtime and dependency decisions made today can remain in Docker images, CI pipelines, templates, and production systems long after the original code ships.\n\nDrawing on insights from **Rafael Gonzaga**, NodeSource Principal Open Source Engineer and Node.js TSC member, we look at:\n\n- 🤖 How AI can influence Node.js runtime and dependency choices\n- ⚠️ Why **End-of-Life Node.js versions** change the security equation\n- 🔐 Why supported releases continue receiving fixes for vulnerabilities that did not exist when your application was written\n- 🧑‍💻 Why developer environments are becoming part of the attack surface\n- 🛠️ How `is-my-node-vulnerable` can validate your runtime against current Node.js security data\n\n**Correct code can still run on the wrong baseline.**\n\n👉 [Read: Correct Code, Wrong Baseline →](https://nodesource.com/blog/correct-code-wrong-baseline-ai-assisted-nodejs-security)\n\n---\n\n## 🌎 Community \u0026 Events\n\n### 🇮🇹 NodeConf EU 2026 is Next Week\n\n**NodeConf EU 2026** takes place **September 29–30 in Bologna, Italy**, bringing together the Node.js community for two days focused on runtimes, performance, observability, architecture, tooling, and production systems.\
1n\nNodeSource’s **Rafael Gonzaga**, Principal Open Source Engineer and Node.js TSC member, will join **Antoine du Hamel** on September 30 for:\n\n**“The New Node.js Release Model: Why Node 27 Changes Everything”**\n\nThe session will explore why the Node.js release process is changing, the challenges behind maintaining releases at ecosystem scale, and what the new model means for developers, maintainers, companies, and contributors.\n\n👉 [Explore NodeConf EU 2026](https://nodeconf.eu/)\n\n### 💚 Get Involved with the Node.js Community\n\nWant to follow what’s happening inside the Node.js project? Several public community meetings are happening this week:\n\n- **Diagnostics WG** — September 24\n- **Build WG** — September 24\n- **Node-API Team** — September 25\n\nNode.js project meetings are public and open to anyone interested in following discussions or contributing.\n\n👉 [See upcoming Node.js meetings](https://nodejs.org/en/about/get-involved/events)\n\n---\n\n## 🤖 AI Corner\n\n### GitHub Copilot expands its agentic workflows\n\nGitHub shipped another round of **Copilot updates** this week, including improved code review, smarter automatic model selection, Sentry integration, and additional agent capabilities in VS Code.\n\nDevelopers can now tune auto model selection around **efficiency, balance, or intelligence**, depending on whether cost, latency, or model quality matters most.\n\nGitHub also announced that several older Copilot models — including **GPT-5.4, GPT-5.5, and Gemini 3.7 Flash** — will be deprecated on **October 19**, with newer models recommended as replacements.\n\n👉 [Explore the latest GitHub Copilot updates](https://github.blog/changelog/2026-09-18-github-copilot-weekly-releases-september-14/)\n\n### 🎙️ Google launches new Gemini models for real-time voice apps\n\nGoogle introduced **Gemini 3.8 Live**, **Gemini 3.8 Live Extended Thinking**, and **Gemini 3.5 Transcribe** for developers building voice-first applications.\n\nThe new models support real-time speech interactions through the Gemini API and Google AI Studio, while Gemini 3.5 Transcribe provides speech-to-text support across **85+ languages**.\n\n👉 [Explore the new Gemini Audio models](https://blog.google/innovation-and-ai/technology/developers-tools/build-real-time-voice-applications-gemini-audio/)\n\n### 🔐 Google is using AI agents to find vulnerabilities before production\n\nGoogle shared how it is embedding **AI-powered security agents directly into its software development lifecycle** to scan code changes, identify vulnerabilities, and generate fixes.\n\nAccording to Google, the system continuously analyzes **hundreds of millions of lines of infrastructure code** and is helping prevent hundreds of vulnerabilities per month from reaching its codebase or production environments.\n\nIt’s another signal that AI agents are moving beyond code generation toward **continuous security analysis and remediation inside the development lifecycle**.\n\n👉 [Read how Google is using AI agents for infrastru
1cture security](https://cloud.google.com/blog/topics/systems/using-ai-agents-to-secure-google-infrastructure/)\n\n---\n\n## 🚀 Node.js Upgrade Program\n\n### Free Expert Help for Your Next Node.js Upgrade\n\nStill running an **End-of-Life version of Node.js**?\n\nThe **Node.js Upgrade Program**, developed in partnership with the **OpenJS Foundation**, helps organizations migrate to supported LTS releases with **free expert guidance** from the Node.js ecosystem.\n\nYou can follow the step-by-step upgrade process yourself using the program's resources, or request assistance from the Upgrade Program team to help plan and execute your migration.\n\nThe program is designed to help organizations:\n\n- ✅ Upgrade from End-of-Life Node.js versions\n- ✅ Reduce security and compliance risks\n- ✅ Plan migrations with confidence\n- ✅ Modernize production applications\n\n**Participation is completely free for organizations.**\n\n🔗 **Learn more and get started:**  \n[https://nodesource.com/products/nodejs-upgrade](https://nodesource.com/products/nodejs-upgrade)\n\n---\n\n## ⚡ Stay Connected\n\nThe Node.js ecosystem never stands still—and neither do we.\n\nSubscribe to stay up to date with future editions featuring the latest **Node.js releases, AI-powered developer tools, observability, security, and community news.**\n\nHave questions, feedback, or ideas for a future edition? We'd love to hear from you.\n\n📩 [Contact NodeSource](https://nodesource.com/pages/contact-us.html)  \n📧 [email protected]\n\n**See you next month! 👋**"])</script>
1<script>self.__next_f.push([1,"12:[\"$\",\"div\",null,{\"children\":[[\"$\",\"$L1d\",null,{}],[\"$\",\"section\",null,{\"className\":\"two-column blog\",\"children\":[\"$\",\"div\",null,{\"className\":\"body-width two-column-layout\",\"children\":[[\"$\",\"div\",null,{\"className\":\"two-column-left blog-content\",\"children\":[[\"$\",\"div\",null,{\"className\":\"breadcrumbs\",\"children\":[\"$\",\"h1\",null,{\"className\":\"category\",\"children\":\"All Posts\"}]}],[[\"$\",\"div\",null,{\"className\":\"post-list\",\"children\":[[\"$\",\"$L1e\",\"0\",{\"item\":{\"id\":679,\"documentId\":\"thixu7j7rvi8czqh5md3cw5u\",\"slug\":\"nodesource-weekly-sept-22-2026-nodejs-26-10-ai-security-nodeconf-eu\",\"title\":\"NodeSource Weekly — Sept 22, 2026: Node.js 26.10.0, AI Security \u0026 NodeConf EU\",\"metaDescription\":\"NodeSource Weekly covers Node.js 26.9.0 and 26.10.0, AI-assisted development security, NodeConf EU 2026, and the Node.js Upgrade Program.\",\"tweetText\":null,\"body\":\"$1f\",\"featuredPost\":false,\"createdAt\":\"2026-09-22T16:55:33.802Z\",\"updatedAt\":\"2026-09-22T17:14:46.194Z\",\"publishedAt\":\"2026-09-22T17:14:45.291Z\",\"category\":{\"slug\":\"Newsletter\",\"title\":\"newsletter\"},\"twitterCard\":{\"id\":14741,\"documentId\":\"r2fxemw17q2uftb2l5v1pno8\",\"name\":\"LinkedIn Article  (12).png\",\"alternativeText\":null,\"caption\":null,\"focalPoint\":null,\"width\":1600,\"height\":900,\"formats\":{\"large\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/large_Linked_In_Article_12_6b29b70a88.png\",\"etag\":\"6d2317159bb108e4bd84faebd8cf9803\",\"hash\":\"large_Linked_In_Article_12_6b29b70a88\",\"mime\":\"image/png\",\"name\":\"large_LinkedIn Article  (12).png\",\"path\":null,\"size\":732.71,\"width\":1000,\"height\":563,\"sizeInBytes\":732705},\"small\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/small_Linked_In_Article_12_6b29b70a88.png\",\"etag\":\"13a63f6469b303226df80d67e7cfc98b\",\"hash\":\"small_Linked_In_Article_12_6b29b70a88\",\"mime\":\"image/png\",\"name\":\"small_LinkedIn Article  (12).png\",\"path\":null,\"size\":207,\"width\":500,\"height\":281,\"
1sizeInBytes\":207004},\"medium\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/medium_Linked_In_Article_12_6b29b70a88.png\",\"etag\":\"514924f9167efe8ac865a74dc505b820\",\"hash\":\"medium_Linked_In_Article_12_6b29b70a88\",\"mime\":\"image/png\",\"name\":\"medium_LinkedIn Article  (12).png\",\"path\":null,\"size\":431.02,\"width\":750,\"height\":422,\"sizeInBytes\":431015},\"thumbnail\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/thumbnail_Linked_In_Article_12_6b29b70a88.png\",\"etag\":\"02ce73f5c3162c8289bfc524ab039d27\",\"hash\":\"thumbnail_Linked_In_Article_12_6b29b70a88\",\"mime\":\"image/png\",\"name\":\"thumbnail_LinkedIn Article  (12).png\",\"path\":null,\"size\":59.29,\"width\":245,\"height\":138,\"sizeInBytes\":59293}},\"hash\":\"Linked_In_Article_12_6b29b70a88\",\"ext\":\".png\",\"mime\":\"image/png\",\"size\":400.03,\"url\":\"https://assets.nodesource.com/strapi-uploads/Linked_In_Article_12_6b29b70a88.png\",\"previewUrl\":null,\"provider\":\"aws-s3\",\"provider_metadata\":null,\"createdAt\":\"2026-09-22T16:55:02.973Z\",\"updatedAt\":\"2026-09-22T16:55:02.973Z\",\"publishedAt\":\"2026-09-22T16:55:02.974Z\"}}}],\"$L20\",\"$L21\",\"$L22\",\"$L23\",\"$L24\",\"$L25\",\"$L26\",\"$L27\",\"$L28\",\"$L29\",\"$L2a\"]}],\"$L2b\"]]}],\"$L2c\"]}]}]]}]\n"])</script>
1<script>self.__next_f.push([1,"38:I[8590,[\"586\",\"static/chunks/13b76428-8a44d6718d54fa7a.js\",\"1356\",\"static/chunks/1356-05a24602620546b0.js\",\"2619\",\"static/chunks/2619-38012e79151e370a.js\",\"6581\",\"static/chunks/6581-5a59c9fda9fdaf5d.js\",\"7965\",\"static/chunks/7965-bf824f1784f24116.js\",\"3115\",\"static/chunks/3115-89bdcd254bfb768d.js\",\"3831\",\"static/chunks/app/blog/page-fdd9771c982bc6d0.js\"],\"Pagination\"]\n2d:T4596,"])</script>
1<script>self.__next_f.push([1,"AI coding tools are becoming increasingly capable of writing software that compiles, passes tests, and solves real engineering problems.\n\nBut generating working code is only part of what these systems now do.\n\nWhen an AI assistant creates a Node.js project, it may also influence decisions about:\n\n- which Node.js version to use\n- which dependency versions to install\n- which Docker image becomes the production baseline\n- how CI environments are configured\n- which packages developers introduce to solve a problem\n- which APIs and security practices become part of the application\n\nThose decisions can survive much longer than the generated code itself.\n\nA runtime version placed in a Dockerfile today can remain in CI pipelines, internal templates, base images, and production infrastructure for years.\n\nThat changes the security question.\n\nThe question is no longer only:\n\n\u003e **Can AI generate secure code?**\n\nIt is also:\n\n\u003e **Can we trust the technical defaults AI helps us choose to remain correct as the ecosystem changes?**\n\nThat distinction matters in Node.js, where the runtime, its bundled dependencies, the package ecosystem, and the security landscape continue evolving long after an application is first deployed.\n\nA Node.js version does not become “old” only because newer features exist.\n\n**Supported releases keep receiving security fixes for vulnerabilities that developers could not have anticipated when the original code was written.**\n\nAnd that is where AI-assisted development and runtime security begin to intersect.\n\n---\n\n## Running an EOL Version of Node.js?\n\nAn unsupported runtime may continue working today while security, dependency compatibility, and operational risk accumulate around it.\n\nUnderstand your application's upgrade risk and build a clear path to a supported Node.js release with the **NodeSource Upgrade Program**.\n\n[![ChatGPT Image Sep 8, 2026](https://assets.nodesource.com/strapi-uploads/Chat_GPT_Image_Sep_8_2026_04_34_41_PM_266756aabd.png)](https://nodesource.com/upgrade)\n[**Assess Your Node.js Upgrade Risk →**](https://nodesource.com/upgrade)\n\n---\n\n## Your Code Can Be Correct While the Baseline Is Wrong\n\nA growing body of research suggests that generating correct code and selecting safe software versions are not necessarily the same problem.\n\nA 2026 study titled *Correct Code, Vulnerable Dependencies* evaluated 10 LLMs across 1,000 programming tasks. The research focused on Python rather than Node.js, so its percentages should not be interpreted as measurements of the npm ecosystem. But the underlying finding is important.\n\nWhen models explicitly selected library versions, **36.7% to 55.7% of evaluated tasks included at least one dependency version associated with a known CVE**. More strikingly, in **72.27% to 91.37%** of those cases, the relevant CVE had already been publicly disclosed before the model's stated knowledge cutoff. The researchers concluded that version selection itself represents a distinct risk surface in AI-assisted development.\n\n[**Read: Correct Code, Vulnerable Dependencies**](https://arxiv.org/abs/2605.06279)\n\nAnother 2026 study, *When LLMs Lag Behind*, examined what happens when software APIs evolve after patterns have already been learned by a model. Researchers found that stale internal knowledge can continue influencing generated code even when newer documentation is supplied as context. Structured documentation and reasoning techniques improved results, but did not completely eliminate the problem.\n\n[**Read: When LLMs Lag Behind**](https://arxiv.org/abs/2604.09515)\n\nThe implication is not that AI coding assistants are inherently unsafe.\n\nIt is that software changes continuously, while learned patterns can persist.\n\nA recommendation that was reasonable two years ago can become a poor production default today.\n\nNode.js gives us a particularly clear example.\n\nAs of September 2026, Node.js 24 is Active LTS, Node.js 22 is Maintenance LTS, and Node.js 26 is Current. Node.js 20 reached End-of-Life on April 30, 2026.\n\nThat lifecycle distinction has real security consequences.\n\n## Security Does 
1Not Stop When the Application Ships\n\nRafael Gonzaga, Principal Open Source Engineer at NodeSource and a Node.js TSC member involved in Node.js security, addressed this directly in his 2026 talk *The State of Node.js Security*.\n\nOne of the central themes of the talk is that application security extends beyond the JavaScript developers write themselves.\n\nNode.js includes native dependencies such as OpenSSL, nghttp2, llhttp, V8, and others. When vulnerabilities are disclosed in those components, the Node.js Security Team evaluates whether the APIs used by Node.js make the runtime itself affected. Depending on that assessment, fixes may ship through security releases or regular releases.\n\n[**Watch Rafael Gonzaga: The State of Node.js Security**](https://gitnation.com/contents/the-state-of-nodejs-security)\n\nThis is an important distinction.\n\nYour application's business logic may not change for six months.\n\nThe security environment around it can.\n\nNew vulnerabilities are discovered.\n\nBundled dependencies change.\n\nAttack techniques evolve.\n\nSecurity boundaries are tested in ways developers did not anticipate when the application was created.\n\nThat is precisely why supported runtime versions continue receiving fixes.\n\nIn June 2026 alone, Node.js issued security updates across the supported 22.x, 24.x, and 26.x release lines. The release included fixes affecting WebCrypto, HTTP/2, the Permission Model, HTTP agents, and several bundled dependencies including OpenSSL, nghttp2, llhttp, and Undici. Rafael Gonzaga and Matteo Collina were among the contributors credited 
1with fixes in that release.\n\nA month later, another security release addressed multiple issues, including two High-severity HTTP/2 vulnerabilities, Permission Model bypasses, HTTPS behavior, DNS handling, zlib, SQLite, and HTTP request processing. Rafael and Matteo again appear among the contributors responsible for fixes.\n\nNone of those fixes could have been encoded into an application before the vulnerabilities were discovered.\n\nThat is the point.\n\n**Keeping the runtime supported is part of application security, even when the application code itself has not changed.**\n\n## EOL Changes the Security Equation\n\nWhen a Node.js release reaches End-of-Life, the project stops maintaining it.\n\nThat includes security patches.\n\nThe Node.js EOL documentation explains that if a vulnerability disclosed in a newer release also affects an unsupported version, the project will not publish a new upstream release for that EOL line. It also warns about ecosystem drift, tooling compatibility, and compliance concerns that accumulate as an application stays on an unsupported runtime.\n\nNode.js security announcements make this even more explicit.\n\nThe June and July 2026 security releases both warn that End-of-Life versions should be considered affected when security releases occur and direct users to stay on versions covered by the current release schedule.\n\nThis creates a simple but important difference:\n\n\u003e A vulnerability may be discovered tomorrow.  \n\u003e A supported Node.js line can receive a fix.  \n\u003e An End-of-Life line will not receive that fix from the Node.js project.\n\nThat is why selecting a runtime version is not merely a compatibility choice.\n\n**It is a future security decision.**\n\nAnd increasingly, AI may participate in making that decision.\n\n## AI Is Already Influencing More Than Code\n\nRafael highlighted another scenario in *The State of Node.js Security* that feels increasingly familiar.\n\nA developer has a problem.\n\nThey ask an LLM for help.\n\nThe model suggests installing a package.\n\nThe package solves the immediate problem.\n\nBut what else does that package do?\n\nRafael uses this scenario while discussing the Node.js Permission Model: a package could have been compromised or behave maliciously behind the scenes, reading sensitive files or communicating externally. The Permission Model can restrict what an application is allowed to access, acting as a defensive boundary if something unexpected happens.\n\nHis larger point is important: developers remain responsible for evaluating what they install and execute.\n\nNode.js' own security policy makes the trust boundary explicit. Malicious third-party modules are not considered vulnerabilities in Node.js itself because Node.js treats executed code as trusted.\n\nApplication developers therefore need their own protections against supply-chain risks and untrusted packages.\n\nThe Node.js Security Best Practices documentation similarly calls out third-party libraries, malicious packages, typosquatting, and related application-level threats that teams should account for.\n\nSo when AI recommends a dependency, the recommendation should not become automatic trust.\n\nThe same principle applies to runtime versions.\n\nAI can help make the decision.\n\n**It should not be the source of truth for whether that decision is still secure.**\n\n## AI Is Changing Vulnerability Discovery Too\n\nThere is another side to this story.\n\nAI is not only generating software decisions.\n\nIt is increasingly being used to look for security problems.\n\nDuring the 2026 Node.js Collaborator Summit, Rafael discussed a large influx of AI-generated vulnerability reports reaching the Node.js security process. The Node.js event summary describes high volumes of noisy, duplicated, or poorly reproduced submissions that placed significant pressure on maintainers responsible for determining which reports represented genuine security issues.\n\nOpenJS Foundation later quantified the shift.\n\nAccording to its Q2 2026 security update, the Node.js security team had received **352 HackerOne reports over the preceding two years**. In February 2026, report volume increased **4.6x** following the emergence of AI agent-assisted scanning tools, and March alone produced **65 reports**.\n\nThat does not mean AI-generated reports are inherently invalid.\n\nAI-assisted security research may 
1surface real bugs.\n\nThe challenge is verification.\n\nA generated report still needs to demonstrate reproducible impact, respect the Node.js threat model, and be evaluated by people who understand where Node.js' security responsibility begins and ends.\n\nRafael makes that distinction repeatedly in *The State of Node.js Security*: not every crash, malicious package, prototype modification, or application-level issue qualifies as a vulnerability in Node.js core. The project's threat model exists specifically to define those boundaries.\n\nThis creates an interesting parallel.\n\nAI can generate a security report that looks convincing but requires expert verification.\n\nAI can also generate a technical recommendation that looks reasonable but requires current ecosystem context.\n\nIn both cases:\n\n\u003e **Plausibility is not the same as correctness.**\n\n## The Developer Machine Is Part of the Attack Surface\n\nAnother observation from Rafael's talk is particularly relevant to AI-assisted workflows.\n\nWhile reviewing HackerOne reports, the Node.js Security Team found that many security issues did not primarily threaten production servers.\n\nThey threatened developers.\n\nInstalling packages, executing unfamiliar code, running installation scripts, testing generated commands, and granting development tools access to local environments can expose credentials, company information, source code, or other sensitive data. Rafael specifically calls attention to malicious packages and post-install behavior as risks developers need to consider.\n\n[**Watch Rafael's earlier talk: 5 Ways You Could Have Hacked Node.js**](https://gitnation.com/contents/5-ways-you-could-have-hacked-nodejs)\n\nThat matters even more as coding agents become capable of executing commands rather than simply suggesting them.\n\nThe transition from:\n\n\u003e “Here is some code you could run.”\n\nto:\n\n\u003e “I ran this package installation for you.”\n\nchanges the security boundary.\n\nAI-assisted development therefore needs the same engineering discipline we expect from any other automation system: **least privilege, controlled environments, trusted sources, version verification, and human review for consequential changes.**\n\n## Check the Runtime Instead of Assuming\n\nOne practical step is remarkably simple.\n\nCheck the version of Node.js you are actually running against known security data.\n\nRafael recommends `is-my-node-vulnerable`, a Node.js tool designed specifically for this purpose.\n\nRun:\n\n```text\nnpx is-my-node-vulnerable\n```\n\nThe tool compares the current `process.version` against the Node.js Security Database and reports known vulnerabilities that affect the installed runtime. End-of-Life versions are treated as unsafe because new Node.js security releases are no longer tracked and backported for those release lines. The project also recommends integrating the check into CI so a vulnerable runtime can prevent a deployment rather than being discovered after it reaches production.\n\n[**Explore is-my-node-vulnerable**](https://github.com/marketplace/actions/is-my-node-vulnerable)\n\nThis is the kind of grounding AI-assisted development needs.\n\nDo not rely on whether a runtime version sounds current.\n\nDo not rely on whether a Dockerfile builds successfully.\n\nDo not rely on whether the tests pass.\n\n**Check against authoritative, current security information.**\n\n## AI Should Accelerate Engineering — Not Replace the Source of Truth\n\nThere is an important distinction between using AI to help make a decision and using AI as the authority behind that decision.\n\nA coding assistant can help create a Dockerfile.\n\nThe Node.js release schedule should determine whether the runtime inside it is supported.\n\nAn AI agent can suggest a dependency.\n\nCurrent vulnerability and package information should determine whether that version is appropriate.\n\nAn AI security tool can identify suspicious behavior.\n\nThe Node.js threat model, reproduction steps, maintainers, and security process determine whether that behavior constitutes a Node.js vulnerability.\n\nThis does not diminish the value of AI.\n\n
