Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
280 commits
Select commit Hold shift + click to select a range
5196a56
lib: use validateArray for array arguments
DevJunz Aug 17, 2026
587b921
perf_hooks: add CBOR export/import for histogram exchange
jasnell Aug 20, 2026
037d651
doc: move histogram.burnRate to correct location in doc
jasnell Aug 20, 2026
b351c90
test: document WPT runner workflows
panva Aug 23, 2026
75096a6
test: support inspecting WPTs in child processes
panva Aug 23, 2026
566f819
test: cover Readable.from() sync iterator errors
jakecastelli Aug 26, 2026
23f26ee
doc: clarify security triage dispositions and permission boundaries
RafaelGSS Aug 26, 2026
a7856ab
fs: add maxDepth option to glob
TheAlexLichter Aug 26, 2026
fee97e1
http2: fix write deadlock exposed by larger window sizes
pimterry Aug 26, 2026
06ef4e9
test: deflake fastutf8stream destroy and reopen tests
christianaurichzm Aug 26, 2026
86c0a7f
lib: optimize async context frame activation
pimterry Aug 26, 2026
8d8dca0
typings: add typing for permission binding
nhjbest22 Aug 26, 2026
a7524cb
crypto: prevent Hmac.digest() from returning uninitialized memory
mcollina Aug 26, 2026
d52e9bc
http2: fix async context loss when trailers carry END_STREAM
orgads Aug 26, 2026
8106d02
crypto: add null checks for OPENSSL_INIT_new()
ndossche Aug 26, 2026
36aaae8
tools: enable concurrency for eslint
JLHwung Aug 26, 2026
3c78e86
benchmark: add crypto class benchmarks
panva Aug 24, 2026
cee1dbd
crypto: optimize key slot caching
panva Aug 24, 2026
0f3c615
crypto: harden X509Certificate state
panva Aug 23, 2026
b925c8f
test: add coverage for removeEventListener boolean capture
lazerg Aug 27, 2026
1c4c3ed
fs: fix rmSync error messages for non-ASCII paths
Yeaseen Aug 27, 2026
c6789e8
quic: release stream arenas before cleanup
trivikr Aug 27, 2026
db036ea
meta: refine the security vuln posture for experimental features
jasnell Aug 20, 2026
aeb78a5
sea: keep ELF segments on separate pages in --build-sea output
codebytere Aug 27, 2026
de27fd7
ffi: validate DynamicLibrary getter receivers
trivikr Aug 27, 2026
8823a5c
tools: welcome first-time contributors
panva Aug 27, 2026
358bf6a
crypto: correct CCM decryption FIPS error message
kyungrae2002 Aug 21, 2026
91132e3
doc: add test reporter event lifecycle diagram
Han5991 Jun 7, 2026
6fd0785
build,win: remove LTO parallelisation limit
StefanStojanovic Aug 27, 2026
f78b247
permission: block FileHandle fsync and fdatasync
RafaelGSS Aug 27, 2026
02e0f3a
quic: apply multiple fixes to flow control signaling
jasnell Aug 15, 2026
3b203bf
crypto: fix RSA-PSS oversized salt handling
panva Aug 25, 2026
37df4ac
crypto: fix private SPKI export error
panva Aug 25, 2026
8861722
crypto: validate JWK usages before key_ops
panva Aug 25, 2026
c3d0976
util: canonicalize namespaced tags in inspect()
Renegade334 Aug 27, 2026
655a8cd
tools: label PRs lacking second approval
panva Aug 25, 2026
4e69bef
ffi: enable module by default
mcollina Aug 28, 2026
3e908d1
test: use common spawnSync helpers in more tests
greenheadHQ Aug 28, 2026
f40e994
deps: upgrade openssl sources to openssl-3.5.8
nodejs-github-bot Aug 25, 2026
221f4d5
deps: update archs files for openssl-3.5.8
nodejs-github-bot Aug 25, 2026
8507c27
