惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Schneier on Security
博客园_首页
量子位
博客园 - 司徒正美
S
SegmentFault 最新的问题
J
Java Code Geeks
小众软件
小众软件
博客园 - 【当耐特】
The Register - Security
The Register - Security
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Microsoft Azure Blog
Microsoft Azure Blog
G
Google Developers Blog
Blog — PlanetScale
Blog — PlanetScale
T
Tailwind CSS Blog
博客园 - Franky
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
G
GRAHAM CLULEY
Cyberwarzone
Cyberwarzone
腾讯CDC
Apple Machine Learning Research
Apple Machine Learning Research
V
Visual Studio Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
The Hacker News
The Hacker News
aimingoo的专栏
aimingoo的专栏
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
Scott Helme
Scott Helme
L
LINUX DO - 热门话题
F
Full Disclosure
D
DataBreaches.Net
Martin Fowler
Martin Fowler
Cisco Talos Blog
Cisco Talos Blog
L
LINUX DO - 最新话题
云风的 BLOG
云风的 BLOG
C
Check Point Blog
T
Threatpost
Google DeepMind News
Google DeepMind News
WordPress大学
WordPress大学
W
WeLiveSecurity
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
有赞技术团队
有赞技术团队
Hugging Face - Blog
Hugging Face - Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
L
Lohrmann on Cybersecurity
Last Week in AI
Last Week in AI
T
Tor Project blog
T
Troy Hunt's Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
Security Affairs
SecWiki News
SecWiki News

Deno

Deno 2.8 | Deno Claw Patrol: an open-source security firewall for agents | Deno Fresh 2.3: Zero JS by default, View Transitions, and Temporal support | Deno Build a dinosaur runner game with Deno, pt. 6 | Deno Build a dinosaur runner game with Deno, pt. 5 | Deno Deno Deploy is Generally Available | Deno Introducing Deno Sandbox | Deno Build a dinosaur runner game with Deno, pt. 4 | Deno Build a dinosaur runner game with Deno, pt. 3 | Deno Build a dinosaur runner game with Deno, pt. 2 | Deno React / Next.js Denial-of-Service Vulnerability: Deno Deploy users protected | Deno Deno 2.6: dx is the new npx | Deno Build a dinosaur runner game with Deno, pt. 1 | Deno React Server Functions / Next.js Vulnerability: Deno Deploy users protected | Deno My highlights from the new Deno Deploy | Deno Deno's Other Open Source Projects | Deno How Deno protects against npm exploits | Deno Help Us Raise $200k to Free JavaScript from Oracle | Deno Deno 2.5: Permissions in the config file | Deno Fresh 2.0 Graduates to Beta, Adds Vite Support | Deno Deno 2.4: deno bundle is back | Deno JavaScript™ Trademark Update | Deno What's coming to JavaScript | Deno A brief history of JavaScript | Deno Reports of Deno's Demise Have Been Greatly Exaggerated | Deno An Update on Fresh | Deno How Plaid migrated 100 services to a new database platform 5x faster with Deno | Deno Deno 2.3: Improved deno compile, local npm packages, and more | Deno Add JSR packages with pnpm and Yarn | Deno Zero-config Debugging with Deno and OpenTelemetry | Deno Exploring Art with TypeScript, Jupyter, Polars, and Observable Plot | Deno Deno v Oracle Update 3: Fighting the JavaScript Trademark | Deno Build a custom RAG AI agent in TypeScript and Jupyter | Deno How to get deep traces in your Node.js backend with OTel and Deno | Deno toranoana.deno #20 登録受付中(2025年3月14日) | Deno Node just added TypeScript support. What does that mean for Deno? | Deno The Dino 🦕, the Llama 🦙, and the Whale 🐋 | Deno Publish a lint rule, get a prize | Deno Deno 2.2: OpenTelemetry, Lint Plugins, node:sqlite | Deno If you're not using npm specifiers, you're doing it wrong | Deno How Deno's documentation is evolving | Deno Oracle justified its JavaScript trademark with Node.js—now it wants that ignored | Deno Introducing the JSR open governance board | Deno Intro to Wasm in Deno | Deno Announcing OpenAI on JSR | Deno Deno in 2024 | Deno Goodbye WinterCG, welcome WinterTC | Deno Build a SolidJS app with Deno | Deno Run your Next.js SSR app on Deno Deploy | Deno Solve Advent of Code 2024 with Deno and Win Prizes! | Deno Deno v. Oracle: Canceling the JavaScript Trademark | Deno Deno 2.1: Wasm Imports and other enhancements | Deno Build a Typesafe API with tRPC and Deno | Deno Self-contained Executable Programs with Deno Compile | Deno Build a Database App with Drizzle ORM and Deno | Deno Introducing your new JavaScript package manager: Deno | Deno Announcing Growthbook on JSR | Deno Build an Astro site with Deno | Deno How to convert CommonJS to ESM | Deno Announcing Deno 2 | Deno The Final Touches: What’s New In v2.0.0-rc.10 | Deno Announcing Stable V8 Bindings for Rust | Deno Deno 2.0 Release Candidate | Deno Secure, efficient private npm registries with Cloudsmith and Deno | Deno Painting the Plane as We Fly It: Designing JSR | Deno Introducing Web Cache API support on Deno Deploy | Deno Deno 1.46: The Last 1.x Release | Deno Protect your cloud spend with new Deno Deploy spend limits | Deno What we got wrong about HTTP imports | Deno Benchmarking AWS Lambda Cold Starts Across JavaScript Runtimes | Deno Announcing Supabase on JSR | Deno Deno 1.45: Workspace and Monorepo Support | Deno Introducing KV Backup for Deno Subhosting | Deno A Gentle Intro to TypeScript | Deno Announcing Hono on JSR | Deno How We Made the Deno Language Server Ten Times Faster | Deno How the Guardian uses Deno to audit accessibility and performance across their 2.7 million articles | Deno Introducing More Flexible Domain Association for Deno Subhosting | Deno The stabilization process of the Standard Library has begun | Deno Deno 1.44: Private npm registries, improved Node.js compat, and performance boosts | Deno How we built a secure, performant, multi-tenant cloud platform to run untrusted code | Deno The Deno Standard Library is now available on JSR | Deno How to document your JavaScript package | Deno Your Low Code Solution Needs an Escape Hatch | Deno Deno 1.43: Improved Language Server performance | Deno How Slack used Deno to save months of engineering effort in launching their new platform | Deno JSR Is Not Another Package Manager | Deno Announcing the Hookdeck SDK on JSR | Deno Announcing the Neon Serverless Driver on JSR | Deno An intro to TSConfig for JavaScript Developers | Deno How we built JSR | Deno How Netlify used Deno Subhosting to build a successful edge functions product | Deno Introducing Simpler Project Creation in Deno Deploy | Deno Deno 1.42: Better dependency management with JSR | Deno Introducing deployctl, the command line interface for Deno Deploy | Deno Introducing JSR - the JavaScript Registry | Deno How to add Monaco to a Next.js app and securely run untrusted user code | Deno Survey Results and Roadmap | Deno Deno 1.41: smaller deno compile binaries | Deno Webhooks suck, but here are alternatives | Deno
Deno 2.7: Temporal API, Windows ARM, and npm overrides | Deno
2026-02-25 · via Deno