1It makes AI more useful.\n\nThe most reliable AI-assisted development workflows will increasingly combine model reasoning with current, authoritative evidence.\n\nThat is particularly important in an ecosystem that moves as quickly as Node.js.\n\n## Your Runtime Is a Living Dependency\n\nWe often think of Node.js as the platform underneath our dependencies.\n\nOperationally, however, the runtime behaves much like one of the most important dependencies in the entire application.\n\nIt has versions.\n\nIt has a support lifecycle.\n\nIt contains dependencies of its own.\n\nIt receives security fixes.\n\nEventually, it reaches End-of-Life.\n\nAnd every application built on top of it inherits those realities.\n\nSo when AI helps create the next Node.js application, the question should not only be:\n\n\u003e **Did it generate code that works?**\n\nWe should also ask:\n\n\u003e **What technical assumptions did it make for us?**\n\nBecause correct code can still run on the wrong baseline.\n\nAnd the security of that baseline will continue changing long after the code has shipped.\n\n---\n\n## Running an Unsupported Node.js Version?\n\nKnowing that a runtime needs to be upgraded is often easier than completing the upgrade.\n\nLegacy dependencies, native addons, deprecated APIs, testing requirements, and production constraints can turn a version change into a significant engineering project.\n\nThat is why NodeSource participates in the **Node.js LTS Upgrade \u0026 Modernization Program with the OpenJS Foundation**.\n\nThe program helps organizations identify upgrade blockers, understand migration risk, and build a practical path from unsupported Node.js versions to supported releases. NodeSource's Upgrade Discovery tooling can inspect dependencies, native addons, and Node.js API usage to help turn an uncertain migration into a measurable engineering project.\n\nIf your application is still running Node.js 20, Node.js 18, or another End-of-Life release, start by understanding what is actually preventing the upgrade.\n\n[![ChatGPT Image Sep 8, 2026](https://assets.nodesource.com/strapi-uploads/Chat_GPT_Image_Sep_8_2026_04_34_41_PM_266756aabd.png)](https://nodesource.com/upgrade)\n\n[**Explore the Node.js Upgrade Program**](https://nodesource.com/products/nodejs-upgrade)\n\n---\n\n## Further Reading\n\n### Rafael Gonzaga — The State of Node.js Security\n\nNode Congress 2026: Node.js threat model, Permission Model, EOL releases, developer security, dependency vulnerability assessments, and `is-my-node-vulnerable`.\n\n[**Watch the talk**](https://gitnation.com/contents/the-state-of-nodejs-security)\n\n### Rafael Gonzaga — 5 Ways You Could Have Hacked Node.js\n\nA walkthrough of real Node.js vulnerabilities and how the Node.js Security Team handles security reports and fixes.\n\n[**Watch the talk**](https://gitnation.com/contents/5-ways-you-could-have-hacked-nodejs)\n\n### Node.js — July 2026 Security Releases\n\nRecent real-world examples of runtime vulnerabilities fixed across supported release lines.\n\n[**Read the security release**](https://nodejs.org/uk/blog/vulnerability/july-2026-security-releases)\n\n### Node.js — End-of-Life Releases\n\nOfficial guidance on what happens when a Node.js release stops receiving upstream maintenance and security patches.\n\n[**Read the EOL documentation**](https://nodejs.org/en/about/eol)\n\n### OpenJS Foundation — Q2 2026 Security Update\n\nDetails on the increase in AI-assisted security reports reaching the Node.js security process and how maintainers are adapting.\n\n[**Read the OpenJS security update**](https://openjsf.org/blog/openjs-security-update-q2-2026)\n\n### Correct Code, Vulnerable Dependencies\n\n2026 research on version-selection risk in LLM-generated software.\n\n[**Read the paper**](https://arxiv.org/abs/2605.06279)"])</script>
1<script>self.__next_f.push([1,"20:[\"$\",\"$L1e\",\"1\",{\"item\":{\"id\":678,\"documentId\":\"hfmkmtk91dmwawua4n2myfv0\",\"slug\":\"correct-code-wrong-baseline-ai-assisted-nodejs-security\",\"title\":\"Correct Code, Wrong Baseline: The Hidden Security Risk of AI-Assisted Node.js Development\",\"metaDescription\":\"AI can generate correct Node.js code while choosing outdated runtimes or vulnerable dependencies. Learn why current baselines matter for security.\",\"tweetText\":null,\"body\":\"$2d\",\"featuredPost\":false,\"createdAt\":\"2026-09-17T18:29:41.786Z\",\"updatedAt\":\"2026-09-17T18:29:41.786Z\",\"publishedAt\":\"2026-09-17T18:29:41.704Z\",\"category\":{\"slug\":\"ai\",\"title\":\"ai\"},\"twitterCard\":{\"id\":14740,\"documentId\":\"us1h3netj6iw2dsy0xkbalsu\",\"name\":\"LinkedIn Article  (11).png\",\"alternativeText\":null,\"caption\":null,\"focalPoint\":null,\"width\":1600,\"height\":900,\"formats\":{\"large\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/large_Linked_In_Article_11_8ff32fa814.png\",\"etag\":\"2fbb6c8f44e7409654e208101bb283b9\",\"hash\":\"large_Linked_In_Article_11_8ff32fa814\",\"mime\":\"image/png\",\"name\":\"large_LinkedIn Article  (11).png\",\"path\":null,\"size\":756.93,\"width\":1000,\"height\":563,\"sizeInBytes\":756929},\"small\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/small_Linked_In_Article_11_8ff32fa814.png\",\"etag\":\"87cb5a93cd39c413a25058211c2b232f\",\"hash\":\"small_Linked_In_Article_11_8ff32fa814\",\"mime\":\"image/png\",\"name\":\"small_LinkedIn Article  (11).png\",\"path\":null,\"size\":220.7,\"width\":500,\"height\":281,\"
1sizeInBytes\":220697},\"medium\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/medium_Linked_In_Article_11_8ff32fa814.png\",\"etag\":\"92cb00a9cb859eec198a3851d3eb455a\",\"hash\":\"medium_Linked_In_Article_11_8ff32fa814\",\"mime\":\"image/png\",\"name\":\"medium_LinkedIn Article  (11).png\",\"path\":null,\"size\":449.23,\"width\":750,\"height\":422,\"sizeInBytes\":449233},\"thumbnail\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/thumbnail_Linked_In_Article_11_8ff32fa814.png\",\"etag\":\"ad605b7db28b05bf3f5da6a49e481703\",\"hash\":\"thumbnail_Linked_In_Article_11_8ff32fa814\",\"mime\":\"image/png\",\"name\":\"thumbnail_LinkedIn Article  (11).png\",\"path\":null,\"size\":65.58,\"width\":245,\"height\":138,\"sizeInBytes\":65580}},\"hash\":\"Linked_In_Article_11_8ff32fa814\",\"ext\":\".png\",\"mime\":\"image/png\",\"size\":373.3,\"url\":\"https://assets.nodesource.com/strapi-uploads/Linked_In_Article_11_8ff32fa814.png\",\"previewUrl\":null,\"provider\":\"aws-s3\",\"provider_metadata\":null,\"createdAt\":\"2026-09-17T18:29:31.537Z\",\"updatedAt\":\"2026-09-17T18:29:31.537Z\",\"publishedAt\":\"2026-09-17T18:29:31.538Z\"}}}]\n"])</script>
1<script>self.__next_f.push([1,"2e:T213b,"])</script>
1<script>self.__next_f.push([1,"## 👋 Welcome to This Week’s Edition!\n\nHere’s what’s inside:\n\n🟢 Node.js Releases: What’s new in Node.js 24.21.0 LTS and Node.js 26.8.2 Current, including updates across OpenSSL, Undici, performance, and runtime maintenance.\n\n📈 N|Solid Growth: N|Solid downloads surged 98% in August, DevTools passed 2.5K downloads, and N|Solid reached 1.15M downloads in 2026.\n\n🌎 Community \u0026 Events: Highlights from ParaíbaJS 2026 and a look ahead to NodeConf EU, where Rafael Gonzaga will represent NodeSource.\n\n🤖 AI Corner: New developments around AI agents, the Agents API, and practical guidance for building safer MCP tools in Node.js.\n\n🚀 Node.js Upgrade Program: Resources and expert support for teams moving from End-of-Life Node.js versions to supported releases.\n\nHappy reading! 🚀\n\n[![N|Solid DevTools — Deeper visibility for your Node.js apps](https://assets.nodesource.com/strapi-uploads/devtools_banner_24a0f29f12.png)](https://nodesource.com/products/nsolid/devtools?ref=nodesource_weekly_2026_09_15\u0026placement=devtools_banner)\n\n---\n\n## 🟢 Last Week in [Node.js](http://node.js)\n\nLast week brought new releases across both the LTS and Current release lines, with updates focused on security dependencies, networking performance, diagnostics, and runtime maintenance.\n\n### Node.js 24.21.0 (LTS) — Krypton\n\nNode.js 24.21.0 landed with several notable improvements across cryptography, networking, and performance tooling.\n\n- 🔐 **OpenSSL updated to 3.5.8**, alongside updated root certificates from NSS 3.126.\n- 🌐 **Undici updated to 7.29.1**, bringing the latest improvements to Node.js' HTTP client stack.\n- ⚡ **`net.BlockList` performance improvements** make IP and network filtering more efficient.\n- 📊 **Histogram tooling gets smarter**, including improved implementation and statistical hypothesis testing in `perf_hooks`.\n- 🔑 **Crypto now supports loading private keys through OpenSSL STORE loaders**, expanding key-loading options.\n- 🧩 **`MIMEType.parse()` gains a non-throwing parsing option**, making MIME type validation easier to handle in application code.\n\nThe release also includes fixes and performance improvements across HTTP, file system operations, DNS, ESM, and diagnostics.\n\n👉 **[Explore Node.js 24.21.0](https://nodejs.org/en/blog/release/v24.21.0)**\n\n### Node.js 26.8.2 (Current)\n\nNode.js 26.8.2 continues stabilizing the Current release line with dependency updates and runtime maintenance ahead of the Node.js 26 LTS transition.\n\n- 🔐 **OpenSSL updated to 3.5.8.**\n- 🌐 **Undici updated to 8.10.2.**\n- 📦 **npm updated to 11.19.1 and Corepack to 0.36.0.**\n- 🛡️ The project **refined its security vulnerability posture for experimental features**, clarifying how security issues affecting experimental APIs are handled.\n- ⚠️ **`Server.prototype._listen2` in `node:net` is now deprecated**, further discouraging reliance on an internal API.\n\nThe release also includes build improvements for Windows and RISC-V, documentation updates, and reliability fixes across Node.js' test infrastru
1cture.\n\n👉 **[Explore Node.js 26.8.2](https://nodejs.org/en/blog/release/v26.8.2)**\n\n---\n\n## 🚀 Featured from NodeSource\n\n### 📈 N|Solid Downloads Surged 98% in August\n\nN|Solid downloads nearly doubled in August, growing from **105K+ downloads in July to 209K+ in August**.\n\n**N|Solid is NodeSource’s enterprise Node.js runtime, built to give teams deeper visibility into application performance, security, and production diagnostics.**\n\nThe jump is more than a monthly spike. It reflects growing adoption of production-grade Node.js tooling as teams look for better performance visibility, diagnostics, and runtime control.\n\nIn our latest analysis, we break down the numbers, the versions developers are running, and what the data tells us about Node.js runtime adoption in 2026.\n\n👉 **[Read the full analysis](https://nodesource.com/blog/nsolid-downloads-98-percent-growth-nodejs-runtime-adoption)**\n\n### 🧩 N|Solid DevTools Reaches 2.5K+ Downloads\n\nThe **N|Solid Extension for code editors has now passed 2.5K downloads**, another milestone for our developer tooling ecosystem.\n\nN|Solid DevTools brings runtime diagnostics closer to where developers already work, making it easier to inspect CPU, memory, event loop activity, package security, and application behavior directly from the development workflow.\n\nWhether you're working in VS Code, Windsurf, or alongside AI coding agents, the goal is the same: **make Node.js diagnostics easier to access before issues reach production.**\n\n👉 **[Explore N|Solid DevTools](https://nodesource.com/products/nsolid/devtools)**\n\n### 🚀 N|Solid Reaches 1.15M Downloads in 2026\n\nN|Solid has now been downloaded **more than 1.15 million times in 2026**, bringing total downloads to **2.4M+**.\n\nBuilt on Node.js, **N|Solid adds enterprise-grade observability, performance monitoring, diagnostics, and security capabilities for teams running Node.js applications in production.**\n\nThe milestone reflects increasing adoption of tooling designed to help engineering teams understand what is happening inside their Node.js applications and troubleshoot issues faster.\n\n👉 **[Explore N|Solid on GitHub](https://github.com/nodesource/nsolid)**\n\n---\n\n## 🌎 Community \u0026 Events\n\n### 🇧🇷 NodeSource at ParaíbaJS 2026\n\nThis past weekend, **Rafael Gonzaga, Principal Open Source Engineer at NodeSource and Node.js TSC member**, joined the community at ParaíbaJS in João Pessoa, Brazil.\n\nRafael took the stage with **“5 Ways You Could Have Hacked Node.js,”** sharing lessons from real vulnerabilities fixed in Node.js and a behind-the-scenes look at security inside the runtime.\n\n👉 **[See the highlights from ParaíbaJS](https://x.com/NodeSource/status/2099527984084349140?s=20)**\n\n### 🇮🇹 Next Stop: NodeConf EU 2026\n\nRafael will also represent NodeSource at **NodeConf EU 2026**, happening **September 29–30 in Bologna, Italy**.\n\nAlongside Antoine du Hamel, he’ll present **“The New Node.js Release Model: Why Node 27 Changes Everything,”** exploring why the Node.js release process is changing and what the new model means for maintainers, companies, contributors, and developers across the ecosystem.\n\n👉 **[Explore NodeConf EU 2026](https://nodeconf.eu/)**\n\n---\n\n## 🤖 AI Corner\n\n- 🧠 **OpenAI introduced the Agents API** in public beta, bringing the infrastructure behind Codex to developers for building long-running agents with tool use, subagents, persistent context, and sandboxed environments.\n\n  👉 **[Explore the Agents API](https://openai.com/index/introducing-the-agents-api/)**\n\n- 🔌 **Building MCP tools in Node.js? Keep the tool surface small.** Give agents only the tools and permissions they actually need, validate inputs, keep authorization outside the model, and treat external content as untrusted. A recent SitePoint guide has a solid overview of production-ready MCP patterns.\n\n  👉 **[Read: Building AI Agents That Can Safely Work With Live Web Data Using MCP](https://www.sitepoint.com/building-ai-agents-that-can-safely-work-with-live-web-data-using-mcp/)**\n\n---\n\n## 🚀 Node.js Upgrade Program\n\n### Free Expert Help for Your Next Node.js Upgrade\n\nStill running an End-of-Life version of Node.js?\n\nThe **Node.js Upgrade Program**, developed in partnership with the **OpenJS Foundation**, helps organizations migrate to supp
1orted LTS releases with **free expert guidance** from the Node.js ecosystem.\n\nYou can follow the step-by-step upgrade process yourself using the program's resources, or request assistance from the Upgrade Program team to help plan and execute your migration.\n\nThe program is designed to help organizations:\n\n- ✅ Upgrade from End-of-Life Node.js versions\n- ✅ Reduce security and compliance risks\n- ✅ Plan migrations with confidence\n- ✅ Modernize production applications\n\n**Participation is completely free for organizations.**\n\n🔗 **[Learn more and get started](https://nodesource.com/products/nodejs-upgrade)**\n\n---\n\n## ⚡ Stay Connected\n\nThe Node.js ecosystem never stands still—and neither do we.\n\nSubscribe to stay up to date with future editions featuring the latest Node.js releases, AI-powered developer tools, observability, security, and community news.\n\nHave questions, feedback, or ideas for a future edition? We'd love to hear from you.\n\n📩 [Contact NodeSource](https://nodesource.com/pages/contact-us.html)  \n📧 [email protected]\n\n**See you next month! 👋**"])</script>
1<script>self.__next_f.push([1,"21:[\"$\",\"$L1e\",\"2\",{\"item\":{\"id\":677,\"documentId\":\"cdir53rfegumqk8b8e4qky9a\",\"slug\":\"nodesource-weekly-nodejs-24-21-0-nsolid-growth-ai-agents\",\"title\":\"NodeSource Weekly — Sept 15, 2026: Node.js 24.21.0, N|Solid Growth \u0026 AI Agents\",\"metaDescription\":\"Catch up on Node.js 24.21.0 and 26.8.2, N|Solid's 98% August growth, 2.5K DevTools downloads, NodeConf EU, and the latest AI agent updates.\",\"tweetText\":null,\"body\":\"$2e\",\"featuredPost\":false,\"createdAt\":\"2026-09-15T17:22:05.330Z\",\"updatedAt\":\"2026-09-15T17:29:29.921Z\",\"publishedAt\":\"2026-09-15T17:29:29.778Z\",\"category\":{\"slug\":\"Newsletter\",\"title\":\"newsletter\"},\"twitterCard\":{\"id\":14738,\"documentId\":\"s2o9af0tcwy8ky53m7w6bhts\",\"name\":\"LinkedIn Article  (9).png\",\"alternativeText\":null,\"caption\":null,\"focalPoint\":null,\"width\":1600,\"height\":900,\"formats\":{\"large\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/large_Linked_In_Article_9_8d9427dd47.png\",\"etag\":\"78fc100203dc50c017badeb99a14e67a\",\"hash\":\"large_Linked_In_Article_9_8d9427dd47\",\"mime\":\"image/png\",\"name\":\"large_LinkedIn Article  (9).png\",\"path\":null,\"size\":720.35,\"width\":1000,\"height\":563,\"sizeInBytes\":720352},\"small\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/small_Linked_In_Article_9_8d9427dd47.png\",\"etag\":\"9577ff2131247e61c25c9ff6ee0e2fc7\",\"hash\":\"small_Linked_In_Article_9_8d9427dd47\",\"mime\":\"image/png\",\"name\":\"small_LinkedIn Article  (9).png\",\"path\":null,\"size\":203.14,\"width\":500,\"height\":281,\"
1sizeInBytes\":203140},\"medium\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/medium_Linked_In_Article_9_8d9427dd47.png\",\"etag\":\"c3ce4ac72564150498a88aa62d799689\",\"hash\":\"medium_Linked_In_Article_9_8d9427dd47\",\"mime\":\"image/png\",\"name\":\"medium_LinkedIn Article  (9).png\",\"path\":null,\"size\":423.74,\"width\":750,\"height\":422,\"sizeInBytes\":423744},\"thumbnail\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/thumbnail_Linked_In_Article_9_8d9427dd47.png\",\"etag\":\"4220c470ef882d5083fc515c85d3baaf\",\"hash\":\"thumbnail_Linked_In_Article_9_8d9427dd47\",\"mime\":\"image/png\",\"name\":\"thumbnail_LinkedIn Article  (9).png\",\"path\":null,\"size\":58.45,\"width\":245,\"height\":138,\"sizeInBytes\":58445}},\"hash\":\"Linked_In_Article_9_8d9427dd47\",\"ext\":\".png\",\"mime\":\"image/png\",\"size\":403.89,\"url\":\"https://assets.nodesource.com/strapi-uploads/Linked_In_Article_9_8d9427dd47.png\",\"previewUrl\":null,\"provider\":\"aws-s3\",\"provider_metadata\":null,\"createdAt\":\"2026-09-15T17:02:34.369Z\",\"updatedAt\":\"2026-09-15T17:02:40.819Z\",\"publishedAt\":\"2026-09-15T17:02:34.369Z\"}}}]\n"])</script>
1<script>self.__next_f.push([1,"2f:T190e,"])</script>
1<script>self.__next_f.push([1,"N|Solid Runtime has been downloaded more than **1.15 million times in 2026**, bringing total downloads to more than **2.4 million**. In August alone, download activity increased from **105,619 to 209,052**, a **98% month-over-month increase**.\n\nThe growth is notable, but the more useful signal is what sits underneath it: how Node.js runtimes are being pulled across development and production infrastructure, which versions are gaining ground, and which older generations remain active long after newer releases become available.\n\n**Want to try N|Solid?** N|Solid Runtime is an **open-source, cross-platform JavaScript runtime based on Node.js**, with performance, security, and diagnostic visibility built directly into the runtime.\n\n[![N|Solid Runtime](https://assets.nodesource.com/strapi-uploads/Chat_GPT_Image_Sep_8_2026_04_32_13_PM_c0882bc887.png)](https://github.com/nodesource/nsolid)\n\n[**Install N|Solid Runtime →**](https://github.com/nodesource/nsolid)\n\n## N|Solid Download Activity Nearly Doubled in August\n\nN|Solid download activity has continued to grow throughout 2026, with August showing a significant jump:\n\n- **July 2026:** 105,619 downloads\n- **August 2026:** 209,052 downloads\n- **Month-over-month growth:** ~98%\n- **2026 YTD:** 1.15M+ downloads\n- **All-time:** 2.4M+ downloads\n\nThe cumulative number gives us a sense of scale. The month-over-month change tells us something different: N|Solid is being pulled more frequently across the systems that build, provision, and run Node.js applications.\n\nThose downloads can come from developer machines, containers, CI/CD pipelines, automated builds, cloud infrastructure, and other environments where runtimes are installed or provisioned.\n\nThat is also why we treat downloads as a measure of **runtime activity**, rather than a direct count of users or applications.\n\n[![N|Solid Download Metrics](https://assets.nodesource.com/strapi-uploads/Chat_GPT_Image_Sep_8_2026_04_32_22_PM_4cf991a690.png)](https://distributions.nodesource.io/?year=2026\u0026package=nsolid)\n\n[**Explore the N|Solid distribution metrics →**](https://distributions.nodesource.io/?year=2026\u0026package=nsolid)\n\n## What N|Solid Adds to Node.js\n\nN|Solid is built on Node.js, but adds observability directly at the runtime layer.\n\nThat allows engineering teams to capture performance, security, and diagnostic information from inside the Node.js process, including CPU and memory behavior, event loop activity, CPU profiles, heap snapshots, application performance signals, and package and security intelligence.\n\nThe distinction matters because some of the most useful information about a Node.js application originates inside the runtime itself.\n\nInstead of treating Node.js as a black box beneath the application, N|Solid exposes runtime evidence that developers and operations teams can use to investigate why an application is consuming resources, slowing down, or behaving unexpectedly.\n\nN|Solid Runtime can be used independently and also provides the runtime intelligence behind NodeSource tooling such as N|Solid Console, the N|Solid Extension for code editors, and the N|Solid Plugin for AI coding agents.\n\n## The Version Mix Tells a Bigger Story\n\nThe broader Node.js ecosystem has also been moving quickly in 2026.\n\nOfficial Node.js distribution data recorded **4.61 billion downloads through July**, already exceeding the total recorded during all of 2025. Node.js 24 also became the most downloaded major release in July.\n\nBut newer releases gaining traction does not mean older runtimes disappear immediately.\n\nNode.js 20 still recorded more than **103 million downloads in July**, despite reaching **End-of-Life on April 30, 2026**. Node.js 18, which reached EOL a year earlier, continued to appear in tens of millions of downloads.\n\nN|Solid distribution data reflects the same broader reality: **runtime modernization happens gradually**. Supported releases gain adoption while older Node.js generations remain embedded in applications, containers, build systems, and deployment infrastru
1cture.\n\nFor engineering teams, that version mix is more than an adoption trend.\n\nOnce a Node.js release reaches EOL, continuing to run it can introduce increasing security, compatibility, maintenance, and operational risk as the ecosystem around the application continues to move forward.\n\n## Downloads Measure Activity, Not Users\n\nA runtime download does not equal one developer, one production server, or one application.\n\nThe same package may be pulled repeatedly by Docker builds, ephemeral CI environments, version managers, automated provisioning, or local development workflows.\n\nThat makes individual download counts unsuitable as a user metric, but the trends are still useful.\n\nOver time, distribution data can show how runtime activity changes, how quickly newer Node.js releases enter infrastructure, and how long legacy versions continue to persist.\n\nWith Node.js 24 adoption growing and Node.js 26 approaching LTS, that transition is worth watching closely throughout the rest of 2026.\n\n## Better Runtime Data Leads to Better Decisions\n\nKnowing which Node.js version an application runs is only one part of understanding its production behavior.\n\nTeams also need to know where CPU time is being spent, how memory behaves under load, whether the event loop is becoming constrained, what dependencies introduce risk, and what changes when the underlying runtime moves to a newer release.\n\nN|Solid is designed to expose that layer.\n\nThe growth we're seeing in 2026 is encouraging, but the more interesting outcome is the visibility the distribution data provides into how Node.js itself moves through real infrastructure.\n\n[**Explore N|Solid Runtime on GitHub →**](https://github.com/nodesource/nsolid)\n\n[**View N|Solid download trends →**](https://distributions.nodesource.io/?year=2026\u0026package=nsolid)\n\n---\n\n## Running an EOL Version of Node.js?\n\nAn unsupported runtime may continue working today while security, dependency compatibility, and operational risk accumulate around it.\n\nUnderstand your application's upgrade risk and build a clear path to a supported Node.js release with the **NodeSource Upgrade Program**.\n\n[![NodeSource Upgrade Program](https://assets.nodesource.com/strapi-uploads/Chat_GPT_Image_Sep_8_2026_04_34_41_PM_266756aabd.png)](https://nodesource.com/upgrade)\n\n[**Assess Your Node.js Upgrade Risk →**](https://nodesource.com/upgrade)"])</script>