test: account for varied OpenSSL CCM final behaviours
panva Aug 26, 2026
09202e8
sqlite: throw on disposal of an in-use session
araujogui Aug 28, 2026
5814d60
tools: offset GitHub crons by 3 minutes
targos Aug 28, 2026
aa51e43
test: mark platform-specific tests as flaky
panva Aug 28, 2026
d2bc30f
src: report libuv error when openAsBlob cannot stat
bitpshr Aug 28, 2026
f01ddaf
test: riscv64: skip node-api sea test
sxa Aug 28, 2026
c98bb52
doc: clarify signal listener behavior
SomSamantray Aug 28, 2026
ba1b440
doc: clarify stream direction in options.stdio note
zeexzeex Aug 28, 2026
5b4521f
doc: fix fsPromises.watch overflow value
mradbourne Aug 28, 2026
922d4c4
doc: fix triggerAsyncId() comment in async_hooks example
soreavis Aug 28, 2026
4b7abe8
events: fix weak listener retention overwrite
aryansaves Aug 28, 2026
1918001
fs: cancel in-flight stat on abort
mertcanaltin Aug 28, 2026
6ead515
http: coalesce chunked writes during auto-corking
GetThatCookie Aug 4, 2026
035a9b8
sqlite: keep sessions alive across SQLite callbacks
TrevorBurnham Aug 28, 2026
b353cd6
doc: refactor the AI guidelines
joyeecheung Aug 28, 2026
9324880
crypto: add a generic MAC API
panva Aug 23, 2026
fe95256
test: use native builder for legacy SEA tests
panva Aug 28, 2026
1c98128
doc: fix stale TOC in maintaining-dependencies
greenheadHQ Aug 29, 2026
1f57046
module: derive builtinModules from enabled builtin set
sjungwon03 Aug 29, 2026
f4aa1a6
typings: add encodeIntoResults to EncodingBinding
greenheadHQ Aug 29, 2026
96fc61a
test: fix link-local dgram scope assertion
panva Aug 28, 2026
6438c5b
test: expect node:ffi to be enabled by default
mcollina Aug 29, 2026
6aedc56
doc: fix some broken links
aduh95 Aug 29, 2026
8909c74
src: disable V8 external memory reasonable size check
bitpshr Aug 29, 2026
033e727
tools: query first-time contributor status
panva Aug 29, 2026
6062fc3
benchmark: add --analyze option to benchmark/scatter.js
jasnell Aug 29, 2026
cadab22
test: remove `console.log` call in `node_run_list`
aduh95 Aug 29, 2026
7e7e3fb
build: define V8_CONTIGUOUS_COMPRESSED_RO_SPACE for shared cage
codebytere Aug 29, 2026
2aafc4c
worker: add ref/unref to web workers
avivkeller Aug 29, 2026
dcbb380
benchmark: fix max-regressions detection in compare.js
jasnell Aug 27, 2026
aab6dd1
crypto: fix public PKCS8 export error
koreahghg Aug 30, 2026
1db96e7
quic: remove unused fin flag from blob reader wakeup
trivenay Aug 30, 2026
211ec5a
zlib: avoid waiting for paused ZIP iterators
trivikr Aug 30, 2026
00add61
node-api: enter env context for async callbacks
codebytere Aug 30, 2026
527f148
src: add missing vector include
panva Aug 30, 2026
21f18aa
sqlite: reject closing a session from a callback
TrevorBurnham Aug 21, 2026
cde19de
deps: update zlib to 1.3.2.1-motley-5eb4d7e
nodejs-github-bot Aug 30, 2026
e7c2863
src: reuse cached strings in CompileSerializeMain
agape1225 Aug 31, 2026
bcd6da7
doc: fix broken `using` link in ffi.md
soulee-dev Aug 31, 2026
81abe3b
stream: fix early drain after Utf8Stream reopen
mcollina Aug 31, 2026
75e93e9
src: add re-entrancy guard to TriggerUncaughtException
themuuln Jul 6, 2026
6be311e
fs: fix recursive watch error handling
panva Aug 31, 2026
06ecd22
test: update streams WPT
standard-Chan Aug 31, 2026