We are happy to announce the release of version 2.7 of the Deno runtime, which brings a number of improvements and additions.

To upgrade to Deno 2.7, run the following in your terminal:

If Deno is not yet installed, run one of the following commands to install or learn how to install it here.


curl -fsSL https://deno.land/install.sh | sh


iwr https://deno.land/install.ps1 -useb | iex

What’s new in Deno 2.7

  • Temporal API stabilized
  • Windows on ARM support
  • package.json overrides support
  • Deno.spawn() and friends (unstable)
  • Node.js compatibility
  • API changes
  • Quality of life improvements
  • V8 14.5
  • Acknowledgments

Temporal API stabilized

The Temporal API is now stable in Deno. The --unstable-temporal flag is no longer required. Chrome 144 shipped Temporal in January 2026, and Deno now follows suit as part of the V8 14.5 upgrade.

const today = Temporal.Now.plainDateISO();
const nextMonth = today.add({ months: 1 }); 

const meeting = Temporal.ZonedDateTime.from(
  "2026-03-15T14:30[America/New_York]",
);
const inTokyo = meeting.withTimeZone("Asia/Tokyo"); 

For a deeper dive, see Mat’s fantastic post.

Windows on ARM support

Deno now provides official builds for Windows on ARM (aarch64-pc-windows-msvc). This means native performance on ARM-based Windows devices like Surface Pro X, Lenovo ThinkPad X13s, and other Snapdragon-powered laptops, with no x86 emulation overhead.