1<script>self.__next_f.push([1,"22:[\"$\",\"$L1e\",\"3\",{\"item\":{\"id\":676,\"documentId\":\"yu9vqeksqnkauxog67ofzgnw\",\"slug\":\"nsolid-downloads-98-percent-growth-nodejs-runtime-adoption\",\"title\":\"N|Solid Downloads Surged 98% in August 2026 — What It Says About Node.js Runtime Adoption\",\"metaDescription\":\"N|Solid reached 1.15M+ downloads in 2026, with 98% growth in August. See what the latest data shows about Node.js runtime adoption and version trends.\",\"tweetText\":null,\"body\":\"$2f\",\"featuredPost\":false,\"createdAt\":\"2026-09-10T15:52:32.516Z\",\"updatedAt\":\"2026-09-10T15:52:32.516Z\",\"publishedAt\":\"2026-09-10T15:52:32.479Z\",\"category\":{\"slug\":\"product\",\"title\":\"Product\"},\"twitterCard\":{\"id\":14737,\"documentId\":\"fapi1soyv19pe36ljx2tvn2h\",\"name\":\"LinkedIn Article  (7).png\",\"alternativeText\":null,\"caption\":null,\"focalPoint\":null,\"width\":1600,\"height\":900,\"formats\":{\"large\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/large_Linked_In_Article_7_0bc438f52a.png\",\"etag\":\"c2e7ceb35c57e93b6b9a8b1dbedb5829\",\"hash\":\"large_Linked_In_Article_7_0bc438f52a\",\"mime\":\"image/png\",\"name\":\"large_LinkedIn Article  (7).png\",\"path\":null,\"size\":472.87,\"width\":1000,\"height\":563,\"sizeInBytes\":472870},\"small\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/small_Linked_In_Article_7_0bc438f52a.png\",\"etag\":\"a6ff3fa6d126680e92e4f4e8dd6c6ab8\",\"hash\":\"small_Linked_In_Article_7_0bc438f52a\",\"mime\":\"image/png\",\"name\":\"small_LinkedIn Article  (7).png\",\"path\":null,\"size\":141.02,\"width\":500,\"height\":281,\"
1sizeInBytes\":141017},\"medium\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/medium_Linked_In_Article_7_0bc438f52a.png\",\"etag\":\"bd6c1fc0a30c8264a81f715edcae38c8\",\"hash\":\"medium_Linked_In_Article_7_0bc438f52a\",\"mime\":\"image/png\",\"name\":\"medium_LinkedIn Article  (7).png\",\"path\":null,\"size\":282.38,\"width\":750,\"height\":422,\"sizeInBytes\":282381},\"thumbnail\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/thumbnail_Linked_In_Article_7_0bc438f52a.png\",\"etag\":\"5e5905cb7e0a1667adee155ace93b138\",\"hash\":\"thumbnail_Linked_In_Article_7_0bc438f52a\",\"mime\":\"image/png\",\"name\":\"thumbnail_LinkedIn Article  (7).png\",\"path\":null,\"size\":43.11,\"width\":245,\"height\":138,\"sizeInBytes\":43106}},\"hash\":\"Linked_In_Article_7_0bc438f52a\",\"ext\":\".png\",\"mime\":\"image/png\",\"size\":234.36,\"url\":\"https://assets.nodesource.com/strapi-uploads/Linked_In_Article_7_0bc438f52a.png\",\"previewUrl\":null,\"provider\":\"aws-s3\",\"provider_metadata\":null,\"createdAt\":\"2026-09-10T15:51:42.036Z\",\"updatedAt\":\"2026-09-10T15:51:42.036Z\",\"publishedAt\":\"2026-09-10T15:51:42.036Z\"}}}]\n"])</script>
1<script>self.__next_f.push([1,"30:T3eb0,"])</script>
1<script>self.__next_f.push([1,"**Legacy Node.js is rarely an awareness problem. It is a risk, cost, and uncertainty problem.**\n\nLast week, we looked at a striking signal in the official Node.js download data in [Node.js Downloads Surge in 2026 as Node.js 24 Takes the Lead](https://nodesource.com/blog/nodejs-downloads-2026-node-24-adoption).\n\nNode.js 24 had become the most downloaded Node.js release, a strong indication that modernization across the ecosystem is accelerating.\n\nBut something else stood out.\n\nNode.js 20, which reached End-of-Life on April 30, 2026, still recorded more than **103 million downloads in July alone**. Together, the already-EOL Node.js 18 and 20 release lines accounted for more than **136 million downloads** that month.\n\n![ChatGPT Image Sep 1, 2026, 04_41_53 PM.png](https://assets.nodesource.com/strapi-uploads/Chat_GPT_Image_Sep_1_2026_04_41_53_PM_b7cc12f55e.png)\n\nThe obvious question was:\n\n**Why are so many organizations still running an unsupported runtime?**\n\nSo we took the question to the community on LinkedIn — [in a Spanish-language post](https://www.linkedin.com/posts/teffcode_qu%C3%A9-estar%C3%A1-pasando-por-la-mente-de-quienes-activity-7498840156343353345-hJnd?utm_source=share\u0026utm_medium=member_desktop\u0026rcm=ACoAACHgPfMBh9zDMeO9q-ExhbydRTUAh9fiGOA) — and the responses from developers and engineers pointed to a much more complicated reality.\n\nThey talked about applications that have been stable in production for years. Dependencies that may break. Base images that need to change. CI/CD pipelines that need to be revalidated. Regression testing, certifications, limited engineering capacity, and the simple reality that somebody has to take responsibility if an upgrade breaks checkout, billing, or another business-critical workflow.\n\nOne comment captured the organizational challenge particularly well: for a large application, a runtime migration is not simply an upgrade.\n\nIt is a project, with its own budget, timeline, validation requirements, and production risk.\n\nThose responses matter because they expose something the Node.js community sometimes oversimplifies.\n\nCompanies are not necessarily staying on EOL Node.js because they do not know newer versions exist.\n\nIn many cases, they know exactly where they are.\n\nThe harder question is whether they believe changing it today is safer than leaving it alone.\n\n#### Still running an End-of-Life version of Node.js?\n\nThrough the [Node.js Upgrade Program](https://nodesource.com/upgrade), NodeSource helps organizations understand what is blocking their upgrade before changing the runtime.\n\n[![node-upgrade.png](https://assets.nodesource.com/strapi-uploads/upgrade_23b73580d5.png)](https://nodesource.com/products/nodejs-upgrade)\n\n[Get your free Node.js Upgrade Assessment →](https://nodesource.com/upgrade)\n\n## EOL Does Not Mean the Application Stops Working\n\nThis is the first misconception worth clearing up.\n\nWhen Node.js 20 reached End-of-Life, applications running on Node.js 20 did not suddenly stop on April 30.\n\nServers kept accepting requests.\n\nContainers kept starting.\n\nAPIs kept returning responses.\n\nCI pipelines kept building.\n\nThat is precisely why EOL can be so easy to postpone.\n\n**End-of-Life describes the support state of the runtime, not the immediate operational state of your application.**\n\nThe Node.js project is very clear about what changes after EOL: the release line no longer receives updates, including security fixes. Over time, teams can also encounter toolchain breakage, ecosystem drift as packages abandon old releases, and compliance problems associated with unsupported software.\n\nSo there are two statements that can simultaneously be true:\n\nOur Node.js 20 application works perfectly today.\n\nAnd:\n\nRunning it indefinitely creates increasing operational and security risk.\n\nUnderstanding that distinction is essential.\n\n## Why “Just Upgrade Node.js” Is Bad Advice\n\nOn a development laptop, upgrading Node.js might look like this:\n\n`nvm install 24`\n\n`nvm use 24`\n\nProduction systems are different.\n\nThe runtime sits underneath an application dependency graph, build system, deployment infrastru
1cture, operating system, container environment, observability stack, security controls, native modules, and years of accumulated technical decisions.\n\nChanging Node.js can expose assumptions throughout that entire system.\n\nThis is why engineering teams resist advice that sounds like:\n\n“Node.js 20 is EOL. Just move to Node.js 24.”\n\nThey know what the version number does not tell you.\n\n### 1. The code change may be the cheapest part\n\nA major runtime migration can surface incompatible dependencies, deprecated Node.js APIs, changes in V8 or OpenSSL behavior, native C/C++ addons that must be rebuilt, new compiler requirements, or packages whose maintainers never added support for newer Node.js versions.\n\nYour own code may require very little modification.\n\nYour dependency graph may require much more.\n\nNodeSource's own Upgrade Discovery tooling focuses specifically on dependencies, native addons, static API usage, deprecated APIs, vulnerabilities, and other potential migration blockers for exactly this reason.\n\n### 2. The Real Cost Is Often Validation\n\nDevelopers frequently frame migrations in terms of how much code needs to change.\n\nOrganizations tend to think differently.\n\nThey ask:\n\n- How much regression testing is required?\n- Which critical workflows need manual validation?\n- Do we need to rebuild deployment images?\n- Will our third-party integrations continue working?\n- Do our native modules compile correctly?\n- Will performance characteristics change?\n- What is our rollback strategy?\n- Who owns the incident if something breaks?\n\nFor a checkout service processing millions of dollars in transactions, “the new version works on my machine” is not an acceptable migration strategy.\n\nThe more critical the system, the larger the validation surface becomes.\n\nAnd that creates an uncomfortable paradox:\n\n**The applications that most need modernization are often the applications organizations are most afraid to change.**\n\n### 3. Stability Has Business Value\n\nEngineers are trained to improve systems.\n\nBusinesses are trained to protect working systems.\n\nThose goals usually align, but not always.\n\nImagine an internal service that:\n\n- has operated reliably for five years,\n- rarely receives feature changes,\n- meets its SLA,\n- generates no customer complaints,\n- and runs on Node.js 20.\n\nNow imagine asking the business for six weeks of engineering capacity to modernize it.\n\nThe first question probably will not be:\n\nWhich V8 version are we running?\n\nIt will be:\n\nWhat happens if we don't do this?\n\nThat is a reasonable question.\n\nRuntime upgrades compete against customer features, revenue projects, infrastructure work, reliability improvements, security initiatives, and every other item on an engineering roadmap.\n\nModernization therefore needs something developers sometimes overlook:\n\na business case.\n\n### 4. Technical Debt Is Often Accepted Deliberately\n\nTechnical debt is not automatically a failure of engineering.\n\nSometimes organizations knowingly accept it.\n\nThey may decide that maintaining an older system for another six months is cheaper than migrating it immediately.\n\nThat can be a perfectly rational decision.\n\nThe problem begins when:\n\n“We are intentionally postponing this upgrade until Q4.”\n\nquietly becomes:\n\n“Nobody has looked at this runtime in three years.”\n\nThose are very different situations.\n\nThe first is risk management.\n\nThe second is unmanaged technical debt.\n\nA mature organization does not necessarily upgrade every runtime the moment a newer release arrives.\n\nBut it should know:\n\n- what versions are running,\n- which versions are unsupported,\n- what the exposure is,\n- what is blocking modernization,\n- who owns the decision,\n- and when that decision will be revisited.\n\n### 5. AI Can Reduce Upgrade Work. It Cannot Own Production Risk.\n\nAnother interesting theme in the discussion was AI.\n\nCould Claude Code, Codex, or another coding agent make migration dramatically easier?\n\nAbsolutely.\n\nAI can already accelerate parts of modernization:\n\n- identify deprecated APIs,\n- research dependency breaking changes,\n- generate refactors,\n- propose replacement packages,\n- update configuration,\n- generate tests,\n- explain migration guides,\n- and help developers investigate failures.\n\nThat changes the economics of modernization.\n\nBut there is an important distinction:\n\n**AI can reduce the cost of making changes. It does not eliminate the cost of proving those changes are safe.**\n\nAn AI agent cannot take organizational responsibility for your production checkout.\n\nIt cannot decide whether your regression coverage is sufficient.\n\nIt cannot accept your compliance risk.\n\nIt cannot determine your maintenance window.\n\nAnd it cannot own the incident if the migration fails.\n\nThe future of legacy modernization is therefore unlikely to be “AI upgrades everything automatically.”\n\nIt is more likely to be:\n\n**AI makes the engineering work dramatically faster while humans retain control of risk, val
1idation, architecture, and production decisions.**\n\nThat is a far more interesting—and useful—model.\n\n## The Real Problem Is Uncertainty\n\nWhen engineering teams postpone Node.js upgrades, one factor appears repeatedly:\n\nThey do not know how large the migration actually is.\n\nThat uncertainty makes planning difficult.\n\nWithout inspecting the application, the conversation sounds like this:\n\n“How hard would moving from Node.js 20 to a supported release be?”\n\n“It depends.”\n\nHow many dependencies will break?\n\nIt depends.\n\nDo we have native addons?\n\nMaybe.\n\nDo we use deprecated APIs?\n\nProbably.\n\nWill our build environment need changes?\n\nPossibly.\n\nHow long will this take?\n\nTwo days?\n\nTwo weeks?\n\nThree months?\n\nWhen that is the level of confidence available to engineering leadership, delaying the project is predictable.\n\nIt is difficult to fund work that cannot be scoped.\n\nThat changes the upgrade problem entirely.\n\nThe first step should not necessarily be:\n\nUpgrade the runtime.\n\nIt should be:\n\nReduce the uncertainty.\n\n## Turn the Upgrade Into a Measurable Engineering Project\n\nThis is one of the reasons NodeSource participates in the OpenJS Foundation's Node.js LTS Upgrade \u0026 Modernization program.\n\nThe program exists because the ecosystem recognizes that moving enterprise applications away from unsupported Node.js versions involves real challenges around dependencies, testing, architecture, and production stability—not simply developer awareness. The OpenJS Foundation describes the program as a way to connect organizations running legacy Node.js environments with qualified partners capable of helping them modernize safely.\n\nAt NodeSource, we approach that problem by starting with discovery.\n\nBefore deciding whether an upgrade is a two-day task or a multi-quarter modernization effort, understand what is actually inside the application.\n\n### Step 1: Scan the application\n\nDevelopers can run the free Upgrade Discovery CLI locally:\n\n`npx @nodesource/upgrade`\n\nThe scanner inspects areas such as application dependencies, native C++ addons, and static Node.js API usage while keeping source code in the local environment.\n\n### Step 2: Analyze the actual upgrade risk\n\nThe resulting discovery data can be analyzed to identify:\n\n- security and upgrade risk,\n- critical blockers,\n- native addon conflicts,\n- deprecated APIs,\n- and vulnerable dependencies.\n\nInstead of estimating modernization risk from the Node.js version number alone, teams can begin evaluating their actual application.\n\n### Step 3: Build the migration around evidence\n\nFor applications that need additional support, NodeSource engineers can turn those findings into a modernization plan covering dependency changes, automated refactoring opportunities, native addon work, testing, environment changes, and a phased migration path.\n\nThat changes the internal conversation considerably.\n\nInstead of:\n\n“We should probably upgrade Node.js sometime.”\n\nengineering leadership can work from something closer to:\n\n“These are the blockers.\n\nThese are the dependencies that need intervention.\n\nThese are the applications carrying the most risk.\n\nThis is the expected migration path.\n\nThis is where engineering effort is actually required.”\n\nThat is a project a business can evaluate.\n\n## Postponing an Upgrade and Ignoring an Upgrade Are Not the Same Thing\n\nNot every Node.js 20 application needs to be migrated this afternoon.\n\nSome organizations will need time.\n\nSome systems will require careful testing.\n\nSome applications may contain proprietary native addons or deeply embedded dependencies.\n\nSome companies may deliberately accept temporary EOL risk while a broader modernization project is underway.\n\nNodeSource's program even accounts for that reality, including optional temporary security support for systems that cannot immediately complete the migration.\n\nThe mistake is not necessarily staying on Node.js 20 for another month.\n\nThe mistake is not knowing what staying there means.\n\nNode.js currently lists Node.js 20 as End-of-Life and associates the release line with 27 high-, 24 medium-, and 9 low-severity vulnerabilities in its EOL inventory. That does not mean every Node.js 20 application is automatically exploitable by every one of those issues—the actual exposure depends on the application, affected code paths, dependencies, and environment.\n\nBut it does mean the upstream project is no longer providing the normal patch path that supported releases receive.\n\nThat is an engineering condition worth understanding deliberately.\n\n## The Goal Is Not “Latest.” The Goal Is Supported and Sustainable.\n\nModernization should not become version-chasing.\n\nNode.js 26 is Current today. Node.js 24 is Active LTS, while Node.js 22 remains in Maintenance LTS. The appropriate destination for a production application depends on its requirements, migration timeline, ecosystem compatibility, and support horizon.\n\nThe objective is not to move every production workload to the highest version number available.\n\nThe objective is to prevent business-critical infrastru
1cture from becoming permanently trapped on software the upstream ecosystem can no longer maintain.\n\nThat requires treating runtime lifecycle management as ongoing engineering work rather than an emergency project that begins after EOL.\n\n## If Your Node.js 20 Application “Still Works,” Start There\n\nYou do not need to begin by rewriting it.\n\nYou do not need to begin by changing the runtime.\n\nYou do not even need to begin by committing to a migration date.\n\nBegin by understanding the application.\n\nWhat would actually break?\n\nWhat would need testing?\n\nWhich dependencies are holding you back?\n\nWhat security exposure already exists?\n\nWhat can be automated?\n\nWhat needs human engineering?\n\nHow large is the project you are actually dealing with?\n\nBecause perhaps the most important lesson from those 103 million Node.js 20 downloads is not that organizations are refusing to modernize.\n\nIt is that legacy software survives because production systems are complicated, valuable, and risky to change.\n\nThe answer is not to tell those teams to “just upgrade.”\n\nThe answer is to make the upgrade understandable, measurable, and manageable enough that they can actually do it.\n\n## Find Out What Is Blocking Your Node.js Upgrade\n\nIf your organization is still running Node.js 20, Node.js 18, or another legacy release, start with evidence.\n\n[![node-upgrade.png](https://assets.nodesource.com/strapi-uploads/upgrade_23b73580d5.png)](https://nodesource.com/products/nodejs-upgrade)\n\n[Get your free Node.js Upgrade Assessment →](https://nodesource.com/upgrade)\n\nRun the free NodeSource Upgrade Discovery CLI:\n\n`npx @nodesource/upgrade`\n\nThen use the Node.js Upgrade Assessment to understand the security risk, compatibility issues, and migration blockers in your application before changing the runtime.\n\nAssess first. Scope the work. Build the plan. Then upgrade."])</script>
1<script>self.__next_f.push([1,"23:[\"$\",\"$L1e\",\"4\",{\"item\":{\"id\":674,\"documentId\":\"upzykmubjebyjdk6sajo9nzr\",\"slug\":\"risk-behind-103m-eol-nodejs-downloads\",\"title\":\"The Risk Behind 103M EOL Node.js Downloads\",\"metaDescription\":\"103M Node.js 20 downloads in July 2026 show EOL adoption is still widespread. Explore why teams stay on unsupported versions and the risks involved.\",\"tweetText\":null,\"body\":\"$30\",\"featuredPost\":false,\"createdAt\":\"2026-09-03T20:13:02.254Z\",\"updatedAt\":\"2026-09-08T20:26:17.556Z\",\"publishedAt\":\"2026-09-08T20:26:17.406Z\",\"category\":{\"slug\":\"node-js\",\"title\":\"Node.js\"},\"twitterCard\":{\"id\":14733,\"documentId\":\"y1codqptf9d28z9v90kqwczj\",\"name\":\"LinkedIn Article  (6).png\",\"alternativeText\":null,\"caption\":null,\"focalPoint\":null,\"width\":1600,\"height\":900,\"formats\":{\"large\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/large_Linked_In_Article_6_6dd95f8ce2.png\",\"etag\":\"050c4b590e6b69355bbe95ec10bbd901\",\"hash\":\"large_Linked_In_Article_6_6dd95f8ce2\",\"mime\":\"image/png\",\"name\":\"large_LinkedIn Article  (6).png\",\"path\":null,\"size\":478.77,\"width\":1000,\"height\":563,\"sizeInBytes\":478774},\"small\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/small_Linked_In_Article_6_6dd95f8ce2.png\",\"etag\":\"a617ccc3c98530f3dde703b49ddb7fd0\",\"hash\":\"small_Linked_In_Article_6_6dd95f8ce2\",\"mime\":\"image/png\",\"name\":\"small_LinkedIn Article  (6).png\",\"path\":null,\"size\":138.84,\"width\":500,\"height\":281,\"
1sizeInBytes\":138842},\"medium\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/medium_Linked_In_Article_6_6dd95f8ce2.png\",\"etag\":\"a4dbfecbc292dfa8b9c91797e210f760\",\"hash\":\"medium_Linked_In_Article_6_6dd95f8ce2\",\"mime\":\"image/png\",\"name\":\"medium_LinkedIn Article  (6).png\",\"path\":null,\"size\":283.8,\"width\":750,\"height\":422,\"sizeInBytes\":283801},\"thumbnail\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/thumbnail_Linked_In_Article_6_6dd95f8ce2.png\",\"etag\":\"e85e10dc19e1e6238582fd78cf9acaf0\",\"hash\":\"thumbnail_Linked_In_Article_6_6dd95f8ce2\",\"mime\":\"image/png\",\"name\":\"thumbnail_LinkedIn Article  (6).png\",\"path\":null,\"size\":41.1,\"width\":245,\"height\":138,\"sizeInBytes\":41101}},\"hash\":\"Linked_In_Article_6_6dd95f8ce2\",\"ext\":\".png\",\"mime\":\"image/png\",\"size\":278.17,\"url\":\"https://assets.nodesource.com/strapi-uploads/Linked_In_Article_6_6dd95f8ce2.png\",\"previewUrl\":null,\"provider\":\"aws-s3\",\"provider_metadata\":null,\"createdAt\":\"2026-09-08T20:26:07.905Z\",\"updatedAt\":\"2026-09-08T20:26:07.905Z\",\"publishedAt\":\"2026-09-08T20:26:07.905Z\"}}}]\n"])</script>
1<script>self.__next_f.push([1,"31:T2397,"])</script>
