惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Schneier on Security
C
Cyber Attacks, Cyber Crime and Cyber Security
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Project Zero
Project Zero
T
The Exploit Database - CXSecurity.com
G
GRAHAM CLULEY
T
Threatpost
A
Arctic Wolf
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Scott Helme
Scott Helme
Simon Willison's Weblog
Simon Willison's Weblog
P
Proofpoint News Feed
C
Cisco Blogs
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
K
Kaspersky official blog
P
Palo Alto Networks Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
T
Threat Research - Cisco Blogs
The Hacker News
The Hacker News
T
Tor Project blog
NISL@THU
NISL@THU
The GitHub Blog
The GitHub Blog
Security Latest
Security Latest
aimingoo的专栏
aimingoo的专栏
C
CERT Recently Published Vulnerability Notes
Recorded Future
Recorded Future
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Google DeepMind News
Google DeepMind News
Martin Fowler
Martin Fowler
N
News | PayPal Newsroom
P
Privacy & Cybersecurity Law Blog
MyScale Blog
MyScale Blog
G
Google Developers Blog
V
V2EX
V
Visual Studio Blog
P
Privacy International News Feed
Google Online Security Blog
Google Online Security Blog
Microsoft Azure Blog
Microsoft Azure Blog
宝玉的分享
宝玉的分享
博客园 - 【当耐特】
L
LINUX DO - 热门话题
MongoDB | Blog
MongoDB | Blog
腾讯CDC
J
Java Code Geeks
The Last Watchdog
The Last Watchdog
L
Lohrmann on Cybersecurity
Cyberwarzone
Cyberwarzone
博客园 - 聂微东
Webroot Blog
Webroot Blog
S
Secure Thoughts