# Install Deno on Windows ARM
iwr https://deno.land/install.ps1 -useb | iex

This has been a long-requested feature and closes the gap for developers working on ARM hardware across all major platforms.

package.json overrides support

Deno has first-class package.json support. Our goal is that Node projects run in Deno with little to no changes. This release adds support for the overrides field, giving you control over the versions of packages deep in your dependency tree.

This is useful when you need to pin a transitive dependency to fix a security vulnerability, force compatibility with a specific version, or replace a package entirely.

package.json

{
  "dependencies": {
    "express": "^4.18.0"
  },
  "overrides": {
    "cookie": "0.7.0",
    "express": {
      "qs": "6.13.0"
    }
  }
}

In this example, cookie is pinned to 0.7.0 everywhere in the dependency graph, while qs is only overridden when required by express.

New APIs for subprocesses

Deno 2.7 introduces a simpler way to run subprocesses. The new Deno.spawn(), Deno.spawnAndWait(), and Deno.spawnAndWaitSync() functions are convenient shorthands for the existing Deno.Command API:


const child = new Deno.Command("echo", { args: ["hello"] }).spawn();


const child = Deno.spawn("echo", ["hello"]);

All three functions support a 3-argument overload where args are passed separately from options:


const child = Deno.spawn("deno", ["fmt", "--check"], {
  stdout: "inherit",
});


const output = await Deno.spawnAndWait("git", ["status"]);
console.log(output.stdout);


const result = Deno.spawnAndWaitSync("echo", ["done"]);

These new APIs are currently marked as unstable, meaning that they may evolve over time until formally stabilised in the runtime.

Node.js compatibility

Dozens of fixes across node:worker_threads, node:child_process, node:zlib, node:sqlite, and more.

node:worker_threads

  • Worker stdout is now forwarded to the parent process (#32160)
  • Worker stdin support (#32165)
  • worker.terminate() now returns the correct exit code (#32168)
  • process.exit() in a worker immediately halts execution (#32169)
  • Exit code propagation fixed (#32124)
  • ref()/unref() is now idempotent like Node.js (#32161)
  • execArgv validation instead of rejecting all flags (#32145)
  • Error events emitted for terminal errors (#32052)
  • threadName property added (#32072)
  • worker.cpuUsage() implemented (#32050)
  • BroadcastChannel ref/unref support (#32036)

node:child_process

  • stdio streams are now proper Socket instances (#31975)
  • stdio streams unrefed by default to match Node.js behavior (#32071)
  • Shell redirections handled in exec (#32087)
  • fork() now accepts URL as modulePath (#32268)
  • timeout and killSignal support for spawn() (#32283)
  • NODE_OPTIONS respected for --require and --inspect-publish-uid (#31949)

node:zlib

  • Zstd compression support added (#32025)
  • Multiple compatibility fixes (#32039)
  • Write callback is now async to match Node.js behavior (#32130)

node:sqlite

  • DatabaseSync.setAuthorizer() implemented (#32009)
  • Defensive option enabled on DatabaseSync (#32004)
  • SQLTagStore implemented (#31945)
  • StatementSync compatibility improvements (#31941)
  • Garbage collection no longer invalidates associated resources (#31737)

Other changes

  • PerformanceObserver implemented (#31875)
  • process.constrainedMemory() added (#32209)
  • process.features properly implemented (#31864)
  • hasColors() added to process.stdout and process.stderr (#31985)
  • util.parseEnv and process.loadEnvFile compatibility (#32183)
  • tls.setDefaultCACertificates support (#31522)
  • inspector.open(), inspector.close(), and inspector.url() support (#31898, #31705)
  • fs.writeFile and FileHandle.writeFile compatibility (#32077)
  • fs.rmdir compatibility (#32144)
  • fs.rm no longer dereferences symlinks (#31886)
  • openAsBlob export added to node:fs (#32261)
  • IPv6 host support in node:http (#32258)
  • AsyncLocalStorage context preserved in unhandledRejection handlers (#32264)
  • Error formatting compatibility (#31970)
  • assert.ok compatibility (#32173)
  • performance.clearResourceTimings() and setResourceTimingBufferSize() implemented (#31603)
  • FileHandle.readableWebStream() implemented (#31745)
  • FileHandle.readv() method added (#31943)
  • HTTP keepAlive connection reuse is now enabled for node:http Agent, reducing latency for repeated requests to the same host (#31709)
  • node:test mock API implemented (#31954)
  • Named pipe listen, connect, and open support (#31624)

API changes

The navigator.platform property is now available in Deno, returning the operating system platform the runtime is running on. This improves compatibility with web code and libraries that check navigator.platform for platform-specific behavior:

console.log(navigator.platform);

Brotli support in CompressionStream and DecompressionStream

The web standard CompressionStream and DecompressionStream APIs now support the "brotli" format alongside the existing "gzip" and "deflate":

const stream = new CompressionStream("brotli");
const response = new Response(body.pipeThrough(stream));

Brotli typically achieves better compression ratios than gzip for text content.