1<script>self.__next_f.push([1,"## 👋 Welcome to This Week’s Edition!\n\nThis week, we’re looking at new security updates across the Node.js ecosystem, why organizations continue running End-of-Life Node.js versions, N|Solid’s latest download milestone, what’s happening across the JavaScript community, and how AI tooling continues to evolve for developers.\n\nHere’s what’s inside:\n\n🔐 **Node.js Security Updates:** Two new Undici security advisories were disclosed last week, including a high-severity WebSocket denial-of-service vulnerability. Patched versions are already available.\n\n🧭 **Why Companies Stay on EOL Node.js:** More than 103 million Node.js 20 downloads were recorded in July — months after the release reached End-of-Life. We explore what keeps organizations on unsupported runtimes, why staying there introduces real security and operational risk, and what teams can do to move forward.\n\n📈 **N|Solid Reaches 1.15M Downloads in 2026:** N|Solid has now surpassed **1.15 million downloads this year**, bringing total downloads to more than **2.4 million**.\n\n🌍 **Community \u0026 Events:** ParaíbaJS takes place this weekend with NodeSource’s Rafael Gonzaga on stage, while JS Days and NodeConf EU are coming up later this month.\n\n🤖 **AI Corner:** Catch up on the latest developments in AI coding and agent workflows, plus a practical Node.js tip for using `AbortSignal.timeout()` to add failure boundaries around AI API requests.\n\n⬆️ **Node.js Upgrade Program:** Still running an End-of-Life Node.js version? The **Node.js Upgrade Program**, from NodeSource in collaboration with the OpenJS Foundation, helps teams assess migration risk, identify blockers, and build a clear path toward a supported Node.js release.\n\nHappy reading! 🚀\n\n---\n\n![13.png](https://assets.nodesource.com/strapi-uploads/13_9ff7e4754a.png)\n\n## 🟢 Last Week in [Node.js](https://nodejs.org)\n\nNo new Node.js core releases landed last week, but the Node.js team disclosed two **Undici security advisories**, with patched versions already available.\n\n- 🔐 **[High-severity WebSocket DoS vulnerability](https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5)** — A malicious or compromised WebSocket server could trigger an uncaught exception and terminate a Node.js process. Upgrade to Undici **6.28.1, 7.29.1, or 8.10.2**.\n- 🛡️ **[Unsafe HTTP response caching issue](https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv)** — A low-severity issue could cause responses to unsafe HTTP methods such as `POST`, `PUT`, or `DELETE` to be cached and replayed. Fixed in Undici **7.29.1 and 8.10.2**.\n\n---\n\n![14.png](https://assets.nodesource.com/strapi-uploads/14_4b451f08b2.png)\n\n## 🚀 Featured from NodeSource\n\n### 🧭 Why Companies Stay on EOL Node.js — Even When They Know the Risk\n\nNode.js 20 reached End-of-Life in April, yet it still recorded **more than 103 million downloads in July**.\n\nThat doesn’t make running EOL Node.js a safe or sustainable choice.\n\nUnsupported runtimes no longer receive standard security fixes or maintenance, increasing **security, compliance, and operational risk** over time.\n\nSo we asked the community why organizations still struggle to move off legacy Node.js versions. The answers included dependency constraints, native addons, testing complexity, infrastructure changes, and limited engineering capacity.\n\nUnderstanding those blockers is important — **but the goal should still be to upgrade**.\n\nIn this article, we break down what keeps teams on EOL Node.js and how organizations can assess migration risk and move toward a supported runtime.\n\n👉 [Read the full article](https://nodesource.com/blog/why-companies-stay-on-eol-nodejs)\n\n### 📈 N|Solid Reaches 1.15M Downloads in 2026\n\nN|Solid has now been downloaded **1.15 million times so far in 2026**, bringing total downloads to more than **2.4 million**.\n\nMore teams are using N|Solid to run Node.js with deeper runtime diagnostics, security intelligence, and production visibility — while keeping the Node.js experience they already know.\n\n👉 [Explore N|Solid download data](https://distributions.nodesource.io/?year=2026\u0026package=nsolid)\n\n👉 [Try N|Solid on GitHub](https://github.com/nodesource/nsolid)\n\n---\n\n![15.png](https://assets.nodesource.com/strapi-uploads/15_d2c3553745.png)\n\n## 🌎 Community \u0026 Events\n\n### 🇧🇷 ParaíbaJS 2026 — September 12\n\nThe JavaScript community heads to Paraíba this weekend for **ParaíbaJS 2026**, with talks spanning Node.js observability, security, performance, AI, and more.\n\nNodeSource’s **Rafael Gonzaga**, Node.js Core maintainer, will take the stage with **“5 Ways You Could Have Hacked Node.js”**, sharing security lessons and stories from inside the runtime.\n\n👉 [Get your ticket](https://www.sympla.com.br/evento/paraibajs/3494354)\n\n### 💻 JS Days 2026 — September 16–17\n\n**JS Days 2026** returns next week as a free, fully virtual JavaScript conference. This year’s sessions cover AI-powered development, React, modern UI, enterprise JavaScript, and real-world production use cases.\n\n👉 [Explore JS Days 2026](https://www.jsdays.io/)\n\n### 🇮🇹 NodeConf EU 2026 — September 29–30\n\n**NodeConf EU** returns to Bologna with two days and 24 talks focused on Node.js, runtimes, tooling, observability, architecture, and production systems.\
1n\nThe program includes **Rafael Gonzaga and Antoine du Hamel** discussing *“The New Node.js Release Model: Why Node 27 Changes Everything.”*\n\n👉 [Explore the NodeConf EU program](https://www.nodeconf.eu/program)\n\n---\n\n![16.png](https://assets.nodesource.com/strapi-uploads/16_1dd9491c3e.png)\n\n## 🤖 AI Corner\n\n### 🧠 [OpenAI introduces GPT-6 Astra](https://openai.com/index/gpt-6-astra/)\n\nOpenAI introduced **GPT-6 Astra** on September 3, with improvements across coding, research, computer use, cybersecurity, and complex multi-step work.\n\nFor developers, Astra is especially focused on **long-running agentic workflows and software engineering tasks**, making it relevant for teams building AI-assisted developer experiences and autonomous coding workflows.\n\n👉 [Explore GPT-6 Astra](https://openai.com/index/gpt-6-astra/)\n\n### 🤖 [GitHub Copilot expands its agent toolkit](https://github.blog/changelog/2026-09-04-github-copilot-weekly-releases-august-31/)\n\nGitHub shipped several Copilot updates last week, including new model options, stronger content protections, and improvements to agent workflows.\n\nAmong the highlights: **GPT-6 Astra became available in GitHub Copilot**, Copilot app and CLI now respect **content exclusions**, and VS Code introduced **Agent Merge** in public preview to help agents resolve review feedback, failed checks, and merge conflicts.\n\n👉 [See GitHub Copilot’s weekly releases](https://github.blog/changelog/2026-09-04-github-copilot-weekly-releases-august-31/)\n\n### 💡 AI + Node.js Tip of the Week: Put a timeout around your AI calls\n\nAI requests can take longer than traditional API calls — especially when agents are reasoning, invoking tools, or waiting on external services.\n\nNode.js includes `AbortSignal.timeout()`, which creates a signal that automatically aborts after a specified number of milliseconds:\n\n```text\nconst response = await fetch(AI_ENDPOINT, {\n  method: 'POST',\n  signal: AbortSignal.timeout(30_000)\n});\n```\n\nThis gives AI-powered Node.js applications a simple failure boundary, making it easier to retry, fall back, or recover when a provider takes too long.\n\n👉 [Node.js docs: `AbortSignal.timeout()`](https://nodejs.org/api/globals.html#static-method-abortsignaltimeoutdelay)\n\n---\n\n![17.png](https://assets.nodesource.com/strapi-uploads/17_6d17b13b36.png)\n\n## 🚀 Node.js Upgrade Program\n\n### Free Expert Help for Your Next Node.js Upgrade\n\nStill running an End-of-Life version of Node.js?\n\nThe **Node.js Upgrade Program**, developed in partnership with the **OpenJS Foundation**, helps organizations migrate to supported LTS releases with **free expert guidance** from the Node.js ecosystem.\n\nYou can follow the step-by-step upgrade process yourself using the program's resources, or request assistance from the Upgrade Program team to help plan and execute your migration.\n\nThe program is designed to help organizations:\n\n- ✅ Upgrade from End-of-Life Node.js versions\n- ✅ Reduce security and compliance risks\n- ✅ Plan migrations with confidence\n- ✅ Modernize production applications\n\n**Participation is completely free for organizations.**\n\n🔗 **Learn more and get started:**  \nhttps://nodesource.com/products/nodejs-upgrade\n\n---\n\n![18.png](https://assets.nodesource.com/strapi-uploads/18_21af3c64e2.png)\n\n## ⚡ Stay Connected\n\nThe Node.js ecosystem never stands still—and neither do we.\n\nSubscribe to stay up to date with future editions featuring the latest Node.js releases, AI-powered developer tools, observability, security, and community news.\n\nHave questions, feedback, or ideas for a future edition? We'd love to hear from you.\n\n📩 https://nodesource.com/pages/contact-us.html  \n📧 [email protected]\n\n**See you next month! 👋**"])</script>
1<script>self.__next_f.push([1,"24:[\"$\",\"$L1e\",\"5\",{\"item\":{\"id\":675,\"documentId\":\"qqilr0mwz3d4920f5xhf2wn7\",\"slug\":\"nodesource-weekly-sept-8-2026-eol-nodejs-risk-undici-security-nsolid-downloads\",\"title\":\"NodeSource Weekly — Sept 8, 2026: The Risk Behind 103M EOL Node.js Downloads, Undici Security Fixes \u0026 1.15M N|Solid Downloads\",\"metaDescription\":\"Explore the risk behind 103M EOL Node.js 20 downloads, new Undici security fixes, N|Solid’s 1.15M download milestone, AI updates, and Node.js community news.\",\"tweetText\":null,\"body\":\"$31\",\"featuredPost\":false,\"createdAt\":\"2026-09-08T18:56:56.140Z\",\"updatedAt\":\"2026-09-08T18:56:56.140Z\",\"publishedAt\":\"2026-09-08T18:56:56.108Z\",\"category\":{\"slug\":\"Newsletter\",\"title\":\"newsletter\"},\"twitterCard\":{\"id\":14732,\"documentId\":\"h1gt0ozlqneidds02ljd5025\",\"name\":\"LinkedIn Article  (5).png\",\"alternativeText\":null,\"caption\":null,\"focalPoint\":null,\"width\":1600,\"height\":900,\"formats\":{\"large\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/large_Linked_In_Article_5_a9ca3329df.png\",\"etag\":\"2b9ec9de92582baf73fc8e31b8d646db\",\"hash\":\"large_Linked_In_Article_5_a9ca3329df\",\"mime\":\"image/png\",\"name\":\"large_LinkedIn Article  (5).png\",\"path\":null,\"size\":735.55,\"width\":1000,\"height\":563,\"sizeInBytes\":735551},\"small\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/small_Linked_In_Article_5_a9ca3329df.png\",\"etag\":\"5a569cfaaf58cb05b0ebdc49ade86086\",\"hash\":\"small_Linked_In_Article_5_a9ca3329df\",\"mime\":\"image/png\",\"name\":\"small_LinkedIn Article  (5).png\",\"path\":null,\"size\":210.84,\"width\":500,\"height\":281,\"
1sizeInBytes\":210843},\"medium\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/medium_Linked_In_Article_5_a9ca3329df.png\",\"etag\":\"2d1969d39a1f584ad4ace71fac0e611c\",\"hash\":\"medium_Linked_In_Article_5_a9ca3329df\",\"mime\":\"image/png\",\"name\":\"medium_LinkedIn Article  (5).png\",\"path\":null,\"size\":436.16,\"width\":750,\"height\":422,\"sizeInBytes\":436158},\"thumbnail\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/thumbnail_Linked_In_Article_5_a9ca3329df.png\",\"etag\":\"bfd121abd455f96e6ddfb71c42c3ebb7\",\"hash\":\"thumbnail_Linked_In_Article_5_a9ca3329df\",\"mime\":\"image/png\",\"name\":\"thumbnail_LinkedIn Article  (5).png\",\"path\":null,\"size\":60.89,\"width\":245,\"height\":138,\"sizeInBytes\":60893}},\"hash\":\"Linked_In_Article_5_a9ca3329df\",\"ext\":\".png\",\"mime\":\"image/png\",\"size\":418.87,\"url\":\"https://assets.nodesource.com/strapi-uploads/Linked_In_Article_5_a9ca3329df.png\",\"previewUrl\":null,\"provider\":\"aws-s3\",\"provider_metadata\":null,\"createdAt\":\"2026-09-08T18:56:10.737Z\",\"updatedAt\":\"2026-09-08T18:56:10.737Z\",\"publishedAt\":\"2026-09-08T18:56:10.738Z\"}}}]\n"])</script>
1<script>self.__next_f.push([1,"32:T2562,"])</script>
1<script>self.__next_f.push([1,"## 👋 Welcome to the September Edition!\n\nThis week, we’re looking at how AI agents are moving deeper into developer workflows, what’s happening across the Node.js community, and how NodeSource is bringing runtime diagnostics and security context directly into developer and AI-assisted environments.\n\nHere’s what’s inside:\n\n🤖 **AI-Powered Dependency Auditing:** See how the N|Solid Plugin + Codex can turn Node.js dependency vulnerabilities into actionable upgrade recommendations using NCM vulnerability intelligence.\n\n🧩 **N|Solid DevTools:** Bring live Node.js telemetry, CPU profiles, heap snapshots, performance insights, and package security directly into VS Code, Cursor, Windsurf, and compatible editors.\n\n🌎 **Community \u0026 Events:** Catch up on Node.js Interactive 2026, explore the NodeConf EU program, and discover the upcoming virtual JS Days 2026 conference.\n\n🤖 **AI Corner:** Recommended reads on autonomous coding agents, collaborative agent workflows, and how tools like Cursor, Slack, Codex, and GitLab are pushing AI deeper into the software development lifecycle.\n\n🚀 **Node.js Upgrade Program:** Learn how organizations running End-of-Life Node.js versions can get free expert guidance to plan and execute their next upgrade.\n\nHappy reading! 🚀\n\n---\n\n![13.png](https://assets.nodesource.com/strapi-uploads/13_9ff7e4754a.png)\n\n## 🟢 Last Week in Node.js\n\n### Node.js 24.20.0 (LTS) — More Control, Better Diagnostics\n\nNode.js 24.20.0 **“Krypton”** landed with several useful additions for production applications and tooling.\n\nHighlights include:\n\n- 🔐 New `permission.drop()` API to revoke permissions at runtime\n- 🔎 New `--permission-audit` flag for auditing permission usage\n- 📦 Package maps support in loaders\n- 🌊 New `node:stream/iter` implementation\n- 🧪 `context.log()` and new events in the built-in test runner\n- ⚡ JavaScript Promise Integration (JSPI) enabled for WebAssembly\n- 🔒 Root certificates updated to NSS 3.125\n- 📦 npm updated to 11.19.0\n\n👉 **Explore Node.js 24.20.0:** https://nodejs.org/en/blog/release/v24.20.0\n\n### Node.js 26.8.0 \u0026 26.8.1 (Current) — Crypto, Performance \u0026 Developer Experience\n\nNode.js 26.8.0 introduced a broad set of improvements across performance tooling, cryptography, diagnostics, SQLite, and the REPL.\n\nNotable updates include:\n\n- 🔐 SIV and GCM-SIV encryption modes added to Cipher/Decipher APIs\n- 📊 Statistical hypothesis testing added to performance histograms\n- 🔭 `TracingChannel` is now stable\n- ⚡ Performance improvements for `net.BlockList`\n- New `close()` and `Symbol.dispose` support for SQLite statements\n- 📦 New `ZipEntry`, `ZipFile`, and `ZipBuffer` APIs\n- ✨ Basic syntax highlighting in the Node.js REPL\n- 🧪 New benchmark analysis tooling\n\nNode.js **26.8.1** followed as an out-of-band release to fix an issue where `node --version` incorrectly reported an alpha version.\n\n👉 **Explore Node.js 26.8.0:** https://nodejs.org/en/blog/release/v26.8.0  \n👉 **Explore Node.js 26.8.1:** https://nodejs.org/en/blog/release/v26.8.1\n\n---\n\n![14.png](https://assets.nodesource.com/strapi-uploads/14_4b451f08b2.png)\n\n## 🚀 Featured from NodeSource\n\n### 🤖 nsolid-plugin v1.0.3 is now available\n\nA new version of the **N|Solid Plugin** is out, making it easier to work across organizations and improving the experience for AI coding agents connected to N|Solid.\n\nThis release includes:\n\n- 🏢 Organization switching with the new `switch-org` command and `ns-switch-org` skill\n- 🔗 Improved MCP URL handling\n- 🧪 Test reliability fixes\n\nThe N|Solid Plugin gives AI coding agents access to real Node.js runtime context — including telemetry, CPU profiles, heap snapshots, package security insights, and application benchmarks — so they can investigate issues using production evidence, not just source code.\n\n👉 **Install nsolid-plugin v1.0.3**  \nhttps://npmjs.com/package/nsolid-plugin?activeTab=readme\n\n👉 **Using Pi Agent?**  \nhttps://npmjs.com/package/nsolid-pi-plugin\n\n👉 **Explore N|Solid DevTools**  \nhttps://nodesource.com/products/nsolid/devtools\n\n### 🟢 N|Solid is getting ready for Node.js 26 LTS\n\nN|Solid is already running on top of **Node.js 26.7.0**, with the full test suite passing.\n\nThat means the groundwork is in place for N|Solid to 
1support Node.js 26 as it moves toward LTS — helping teams adopt the next LTS line while keeping the production diagnostics, security intelligence, and runtime visibility they rely on.\n\n👉 **Learn more about N|Solid**  \nhttps://nodesource.com/products/nsolid\n\n👉 **Explore N|Solid DevTools**  \nhttps://nodesource.com/products/nsolid/devtools\n\n---\n\n![15.png](https://assets.nodesource.com/strapi-uploads/15_d2c3553745.png)\n\n## 🌎 Community \u0026 Events\n\n### 🇮🇹 NodeConf EU 2026 is coming this month\n\nNodeConf EU returns **September 29–30 in Bologna, Italy**, bringing together the Node.js community for two days of talks focused on runtimes, performance, tooling, observability, and production systems.\n\nThis year’s program includes sessions on:\n\n- The new **Node.js release model** and what changes with Node.js 27\n- Node.js runtime interoperability\n- Performance optimization\n- Memory leaks and debugging\n- Production Node.js systems\n\n👉 Explore the program and get tickets:  \nhttps://nodeconf.eu/\n\n### 💚 Get involved with the Node.js community this week\n\nSeveral public Node.js project meetings are happening this week, and anyone in the community can join:\n\n- **Node.js Next 10 Years** — September 2\n- **Diagnostics WG** — September 3\n- **Build WG** — September 3\n- **Node-API team meeting** — September 4\n\nA great way to follow what’s happening inside the project, connect with contributors, and get involved in the Node.js community.\n\n👉 See upcoming Node.js meetings:  \nhttps://nodejs.org/en/about/get-involved/events\n\n---\n\n![16.png](https://assets.nodesource.com/strapi-uploads/16_1dd9491c3e.png)\n\n## 🤖 AI Corner\n\n### AI coding agents are becoming collaborative workflows\n\nGitHub’s latest Copilot updates show where AI-assisted development is heading: beyond a single developer chatting with an agent.\n\nRecent additions include shared agent sessions from Slack and Microsoft Teams, the ability to continue Copilot or Claude agent sessions inside VS Code, organization-wide custom agents, and even an experimental `/rubber-duck` command that asks a complementary model for a second opinion.\n\nThe interesting shift: agents are becoming part of the development workflow itself — across IDEs, repositories, reviews, and team conversations.\n\n👉 Explore GitHub Copilot’s latest updates\n\n### 💡 AI Tip of the Week\n\n#### Ask another agent to challenge the first one\n\nDon’t only ask your coding agent to generate a solution.\n\nBefore accepting a meaningful change, try asking a second model or agent to review it specifically for:\n\n- incorrect assumptions\n- edge cases\n- security issues\n- unnecessary complexity\n- regressions\n\nA useful prompt can be as simple as:\n\n“Review this solution as a skeptical senior engineer. Don’t rewrite it yet — identify assumptions, risks, and edge cases the original implementation may have missed.”\n\nThis “second opinion” pattern is becoming increasingly common in agentic development workflows — and GitHub is even experimenting with it directly through Copilot’s `/rubber-duck` command.\n\n### 📚 Recommended Reading\n\n#### Automating repetitive work at OpenAI with Codex\n\nA practical look at how an OpenAI engineer uses Codex to handle recurring engineering work while keeping humans involved in planning, approvals, and consequential decisions.\n\nInstead of creating one-off automation for every repeated task, the workflow captures **context, commands, results, decisions, and lessons learned** so future agent runs can build on previous work.\n\nIt’s a particularly interesting example of an important agentic pattern: **don’t just automate the task — preserve the context generated while solving it.**\n\n👉 Read “Automating repetitive work at OpenAI with Codex”\n\n---\n\n![17.png](https://assets.nodesource.com/strapi-uploads/17_6d17b13b36.png)\n\n## 🚀 Node.js Upgrade Program\n\n### Free Expert Help for Your Next Node.js Upgrade\n\nStill running an End-of-Life version of Node.js?\n\nThe **Node.js Upgrade Program**, developed in partnership with the **OpenJS Foundation**, helps organizations migrate to supp
1orted LTS releases with **free expert guidance** from the Node.js ecosystem.\n\nYou can follow the step-by-step upgrade process yourself using the program's resources, or request assistance from the Upgrade Program team to help plan and execute your migration.\n\nThe program is designed to help organizations:\n\n- ✅ Upgrade from End-of-Life Node.js versions\n- ✅ Reduce security and compliance risks\n- ✅ Plan migrations with confidence\n- ✅ Modernize production applications\n\n**Participation is completely free for organizations.**\n\n🔗 **Learn more and get started:**  \nhttps://nodesource.com/products/nodejs-upgrade\n\n---\n\n![18.png](https://assets.nodesource.com/strapi-uploads/18_21af3c64e2.png)\n\n## ⚡ Stay Connected\n\nThe Node.js ecosystem never stands still—and neither do we.\n\nSubscribe to stay up to date with future editions featuring the latest Node.js releases, AI-powered developer tools, observability, security, and community news.\n\nHave questions, feedback, or ideas for a future edition? We'd love to hear from you.\n\n📩 https://nodesource.com/pages/contact-us.html  \n📧 [email protected]\n\n**See you next month! 👋**"])</script>
1<script>self.__next_f.push([1,"25:[\"$\",\"$L1e\",\"6\",{\"item\":{\"id\":673,\"documentId\":\"td43n19taib225e0cjfepde5\",\"slug\":\"nodesource-weekly-sept-1-2026-ai-agents-nodejs-devtools-community\",\"title\":\"NodeSource Weekly — Sept 1, 2026: New Node.js releases, N|Solid Plugin v1.0.3 \u0026 the road to Node.js 26 LTS\",\"metaDescription\":\"Explore this week’s Node.js updates, N|Solid DevTools, AI coding agent workflows, NodeConf EU 2026, and the Node.js Upgrade Program.\",\"tweetText\":null,\"body\":\"$32\",\"featuredPost\":false,\"createdAt\":\"2026-09-01T17:36:46.853Z\",\"updatedAt\":\"2026-09-01T17:36:46.853Z\",\"publishedAt\":\"2026-09-01T17:36:46.816Z\",\"category\":{\"slug\":\"Newsletter\",\"title\":\"newsletter\"},\"twitterCard\":{\"id\":14729,\"documentId\":\"oy3t0iw62360gzrxjhf7qr5f\",\"name\":\"LinkedIn Article  (3).png\",\"alternativeText\":null,\"caption\":null,\"focalPoint\":null,\"width\":1600,\"height\":900,\"formats\":{\"large\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/large_Linked_In_Article_3_1bc55aff4a.png\",\"etag\":\"e2924987f5670a4f4108ce26173d2e5f\",\"hash\":\"large_Linked_In_Article_3_1bc55aff4a\",\"mime\":\"image/png\",\"name\":\"large_LinkedIn Article  (3).png\",\"path\":null,\"size\":715.4,\"width\":1000,\"height\":563,\"sizeInBytes\":715395},\"small\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/small_Linked_In_Article_3_1bc55aff4a.png\",\"etag\":\"0a4fa568a99abf66f8fe970589a46a7d\",\"hash\":\"small_Linked_In_Article_3_1bc55aff4a\",\"mime\":\"image/png\",\"name\":\"small_LinkedIn Article  (3).png\",\"path\":null,\"size\":207.14,\"width\":500,\"height\":281,\"
1sizeInBytes\":207140},\"medium\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/medium_Linked_In_Article_3_1bc55aff4a.png\",\"etag\":\"e70524eefe81c501139b7512ad7eb3f6\",\"hash\":\"medium_Linked_In_Article_3_1bc55aff4a\",\"mime\":\"image/png\",\"name\":\"medium_LinkedIn Article  (3).png\",\"path\":null,\"size\":426.47,\"width\":750,\"height\":422,\"sizeInBytes\":426469},\"thumbnail\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/thumbnail_Linked_In_Article_3_1bc55aff4a.png\",\"etag\":\"9fef6923671338f5898e761b99416c26\",\"hash\":\"thumbnail_Linked_In_Article_3_1bc55aff4a\",\"mime\":\"image/png\",\"name\":\"thumbnail_LinkedIn Article  (3).png\",\"path\":null,\"size\":60.63,\"width\":245,\"height\":138,\"sizeInBytes\":60626}},\"hash\":\"Linked_In_Article_3_1bc55aff4a\",\"ext\":\".png\",\"mime\":\"image/png\",\"size\":393.55,\"url\":\"https://assets.nodesource.com/strapi-uploads/Linked_In_Article_3_1bc55aff4a.png\",\"previewUrl\":null,\"provider\":\"aws-s3\",\"provider_metadata\":null,\"createdAt\":\"2026-09-01T17:35:29.701Z\",\"updatedAt\":\"2026-09-01T17:35:29.701Z\",\"publishedAt\":\"2026-09-01T17:35:29.701Z\"}}}]\n"])</script>
1<script>self.__next_f.push([1,"33:T3634,"])</script>