Node.js Blog

Node.js — Security Bug Bounty Program Paused Due to Loss of Funding Node.js — Node.js 25.9.0 (Current) Node.js — Developing a minimally HashDoS resistant, yet quickly reversible integer hash for V8 Node.js — Node.js 25.8.2 (Current) Node.js — Node.js 24.14.1 (LTS) Node.js — Node.js 22.22.2 (LTS) Node.js — Node.js 20.20.2 (LTS) Node.js — Tuesday, March 24, 2026 Security Releases Node.js — Node.js 25.8.1 (Current) Node.js — Node.js 22.22.1 (LTS) Node.js — Node.js 20.20.1 (LTS) Node.js — Node.js 25.8.0 (Current) Node.js — Node.js 25.7.0 (Current) Node.js — Node.js 24.14.0 (LTS) Node.js — New HackerOne Signal Requirement for Vulnerability Reports Node.js — Node.js 25.6.1 (Current) Node.js — Node.js 24.13.1 (LTS) Node.js — Node.js 25.6.0 (Current) Node.js — OpenSSL Security Advisory Assessment, January 2026 Node.js — Node.js 25.5.0 (Current) Node.js — Chalk to Node.js util styleText Node.js — Node.js 25.4.0 (Current) Node.js — Mitigating Denial-of-Service Vulnerability from Unrecoverable Stack Space Exhaustion for React, Next.js, and APM Users Node.js — Node.js 22.22.0 (LTS) Node.js — Node.js 25.3.0 (Current) Node.js — Node.js 24.13.0 (LTS) Node.js — Node.js 20.20.0 (LTS) Node.js — Tuesday, January 13, 2026 Security Releases Node.js — Node.js 24.12.0 (LTS) Node.js — Node.js 20.19.6 (LTS) Node.js — Node.js 25.2.1 (Current) Node.js — Node.js 24.11.1 (LTS) Node.js — Node.js 25.2.0 (Current) Node.js — Node.js 25.1.0 (Current) Node.js — Node.js 22.21.1 (LTS) Node.js — Node.js 24.11.0 (LTS) Node.js — Node.js v22 to v24 Node.js — Node.js v20 to v22 Node.js — Node.js v14 to v16 Node.js — Node.js v12 to v14 Node.js — Node.js 22.21.0 (LTS) Node.js — Node.js 25.0.0 (Current) Node.js — Node.js 24.10.0 (Current) Node.js — Node.js 24.9.0 (Current) Node.js — Node.js 22.20.0 (LTS) Node.js — Node.js 24.8.0 (Current) Node.js — Node.js 20.19.5 (LTS) Node.js — Node.js 22.19.0 (LTS) Node.js — Node.js 24.7.0 (Current) Node.js — Node.js 24.6.0 (Current) Node.js — Node.js 22.18.0 (LTS) Node.js — Node.js 24.5.0 (Current) Node.js — Node.js 20.19.4 (LTS) Node.js — Node.js 22.17.1 (LTS) Node.js — Node.js 24.4.1 (Current) Node.js — Tuesday, July 15, 2025 Security Releases Node.js — Node.js 24.4.0 (Current) Node.js — Node.js LGBTQIA+ Stories: Emelia Smith Node.js — Open sourced identity Node.js — Node.js 22.17.0 (LTS) Node.js — Node.js 24.3.0 (Current) Node.js — Node.js 20.19.3 (LTS) Node.js — In Memory of Mikeal Rogers: A Builder of Communities Node.js — Node.js 24.2.0 (Current) Node.js — Beware of End-of-Life Node.js Versions - Upgrade or Seek Post-EOL Support Node.js — Trip report: Node.js collaboration summit (2025 Paris) Node.js — Node.js 22.16.0 (LTS) Node.js — Node.js 24.1.0 (Current) Node.js — Node.js 24.0.2 (Current) Node.js — Node.js 23.11.1 (Current) Node.js — Node.js 22.15.1 (LTS) Node.js — Node.js 20.19.2 (LTS) Node.js — Wednesday, May 14, 2025 Security Releases Node.js — Node.js 24.0.1 (Current) Node.js — Node.js 24.0.0 (Current) Node.js — Node.js Test CI Security Incident Node.js — Node.js 22.15.0 (LTS) Node.js — Node.js 20.19.1 (LTS) Node.js — Making Node.js Downloads Reliable Node.js — Node.js 23.11.0 (Current) Node.js — Node.js 23.10.0 (Current) Node.js — Node.js 20.19.0 (LTS) Node.js — Updates on CVE for End-of-Life Versions Node.js — Node.js 23.9.0 (Current) Node.js — Node.js 18.20.7 (LTS) Node.js — Node.js 20.18.3 (LTS) Node.js — Node.js 9.3.0 (Current) Node.js — Data Confidentiality/Integrity Vulnerability, December 2017 Node.js — Node.js 9.2.1 (Current) Node.js — Node.js 8.9.3 (LTS) Node.js — Node.js 4.8.7 (Maintenance) Node.js — Node.js 8.9.2 (LTS) Node.js — Node.js 6.12.1 (LTS) Node.js — Node.js 9.2.0 (Current) Node.js — Node.js 8.9.1 (LTS) Node.js — Node.js 9.1.0 (Current) Node.js — Node.js 0.10.35 (Stable) Node.js — Node.js 0.10.34 (Stable) Node.js — Node.js 0.10.29 (Stable) Node.js — Node.js 0.10.27 (Stable)
Node.js — Evolving the Node.js Release Schedule
2026-03-10 · via Node.js Blog

Node.js Releasers

Starting with 27.x, Node.js will move from two major releases per year to one. This post explains what's changing, why, and what it means for users. For the full discussion and background, see nodejs/Release#1113.

TL;DR: If you already only upgrade to LTS versions, little changes beyond version numbering. LTS support windows remain similar, and now every release becomes LTS.

Library authors: Please integrate Alpha releases to your CI as early as possible; if you only test on LTS releases, you will not be able to report bugs before they affect your users.

Why This Change

The current release schedule is 10 years old. It was created during the io.js merger to balance the needs of a growing ecosystem. As one contributor put it at the time, it was "an educated guess of what enterprises would need."

We now have a decade of data showing how people actually use Node.js:

  • Odd-numbered releases see minimal adoption. Most users wait for Long-Term Support.
  • The odd/even distinction confuses newcomers.
  • Many organizations skip odd releases entirely, upgrading only to LTS versions.

We also recognize that enterprises need predictability. The new schedule is designed to be well-defined, so teams can plan upgrades and allocate resources accordingly.

Volunteer Sustainability

Node.js is maintained primarily by volunteers. While some contributors receive sponsorship, most of the work (reviewing Pull Requests, handling security issues, cutting releases, backporting fixes) is done by people in their spare time.

Managing security releases across four or five active release lines has become difficult to sustain. Each additional line increases backporting complexity. By reducing the number of concurrent release lines, we can focus on better supporting the releases people actually use.