e1c807a
vfs: integrate with CJS and ESM module loaders
mcollina Jun 16, 2026
0aef8ce
typings: update zlib binding declarations
hyemimi Aug 31, 2026
fb1c62f
fs: preserve directory timestamps in cp
abhi128nandan Aug 25, 2026
71b9537
doc: remove outdated TLS authorized warning
pimterry Aug 31, 2026
cdbd354
build: derive NODE_ARCH from target_cpu in the GN build
codebytere Aug 31, 2026
a6d4389
fs: watch directories, not files, in recursive fs.watch fallback
codebytere Aug 31, 2026
1609883
fs: do not descend into symlinks for ** unless following symlinks
RafaelGSS Aug 4, 2026
47dc433
test: avoid orphaned child on Windows abort test
PickBas Aug 31, 2026
e46f5e1
permission: support URL and Uint8Array as has()/drop() reference
nhjbest22 Aug 31, 2026
a2548a0
src: apply IsolateSettings when using a snapshot
codebytere Aug 31, 2026
9bf28b5
sqlite: copy changeset before applying it
mcollina Aug 31, 2026
9966aa0
test: fix recursive fs.watch error fixture
panva Aug 31, 2026
8916332
test: deflake test-watch-mode-restart-esm-loading-error
christianaurichzm Aug 31, 2026
b84e0d7
test: deflake test-inspect-async-hook-setup-at-inspect
christianaurichzm Aug 31, 2026
714a787
tls: read the peer certificate chain without consuming it
tgies Aug 31, 2026
3abe134
tools: retry first-time contributor query
panva Aug 31, 2026
d5641ac
deps: update perfetto to 58.2
nodejs-github-bot Sep 1, 2026
88b68ce
deps: update simdjson to 4.6.9
nodejs-github-bot Sep 1, 2026
8abc083
deps: update googletest to 36ba75f0ad5383a9759f17f3f72fd4661c72cb6d
nodejs-github-bot Sep 1, 2026
cf05a2e
deps: update corepack to 0.36.0
nodejs-github-bot Sep 1, 2026
5173d2e
test: update WPT for url to c23755a144
nodejs-github-bot Sep 1, 2026
1304474
test: skip `fs-watch-recursive-delete-race` on AIX
aduh95 Sep 1, 2026
b091d93
meta: document collaborator automation
panva Sep 1, 2026
1311e08
test: deflake WASI poll timing checks
panva Sep 2, 2026
ed80eef
url: align URLPatternInit dictionary conversion with WebIDL
piyushrajyadav Sep 2, 2026
f1f6d17
net: recognize bare IPv6 loopback addresses in isLoopback
watilde Sep 2, 2026
0dfd691
src: fix live lock between environments with blocked requests
IlyasShabi Sep 2, 2026
7254bc1
v8: add setHeapProfileNearHeapLimit
IlyasShabi Sep 2, 2026
75fcb1b
node-api: make object property arrays const
umuoy1 Sep 2, 2026
01f2e2e
vfs: add ZipProvider
pipobscure Sep 2, 2026
2aef11a
crypto: add FIPS indicator diagnostics channel
panva Aug 29, 2026
4e7015f
crypto: add strict mode to --force-fips
panva Aug 29, 2026
310505e
quic: reuse TLS pause machinery to drop event deferral & improve 0RTT
pimterry Sep 2, 2026
8095849
test: bump WPT webidl and interfaces
panva Sep 2, 2026
16451fc
stream: fixup cancelation handling in pull()
jasnell Aug 29, 2026
0ae8181
stream: ensure iterator cleanup on done, reject, etc
jasnell Aug 29, 2026
4f7b87e
stream: fixup writer to terminate on consumer return/throw
jasnell Aug 29, 2026
2b5e062
stream: ensure stability of stored metadata
jasnell Aug 30, 2026
9a9246a
stream: defend against re-entrancy in writev
jasnell Aug 30, 2026
1ba8787
stream: ensure full-close semantics when closed
jasnell Aug 30, 2026
21cc4b7
stream: fix merge settlement tagging and falsy error tracking
jasnell Aug 30, 2026