1<script>self.__next_f.push([1,"2026 is shaping up to be a remarkable year for **Node.js download activity**. Through July, downloads recorded through the **official Node.js distribution infrastructure** have already surpassed the total recorded during all of 2025: **4.61 billion downloads in the first seven months of 2026, compared with 4.48 billion across the entire previous year**. That puts 2026 roughly 128 million downloads ahead of the 2025 total, with five months still left in the year.\n\n![nodejs_graph_1_2025_vs_2026_ytd.png](https://assets.nodesource.com/strapi-uploads/nodejs_graph_1_2025_vs_2026_ytd_0bfd752697.png)\n\n*Figure 1. Node.js recorded 4.61 billion downloads from January through July 2026, already surpassing the 4.48 billion recorded throughout all of 2025. Source: Node.js Download Metrics, aggregated by Matteo Collina’s Node.js Download Statistics project (https://github.com/mcollina/nodejs-download-stats/).*\n\nThe growth is interesting on its own, but the version mix tells an even more useful story. In July, **Node.js 24 was the most downloaded major version in the official Node.js download data**, reaching approximately **358.8 million downloads**. Node.js 22 followed with 283.9 million, while Node.js 20 still accounted for more than 103.7 million downloads despite reaching End-of-Life earlier this year.\n\n![nodejs_graph_2_major_versions_july_2026.png](https://assets.nodesource.com/strapi-uploads/nodejs_graph_2_major_versions_july_2026_fd83167eb8.png)\n\n*Figure 2. Node.js 24 led major-version downloads in July 2026 with 358.8 million downloads, followed by Node.js 22 with 283.9 million. Source: Node.js Download Metrics, aggregated by Matteo Collina’s Node.js Download Statistics project (https://github.com/mcollina/nodejs-download-stats/).*\n\nSeeing Node.js 24 at the top is an encouraging signal. It is a currently supported LTS release, so its growing share of download activity suggests that a meaningful part of the ecosystem is moving toward a modern, actively maintained runtime baseline. The timing is particularly relevant as Node.js 26, currently the Current release, approaches its transition to LTS later this year.\n\nN|Solid Runtime is showing similar momentum. From January 2024 through July 2026, NodeSource Distribution Stats recorded more than **2.23 million N|Solid Runtime downloads across 190 countries and territories**, while 2025 download volume grew **229.4% compared with 2024**. With only seven months of data, 2026 is already approaching the full N|Solid download volume recorded during 2025.\n\n![nsolid_runtime_downloads_graph_3_fixed_v3.png](https://assets.nodesource.com/strapi-uploads/nsolid_runtime_downloads_graph_3_fixed_v3_1fcffa0072.png)\n\n*Figure 3. N|Solid Runtime download activity has accelerated significantly since 2024, with 2026 already approaching the full 2025 total through July. Source: NodeSource Distribution Stats (https://distributions.nodesource.io/?year=all\u0026package=nsolid).*\n\nTaken together, these numbers show strong download activity across both Node.js and N|Solid Runtime, while supported LTS releases are gaining ground. But the data also reveals an important contrast: modernization is not happening everywhere at the same pace. But the data also reveals an important contrast: **modernization is not happening everywhere at the same pace**.\n\nOlder, unsupported Node.js versions continue to generate substantial download activity. That does not necessarily mean developers are consciously choosing an EOL runtime every day. In many cases, those versions are already embedded in Docker images, CI pipelines, build systems, version managers, and deployment infrastru
1cture, where they can continue to be downloaded automatically long after the original version decision was made.\n\nThat is what makes the latest download data worth examining. It does not simply tell us that Node.js is growing; it gives us a view into **how quickly the ecosystem is moving toward supported releases—and where legacy runtime decisions are still holding applications back**.\n\n## What the 2026 Download Data Is Actually Telling Us\n\nBefore drawing conclusions from the numbers, it is worth clarifying what a “download” actually represents. A download does not necessarily map to a unique developer, a production server, or even a brand-new Node.js installation. Runtime packages can be pulled automatically by CI/CD pipelines, Docker builds, ephemeral runners, developer machines, version managers, cloud build systems, provisioning tools, and other parts of the software delivery process.\n\nThat makes the data useful in a different way. Rather than treating downloads as a proxy for the number of Node.js users, they are better understood as a signal of **runtime activity across development and infrastructure workflows**. If a release continues to generate large numbers of downloads month after month, that version may still be actively rebuilt, deployed, or provisioned throughout real software delivery systems.\n\nThis distinction becomes particularly important when looking at the version mix. A runtime can remain highly active even when nobody is consciously choosing it anymore. A Node.js version pinned years ago in a Dockerfile, CI configuration, base image, or version manager can continue generating downloads every time that environment is recreated.\n\nSo the interesting story behind the 2026 numbers is not simply that Node.js download activity is growing. **It is that download activity is increasing while the runtime mix is changing**, giving us a useful view into how quickly applications and infrastructure may be moving toward supported releases.\n\n## Why Node.js 24 Taking the Lead Matters\n\nNode.js 24, co
1denamed **Krypton**, was released in May 2025 and is now an LTS release. Seeing it lead the July download data is therefore more meaningful than watching one version number overtake another: it suggests that a growing share of Node.js activity is landing on a modern, actively maintained runtime baseline.\n\nThere are meaningful technical changes behind that transition. Node.js 24 introduced **V8 13.6, npm 11, URLPattern as a global API, improvements to the Permission Model and test runner, changes to AsyncLocalStorage, and Undici 7**, alongside new platform requirements and deprecations. Moving to a supported release also means continuing to receive the security and maintenance updates provided throughout the Node.js release lifecycle.\n\nNode.js 26 is already showing what comes next. Released in May 2026, it includes **Temporal enabled by default, V8 14.6, Undici 8**, and further runtime modernization. It is scheduled to transition to LTS in October 2026, giving application and library maintainers time to evaluate compatibility before broader production adoption.\n\nThe current pattern is therefore encouraging: **Node.js 24 is seeing strong download activity** while Node.js 26 is already available for testing. The challenge is that not every application is moving along that path at the same pace.\n\n## Modernization Is Growing, but Legacy Runtime Activity Has Not Disappeared\n\nNode.js 20 reached End-of-Life on April 30, 2026, while Node.js 18 reached EOL a year earlier, on April 30, 2025. Yet both releases continue to appear prominently in download data. In July alone, Node.js 20 and 18 accounted for more than 136 million downloads combined **in the official Node.js download data**.\n\nThis does not necessarily mean millions of teams deliberately chose an unsupported runtime in July. In many cases, the choice may have been made months or years ago and then encoded into infrastructure.\n\nA Dockerfile may still contain:\n\n```dockerfile\nFROM node:20\n```\n\nA CI workflow may still specify:\n\n```yaml\n- uses: actions/setup-node@v4\n  with:\n    node-version: 20\n```\n\nAn `.nvmrc`, build image, Terraform configuration, or internal deployment template can preserve the same decision indefinitely. Every clean build or new CI runner can then request that runtime again, even though nobody actively revisited the version choice.\n\nThis is what makes EOL activity important from an engineering perspective. An old Node.js release can be **legacy and highly active at the same time**. It may be powering applications that are rebuilt every day, deployed hundreds of times per month, and continuously recreated in ephemeral infrastructure.\n\nThe Node.js project is very clear about what changes once a release reaches End-of-Life. EOL lines no longer receive updates, including security patches. Over time, they can also face toolchain breakage, ecosystem drift as packages remove support, and compliance issues in environments that prohibit unmaintained runtimes.\n\nThe risk is subtle because reaching EOL does not make an application immediately stop working. Tests may continue passing, health checks may remain green, and production traffic may look completely normal. What changes is the ability to rely on the upstream Node.js project when new bugs or vulnerabilities are discovered.\n\nThat difference becomes more important the longer an application stays behind.\n\n## The Cost of Waiting Is Usually Bigger Than the Version Change\n\nFor many engineering teams, postponing a runtime upgrade can feel safer than changing a stable production system. If the application works today, it is understandable to ask why the runtime needs attention now.\n\nThe problem is that the rest of the ecosystem does not stay still. Dependencies move to newer Node.js requirements, operating systems and container images evolve, native addons adopt newer toolchains, cloud platforms retire older runtimes, and deprecated Node.js APIs eventually become migration blockers.\n\nWhat begins as a relatively contained runtime upgrade can gradually turn into a broader modernization project.\n\nA team moving from Node.js 20 to Node.js 24, for example, may need to evaluate far more than the executable itself. Direct and transitive dependencies may have changed their supported engines. Native C or C++ modules may need to be rebuilt or replaced. Deprecated runtime APIs may need refactoring, and changes to V8, OpenSSL, networking behavior, build environments, or CI images can surface compatibility issues that application-level tests alone do not reveal.\n\nThis is why a production Node.js upgrade is rarely just:\n\n```shell\nnode --version\n```\n\nThe more useful question is: **what stands between this application and a supp
1orted runtime?**\n\n## Find the Upgrade Blockers Before Changing the Runtime\n\nThis is the problem the **Node.js Upgrade Program**, developed by NodeSource in partnership with the OpenJS Foundation, is designed to address. The goal is not simply to tell teams that they should upgrade; it is to make the path to a supported release easier to understand before changes reach production.\n\nNode.js's own EOL documentation recognizes that organizations can be prevented from upgrading immediately by legacy applications, complex dependency chains, and other operational constraints. The project's official EOL page lists NodeSource as a commercial support provider through the OpenJS Ecosystem Sustainability Program and specifically describes the NodeSource Upgrade Program as providing risk analysis, migration-blocker identification, and upgrade roadmaps.\n\nTeams can begin with the free Upgrade Discovery CLI:\n\n```shell\nnpx @nodesource/upgrade\n```\n\nThe scan runs in the application's environment and analyzes direct and transitive dependencies, native C/C++ addons, and static Node.js API usage to help identify potential migration blockers before the runtime is changed. The resulting discovery data can then be used to evaluate security and upgrade risk, deprecated APIs, native addon conflicts, vulnerable dependencies, and other compatibility concerns.\n\nThat changes the starting point of an upgrade. Instead of installing a new Node.js version and waiting to discover what breaks, teams can first understand where the risk is, what needs attention, and how much work the migration is likely to require.\n\n[![node-upgrade.png](https://assets.nodesource.com/strapi-uploads/upgrade_23b73580d5.png)](https://nodesource.com/products/nodejs-upgrade)\n\n[Get your free Node.js Upgrade Assessment →](https://nodesource.com/upgrade)\n\n## A Healthy Trend—and a Useful Reminder\n\nThe 2026 distribution numbers are encouraging. In the official Node.js download data, activity through July has already surpassed the total recorded during all of 2025, while Node.js 24 reached the top position for the first time. N|Solid Runtime download activity also continues to accelerate, and Node.js 26 is preparing for its LTS transition this fall.\n\nTogether, these trends show download activity increasingly concentrating around newer, actively maintained releases.\n\nAt the same time, continued activity around EOL runtimes is a reminder that modernization rarely happens everywhere at once. Node.js versions can remain embedded in Dockerfiles, CI pipelines, build infrastructure, dependencies, and production environments long after their official support window ends.\n\nFor teams already running Node.js 24, the current data is a good sign of where the ecosystem is heading. For teams still relying on Node.js 20, Node.js 18, or an even older release, it is an opportunity to understand the upgrade path before security pressure, infrastructure changes, or dependency incompatibilities make the decision for them.\n\nThe ecosystem is moving forward. The most important question is whether your applications have a clear path to move with it.\n\n## Further Reading\n\nFor readers who want to explore the underlying release and lifecycle information:\n\n- Official Node.js release and LTS status\n- Official Node.js End-of-Life guidance\n- Node.js 24.0.0 release notes\n- Node.js 26.0.0 release notes\n- Official Node.js release schedule\n- NodeSource Distribution Stats\n- Node.js Download Stats\n- Free Node.js Upgrade Assessment"])</script>
1<script>self.__next_f.push([1,"26:[\"$\",\"$L1e\",\"7\",{\"item\":{\"id\":672,\"documentId\":\"c4z7r3ca40egv02e0fwptybs\",\"slug\":\"nodejs-downloads-2026-node-24-adoption\",\"title\":\"Node.js Downloads Surge in 2026 as Node.js 24 Takes the Lead\",\"metaDescription\":\"Official Node.js download data shows 2026 has already surpassed 2025 totals, while Node.js 24 leads for the first time. See what the data means for LTS adoption, EOL risk, and modernization. \",\"tweetText\":null,\"body\":\"$33\",\"featuredPost\":false,\"createdAt\":\"2026-08-27T19:27:20.685Z\",\"updatedAt\":\"2026-08-27T19:30:13.766Z\",\"publishedAt\":\"2026-08-27T19:30:13.090Z\",\"category\":{\"slug\":\"node-js\",\"title\":\"Node.js\"},\"twitterCard\":{\"id\":14722,\"documentId\":\"g5y2cxalpuligis243wm8srv\",\"name\":\"LinkedIn Article  (2).png\",\"alternativeText\":null,\"caption\":null,\"focalPoint\":null,\"width\":1600,\"height\":900,\"formats\":{\"large\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/large_Linked_In_Article_2_29d5649ff8.png\",\"etag\":\"2a0c7747587ab123405da2d4c39bdc06\",\"hash\":\"large_Linked_In_Article_2_29d5649ff8\",\"mime\":\"image/png\",\"name\":\"large_LinkedIn Article  (2).png\",\"path\":null,\"size\":498.11,\"width\":1000,\"height\":563,\"sizeInBytes\":498113},\"small\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/small_Linked_In_Article_2_29d5649ff8.png\",\"etag\":\"8bf2a53150aab9ee93b3f4ecc49dc959\",\"hash\":\"small_Linked_In_Article_2_29d5649ff8\",\"mime\":\"image/png\",\"name\":\"small_LinkedIn Article  (2).png\",\"path\":null,\"size\":146.83,\"width\":500,\"height\":281,\"
1sizeInBytes\":146826},\"medium\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/medium_Linked_In_Article_2_29d5649ff8.png\",\"etag\":\"e4d890b02f3809be0e5ec5d46f37b439\",\"hash\":\"medium_Linked_In_Article_2_29d5649ff8\",\"mime\":\"image/png\",\"name\":\"medium_LinkedIn Article  (2).png\",\"path\":null,\"size\":297.15,\"width\":750,\"height\":422,\"sizeInBytes\":297152},\"thumbnail\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/thumbnail_Linked_In_Article_2_29d5649ff8.png\",\"etag\":\"a2350dce81db727eb8929c0a0adc121f\",\"hash\":\"thumbnail_Linked_In_Article_2_29d5649ff8\",\"mime\":\"image/png\",\"name\":\"thumbnail_LinkedIn Article  (2).png\",\"path\":null,\"size\":45.7,\"width\":245,\"height\":138,\"sizeInBytes\":45699}},\"hash\":\"Linked_In_Article_2_29d5649ff8\",\"ext\":\".png\",\"mime\":\"image/png\",\"size\":219.49,\"url\":\"https://assets.nodesource.com/strapi-uploads/Linked_In_Article_2_29d5649ff8.png\",\"previewUrl\":null,\"provider\":\"aws-s3\",\"provider_metadata\":null,\"createdAt\":\"2026-08-27T19:26:49.748Z\",\"updatedAt\":\"2026-08-27T19:26:49.748Z\",\"publishedAt\":\"2026-08-27T19:26:49.749Z\"}}}]\n"])</script>
1<script>self.__next_f.push([1,"34:T225a,"])</script>
1<script>self.__next_f.push([1,"## 👋 Welcome to the August Edition!\n\nThis week, we’re looking at how AI agents are moving deeper into developer workflows, what’s happening across the Node.js community, and how NodeSource is bringing runtime diagnostics and security context directly into developer and AI-assisted environments.\n\nHere’s what’s inside:\n\n🤖 **AI-Powered Dependency Auditing:** See how the N|Solid Plugin + Codex can turn Node.js dependency vulnerabilities into actionable upgrade recommendations using NCM vulnerability intelligence.\n\n🧩 **N|Solid DevTools:** Bring live Node.js telemetry, CPU profiles, heap snapshots, performance insights, and package security directly into VS Code, Cursor, Windsurf, and compatible editors.\n\n🌎 **Community \u0026 Events:** Catch up on Node.js Interactive 2026, explore the NodeConf EU program, and discover the upcoming virtual JS Days 2026 conference.\n\n🤖 **AI Corner:** Recommended reads on autonomous coding agents, collaborative agent workflows, and how tools like Cursor, Slack, Codex, and GitLab are pushing AI deeper into the software development lifecycle.\n\n🚀 **Node.js Upgrade Program:** Learn how organizations running End-of-Life Node.js versions can get free expert guidance to plan and execute their next upgrade.\n\nHappy reading! 🚀\n\n---\n\n![9.png](https://assets.nodesource.com/strapi-uploads/9_ef2eff462a.png)\n\n## 🚀 Featured from NodeSource\n\n### 🤖 Audit Node.js Dependencies with AI | N|Solid Plugin + Codex\n\nWhat if your AI coding agent could turn Node.js dependency vulnerabilities into actionable upgrade recommendations?\n\nIn this demo, we use the **N|Solid Plugin with Codex** and the `ns-audit-dependencies` skill to audit direct and transitive npm dependencies against **NCM vulnerability intelligence**.\n\nThe audit helps identify vulnerable packages, severity, recommended upgrades, target remediation versions, unresolved findings, and generates a complete Markdown security report.\n\nFinding a vulnerable dependency is only the first step. The goal is to give developers and AI coding agents better security context to understand **what needs attention and what to upgrade next**.\n\n👉 https://youtu.be/YWgcAmRGgp4\n\n### 🧩 Bring production Node.js diagnostics into your editor\n\nThe N|Solid Extension brings real runtime intelligence directly into the tools developers already use, helping teams investigate production issues without constantly switching context.\n\nWith the extension, developers can access:\n\n- Live runtime telemetry\n- Heap snapshots\n- CPU profiles\n- Event loop and performance insights\n- Package security information\n- AI-assisted diagnostics\n\nIt works with VS Code, Cursor, Windsurf, Antigravity, and other compatible editors.\n\n👉 Install the N|Solid Extension:\n\nVS Code:  \nhttps://marketplace.visualstudio.com/items?itemName=nodesource-inc.nsolid\n\nWindsurf, Cursor, and compatible editors:  \nhttps://marketplace.windsurf.com/extension/nodesource-inc/nsolid/1.0.2\n\n### 🤖 Give your AI coding agent real production context\n\nThe N|Solid Plugin extends that same runtime intelligence to AI coding agents, allowing them to investigate applications using real production evidence instead of relying only on source code.\n\nAI agents can work with:\n\n- Heap snapshots\n- CPU profiles\n- Runtime telemetry\n- Package security insights\n- Application benchmarks\n\nIt works with Claude Code, Codex CLI, OpenCode, Antigravity CLI, Pi Agent, and other supported AI coding tools.\n\n👉 Learn more about the N|Solid Plugin:  \nhttps://nodesource.com/blog/introducing-nsolid-plugin-ai-coding-agents\n\n👉 Install the N|Solid Plugin:  \nhttps://www.npmjs.com/package/nsolid-plugin?activeTab=readme\n\n---\n\n![5.png](https://assets.nodesource.com/strapi-uploads/5_a24b34bdb0.png)\n\n## 🌎 Community \u0026 Events\n\n### Node.js Interactive 2026: Key Takeaways from Atlanta\n\nNode.js published the official recap of **Node.js Interactive 2026**, held August 12–13 in Atlanta.\n\nTopics included open source sustainability, supply chain security, WinterTC interoperability, the evolving Node.js release model, QUIC/HTTP/3, performance, and the role of AI in developer workflows.\n\nThe event also wrapped up with a **Code \u0026 Learn** session where developers worked directly with Node.js core maintainers.\n\n[Read the Node.js Interactive 2026 recap](https://nodejs.org/en/blog/events/nodejs-interactive-2026?utm_source=chatgpt.com)\n\n### NodeConf EU 2026 Program Takes Shape\n\nInstead of simply highlighting the event again, this week we can point readers to the **NodeConf EU 2026 program**.\n\nThe agenda includes talks on Node.js runtime interoperability, performance, memory leaks, observability, production systems, and platform architecture, with several sessions especially relevant to developers working close to the runtime.\n\n[Explore the NodeConf EU 2026 program](https://nodeconf.eu/program?utm_source=chatgpt.com)\n\n### JS Days 2026 — Free Virtual JavaScript Conference\n\n**September 16–17 · Online · Free**\n\nJS Days 2026 brings together sessions around **JavaScript, React, AI-powered development, and enterprise applications**, making it an accessible option for developers who want to follow the broader JavaScript ecosystem without traveling.\n\n[Learn more about JS Days 2026](https://www.jsdays.io/)\n\n---\n\n![3.png](https://assets.nodesource.com/strapi-uploads/3_33da781366.png)\n\n## 🤖 AI Corner\n\n### 📚 Recommended reads: autonomous agents, collaborative coding \u0026 developer workflows.\n\n- **Cloud Agents and Cursor Harness Improvements — Cursor**\n\n  Probablemente la más relevante. Cursor está llevando los coding agents hacia un modelo **always-on**: ahora pueden reaccionar a eventos, monitorear PRs y threads de Slack, ejecutar tareas programadas y mantener objetivos de largo plazo con `/goal`. También pueden ejecutar subagents en VMs aisladas para probar cambios o trabajar en paralelo. Es una señal muy clara del cambio de “AI coding assistant” a **autonomous software agents**.\n\n  [Cursor — Cloud Agents and Cursor Harness Improvements](https://cursor.com/changelog/08-19-26?utm_source=chatgpt.com)\n\n- **Slack Code: Where Your Team and Agents Build Together — Slack**\n\n  Slack lanzó **Code Channels**, espacios donde developers y coding agents pueden planear, escribir, revisar y seguir cambios juntos. La integración arranca con agentes de Anthropic, Cognition, GitHub y Vercel, con OpenAI también anunciado. Lo interesante es el cambio de agentes usados individualmente hacia **collaborative, team-based agentic development**, con diffs, previews, approvals y contexto compartido dentro del workflow.\n\n  [Slack — Slack Code: Where Your Team and Agents Build Together](https://slack.com/blog/news/slack-code-channels-for-agents?utm_source=chatgpt.com)\n\n- **GitLab Support in Codex Cloud — OpenAI**\n\n  OpenAI añadió soporte de **GitLab a Codex Cloud** en beta. Los developers pueden conectar proyectos, iniciar tareas desde issues o merge requests usando `@codex`, y solicitar reviews manuales o automáticos de merge requests. Es un buen ejemplo de cómo los coding agents están dejando de ser herramientas separadas y entrando directamente en los **existing software delivery workflows**.\n\n  [OpenAI — Codex GitLab support release notes](https://