FsFile.tryLock()

A new non-blocking file lock method. Unlike lock() which blocks until the lock is acquired, tryLock() returns immediately with a boolean indicating whether the lock was obtained:

const file = await Deno.open("data.db", { read: true, write: true });

if (await file.tryLock(true)) {
  
  await file.write(data);
  await file.unlock();
} else {
  console.log("File is locked by another process");
}

SHA3 support in crypto.subtle

The Web Crypto API now supports SHA3 hash algorithms (SHA3-256, SHA3-384, SHA3-512) for generateKey, encrypt, and decrypt operations with RSA-OAEP:

const keyPair = await crypto.subtle.generateKey(
  {
    name: "RSA-OAEP",
    modulusLength: 2048,
    publicExponent: new Uint8Array([1, 0, 1]),
    hash: "SHA3-256",
  },
  true,
  ["encrypt", "decrypt"],
);

const data = new TextEncoder().encode("Hello, Deno!");
const encrypted = await crypto.subtle.encrypt(
  { name: "RSA-OAEP" },
  keyPair.publicKey,
  data,
);
const decrypted = await crypto.subtle.decrypt(
  { name: "RSA-OAEP" },
  keyPair.privateKey,
  encrypted,
);

GIF and WebP support for createImageBitmap

createImageBitmap now supports GIF and WebP image formats in addition to the previously supported PNG, JPEG, and BMP:

const res = await fetch("https://example.com/animation.webp");
const blob = await res.blob();
const bitmap = await createImageBitmap(blob);
console.log(`${bitmap.width}x${bitmap.height}`);

Package manager improvements

deno create

Deno supported scaffolding projects from templates using deno init subcommand. This release adds a familiar deno create alias users might be familiar from other package managers.


$ deno create npm:vite -- my-project

It works with JSR packages as well - as long as the JSR package exports a ./create entry point, you can use it as a template source:

# From JSR (uses the ./create export)
$ deno create jsr:@std/http

deno install --compile

You can now compile npm packages into standalone executables during global installation. Compiled executables are faster to start and don’t depend on a Deno installation:

$ deno install --global --compile -A npm:@anthropic-ai/claude-code

This produces a native binary that can be distributed and run without Deno .

--save-exact for deno add

By default, deno add saves dependencies with a caret range (^), allowing compatible updates. The new --save-exact (or --exact) flag pins to the exact version instead. Useful when you need to pin a specific version or are working in environments where even minor version bumps need to be deliberate:

$ deno add --save-exact npm:express

This also works with deno install.

jsr: scheme support in package.json

You can now use jsr: specifiers directly in your package.json dependencies. This means projects using package.json can depend on JSR packages without needing a deno.json:

package.json

{
  "dependencies": {
    "@std/path": "jsr:^1.0.9"
  }
}

This works with deno install and brings JSR packages to any project that uses package.json for dependency management.

deno audit --ignore

You can now filter out known advisories by CVE ID when running deno audit. This is useful for suppressing false positives or accepted risks in CI:

$ deno audit --ignore=CVE-2024-12345,CVE-2024-67890

Quality of life improvements

deno compile gains a --self-extracting flag. Instead of serving files from an in-memory virtual file system, the compiled binary extracts all embedded files to disk on first run and uses real file system operations at runtime.

This unlocks full Node API support for compiled binaries, including native addons that need real files on disk. The extraction directory is chosen automatically: next to the binary if writable, otherwise in the platform’s data directory (~/.local/share/ on Linux, ~/Library/Application Support/ on macOS, %LOCALAPPDATA% on Windows):

$ deno compile --self-extracting -A main.ts -o my-app
$ ./my-app  

deno task improvements

Deno’s built-in task runner shell becomes more configurable in this release. You can now turn on pipefail:

deno.json

{
  "tasks": {
    "lint": "set -o pipefail && deno lint **/*.ts | tee lint-output.txt"
  }
}

You can also control glob behavior with shopt: nullglob, failglob, and globstar are all configurable.