ab1f40d
stream: cancel active stream/iter pulls
jasnell Aug 30, 2026
217a5de
stream: ensure pipeToSync requires synchronous close
jasnell Aug 30, 2026
ba9144a
stream: replace object sentinel with symbol
jasnell Aug 30, 2026
7a1fc2b
stream: address stream/iter review feedback
jasnell Aug 30, 2026
99ce799
deps: upgrade npm to 11.19.1
npm-cli-bot Sep 2, 2026
90871a3
src: let embedders supply a builtin code cache without a snapshot
codebytere Aug 16, 2026
aa0fc9e
tools: do not hardcode path to Ruff
aduh95 Sep 2, 2026
9ff86e4
perf_hooks: add missing resource timing attributes
greenheadHQ Sep 2, 2026
b25de1e
diagnostics_channel: lazily create tracing context
RomainLanz Sep 2, 2026
7623913
lib: defer source map payload decoding until first use
codebytere Aug 22, 2026
62a0e08
src: fix startup snapshot reproducibility of InternalFieldInfo
legendecas Sep 2, 2026
f2f6420
fs: improve performance of recursive directory read
avivkeller Aug 24, 2026
113180a
sqlite: run backup completion in callback scope
panva Sep 2, 2026
5c86964
vfs: fix rename over non-empty directory
christianaurichzm Aug 28, 2026
3f9236a
buffer: pad aligned allocations by a multiple of 8
lazerg Sep 3, 2026
187b299
fs: apply nocase to literal glob exclude patterns
yhay81 Sep 3, 2026
e1de66d
fs: handle recursive watch setup races
panva Sep 3, 2026
8c90fa8
test: set type=none on IBM i for empty source
abmusse Aug 19, 2026
b570e18
test: fix flaky cleanup in http2 test
pimterry Sep 3, 2026
af67dc7
tools: do not flag force push as invalid message
aduh95 Sep 3, 2026
0e1443b
deps: V8: backport f3d4d458fe59
o- Aug 18, 2026
d34c3af
lib: use `Float16Array` from primordials
aduh95 Sep 1, 2026
fa4bc30
doc: add stability status to `crypto.setEngine`
aduh95 Sep 4, 2026
ce7866e
sea: mount bundled assets as a virtual file system
mcollina Sep 3, 2026
d234dbb
net: fix BlockList.fromJSON for IPv4-mapped IPv6 rules
watilde Sep 3, 2026
a21044c
https: limit proxy CONNECT response headers
mcollina Jul 16, 2026
9a6bef4
fs: write files in one thread pool round trip
codebytere Aug 22, 2026
2ba8fa0
sqlite: re-validate database state after reading options
TrevorBurnham Sep 3, 2026
2808a90
perf_hooks: implement Histogram meanCI API
jasnell Aug 27, 2026
203fbf1
lib: implement node:bench
jasnell Aug 27, 2026
385d750
lib: implement bench/reporters
jasnell Aug 27, 2026
798abea
lib: complete the implementation of node:bench and cli
jasnell Aug 27, 2026
6924506
benchmark: implement node:bench version of bench tools
jasnell Aug 28, 2026
03f2119
src: fixup histogram and options linting issues
jasnell Aug 28, 2026
5bc9f7e
lib: add `node:bench` explicit createRunner
jasnell Aug 28, 2026
75f77c6
test: update bench tests to not fail on no-crypto
jasnell Aug 28, 2026
4be08e0
test: improve node:bench test coverage
jasnell Aug 28, 2026
d2b6bf4
test: fix node:bench test timing
jasnell Aug 30, 2026
5245a67
build: activate correct default flags for riscv64
sxa Sep 3, 2026
2284a18
doc: update `changelog-maker` instructions for releasing
juanarbol Sep 3, 2026
6f347a1
build: skip dockit on riscv64
sxa Sep 3, 2026
032ebf1
meta: bump github/codeql-action/analyze from 4.37.3 to 4.37.9
dependabot[bot] Sep 3, 2026
5481c25
meta: bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.9