1openai.com/products/release-notes/?utm_source=chatgpt.com)\n  \n---\n\n![8.png](https://assets.nodesource.com/strapi-uploads/8_1dc84b3a08.png)\n\n## 🚀 Node.js Upgrade Program\n\n### Free Expert Help for Your Next Node.js Upgrade\n\nStill running an End-of-Life version of Node.js?\n\nThe **Node.js Upgrade Program**, developed in partnership with the **OpenJS Foundation**, helps organizations migrate to supported LTS releases with **free expert guidance** from the Node.js ecosystem.\n\nYou can follow the step-by-step upgrade process yourself using the program's resources, or request assistance from the Upgrade Program team to help plan and execute your migration.\n\nThe program is designed to help organizations:\n\n- ✅ Upgrade from End-of-Life Node.js versions\n- ✅ Reduce security and compliance risks\n- ✅ Plan migrations with confidence\n- ✅ Modernize production applications\n\n**Participation is completely free for organizations.**\n\n🔗 **Learn more and get started:**  \nhttps://nodesource.com/products/nodejs-upgrade\n\n---\n\n![6.png](https://assets.nodesource.com/strapi-uploads/6_0a05b60c42.png)\n\n## ⚡ Stay Connected\n\nThe Node.js ecosystem never stands still—and neither do we.\n\nSubscribe to stay up to date with future editions featuring the latest Node.js releases, AI-powered developer tools, observability, security, and community news.\n\nHave questions, feedback, or ideas for a future edition? We'd love to hear from you.\n\n📩 https://nodesource.com/pages/contact-us.html  \n📧 [email protected]\n\n**See you next month! 👋**"])</script>
1<script>self.__next_f.push([1,"27:[\"$\",\"$L1e\",\"8\",{\"item\":{\"id\":671,\"documentId\":\"mfs1rr64l22b4hrqgpln2q7x\",\"slug\":\"nodesource-weekly-august-25-2026-ai-agents-nodejs-devtools-community\",\"title\":\"NodeSource Weekly — Aug 25, 2026: AI Agents, Node.js DevTools \u0026 Community\",\"metaDescription\":\"Explore this week’s NodeSource updates on AI coding agents, N|Solid DevTools, Node.js community events, dependency security, and the Node.js Upgrade Program.\",\"tweetText\":null,\"body\":\"$34\",\"featuredPost\":false,\"createdAt\":\"2026-08-25T20:12:41.939Z\",\"updatedAt\":\"2026-08-25T20:12:41.939Z\",\"publishedAt\":\"2026-08-25T20:12:41.907Z\",\"category\":{\"slug\":\"Newsletter\",\"title\":\"newsletter\"},\"twitterCard\":{\"id\":14718,\"documentId\":\"wekpa0pvj1imjug1urap5rdb\",\"name\":\"LinkedIn Article  (1).png\",\"alternativeText\":null,\"caption\":null,\"focalPoint\":null,\"width\":1600,\"height\":900,\"formats\":{\"large\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/large_Linked_In_Article_1_e6064c0ec4.png\",\"etag\":\"ff0d0d8180a6480ea230b114078a5e0e\",\"hash\":\"large_Linked_In_Article_1_e6064c0ec4\",\"mime\":\"image/png\",\"name\":\"large_LinkedIn Article  (1).png\",\"path\":null,\"size\":565.76,\"width\":1000,\"height\":563,\"sizeInBytes\":565756},\"small\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/small_Linked_In_Article_1_e6064c0ec4.png\",\"etag\":\"a763eb63d14b36b0eb0f48b2a8a08948\",\"hash\":\"small_Linked_In_Article_1_e6064c0ec4\",\"mime\":\"image/png\",\"name\":\"small_LinkedIn Article  (1).png\",\"path\":null,\"size\":153,\"width\":500,\"height\":281,\"
1sizeInBytes\":153002},\"medium\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/medium_Linked_In_Article_1_e6064c0ec4.png\",\"etag\":\"f0cb46a770f09b93850dd8a9be2cd616\",\"hash\":\"medium_Linked_In_Article_1_e6064c0ec4\",\"mime\":\"image/png\",\"name\":\"medium_LinkedIn Article  (1).png\",\"path\":null,\"size\":320.96,\"width\":750,\"height\":422,\"sizeInBytes\":320963},\"thumbnail\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/thumbnail_Linked_In_Article_1_e6064c0ec4.png\",\"etag\":\"0c5de46c2bfc85c341552684c509f211\",\"hash\":\"thumbnail_Linked_In_Article_1_e6064c0ec4\",\"mime\":\"image/png\",\"name\":\"thumbnail_LinkedIn Article  (1).png\",\"path\":null,\"size\":46.48,\"width\":245,\"height\":138,\"sizeInBytes\":46484}},\"hash\":\"Linked_In_Article_1_e6064c0ec4\",\"ext\":\".png\",\"mime\":\"image/png\",\"size\":266.8,\"url\":\"https://assets.nodesource.com/strapi-uploads/Linked_In_Article_1_e6064c0ec4.png\",\"previewUrl\":null,\"provider\":\"aws-s3\",\"provider_metadata\":null,\"createdAt\":\"2026-08-25T20:12:31.999Z\",\"updatedAt\":\"2026-08-25T20:12:31.999Z\",\"publishedAt\":\"2026-08-25T20:12:32.000Z\"}}}]\n"])</script>
1<script>self.__next_f.push([1,"35:T3e74,"])</script>
1<script>self.__next_f.push([1,"Updating Node.js can be as simple as installing a new version. But a **safe Node.js upgrade is more than changing the number returned by** `node -v`.\n\nA major release can affect dependencies, native addons, Node.js APIs, OpenSSL, build environments, and runtime behavior. Before changing the runtime, the first question should be:\n\n**What could break?**\n\n[![node-upgrade.png](https://assets.nodesource.com/strapi-uploads/upgrade_23b73580d5.png)](https://nodesource.com/products/nodejs-upgrade)\n\n[Get your free Node.js Upgrade Assessment →](https://nodesource.com/upgrade)\n\n### Before you upgrade, check your application\n\nRun NodeSource's free Upgrade Discovery CLI:\n\n```shell\nnpx @nodesource/upgrade\n```\n\nIt analyzes your dependencies, native C/C++ addons, and static Node.js API usage locally to help identify potential upgrade blockers before you change the runtime. Your source code stays in your environment.\n\nFor production applications—especially those moving from older or End-of-Life (EOL) releases—finding those blockers early can turn an unpredictable migration into a manageable engineering project.\n\n## Check Whether Your Current Node.js Version Is Already Vulnerable\n\nBefore asking what might break during an upgrade, start with a more immediate question:\n\n**Is the Node.js version you're running today already affected by known vulnerabilities?**\n\nThe Node.js project provides [`is-my-node-vulnerable`](https://github.com/marketplace/actions/is-my-node-vulnerable), a lightweight tool that compares your installed Node.js version against the Node.js Security Database.\n\n![check-current-node-v.png](https://assets.nodesource.com/strapi-uploads/check_current_node_v_a4c1b30552.png)\n\nRun:\n\n```shell\nnpx is-my-node-vulnerable\n```\n\nThe tool checks `process.version` and reports known vulnerabilities affecting that release, including patched versions where available. The project also recommends including the check in application CI.\n\nFor an EOL release, the warning is broader. Because retired Node.js versions do not keep track of recent security releases, `is-my-node-vulnerable` considers them vulnerable by default and recommends upgrading.\n\nThat matters because an application can continue starting, accepting traffic, and passing health checks long after the runtime underneath it has stopped receiving upstream maintenance.\n\nAs of August 2026, Node.js 26 is Current, Node.js 24 and 22 are supported LTS lines, while Node.js 20 and 18 are EOL. The Node.js project recommends Active LTS or Maintenance LTS releases for production applications.\n\nThe official Node.js EOL inventory currently associates Node.js 20 with **27 High, 24 Medium, and 9 Low** vulnerabilities, and Node.js 18 with **15 High, 19 Medium, and 4 Low**. These counts do not mean every application is exploitable through every issue, but they show the growing body of publicly documented risk attached to release lines that no longer have an upstream patch train.\n\nSo `is-my-node-vulnerable` can answer:\n\n**“Do I need to move?”**\n\nBut that leads to the harder question:\n\n**“What could break when I do?”**\n\n## What Can Actually Break in a Node.js Upgrade?\n\nNode.js is more than the JavaScript executable running your application. A major version can change several layers of the runtime at once.\n\nThe most common upgrade risks fall into five areas:\n\n- **Native addons:** compiled modules may need to be rebuilt, updated, or replaced.\n- **Dependencies and npm:** packages, peer dependencies, lockfiles, and build tooling may not support the target version.\n- **OpenSSL and TLS:** cryptographic changes can affect certificates, keys, ciphers, and external integrations.\n- **Node.js APIs:** deprecated behavior can become runtime warnings, errors, or removals.\n- **CI, containers, and operating systems:** the infrastructure building or running the application may not support the new runtime.\n\nThe important part is that **not every application has the same upgrade risk**.\n\nA service built entirely on actively maintained JavaScript packages may have a relatively straightforward upgrade path.\n\nAn older application with native modules, legacy TLS integrations, unsupported dependencies, and years of deprecated APIs may require a much larger modernization effort.\n\n![5-thinks-can-break.png](https://assets.nodesource.com/strapi-uploads/5_thinks_can_break_5317806313.png)\n\n### 
11. Native Addons Can Become Immediate Blockers\n\nNative C and C++ dependencies are one of the first things to identify before changing Node.js versions.\n\nModules built with `node-gyp`, direct V8 APIs, Node.js C++ APIs, or other native interfaces may depend on assumptions that change between major releases.\n\nThat can result in:\n\n- Addons that no longer load.\n- Packages that need to be recompiled.\n- Missing prebuilt binaries.\n- Compiler or toolchain incompatibilities.\n- Native dependencies that have been abandoned.\n\nThe official Node.js 22 → 24 migration guidance, for example, warns that addons linking directly against V8 APIs may need changes for V8 13.6 and that some builds may require C++20 where C++17 was previously sufficient. Node.js recommends preferring Node-API where possible to reduce this rebuild churn.\n\nNode-API is specifically designed to provide ABI stability across Node.js versions. But an addon that depends directly on V8 or other internal interfaces does not automatically get that protection.\n\nBefore upgrading, identify:\n\n- Which native dependencies exist.\n- Which packages use `node-gyp`.\n- Whether they use Node-API.\n- Whether compatible prebuilt binaries exist for the target runtime.\n- Whether the package is still maintained.\n- Whether the target version requires a newer compiler or build environment.\n\nA native dependency is much easier to replace during planning than after the new runtime fails to start.\n\n### 2. Dependencies and npm Can Block the Target Version\n\nThe next layer is the dependency tree.\n\nPackages can declare which versions of Node.js they support through the `engines` field in `package.json`:\n\n```json\n{\n  \"engines\": {\n    \"node\": \"\u003e=22\"\n  }\n}\n```\n\nA major Node.js upgrade can expose:\n\n- Packages that do not support the target release.\n- Peer dependency conflicts.\n- Abandoned libraries.\n- npm behavior changes.\n- Lockfile differences.\n- Framework restrictions.\n- Build-tool incompatibilities.\n\nThere is also a problem in the opposite direction:\n\n**Staying on an old Node.js version can prevent dependency upgrades.**\n\nOver time, that can create a cycle:\n\n1. A newer package requires a newer Node.js version.\n2. The application stays on an older package release.\n3. Other dependencies become pinned around it.\n4. Security and bug fixes become harder to adopt.\n5. The eventual runtime upgrade becomes larger.\n\nThe Node.js project describes this as ecosystem drift: userland packages gradually stop supporting EOL release lines, forcing applications that remain on them further away from the maintained ecosystem.\n\nThis is why dependency compatibility should be discovered **before** changing the runtime.\n\nYou want to know that a package blocks Node.js 24 while you are planning the upgrade—not halfway through the production migration.\n\n### 3. OpenSSL and TLS Can Break External Integrations\n\nSome of the most disruptive Node.js upgrade issues can appear outside your application code.\n\nNode.js bundles OpenSSL, so a runtime upgrade can change:\n\n- Supported cryptographic algorithms.\n- TLS defaults.\n- Certificate validation.\n- Cipher availability.\n- Minimum key sizes.\n- Compatibility with legacy services.\n\nNode.js 24 provides a concrete example.\n\nIts LTS builds include OpenSSL 3.5 with the default OpenSSL security level set to `2`. Under that policy, RSA, DSA, and DH keys shorter than 2048 bits, ECC keys shorter than 224 bits, and RC4-based cipher suites are prohibited. The official migration guide specifically recommends testing workloads that depend on older keys or weak ciphers before upgrading.\n\nYour JavaScript business logic may be completely compatible.\n\nBut an integration may not be.\n\nA legacy internal API, database connection, proxy, authentication system, service mesh, certificate, or old appliance can become the real upgrade blocker.\n\nBefore upgrading, test the systems that depend on TLS and cryptography—not only the application's JavaScript test suite.\n\n### 4. Deprecated APIs Can Become Runtime Failures\n\nWorking code is not always upgrade-ready code.\n\nNode.js can deprecate APIs long before removing them. That gives developers time to migrate, but it also makes compatibility debt easy to ignore.\n\nAn application can run for years with deprecated behavior and appear completely healthy.\n\nThen a future major release removes that behavior.\n\nThe Node.js 22 → 24 migration guide includes examples of exactly this process. It provides migration paths and codemods for deprecated or removed functionality involving `fs`, cryptography, `process.assert`, TLS APIs, and other runtime behavior.\n\nFor example, `process.assert` reached End-of-Life and was removed, while several APIs received replacements or stricter validation.\n\nThe risk grows when teams skip multiple Node.js majors.\n\nMoving from Node.js 22 to 24 crosses a relatively narrow set of compatibility changes.\n\nMoving from Node.js 14 or 16 to Node.js 24 means dealing with changes accumulated across several generations of the runtime.\n\nYou can expose some of this technical debt before the migration by running with greater deprecation visibility:\n\n```shell\nnode --pending-deprecation a
1pp.js\n```\n\nFor stricter testing:\n\n```shell\nnode --throw-deprecation app.js\n```\n\nWarnings that are survivable today may point directly to failures in a future runtime.\n\nTreat them as early upgrade signals.\n\n### 5. Your CI, Containers, or OS May Be the Real Blocker\n\nSometimes the application supports the new Node.js version.\n\nThe infrastructure around it does not.\n\nA Node.js version may be defined in:\n\n- Docker base images\n- `.nvmrc`\n- `.node-version`\n- `.tool-versions`\n- GitHub Actions workflows\n- Shared CI templates\n- `actions/setup-node`\n- Serverless configuration\n- Kubernetes manifests\n- Buildpacks\n- Infrastructure-as-code\n- Internal developer images\n- Platform defaults\n\nFor example:\n\n```\nFROM node:20\n```\n\nOr:\n\n```\n- uses: actions/setup-node@v4\n  with:\n    node-version: 20\n```\n\nChanging `package.json` updates neither one.\n\nA team can therefore believe an upgrade is complete while CI, production, or an internal deployment template continues provisioning the old runtime.\n\nThe target Node.js version may also require newer infrastructure.\n\nFor Node.js 24, official prebuilt macOS binaries require at least macOS 13.5. The Node.js 22 → 24 migration guide also documents changes to 32-bit platform support, while source builds require GCC 12.2 or later on Linux/AIX and Xcode 16.1 or later on macOS.\n\nThat can expose problems with:\n\n- Old CI runner images.\n- Unsupported operating systems.\n- Native compiler versions.\n- Legacy container images.\n- `node-gyp` environments.\n- Internal golden images.\n- Deployment platforms with pinned runtimes.\n\nThe question is therefore not only:\n\n**“Does the application support the new Node.js version?”**\n\nIt is:\n\n**“Can every system that builds and runs the application support it?”**\n\nAn upgrade is not complete while an old Dockerfile, reusable CI workflow, or platform template can silently bring the previous runtime back.\n\n## The Longer You Wait, the More Upgrade Boundaries You Accumulate\n\nNode.js upgrades rarely become easier with time.\n\nA team that upgrades regularly may only need to address a limited set of dependency changes, runtime differences, and deprecations.\n\nA team moving from Node.js 14 or 16 to Node.js 24 has several generations of change to understand:\n\n```\nNode.js 14\n↓\nNode.js 16\n↓\nNode.js 18\n↓\nNode.js 20\n↓\nNode.js 22\n↓\nNode.js 24\n```\n\nThe Node.js project now publishes official migration guidance for several of these transitions, including 14 → 16, 16 → 18, 20 → 22, and 22 → 24.\n\nAcross a long-lived application, those boundaries can accumulate:\n\n- Native ABI changes.\n- OpenSSL transitions.\n- npm behavior changes.\n- Deprecated and removed APIs.\n- Module-system evolution.\n- Framework upgrades.\n- New operating system requirements.\n- Compiler and build changes.\n- CI/CD updates.\
1n- Container changes.\n- Runtime behavior differences.\n\nThis does **not** mean every intermediate Node.js version needs to reach production.\n\nBut testing and understanding individual migration boundaries can make a large upgrade significantly easier to diagnose.\n\nInstead of asking:\n\n**“Why doesn't our application work on Node.js 24?”**\n\nyou can narrow the problem to:\n\n**“Which version boundary introduced this incompatibility?”**\n\nThat is a much smaller engineering problem.\n\nWaiting also creates another kind of pressure. The Node.js project notes that EOL releases can experience toolchain breakage and ecosystem drift as system libraries and userland packages move forward without them.\n\nWhat begins as a postponed runtime update can eventually become a multi-layer modernization project.\n\n## Practical Pre-Upgrade Checklist\n\nBefore changing Node.js in production:\n\n- Verify the Node.js version actually running in development, CI, staging, and production.\n- Run `npx is-my-node-vulnerable` against the current runtime.\n- Run `npx @nodesource/upgrade` to identify application-level blockers.\n- Inventory direct and transitive dependencies.\n- Review package `engines` requirements.\n- Identify native C/C++ addons and `node-gyp` usage.\n- Check whether native dependencies use Node-API.\n- Find deprecated and removed Node.js APIs.\n- Review OpenSSL and TLS integrations.\n- Test certificates, proxies, mTLS, databases, and external services.\n- Check Docker base images and container build files.\n- Review CI/CD runtime configuration and reusable templates.\n- Validate operating system and compiler requirements.\n- Confirm framework and build-tool support for the target Node.js version.\n- Run the full application test suite on the target runtime.\n- Test HTTP, networking, workers, and child processes under production-like conditions.\n- Benchmark CPU, memory, latency, throughput, and startup behavior.\n- Validate native modules under the target runtime.\n- Define observability and success criteria for the rollout.\n- Prepare a rollback path.\n- Roll out progressively rather than replacing the runtime everywhere at once.\n\nA passing test suite is necessary.\n\nIt is not the complete definition of a safe Node.js upgrade.\n\nThe objective is to validate that the application's **security, dependencies, infrastructure, integrations, and runtime behavior** still hold after the version changes.\n\n## Know What Will Break Before You Upgrade\n\nThe NodeSource **Node.js LTS Upgrade \u0026 Modernization Program** is designed to turn that uncertainty into an actionable migration plan.\n\nStart with the free Upgrade Discovery CLI:\n\n```shell\nnpx @nodesource/upgrade\n```\n\nThe local scan identifies depen
1dencies, native C++ addons, static Node.js API usage, and potential migration blockers. The resulting discovery data can then be analyzed to surface security and upgrade risk, critical blockers, native addon conflicts, deprecated APIs, and vulnerable dependencies.\n\nInstead of starting with:\n\n**“Let's upgrade Node.js and see what breaks.”**\n\nyou can start with:\n\n**“We know the blockers, we understand the risk, and we know what needs to change.”**\n\n[![node-upgrade.png](https://assets.nodesource.com/strapi-uploads/upgrade_23b73580d5.png)](https://nodesource.com/products/nodejs-upgrade)\n\n[Get your free Node.js Upgrade Assessment →](https://nodesource.com/upgrade)\n\nIf the migration requires more than a version change, NodeSource's upgrade experts can help turn the assessment into a phased modernization roadmap covering dependencies, native addons, deprecated APIs, testing, and execution.\n\n**Check the runtime. Assess the application. Plan the upgrade.**\n\nThen change the version."])</script>
1<script>self.__next_f.push([1,"28:[\"$\",\"$L1e\",\"9\",{\"item\":{\"id\":670,\"documentId\":\"iehrckky0888ll85apovuivw\",\"slug\":\"nodejs-upgrade-things-that-can-break-before-you-migrate\",\"title\":\"Node.js Upgrade: 5 Things That Can Break Before You Migrate\",\"metaDescription\":\"Planning a Node.js upgrade? Learn the 5 areas that can break during migration, from native addons and dependencies to OpenSSL, APIs, CI, and OS compatibility.\",\"tweetText\":null,\"body\":\"$35\",\"featuredPost\":false,\"createdAt\":\"2026-08-20T22:11:10.200Z\",\"updatedAt\":\"2026-08-20T22:17:44.863Z\",\"publishedAt\":\"2026-08-20T22:17:44.815Z\",\"category\":{\"slug\":\"upgrade-program\",\"title\":\"Upgrade Program\"},\"twitterCard\":{\"id\":14717,\"documentId\":\"xp0epzwyop9cv78dhtnepim4\",\"name\":\"LinkedIn Article .png\",\"alternativeText\":null,\"caption\":null,\"focalPoint\":null,\"width\":1600,\"height\":900,\"formats\":{\"large\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/large_Linked_In_Article_31aa3b9095.png\",\"etag\":\"c444c95b22fcbec5d34ec9a47fa4944f\",\"hash\":\"large_Linked_In_Article_31aa3b9095\",\"mime\":\"image/png\",\"name\":\"large_LinkedIn Article .png\",\"path\":null,\"size\":424.12,\"width\":1000,\"height\":563,\"sizeInBytes\":424119},\"small\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/small_Linked_In_Article_31aa3b9095.png\",\"etag\":\"005d34ce7fdd633e474a809cc899c6f0\",\"hash\":\"small_Linked_In_Article_31aa3b9095\",\"mime\":\"image/png\",\"name\":\"small_LinkedIn Article .png\",\"path\":null,\"size\":123.83,\"width\":500,\"height\":281,\"
1sizeInBytes\":123834},\"medium\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/medium_Linked_In_Article_31aa3b9095.png\",\"etag\":\"c6a0a926e0b374cfd9395af911559df1\",\"hash\":\"medium_Linked_In_Article_31aa3b9095\",\"mime\":\"image/png\",\"name\":\"medium_LinkedIn Article .png\",\"path\":null,\"size\":249.77,\"width\":750,\"height\":422,\"sizeInBytes\":249769},\"thumbnail\":{\"ext\":\".png\",\"url\":\"https://assets.nodesource.com/strapi-uploads/thumbnail_Linked_In_Article_31aa3b9095.png\",\"etag\":\"8d035e3c243564fe19f0f26de3451727\",\"hash\":\"thumbnail_Linked_In_Article_31aa3b9095\",\"mime\":\"image/png\",\"name\":\"thumbnail_LinkedIn Article .png\",\"path\":null,\"size\":38.24,\"width\":245,\"height\":138,\"sizeInBytes\":38235}},\"hash\":\"Linked_In_Article_31aa3b9095\",\"ext\":\".png\",\"mime\":\"image/png\",\"size\":222.95,\"url\":\"https://assets.nodesource.com/strapi-uploads/Linked_In_Article_31aa3b9095.png\",\"previewUrl\":null,\"provider\":\"aws-s3\",\"provider_metadata\":null,\"createdAt\":\"2026-08-20T22:10:58.556Z\",\"updatedAt\":\"2026-08-20T22:10:58.556Z\",\"publishedAt\":\"2026-08-20T22:10:58.557Z\"}}}]\n"])</script>
1<script>self.__next_f.push([1,"36:T59cc,"])</script>