Additionally, we turned off failglob by default in order to match bash’s defaults. failglob caused too many issues. For example, urls with query parameters would cause an error due to ? not matching a file on the file system.

deno check --check-js

If you have a JavaScript-only project and want to type-check it with Deno, you previously had to either add // @ts-check to every file or set compilerOptions.checkJs in your deno.json. The new --check-js flag lets you do it in a single command with no config changes:

$ deno check --check-js main.js

Fail fast for deno fmt

Stop on the first unformatted file instead of reporting all of them. Useful in large codebases in CI where you just need to know if something is off.

$ deno fmt --check --fail-fast

Chrome DevTools and VSCode debugging improvements

Deno 2.7 brings significant improvements to the debugging experience. You can now debug Web Workers through both Chrome DevTools and VSCode. Previously only the main thread was debuggable. The implementation supports Chrome’s Target.* domain and VSCode’s NodeWorker.* domain, so workers appear automatically in whichever debugger you use.

The --inspect flag now accepts bare hosts and bare ports, matching Node.js behavior:

$ deno run --inspect=9229 main.ts         # 127.0.0.1:9229
$ deno run --inspect=192.168.0.1 main.ts  # 192.168.0.1:9229
$ deno run --inspect=:0 main.ts           # OS-assigned port

A new --inspect-publish-uid flag has also been added to support VSCode’s debugging infrastructure, allowing VSCode to use the same debugging setup for both Node.js and Deno projects.

deno upgrade cache

Downloaded Deno binaries are now cached under $DENO_DIR/dl/ during deno upgrade. If you upgrade to the same version again (e.g. on a different machine profile or after a rollback), the cached archive is reused instead of re-downloading. For canary builds, old cache entries are automatically pruned, keeping only the 10 most recent.

If the cache grows too large, deno clean will remove it along with other cached data.

OpenTelemetry for Deno Cron

Deno.cron jobs are now automatically instrumented with OpenTelemetry. Each cron invocation emits spans with the job name and execution status, so you get observability out of the box when using an OTEL-compatible backend.

deno upgrade checksum verification

You can now verify a deno upgrade download against a known checksum using the new --checksum flag. This is useful for CI pipelines and security-conscious environments where you want to ensure the binary hasn’t been tampered with:

$ deno upgrade --checksum=<sha256-hash> 2.7.0

SHA-256 checksums for each platform are published as .sha256sum files alongside the release archives on the GitHub releases page. You can fetch the checksum for your platform like this:


$ curl -sL https://github.com/denoland/deno/releases/download/v2.7.0/deno-x86_64-unknown-linux-gnu.zip.sha256sum

SSLKEYLOGFILE support

Set the SSLKEYLOGFILE environment variable to log TLS session keys to a file, enabling traffic inspection with tools like Wireshark for debugging encrypted connections:

$ SSLKEYLOGFILE=./keys.log deno run --allow-net main.ts

V8 14.5

Deno 2.7 upgrades the V8 engine to version 14.5, bringing the latest performance improvements, bug fixes, and new JavaScript features from the V8 team.

Acknowledgments

We couldn’t build Deno without the help of our community! Whether by answering questions in our community Discord server or reporting bugs, we are incredibly grateful for your support. In particular, we’d like to thank the following people for their contributions to Deno 2.7: Amol Yadav, Andy Bodnar, AprilNEA, Asher Gomez, Ayu, Bedis Nbiba, Chase Knowlden, Christian Svensson, cui, ddmoney420, Florian Schwalm, Gitoffthelawn, Hajime-san, Haruto, intelliking, iownbey, it-education-md, James Bronder, Jeff Wilson, John Downey, Jose Fernandez, kantrolv, Kenta Moriuchi, kookyleo, Kyle Tse, Lee Dogeon, lif, Mahesh Thakur, Mert Can Altin, MkDev11, Padraic Slattery, Pietro Marchini, Ramnivas Laddad, Ryan Lahman, scarf, Takuro Kitahara, TarikSogukpinar, Tu Shaokun, ud2, and Varun Chawla.

Would you like to join the ranks of Deno contributors? Check out our contribution docs here, and we’ll see you on the list next time.

Believe it or not, the changes listed above still don’t tell you everything that got better in 2.7. You can view the full list of pull requests merged in Deno 2.7 on GitHub.

Thank you for catching up with our 2.7 release, and we hope you love building with Deno!