dependabot[bot] Sep 3, 2026
719c42a
meta: bump step-security/harden-runner from 2.20.0 to 2.21.0
dependabot[bot] Sep 3, 2026
4deaeee
meta: bump actions/setup-node from 6.4.0 to 7.0.0
dependabot[bot] Sep 3, 2026
37d6430
meta: bump cachix/install-nix-action from 31.11.0 to 31.11.1
dependabot[bot] Sep 3, 2026
f3cd08b
meta: bump actions/checkout from 7.0.0 to 7.0.1
dependabot[bot] Sep 3, 2026
5982295
meta: bump github/codeql-action/autobuild from 4.37.3 to 4.37.9
dependabot[bot] Sep 3, 2026
2485a25
tools: bump the eslint group in /tools/eslint with 4 updates
dependabot[bot] Sep 3, 2026
1e39c1d
meta: bump github/codeql-action/init from 4.37.3 to 4.37.9
dependabot[bot] Sep 3, 2026
433117d
test: deflake test-runner-coverage
christianaurichzm Sep 3, 2026
26e7e6f
typings: add types for performance binding
sjungwon03 Sep 4, 2026
6b99b5b
errors: validate constructor name
christianaurichzm Sep 4, 2026
3e345b6
stream: avoid per-chunk promises in webstream adapters
mcollina Sep 4, 2026
a694b91
typings: add ffi internal binding types
HoonDongKang Sep 4, 2026
60e085d
ffi: include SharedArrayBuffer in error message
HoonDongKang Sep 4, 2026
33d588c
meta: cleanup targos emeritus changes
aduh95 Sep 4, 2026
e999757
crypto: cache valid ECDH key pairs
panva Sep 4, 2026
087314e
tools: refine contributor guidance workflow
panva Sep 4, 2026
141a154
worker: start worker threads from the built-in snapshot
codebytere Aug 16, 2026
438224e
build: add `--shared-abseil` configure flag
aduh95 Aug 28, 2026
d0e941b
build: add `--shared-highway` configure flag
aduh95 Aug 29, 2026
e986aea
doc: clarify return type of `fs.mkdtemp*`
aduh95 Sep 4, 2026
84db72b
http: fast-forward teardown of unread messages
mcollina Aug 29, 2026
cc76806
vfs: load native addons from a mounted file system
pipobscure Sep 4, 2026
4eb6133
src: fix use-after-free in CleanupHookThunkRun
everett1992 Sep 4, 2026
6300183
stream: skip unobserved 'readable' emission at EOF
mcollina Sep 4, 2026
e70e099
tools: do not hardcode `yamllint` path
aduh95 Sep 4, 2026
db81249
permission: do not enforce fs and addons in audit mode
theSnackOverflow Sep 4, 2026
e7c5714
lib: add runId, fileRunId, entryFile, namePath to node:bench
jasnell Aug 28, 2026
34afd81
lib: improve node:bench stream handling
jasnell Aug 28, 2026
b89d5d1
lib: clarify mean in node:bench docs
jasnell Aug 28, 2026
4694746
doc: clarify measurement integrity details of node:bench
jasnell Aug 28, 2026
970e2d1
lib: add `bench:plan` event to `node:bench`
jasnell Aug 28, 2026
1e3af01
doc: clarify isolation modes for node:bench
jasnell Aug 28, 2026
0fb3c18
doc: clarify node:bench significance policy
jasnell Aug 28, 2026
5c92c72
lib: add context.diagnostic api to node:bench
jasnell Aug 28, 2026
1c641c3
lib: add runFile api to node:bench
jasnell Aug 29, 2026
6fa8404
lib: have runFile honor permissions and accept URL/Buffer paths
jasnell Aug 29, 2026
36ea329
lib: improve diagnostic message support
jasnell Aug 29, 2026
2f70f2d
lib,benchmark: address multiple review issues
jasnell Aug 29, 2026
312ca1c
lib: fixup node:bench handling of --require option
jasnell Sep 3, 2026
7446e5b
test: expand test coverage of node:bench
jasnell Sep 3, 2026
70118dc
test: zero-fill buffers before the string length limit check