1<script>self.__next_f.push([1,"Updating Node.js on Linux can be as simple as installing a new version—but a **safe Node.js upgrade is more than changing the number returned by `node -v`.**\n\nA new major version can change the V8 engine, npm, OpenSSL, runtime APIs, native addon compatibility, dependency requirements, and application behavior.\n\nIn this guide, we'll show you the best ways to update Node.js on Linux, how to choose the right version, and what to check before moving an application to a newer runtime.\n\n[![node-upgrade.png](https://assets.nodesource.com/strapi-uploads/upgrade_23b73580d5.png)](https://nodesource.com/products/nodejs-upgrade)\n\n[Get your free Node.js Upgrade Assessment →](https://nodesource.com/upgrade)\n\n### Before you upgrade, check your application\n\nRun NodeSource's free Upgrade Discovery CLI:\n\n```bash\nnpx @nodesource/upgrade\n```\n\nIt analyzes your dependencies, native C/C++ addons, and static Node.js API usage locally to help identify potential upgrade blockers before you change the runtime.\n\n### Using another operating system?\n\nLooking for instructions for macOS? Click [here](https://nodesource.com/blog/update-Node.js-versions-on-MacOS). Need help with Windows? Click [here](https://nodesource.com/blog/Update-nodejs-versions-on-windows).\n\n## First: Which Node.js Version Should You Install?\n\nBefore updating anything, it helps to understand that the **latest Node.js version is not always the version you should use in production.**\n\nAs of August 2026, the [official Node.js releases page](https://nodejs.org/en/about/previous-releases) lists:\n\n| Release                | Status          | When to use it                                               |\n| ---------------------- | --------------- | ------------------------------------------------------------ |\n| Node.js 24             | Active LTS      | Best default for most production applications                |\n| Node.js 26             | Current         | Testing new capabilities and preparing for its LTS promotion |\n| Node.js 22             | Maintenance LTS | Still supported, but with less remaining support time        |\n| Node.js 20 and earlier | EOL             | Upgrade planning should be a priority                        |\n\nAt the time of this update, the latest releases are **Node.js 24.19.0 LTS** and **Node.js 26.7.0 Current**. Always check [nodejs.org](https://nodejs.org/en/download) before installing, since patch releases change frequently.\n\nFor production applications, the Node.js project recommends using an **Active LTS or Maintenance LTS release.**\n\nIf your application is still running Node.js 20 or an older release, upgrading becomes more important: End-of-Life versions no longer receive community security fixes.\n\nWe cover those risks in much more detail here:\n\n[Node.js Versions Explained: Why Running an Outdated Release Is a Business Risk](https://nodesource.com/blog/nodejs-versions-lts-eol-outdated-release-risks)\n\nPrefer a quick video explanation?\n\n* [LTS vs Current — What's the Difference in Node.js?](https://youtu.be/QkBVFPNdqcg)\n* [How Many Node.js Versions Exist? LTS, Current \u0026 Release Cycle Explained](https://youtu.be/bXAnzhodlpM)\n\n### One important release-cycle change\n\n**Node.js 26 is also the last release under the historical even/odd release model.**\n\nStarting with Node.js 27, Node.js is moving to one major release per year, and every major version is expected to progress toward LTS after its Current phase. The new schedule introduces an Alpha phase, followed by Current and then LTS.\n\nYou can follow the [official Node.js release schedule](https://nodejs.org/en/blog/announcements/evolving-the-nodejs-release-schedule) for the latest lifecycle information.\n\n## Before You Start: Check What You Are Running\n\nOpen your terminal and run:\n\n```shell\nnode -v\nnpm -v\n```\n\nYou can also check which Node.js executable Linux is actually using:\n\n```shell\ncommand -v node\n```\n\nIf you have installed Node.js using more than one method, you may discover that the runtime being executed is not the one you expected.\n\nFor example, you could have Node.js installed through:\n\n* apt\n* dnf or yum\n* NodeSource binary distributions\n* nvm\n* A manually installed Node.js binary\n* A development container or Docker image\n\nTo see every Node.js executable available through your current PATH, run:\n\n```shell\nwhich -a node\n```\n\nIf this is an existing application, also check whether the project defines a Node.js version in an `.nvmrc` file:\n\n```shell\ncat .nvmrc\n```\n\nYou may also find a N
1ode.js requirement in `package.json`:\n\n```json\n{\n  \"engines\": {\n    \"node\": \"\u003e=24\"\n  }\n}\n```\n\nAnd before changing your runtime, make sure your work is committed so you can easily compare or revert application changes.\n\nThe important distinction is this:\n\n**Updating Node.js on your Linux machine and upgrading the Node.js version used by your application are related, but they are not necessarily the same thing.**\n\nYour local installation may be ready for Node.js 24 or 26 while your application's dependencies, CI pipeline, Docker images, deployment configuration, or production environment still expect an older version.\n\n## The Best Ways to Update Node.js on Linux\n\nThere is no single installation method that works best for every Linux environment.\n\nA simple rule is:\n\n| Method                          | Best for                                                                           |\n| ------------------------------- | ---------------------------------------------------------------------------------- |\n| NodeSource Binary Distributions | System-wide installations, servers, CI environments, and DEB/RPM-based systems     |\n| nvm                             | Developers working across multiple Node.js versions                                |\n| Linux distribution packages     | Simple installations where the distribution-provided Node.js version is acceptable |\n| Manual Node.js binaries         | Advanced users who need direct control over installation paths and binaries        |\n\nFor local development, using a version manager such as nvm is usually the most flexible option.\n\nFor servers and system-wide installations on Debian-, Ubuntu-, RHEL-, Fedora-, and other supported DEB/RPM-based systems, NodeSource binary distributions provide another convenient option.\n\n## Method 1: Update Node.js Using NodeSource Binary Distributions\n\nNodeSource maintains Node.js binary distributions for Linux through common DEB and RPM package formats.\n\nThis allows you to install Node.js through your operating system's package manager while choosing the Node.js major version you want to run.\n\nA useful advantage of this approach is predictability: instead of installing whatever Node.js version your Linux distribution currently provides, you can explicitly configure the NodeSource repository for a specific major release.\n\nFor example:\n\n```text\nsetup_24.x → Node.js 24\nsetup_26.x → Node.js 26\n```\n\nUsing an explicit major version is particularly useful for servers, CI environments, and installation documentation because it prevents your target major from changing automatically later.\n\nNodeSource currently provides setup scripts for both Node.js 24 and Node.js 26 across its DEB and RPM distributions.\n\n### Debian and Ubuntu\n\nFor most production applications, you will probably want Node.js 24 LTS.\n\nFirst, make sure curl is installed:\n\n```shell\nsudo apt update\nsudo apt install -y curl\n```\n\nDownload the NodeSource setup script:\n\n```shell\ncurl -fsSL https://deb.nodesource.com/setup_24.x -o nodesource_setup.sh\n```\n\nRun it:\n\n```shell\nsudo -E bash nodesource_setup.sh\n```\n\nThen install Node.js:\n\n```shell\nsudo apt install -y nodejs\n```\n\nVerify the installation:\n\n```shell\nnode -v\nnpm -v\n```\n\nThe NodeSource setup script configures the repository and signing key before Node.js is installed through apt.\n\n### Installing Node.js 26 Current instead\n\nIf you intentionally want the Current release, change the repository target:\n\n```shell\ncurl -fsSL https://deb.nodesource.com/setup_26.x -o nodesource_setup.sh\nsudo -E bash nodesource_setup.sh\nsudo apt install -y nodejs\n```\n\nThen verify:\n\n```shell\nnode -v\n```\n\nYou should now be running a Node.js 26 release.\n\n### Updating within the same major version\n\nIf your machine is already configured for Node.js 24 through NodeSource, regular package updates can install newer Node.js 24 patch or minor releases:\n\n```shell\nsudo apt update\nsudo apt install --only-upgrade nodejs\n```\n\nThe important difference is:\n\n* 24.18.x → 24.19.x: normal package update within the same major\n* 22.x → 24.x: major Node.js upgrade\n* 24.x → 26.x: major Node.js upgrade\n\nMajor upgrades deserve additional application compatibility testing.\n\n### RHEL, Fedora, Amazon Linux, and RPM-Based Distributions\n\nFor RPM-based distributions, NodeSource provides a separate repository setup.\n\nTo configure Node.js 24 LTS:\n\n```shell\ncurl -fsSL https://rpm.nodesource.com/setup_24.x -o nodesource_setup.sh\nsudo bash nodesource_setup.sh\n```\n\nThen install Node.js using dnf on modern distributions:\n\n```shell\nsudo dnf install -y nodejs\n```\n\nOn environments that use yum, run:\n\n```shell\nsudo yum install -y nodejs\n```\n\nVerify:\n\n```shell\nnode -v\nnpm -v\n```\n\n### Installing Node.js 26 Current\n\nIf you specifically need Node.js 26:\n\n```shell\ncurl -fsSL https://rpm.nodesource.com/setup_26.x -o nodesource_setup.sh\nsudo bash nodesource_setup.sh\nsudo dnf install -y nodejs\n```\n\nOr, on a yum-based system:\n\n```shell\nsudo yum install -y nodejs\n```\n\nThe current NodeSource RPM setup scripts include the repository configuration needed to install Node.js through RPM-based package managers.\n\n### What About setup_lts.x and setup_current.x?\n\nNodeSource also provides convenience scripts such as:\n\n```text\nsetup_lts.x\nsetup_current.x\n```\n\nThese can be useful when you deliberately want whatever NodeSource currently defines as LTS or Current.\n\nHowever, there is an important difference.\n\nThis:\n\n```text\nhttps://deb.nodesource.com/setup_24.x\n```\n\nalways targets the Node.js 24 release line.\n\nThis:\n\n```text\nhttps://deb.nodesource.com/setup_lts.x\n```\n\ncan point to a different major version in the future.\n\nFor local experimentation that may be fine. For long-lived documentation, deployment scripts, Docker builds, or CI infrastru
1cture, pinning the desired major version is usually easier to reason about.\n\n## Method 2: Update Node.js Using nvm\n\nnvm is a Node.js version manager that allows you to install and switch between multiple Node.js versions without replacing the system-wide installation.\n\nThis is especially useful if you maintain several projects.\n\nFor example:\n\n```text\nProject A → Node.js 22\nProject B → Node.js 24\nExperimental project → Node.js 26\n```\n\nAll three versions can exist on the same Linux machine.\n\n### Step 1: Install or Update nvm\n\nThe current nvm installation documentation uses version v0.40.6.\n\nRun:\n\n```shell\ncurl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.6/install.sh | bash\n```\n\nThen reopen your terminal.\n\nDepending on your shell, you can also reload its configuration directly.\n\nFor Bash:\n\n```shell\nsource ~/.bashrc\n```\n\nFor Zsh:\n\n```shell\nsource ~/.zshrc\n```\n\nCheck that nvm is available:\n\n```shell\ncommand -v nvm\n```\n\nIf everything is configured correctly, the command should return:\n\n```text\nnvm\n```\n\n### Step 2: Install Node.js LTS\n\nFor most development environments, LTS is a good default:\n\n```shell\nnvm install --lts\n```\n\nThen use it:\n\n```shell\nnvm use --lts\n```\n\nYou can also explicitly install Node.js 24:\n\n```shell\nnvm install 24\nnvm use 24\n```\n\nnvm currently supports installing and switching between Node.js major versions directly from the command line.\n\n### Step 3: Set Your Default Version\n\nTo make Node.js 24 your default for new terminal sessions:\n\n```shell\nnvm alias default 24\n```\n\nVerify:\n\n```shell\nnode -v\n```\n\n### Installing Node.js 26 with nvm\n\nIf you want to test the Current release:\n\n```shell\nnvm install 26\nnvm use 26\n```\n\nYou can switch back whenever necessary:\n\n```shell\nnvm use 24\n```\n\nThat ability to move between runtime versions is one of the biggest advantages of using a version manager during an upgrade.\n\n### Use .nvmrc to Keep Your Team Consistent\n\nIf a project is expected to use Node.js 24, you can define that version in `.nvmrc`.\n\nFor example:\n\n```shell\necho \"24\" \u003e .nvmrc\n```\n\nThen developers can enter the project and run:\n\n```shell\nnvm use\n```\n\nIf the version is not installed yet:\n\n```shell\nnvm install\n```\n\nThis helps make the expected Node.js major version visible inside the repository instead of relying only on each developer's machine configuration.\n\n## Method 3: Install Node.js Manually from Official Linux Binaries\n\nNode.js also publishes prebuilt Linux binaries directly through nodejs.org.\n\nManual installation can be useful when you need precise control over:\n\n* The exact Node.js version\n* Installation location\n* Architecture\n* PATH configuration\n* Environments where another package manager is not appropriate\n\nHowever, it also means you are responsible for future updates and configuration.\n\nFor most developers, nvm or a package-based installation will be easier to maintain.\n\n### Step 1: Check Your Architecture\n\nRun:\n\n```shell\nuname -m\n```\n\nCommon results include:\n\n```text\nx86_64\naarch64\n```\n\nTypically:\n\n```text\nx86_64 → x64\naarch64 → arm64\n```\n\nMake sure you download the binary that matches your system.\n\n### Step 2: Download Node.js\n\nFor example, the Node.js 24.19.0 release includes Linux binaries for x64, ARM64, ppc64le, and s390x architectures.\n\nFor Linux x64:\n\n```shell\ncurl -O https://nodejs.org/dist/v24.19.0/node-v24.19.0-linux-x64.tar.xz\n```\n\nDownload the official checksum file as well:\n\n```shell\ncurl -O https://nodejs.org/dist/v24.19.0/SHASUMS256.txt\n```\n\n### Step 3: Verify the Download\n\nBefore extracting the binary, verify its SHA-256 checksum:\n\n```shell\ngrep \"node-v24.19.0-linux-x64.tar.xz\" SHASUMS256.txt | sha256sum -c -\n```\n\nIf verification succeeds, you should see:\n\n```text\nnode-v24.19.0-linux-x64.tar.xz: OK\n```\n\nNode.js publishes `SHASUMS256.txt` alongside its release binaries for this purpose.\n\n### Step 4: Extract the Archive\n\nExtract the downloaded file:\n\n```shell\ntar -xJf node-v24.19.0-linux-x64.tar.xz\n```\n\nYou can then place it in a directory dedicated to manually installed runtimes, for example:\n\n```shell\nsudo mkdir -p /usr/local/lib/nodejs\nsudo mv node-v24.19.0-linux-x64 /usr/local/lib/nodejs/\n```\n\nAdd the Node.js binary directory to your PATH:\n\n```shell\nexport PATH=/usr/local/lib/nodejs/node-v24.19.0-linux-x64/bin:$PATH\n```\n\nTo persist this configuration, add the same line to your shell profile, such as:\n\n```text\n~/.bashrc\n```\n\nor:\n\n```text\n~/.zshrc\n```\n\nThen reload your shell and verify:\n\n```shell\nnode -v\nnpm -v\n```\n\n### Be careful with multiple installations\n\nManual installations can create confusing PATH situations if Node.js is already installed using apt, dnf, yum, or nvm.\n\nAfter installing, check:\n\n```shell\ncommand -v node\nwhich -a node\n```\n\nThis tells you which binary is actually being executed.\n\n## Should You Use Your Linux Distribution's Default Node.js Package?\n\nMany Linux distributions also provide Node.js directly through their standard repositories.\n\nFor example:\n\n```shell\nsudo apt install nodejs\n```\n\nor:\n\n```shell\nsudo dnf install nodejs\n```\n\ncan install Node.js without configuring an additional repository.\n\nThe tradeoff is that the Node.js version provided by your distribution may not match the Node.js major version you want for your application.\n\nBefore installing, check what version your package manager offers.\n\nOn Debian or Ubuntu:\n\n```shell\napt policy no
1dejs\n```\n\nOn RPM-based systems:\n\n```shell\ndnf info nodejs\n```\n\nIf the available version matches your application's requirements and support expectations, the distribution package may be perfectly adequate.\n\nIf you need a specific supported Node.js release line, a version manager or explicitly configured NodeSource repository gives you more control.\n\n## After the Upgrade: Verify More Than node -v\n\nOnce Node.js has been updated, start with:\n\n```shell\nnode -v\nnpm -v\ncommand -v node\n```\n\nBut don't stop there.\n\nThe fact that Node.js launches successfully does not mean your application is automatically compatible with the new runtime.\n\nGo to your project and reinstall dependencies if your upgrade process requires it:\n\n```shell\nnpm install\n```\n\nOr, when your lockfile is authoritative:\n\n```shell\nnpm ci\n```\n\nThen run the application's normal validation workflow.\n\nFor example:\n\n```shell\nnpm test\nnpm run lint\nnpm run build\n```\n\nAnd finally start the application:\n\n```shell\nnpm start\n```\n\nThe exact commands depend on your project, but the goal is the same: exercise the application under the new Node.js runtime before promoting that runtime to production.\n\n### Pay Special Attention to Native Addons\n\nOne of the areas most likely to require attention during a major Node.js upgrade is native code.\n\nSome npm packages include native C or C++ addons that interact with Node.js through APIs such as Node-API or V8-facing interfaces.\n\nAfter changing Node.js versions, you may need to rebuild native dependencies:\n\n```shell\nnpm rebuild\n```\n\nIn other situations, upgrading the dependency itself may be necessary.\n\nThis is also one of the areas the NodeSource Upgrade Discovery CLI can help identify before the runtime change:\n\n```shell\nnpx @nodesource/upgrade\n```\n\nCatching native addon risk before deployment is much easier than discovering it when an application fails to start in production.\n\n## Common Problem: node -v Still Shows the Old Version\n\nThis usually means the shell is finding another Node.js executable first.\n\nRun:\n\n```shell\nwhich -a node\n```\n\nYou may see something like:\n\n```text\n/home/user/.nvm/versions/node/v22.x.x/bin/node\n/usr/bin/node\n/usr/local/bin/node\n```\n\nThe first matching path generally wins.\n\nYou can inspect your PATH with:\n\n```shell\necho $PATH\n```\n\nIf you're using nvm, explicitly activate the desired version:\n\n```shell\nnvm use 24\n```\n\nThen check again:\n\n```shell\ncommand -v node\nnode -v\n```\n\nAvoid randomly deleting Node.js binaries until you know how each version was installed.\n\nRemove or update them using the same tool that originally installed them whenever possible.\n\n## Common Problem: Global npm Packages Disappeared\n\nIf you use nvm, global npm packages are installed separately for each Node.js version.\n\nSo after moving from one major to another, commands installed globally under your previous Node.js version may no longer appear.\n\nCheck your global packages:\n\n```shell\nnpm list -g --depth=0\n```\n\nIn many modern projects, relying on project-local dependencies through `package.json` and commands such as `npx` is preferable to depending heavily on globally installed packages.\n\n## Common Problem: Your Application Works Locally but CI Still Uses the Old Node.js Version\n\nUpdating Node.js on your Linux workstation does not automatically update your entire application environment.\n\nCheck places such as:\n\n```text\n.github/workflows/\nDockerfile\ndocker-compose.yml\n.nvmrc\npackage.json\nCI/CD configuration\ncloud runtime settings\n```\n\nFor example, your Dockerfile may still contain:\n\n```text\nFROM node:20\n```\n\nwhile your local environment is already using Node.js 24.\n\nThe runtime upgrade is complete only when the environments that build, test, and run the application are aligned with the intended Node.js version.\n\n## Do You Need to Remove the Old Node.js Version?\n\nNot necessarily.\n\nIf you're using nvm, keeping multiple Node.js versions installed is expected.\n\nYou can list them with:\n\n```shell\nnvm ls\n```\n\nAnd remove a ver
1sion you no longer need:\n\n```shell\nnvm uninstall 20\n```\n\nFor system-wide package installations, be more careful.\n\nRunning:\n\n```shell\nsudo apt purge nodejs\n```\n\ndoes not simply clean up an old Node.js major while leaving another package-managed major untouched. It removes the installed `nodejs` package.\n\nSo don't use `apt purge nodejs` as a generic \"remove old versions\" step.\n\nIf you're moving between NodeSource major release lines, configure the desired repository and install the target package rather than treating each major as a separate side-by-side apt installation.\n\n## Which Linux Update Method Should You Choose?\n\nHere's the simplest way to think about it.\n\n### Use nvm if:\n\n* You develop multiple Node.js applications\n* Different projects require different Node.js versions\n* You want to test an upgrade before changing your system runtime\n* You frequently switch between LTS and Current\n\nExample:\n\n```shell\nnvm install 24\nnvm use 24\n```\n\n### Use NodeSource Binary Distributions if:\n\n* You want a system-wide Node.js installation\n* You're configuring a Linux server\n* You're using Debian, Ubuntu, RHEL, Fedora, Amazon Linux, or another compatible DEB/RPM environment\n* You want to explicitly choose a Node.js major release\n\nExample for Debian/Ubuntu:\n\n```shell\ncurl -fsSL https://deb.nodesource.com/setup_24.x -o nodesource_setup.sh\nsudo -E bash nodesource_setup.sh\nsudo apt install -y nodejs\n```\n\n### Use manual binaries if:\n\n* You have a specialized environment\n* You need direct control over installation paths\n* You understand how your shell PATH is configured\n* You're prepared to manage future updates yourself\n\nFor most application developers, nvm provides the easiest upgrade and rollback workflow.\n\nFor servers and system-wide Linux installations, NodeSource's DEB and RPM distributions provide a convenient way to target a specific supported Node.js release line.\n\n## A Node.js Upgrade Is an Application Change\n\nChanging the Node.js executable is the easy part.\n\nThe more important question is whether your application is ready for the new runtime.\n\nBefore moving a production application from Node.js 20 or 22 to Node.js 24, or beginning compatibility testing against Node.js 26, check:\n\n* Direct and transitive dependencies\n* Native C/C++ addons\n* Node.js APIs used by your application\n* Package engines requirements\n* Tests\n* Build tooling\n* CI/CD runtime versions\n* Docker base images\n* Production runtime configuration\n\nYou can start that process locally with:\n\n```shell\nnpx @nodesource/upgrade\n```\n\nThe NodeSource Upgrade Discovery CLI analyzes your project to surface potential blockers before you begin changing environments.\n\n[Get your free Node.js Upgrade Assessment →](https://nodesource.com/upgrade)\n\n## Final Thoughts\n\nUpdating Node.js on Linux is straightforward once you know which version you need and how your current runtime was installed.\n\nFor most production applications in August 2026, Node.js 24 LTS is the safest default.\n\nNode.js 26 Current is useful for evaluating upcoming capabilities, while applications still running Node.js 20 or older should prioritize an upgrade because those release lines are already End-of-Life.\n\nWhichever installation method you choose, remember that a successful:\n\n```shell\nnode -v\n```\n\nis only the beginning.\n\nA safe Node.js upgrade means validating the application, its dependencies, native modules, build process, CI environment, and production runtime together.\n"])</script>