What's Changing

As of October 2026:

  • One major release per year (April), with LTS promotion in October.
  • Every release becomes LTS. No more odd/even distinction - Node.js 27 will become LTS.
  • Alpha channel for early testing with semver-major changes allowed.
  • Alpha versioning follows semver prerelease format (e.g., 27.0.0-alpha.1).
  • Version numbers align with the calendar year of their initial Current release: 27.0.0 in 2027, 28.0.0 in 2028.
  • Reduced Releasers' burden.

New Schedule

PhaseDurationDescription
Alpha6 monthsOct to Mar. Early testing, semver-major allowed
Current6 monthsApr to Oct. Stabilization
LTS30 monthsLong-term support with security fixes
EOLInfinityThe project no longer provides any support

Total support: 36 months from first Current release to End of Life (EOL).

About the Alpha Channel

The Alpha channel fills the early-testing role that odd-numbered releases once served, but with a key difference: semver-major changes are allowed during Alpha. Alpha releases are signed, tagged, and tested through CITGM. CITGM (Canary in the Goldmine) is a tool we maintain that runs the test suite of major open-source packages on the upcoming version of Node.js, which can let us detect ecosystem breakage and notify the package authors ahead of the release.

This is different from Nightly builds, which remain available as automated untested builds from main – Alpha releases may not contain all changes from main, a change may not be included in an Alpha release if:

  • during Pull Request review, reviewers add a label requesting the change not to be backported (e.g. if an API is getting runtime deprecated in an Alpha release, the change actually removing that API should not land until the next release line).
  • during the Alpha release preparation, the releaser ultimately decides which commits actually make the release (e.g. if a dependency update contains a major bug).

Who it's for: Library authors and CI pipelines testing compatibility with upcoming breaking changes. Not intended for production use.

What to expect:

  • Releases are signed and tagged (unlike nightly).
  • API may change between releases.
  • The release cadence is flexible; the Release Team will determine the timing and frequency of Alpha releases based on the volume of changes and project needs.

Why: Provides early feedback on breaking changes with quality gates that Nightly builds lack. Also allows landing V8 updates earlier in the cycle.

The rules for shipping semver-major commits in Alpha versions will be defined by the Release Team and documented in the Release repository.

What's NOT Changing

  • Long-Term Support duration remains similar (30 months).
  • Migration windows preserved. Overlap between LTS versions remains.
  • Quality standards unchanged. Same testing, same CITGM, same security process.
  • Predictable schedule. April releases, October LTS promotion.
  • V8 adoption cycle. Node.js latest releases will still include a version of V8 that's at most about 6 months old.

Timeline

New Node.js Release Schedule

Node.js 26 Schedule (existing model)

MilestoneDate
26.0.0April 2026
Enters LTSOctober 2026
MaintenanceOctober 2027
End of LifeApril 2029

Node.js 26 follows the existing schedule. This is the last release line under the current model.

Node.js 27 Schedule (new model)

MilestoneDate
Alpha beginsOctober 2026
27.0.0April 2027
Enters LTSOctober 2027
End of LifeApril 2030

Node.js 27 is the first release line under the new schedule.

The Next 10 Years

VersionAlphaCurrentLTSEnd of Life
27.xOct 2026Apr 2027Oct 2027Apr 2030
28.xOct 2027Apr 2028Oct 2028Apr 2031
29.xOct 2028Apr 2029Oct 2029Apr 2032
30.xOct 2029Apr 2030Oct 2030Apr 2033
31.xOct 2030Apr 2031Oct 2031Apr 2034
32.xOct 2031Apr 2032Oct 2032Apr 2035
33.xOct 2032Apr 2033Oct 2033Apr 2036
34.xOct 2033Apr 2034Oct 2034Apr 2037
35.xOct 2034Apr 2035Oct 2035Apr 2038
36.xOct 2035Apr 2036Oct 2036Apr 2039

This schedule is not final and may be amended. Refer to the schedule.json for an up-to-date record of the support claims from the project.

Thank You

This change is the result of discussions across GitHub issues, Release Working Group meetings, and the Collaboration Summit Chesapeake 2025. We will continue discussing this topic at the upcoming Collaboration Summit in London. We thank everyone who contributed feedback.

For questions or comments, see nodejs/Release#1113.