christianaurichzm Sep 5, 2026
a3a8229
tools: bump browserslist from 4.28.4 to 4.28.8 in /tools/eslint
dependabot[bot] Sep 5, 2026
66bf4b2
tools: bump @humanfs/node from 0.16.7 to 0.16.8 in /tools/eslint
dependabot[bot] Sep 5, 2026
8c12bd6
test: deflake test-permission-net-udp-handle
christianaurichzm Sep 5, 2026
0c23ef5
crypto: fix multi-prime RSA JWKs
panva Sep 5, 2026
e2a348e
stream: canWrite and ondrain now reflect physical capacity
jasnell Aug 30, 2026
5532080
stream: ensure factory signals remain active through closing
jasnell Aug 30, 2026
7104591
stream: ensure async dispoal after endSync awaits for drain
jasnell Aug 30, 2026
9c664ee
stream: ensure pre-existing writes drain before EOF and end() waits
jasnell Aug 30, 2026
0b859b1
stream: pre-aborted pipeTo now applies dest failure handling
jasnell Aug 30, 2026
04406b8
stream: make pipeTo source normalization independent of Writer
jasnell Aug 30, 2026
6e1e4cc
stream: make consumer signals on longer alter source precedence
jasnell Aug 30, 2026
d8f6dd6
stream: apply source normalization once at call time
jasnell Aug 30, 2026
52b7199
stream: ensure from() observes returned rejecting promise correctly
jasnell Aug 30, 2026
3816b8f
stream: fix nested async flushing with infinite sources
jasnell Aug 30, 2026
c6979b4
stream: ensure that stateful transforms preserve this
jasnell Aug 30, 2026
2f5a60f
stream: use webidl validation semantics for args
jasnell Aug 30, 2026
8108dab
test: handle EPIPE in closed channel test
christianaurichzm Sep 6, 2026
3a7054a
typings: add profiler internal binding types
leah-1ee Sep 6, 2026
e0d76c7
test: ignore tunnel resets in proxy invalid-char-in-url test
codebytere Sep 4, 2026
9b5b185
test: do not dump core in external memory limit test
codebytere Sep 4, 2026
142c166
test: only count restarts after the write in watch emit-restarted test
codebytere Sep 4, 2026
379f9c3
test: fix the thread-spawn handshake in the WASI threads fixture
codebytere Sep 4, 2026
1222ab3
test: widen the gap in the resolver maxTimeout comparison
codebytere Sep 5, 2026
f635931
test: make node:bench test samples survive a coarse clock
codebytere Sep 5, 2026
becb5e3
typings: add stream_pipe internal binding types
leah-1ee Sep 6, 2026
5ba95e5
typings: add fs_event_wrap internal binding types
leah-1ee Aug 30, 2026
141b722
typings: fix fs_event_wrap start filename type
leah-1ee Aug 30, 2026
a412d2a
ffi: throw on missing memory helper arguments
soulee-dev Sep 6, 2026
0803366
deps: update undici to 8.10.2
nodejs-github-bot Sep 6, 2026
c518f9e
doc: replace `node:modules` documentation header
Renegade334 Sep 6, 2026
9c736a1
quic: stop guarding ngtcp2_recv_stop_sending callback field
Renegade334 Sep 6, 2026
773c7d7
build: enable the V8 sandbox in shared-cage builds
codebytere Aug 21, 2026
4f81950
fs: give directories created by cpSync the source directory's mode
codebytere Aug 22, 2026
d5ac0f4
fs: copy directory trees for fs.cp() on the thread pool
codebytere Aug 22, 2026
b05f8e9
build: allow linking shared dependencies in the GN build
codebytere Sep 4, 2026
e499d03
build: enable V8 gdb/lldb plugin support
legendecas Sep 7, 2026
e4444af
deps: V8: backport ebd15783b7ba
marjakh Mar 30, 2026
bac695c
deps: V8: backport c9c0abfa51f0
schuay Apr 1, 2026
df0f833