1<script>self.__next_f.push([1,"29:[\"$\",\"$L1e\",\"10\",{\"item\":{\"id\":42,\"documentId\":\"bnx3yvk6cfmgqjn7n0tahkkn\",\"slug\":\"Update-Node.js-versions-on-linux\",\"title\":\"How to Update Node.js Versions on Linux\",\"metaDescription\":\" This guide will walk you through multiple methods: using a package manager, nvm, NodeSource distribution binaries, and manually downloading \",\"tweetText\":null,\"body\":\"$36\",\"featuredPost\":false,\"createdAt\":\"2026-03-09T14:55:33.242Z\",\"updatedAt\":\"2026-08-19T21:18:10.584Z\",\"publishedAt\":\"2026-08-19T21:18:10.543Z\",\"category\":null,\"twitterCard\":{\"id\":13760,\"documentId\":null,\"name\":\"twitter-Update-Node.js-versions-on-linux_98ebf54158.png\",\"alternativeText\":null,\"caption\":null,\"focalPoint\":null,\"width\":null,\"height\":null,\"formats\":null,\"hash\":\"98ebf54158\",\"ext\":\"png\",\"mime\":\"image/png\",\"size\":216.99,\"url\":\"https://assets.nodesource.com/strapi-uploads/twitter-Update-Node.js-versions-on-linux_98ebf54158.png\",\"previewUrl\":null,\"provider\":\"aws-s3\",\"provider_metadata\":null,\"createdAt\":\"2026-03-09T14:55:33.196Z\",\"updatedAt\":\"2026-03-09T14:55:33.196Z\",\"publishedAt\":null}}}]\n"])</script>
1<script>self.__next_f.push([1,"37:T4039,"])</script>
1<script>self.__next_f.push([1,"Updating Node.js on macOS can be as simple as installing a new version—but a **safe Node.js upgrade is more than changing the number returned by `node -v`.**\n\nA new major version can change the V8 engine, npm, OpenSSL, runtime APIs, native addon compatibility, dependency requirements, and application behavior.\n\nIn this guide, we'll show you the best ways to update Node.js on macOS, how to choose the right version, and what to check before moving an application to a newer runtime.\n\n[![node-upgrade.png](https://assets.nodesource.com/strapi-uploads/upgrade_23b73580d5.png)](https://nodesource.com/products/nodejs-upgrade)\n\n[Get your free Node.js Upgrade Assessment →](https://nodesource.com/upgrade)\n\n### Before you upgrade, check your application\n\nRun NodeSource's free Upgrade Discovery CLI:\n\n```bash\nnpx @nodesource/upgrade\n```\n\nIt analyzes your dependencies, native C/C++ addons, and static Node.js API usage locally to help identify potential upgrade blockers before you change the runtime.\n\n### Using another operating system?\n\nLooking for instructions for Linux? Click [here](https://nodesource.com/blog/Update-Node.js-versions-on-linux). Need help with Windows? Click [here](https://nodesource.com/blog/Update-nodejs-versions-on-windows).\n\n## First: Which Node.js Version Should You Install?\n\nBefore updating anything, it helps to understand that the **latest Node.js version is not always the version you should use in production.**\n\nAs of August 2026, the [official Node.js releases page](https://nodejs.org/en/about/previous-releases) lists:\n\n| Release                | Status          | When to use it                                               |\n| ---------------------- | --------------- | ------------------------------------------------------------ |\n| Node.js 24             | Active LTS      | Best default for most production applications                |\n| Node.js 26             | Current         | Testing new capabilities and preparing for its LTS promotion |\n| Node.js 22             | Maintenance LTS | Still supported, but with less remaining support time        |\n| Node.js 20 and earlier | EOL             | Upgrade planning should be a priority                        |\n\nAt the time of this update, the latest releases are **Node.js 24.19.0 LTS** and **Node.js 26.7.0 Current**. Always check [nodejs.org](https://nodejs.org/en/download) before installing, since patch releases change frequently.\n\nFor production applications, the Node.js project recommends using an **Active LTS or Maintenance LTS release.**\n\nIf your application is still running Node.js 20 or an older release, upgrading becomes more important: End-of-Life versions no longer receive community security fixes.\n\nWe cover those risks in much more detail here:\n\n[Node.js Versions Explained: Why Running an Outdated Release Is a Business Risk](https://nodesource.com/blog/nodejs-versions-lts-eol-outdated-release-risks)\n\nPrefer a quick video explanation?\n\n* [LTS vs Current — What's the Difference in Node.js?](https://youtu.be/QkBVFPNdqcg)\n* [How Many Node.js Versions Exist? LTS, Current \u0026 Release Cycle Explained](https://youtu.be/bXAnzhodlpM)\n\n### One important release-cycle change\n\n**Node.js 26 is also the last release under the historical even/odd release model.**\n\nStarting with Node.js 27, Node.js is moving to one major release per year, and every major version is expected to progress toward LTS after its Current phase.\n\nYou can follow the [official Node.js release schedule](https://nodejs.org/en/blog/announcements/evolving-the-nodejs-release-schedule) for the latest lifecycle information.\n\n## Before You Start: Check What You Are Running\n\nOpen Terminal and run:\n\n```shell\nnode -v\nnpm -v\n```\n\nYou can also check which Node.js executable macOS is actually using:\n\n```shell\ncommand -v node\n```\n\nThis is useful when you have installed Node.js using more than one method—for example, Homebrew and nvm—and suspect a PATH conflict.\n\nIf you want to see every Node.js executable available through your current PATH, run:\n\n```shell\nwhich -a node\n```\n\nIf this is an existing application, also check whether the project defines a Node.js version in an `.nvmrc` file:\n\n```shell\ncat .nvmrc\n```\n\nYou may also find a N
1ode.js requirement in `package.json`:\n\n```json\n{\n  \"engines\": {\n    \"node\": \"\u003e=24\"\n  }\n}\n```\n\nAnd before changing your runtime, make sure your work is committed so you can easily compare or revert changes.\n\nThe important distinction is this:\n\n**Updating Node.js on your Mac and upgrading the Node.js version used by your application are related, but they are not necessarily the same thing.**\n\nYour local installation may be ready for Node.js 24 or 26 while your application's dependencies, CI pipeline, Docker images, or production environment still expect an older version.\n\n## The Best Ways to Update Node.js on macOS\n\nThere is no single installation method that works best for everyone.\n\nA simple rule is:\n\n| Method            | Best for                                                       |\n| ----------------- | -------------------------------------------------------------- |\n| nvm               | Developers working across multiple Node.js versions            |\n| Homebrew          | macOS users who already manage development tools with Homebrew |\n| n                 | Developers who prefer a lightweight Node.js version manager    |\n| Node.js Installer | Simple setups using one Node.js version                        |\n\n**For most developers, using a version manager is the most flexible option.**\n\nnpm's own documentation also strongly recommends installing Node.js and npm through a Node version manager when possible.\n\n## Method 1: Update Node.js Using nvm — Recommended\n\nnvm lets you install and switch between multiple Node.js versions without replacing your entire system installation.\n\nThis is particularly useful if you maintain several applications that require different Node.js versions.\n\n### Check Whether nvm Is Installed\n\nRun:\n\n```shell\nnvm --version\n```\n\nIf nvm is installed, you'll see its version number.\n\nIf the command is not found, install it by following the instructions in the [official nvm repository](https://github.com/nvm-sh/nvm).\n\nAfter installing it, restart your terminal.\n\nIf necessary, you can also reload your Zsh configuration:\n\n```shell\nsource ~/.zshrc\n```\n\nThen verify the installation again:\n\n```shell\nnvm --version\n```\n\n### Install the Latest LTS Version\n\nFor most production development, the easiest option is:\n\n```shell\nnvm install --lts\n```\n\nThen activate it:\n\n```shell\nnvm use --lts\n```\n\nVerify the result:\n\n```shell\nnode -v\nnpm -v\n```\n\nAt the time of this update, that means installing the Node.js 24 LTS release line.\n\n### Install a Specific Node.js Version\n\nYou can also install a particular major version:\n\n```shell\nnvm install 24\n```\n\nThen switch to it:\n\n```shell\nnvm use 24\n```\n\nIf you maintain an older application that still uses Node.js 22:\n\n```shell\nnvm install 22\n```\n\nThen switch when needed:\n\n```shell\nnvm use 22\n```\n\nAnd return to Node.js 24 with:\n\n```shell\nnvm use 24\n```\n\nThis is one of the main advantages of a version manager: multiple Node.js versions can coexist on the same machine.\n\n### Set a Default Node.js Version\n\nTo use Node.js 24 by default when opening a new terminal:\n\n```shell\nnvm alias default 24\n```\n\nOr use the latest LTS release automatically:\n\n```shell\nnvm alias default 'lts/*'\n```\n\n### Use .nvmrc for Project-Specific Versions\n\nTeams can also define a Node.js version in an `.nvmrc` file.\n\nFor example:\n\n```\n24\n```\n\nThen, inside the project:\n\n```shell\nnvm use\n```\n\nnvm reads the file and switches to the appropriate version.\n\nIf the required version is not installed yet, you can run:\n\n```shell\nnvm install\n```\n\nThis makes it easier to keep development environments consistent across a team.\n\n## Method 2: Update Node.js Using Homebrew\n\nIf you originally installed Node.js through Homebrew, continuing to manage it with Homebrew can be convenient.\n\nFirst, update Homebrew:\n\n```shell\nbrew update\n```\n\nCheck which Node.js formulas are installed:\n\n```shell\nbrew list | grep node\n```\n\nIf you're using Homebrew's standard `node` formula, update it with:\n\n```shell\nbrew upgrade node\n```\n\nThen verify:\n\n```shell\nnode -v\nnpm -v\n```\n\n### Be Careful: brew install node Tracks Current\n\nThis is important.\n\nRunning:\n\n```shell\nbrew install node\n```\n\ninstalls Homebrew's unversioned `node` formula, which tracks the Current Node.js release line.\n\nAt the time of this update, that means Node.js 26—not Node.js 24 LTS.\n\nIf you specifically want Node.js 24 through Homebrew, use:\n\n```shell\nbrew install node@24\n```\n\nHowever, versioned Homebrew formulas such as `node@24` may be installed as keg-only.\n\nThat means Homebrew may not automatically add that version to the default PATH.\n\nAfter installation, Homebrew will display the configuration instructions required for your system.\n\nIf you frequently switch between Node.js versions, using nvm is usually simpler than managing multiple versioned Homebrew formulas.\n\n## Method 3: Update Node.js Using [n](https://github.com/tj/n)\n\nn is another lightweight Node.js version manager.\n\nIf npm is already installed, you can install n globally:\n\n```shell\nnpm install -g n\n```\n\nTo install the latest LTS release:\n\n```shell\nn lts\n```\n\nTo install the latest Current release:\n\n```shell\nn latest\n```\n\nOr install a specific major version:\n\n```shell\nn 24\n```\n\nThen verify:\n\n```shell\nnode -v\nnpm -v\n```\n\nDepending on how your system permissions are configured, n may encounter permission errors when writing to its Node.js installation directory.\n\nAvoid automatically adding `sudo` to every npm or Node.js command.\n\nInstead, check the [n documentation](https://github.com/tj/n) for its recommended installation and permissions options.\n\n## Method 4: Use the Official Node.js macOS Installer\n\nIf you do not want to use a version manager or package manager, you can install Node.js directly from the official website.\n\nGo to the [Node.js download page](https://nodejs.org/en/download) and select the macOS installer.\n\nFor most production development, choose the LTS release.\n\nDownload the installer and follow the installation steps.\n\nWhen the installation finishes, open a new terminal and run:\n\n```shell\nnode -v\nnpm -v\n```\n\nThis approach works well for simple environments where you only need one Node.js version.\n\nHowever, developers maintaining multiple applications will generally find a version manager such as nvm more flexible.\n\n## Verify the Node.js Upgrade\n\nRegardless of which installation method you use, don't stop after the installer or package manager reports success.\n\nRun:\n\n```shell\nnode -v\nnpm -v\ncommand -v node\n```\n\nYou can also inspect the runtime directly:\n\n```shell\nnode -p \"process.version\"\nnode -p \"process.execPath\"\n```\n\nThe first command shows the active Node.js version.\n\nThe second shows exactly which Node.js executable is running.\n\nThis is useful when your Mac has had multiple Node.js installations over time.\n\nFor example, you may have:\n\n* An old Node.js installer installation\n* A Homebrew installation\n* An nvm installation\n* A version installed through n\n\nIf `node -v` still shows an unexpected version after upgrading, the problem may be your PATH, not the installation itself.\n\n## Test Your Application After Updating Node.js\n\nSuccessfully installing a newer Node.js version does not mean your application is automatically ready for it.\n\nOpen your project and install its dependencies:\n\n```shell\nnpm install\n```\n\nThen run your application's usual checks.\n\nFor example:\n\n```shell\nnpm test\n```\n\nBuild the application if applicable:\n\n```shell\nnpm run build\n```\n\nAnd start the development environment:\n\n```shell\nnpm run dev\n```\n\nFor production applications, you should also test:\n\n* Integration tests\n* End-to-end tests\n* Build tooling\n* Native addons\n* Database drivers\n* Deployment scripts\n* Docker images\n* CI/CD pipelines\n* Monitoring and observability tooling\n\nMoving across Node.js major versions can expose compatibility issues involving:\n\n* Deprecated or removed Node.js APIs\n* V8 
1changes\n* Native C/C++ addons\n* npm changes\n* OpenSSL and cryptography\n* Framework requirements\n* Unsupported dependencies\n* Build tools\n* Runtime behavior\n\nThis is why installing a new Node.js version and migrating an application to that version should be treated as two separate steps.\n\n## Troubleshooting: Node.js Still Shows the Old Version\n\nSuppose you upgrade Node.js, but this command still returns the previous version:\n\n```shell\nnode -v\n```\n\nFirst, check where Node.js is coming from:\n\n```shell\ncommand -v node\n```\n\nThen check whether multiple executables are available:\n\n```shell\nwhich -a node\n```\n\nYou might discover something like:\n\n```\n/Users/yourname/.nvm/versions/node/v24.x.x/bin/node\n/opt/homebrew/bin/node\n/usr/local/bin/node\n```\n\nThat means multiple Node.js installations exist on your machine.\n\nIf you're using nvm, check the active version:\n\n```shell\nnvm current\n```\n\nThen switch explicitly:\n\n```shell\nnvm use 24\n```\n\nYou can also inspect the executable Node.js is actually running:\n\n```shell\nnode -p \"process.execPath\"\n```\n\nIf you've recently changed your shell configuration, restarting Terminal may also be necessary.\n\nThe important thing is to identify the active installation before reinstalling Node.js again.\n\nAdding more Node.js installations usually makes PATH problems harder to diagnose.\n\n## Should You Always Upgrade to the Latest Node.js Version?\n\nNo.\n\nThe newest Node.js version is not automatically the best version for every application.\n\nFor experimentation and testing upcoming runtime capabilities, the Current release can be useful.\n\nFor production applications, an LTS release is generally the safer default.\n\nBefore upgrading, ask:\n\n1. Is my current Node.js version still supported?\n2. Which Node.js version does my application support?\n3. Are my dependencies compatible with the target version?\n4. Does the application rely on native addons?\n5. Does my framework support the new Node.js version?\n6. Are CI/CD and production environments ready for the same runtime?\n7. Are my Docker images and deployment configurations using the same version?\n\nIf you're running Node.js 20 or an older release, the situation is more urgent.\n\nThose releases are End-of-Life and no longer receive normal community security fixes from the Node.js project.\n\nFor a deeper explanation of Node.js release statuses and the risks associated with unsupported versions, read:\n\n[Node.js Versions Explained: Why Running an Outdated Release Is a Business Risk](https://nodesource.com/blog/nodejs-versions-lts-eol-outdated-release-risks)\n\n## Find Out What Is Blocking Your Node.js Upgrade\n\nFor a small local application, moving to a newer Node.js version may take only a few commands.\n\nFor production systems, the difficult part usually isn't installing Node.js.\n\nIt's understanding what might break after you change it.\n\nBefore starting a migration, run NodeSource's free Upgrade Discovery CLI:\n\n```shell\nnpx @nodesource/upgrade\n```\n\nThe assessment analyzes areas such as:\n\n* Application dependencies\n* Native C/C++ addons\n* Static Node.js API usage\n* Potential compatibility issues\n* Possible migration blockers\n\nThis gives your team a clearer picture of the work involved before changing the runtime.\n\n[Get your free Node.js Upgrade Assessment →](https://nodesource.com/upgrade)\n\n## Final Thoughts\n\nUpdating Node.js on macOS is straightforward once you understand how Node.js is installed and which version your application actually needs.\n\nFor most developers, nvm is the most flexible option because it makes it easy to install, manage, and switch between multiple Node.js versions.\n\nHomebrew is convenient if your development environment already relies heavily on Homebrew, while n offers another lightweight version-management option. The official macOS installer remains useful for simpler setups that only require one runtime version.\n\nBut remember: updating Node.js locally is only the beginning of an application upgrade.\n\nBefore moving a production workload to a new major version, verify your dependencies, native addons, tests, build tooling, CI/CD pipelines, containers, and deployment environment.\n\nAnd if you're still running an unsupported Node.js release, it's better to understand the blockers before security issues or dependency changes force the migration.\n\n[Start your free Node.js Upgrade Assessment →](https://nodesource.com/upgrade)\n"])</script>
1<script>self.__next_f.push([1,"2a:[\"$\",\"$L1e\",\"11\",{\"item\":{\"id\":41,\"documentId\":\"v06c9dpzgr1ym4ege281te2c\",\"slug\":\"update-Node.js-versions-on-MacOS\",\"title\":\"How to Update Node.js Versions on MacOS\",\"metaDescription\":\"In this guide, we’ll walk through different methods to updated Node.js in MacOS, including Homebrew, Node Version Manager (nvm), and manual installation.\",\"tweetText\":null,\"body\":\"$37\",\"featuredPost\":false,\"createdAt\":\"2026-03-09T14:55:32.894Z\",\"updatedAt\":\"2026-08-19T21:18:00.333Z\",\"publishedAt\":\"2026-08-19T21:18:00.281Z\",\"category\":{\"slug\":\"node-js-1\",\"title\":\"Node.js\"},\"twitterCard\":{\"id\":13759,\"documentId\":null,\"name\":\"twitter-update-Node.js-versions-on-MacOS_7711428d33.png\",\"alternativeText\":null,\"caption\":null,\"focalPoint\":null,\"width\":null,\"height\":null,\"formats\":null,\"hash\":\"7711428d33\",\"ext\":\"png\",\"mime\":\"image/png\",\"size\":258.51,\"url\":\"https://assets.nodesource.com/strapi-uploads/twitter-update-Node.js-versions-on-MacOS_7711428d33.png\",\"previewUrl\":null,\"provider\":\"aws-s3\",\"provider_metadata\":null,\"createdAt\":\"2026-03-09T14:55:32.838Z\",\"updatedAt\":\"2026-03-09T14:55:32.838Z\",\"publishedAt\":null}}}]\n"])</script>
1<script>self.__next_f.push([1,"2b:[\"$\",\"$L38\",null,{\"total\":678,\"route\":\"/blog\",\"currentPage\":1}]\n2c:[\"$\",\"div\",null,{\"className\":\"two-column-right\",\"children\":\"$L39\"}]\n"])</script>
1<script>self.__next_f.push([1,"3a:I[2619,[\"586\",\"static/chunks/13b76428-8a44d6718d54fa7a.js\",\"1356\",\"static/chunks/1356-05a24602620546b0.js\",\"2619\",\"static/chunks/2619-38012e79151e370a.js\",\"6581\",\"static/chunks/6581-5a59c9fda9fdaf5d.js\",\"7965\",\"static/chunks/7965-bf824f1784f24116.js\",\"3115\",\"static/chunks/3115-89bdcd254bfb768d.js\",\"3831\",\"static/chunks/app/blog/page-fdd9771c982bc6d0.js\"],\"\"]\n"])</script>
1<script>self.__next_f.push([1,"39:[\"$\",\"div\",null,{\"className\":\"sidebar\",\"children\":[[\"$\",\"div\",null,{\"className\":\"featured-posts\",\"children\":[[\"$\",\"h4\",null,{\"children\":\"Featured Articles\"}],[\"$\",\"ul\",null,{\"children\":[[\"$\",\"li\",\"0\",{\"children\":[[\"$\",\"$L3a\",null,{\"href\":\"/blog/owning-agentic-sdlc-ai-development-orchestration\",\"children\":\"Owning the Agentic SDLC: How NodeSource Reclaimed Control of AI Development\"}],[\"$\",\"p\",null,{\"className\":\"post-meta\",\"children\":[[\"In  \",[\"$\",\"$L3a\",null,{\"href\":\"/blog/category/ai\",\"children\":\"ai\"}]],\"  on \",\"Aug 12 2026\"]}]]}],[\"$\",\"li\",\"1\",{\"children\":[[\"$\",\"$L3a\",null,{\"href\":\"/blog/2-million-runtime-downloads-nsolid\",\"children\":\"2 Million Runtime Downloads: Thank You for Trusting N|Solid\"}],[\"$\",\"p\",null,{\"className\":\"post-meta\",\"children\":[[\"In  \",[\"$\",\"$L3a\",null,{\"href\":\"/blog/category/nodesource\",\"children\":\"NodeSource\"}]],\"  on \",\"Jul 16 2026\"]}]]}],[\"$\",\"li\",\"2\",{\"children\":[[\"$\",\"$L3a\",null,{\"href\":\"/blog/introducing-nsolid-plugin-ai-coding-agents\",\"children\":\"Introducing the N|Solid Plugin for AI Coding Agents\"}],[\"$\",\"p\",null,{\"className\":\"post-meta\",\"children\":[[\"In  \",[\"$\",\"$L3a\",null,{\"href\":\"/blog/category/ai\",\"children\":\"ai\"}]],\"  on \",\"Jul 08 2026\"]}]]}]]}]]}],[\"$\",\"div\",null,{\"className\":\"categories\",\"children\":[[\"$\",\"h4\",null,{\"children\":\"Categories\"}],[\"$\",\"ul\",null,{\"children\":[[\"$\",\"li\",\"0\",{\"children\":[\"$\",\"$L3a\",null,{\"href\":\"/blog/category/ai\",\"title\":\"ai\",\"className\":\"category-ai}\",\"children\":\"ai\"}]}],[\"$\",\"li\",\"1\",{\"children\":[\"$\",\"$L3a\",null,{\"href\":\"/blog/category/community\",\"title\":\"Community\",\"className\":\"category-Community}\",\"children\":\"Community\"}]}],[\"$\",\"li\",\"2\",{\"children\":[\"$\",\"$L3a\",null,{\"href\":\"/blog/category/debugging\",\"title\":\"Debugging\",\"className\":\"category-Debugging}\",\"children\":\"Debugging\"}]}],[\"$\",\"li\",\"3\",{\"children\":[\"$\",\"$L3a\",null,{\"href\":\"/blog/category/how-to\",\"title\":\"How To\",\"className\":\"category-How To}\",\"children\":\"How To\"}]}],[\"$\",\"li\",\"4\",{\"children\":[\"$\",\"$L3a\",null,{\"href\":\"/blog/category/Newsletter\",\"title\":\"newsletter\",\"className\":\"category-newsletter}\",\"children\":\"newsletter\"}]}],[\"$\",\"li\",\"5\",{\"children\":[\"$\",\"$L3a\",null,{\"href\":\"/blog/category/node-js-1\",\"title\":\"Node.js\",\"className\":\"category-Node.js}\",\"children\":\"Node.js\"}]}],[\"$\",\"li\",\"6\",{\"children\":[\"$\",\"$L3a\",null,{\"href\":\"/blog/category/node-js\",\"title\":\"Node.js\",\"className\":\"category-Node.js}\",\"children\":\"Node.js\"}]}],[\"$\",\"li\",\"7\",{\"children\":[\"$\",\"$L3a\",null,{\"href\":\"/blog/category/nodesource\",\"title\":\"NodeSource\",\"className\":\"category-NodeSource}\",\"children\":\"NodeSource\"}]}],[\"$\",\"li\",\"8\",{\"children\":[\"$\",\"$L3a\",null,{\"href\":\"/blog/category/observability\",\"title\":\"Observability\",\"className\":\"category-Observability}\",\"children\":\"Observability\"}]}],[\"$\",\"li\",\"9\",{\"children\":[\"$\",\"$L3a\",null,{\"href\":\"/blog/category/product\",\"title\":\"Product\",\"className\":\"category-Product}\",\"children\":\"Product\"}]}],[\"$\",\"li\",\"10\",{\"children\":[\"$\",\"$L3a\",null,{\"href\":\"/blog/category/security\",\"title\":\"Security\",\"className\":\"category-Security}\",\"children\":\"Security\"}]}],[\"$\",\"li\",\"11\",{\"children\":[\"$\",\"$L3a\",null,{\"href\":\"/blog/category/upgrade-program\",\"title\":\"Upgrade Program\",\"className\":\"category-Upgrade Program}\",\"children\":\"Upgrade Program\"}]}]]}]]}]]}]\n"])</script>
1</body></html>

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.