deps: V8: backport 1a0089053443
schuay Apr 13, 2026
7c33c4d
build: add `--shared-perfetto` flag
aduh95 Aug 18, 2026
08a3fc8
tools: add GHA workflow to test vendored Perfetto
aduh95 Sep 4, 2026
b37bb62
2026-09-08, Version 26.9.0 (Current)
aduh95 Sep 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
4 changes: 2 additions & 2 deletions .github/workflows/auto-start-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ on:
# optimistic, it can take longer to run.
# To understand why `schedule` is used instead of other events, refer to
# ./doc/contributing/commit-queue.md
- cron: '*/5 * * * *'
- cron: 3/5 * * * *

concurrency: ${{ github.workflow }}

Expand Down Expand Up @@ -51,7 +51,7 @@ jobs:
runs-on: ubuntu-slim
steps:
- name: Install Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: ${{ env.NODE_VERSION }}

Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/benchmark.yml
Original file line number Diff line number Diff line change
Expand Up @@ -78,7 +78,7 @@ jobs:
name: '${{ matrix.system }}: with shared libraries'
runs-on: ${{ matrix.runner }}
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: ${{ inputs.repo || github.repository }}
ref: refs/pull/${{ inputs.pr_id }}/merge
Expand All @@ -92,7 +92,7 @@ jobs:
env:
EXPECTED_SHA: ${{ inputs.commit }}

- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
with:
extra_nix_config: sandbox = true

Expand Down Expand Up @@ -195,7 +195,7 @@ jobs:
contents: read
pull-requests: write
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
sparse-checkout: |
Expand All @@ -211,7 +211,7 @@ jobs:
merge-multiple: true
path: raw-results

- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
with:
extra_nix_config: sandbox = true

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/build-shared.yml
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ jobs:
tar xzf tarballs/*.tar.gz -C "$RUNNER_TEMP"
echo "TAR_DIR=$RUNNER_TEMP/$(basename tarballs/*.tar.gz .tar.gz)" >> "$GITHUB_ENV"

- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
with:
extra_nix_config: sandbox = true

Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/build-tarball.yml
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,7 @@ jobs:
if: github.event.pull_request.draft == false
runs-on: ubuntu-slim
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Set up Python ${{ env.PYTHON_VERSION }}
Expand Down Expand Up @@ -104,7 +104,7 @@ jobs:
SCCACHE_GHA_ENABLED: ${{ github.base_ref == 'main' || github.ref_name == 'main' }}
SCCACHE_IDLE_TIMEOUT: '0'
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
sparse-checkout: .github/actions/install-clang
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,19 +24,19 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4.37.3
uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
languages: ${{ matrix.language }}
config-file: ./.github/codeql-config.yml

- name: Autobuild
uses: github/codeql-action/autobuild@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4.37.3
uses: github/codeql-action/autobuild@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4.37.3
uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
category: /language:${{matrix.language}}
4 changes: 2 additions & 2 deletions .github/workflows/commit-lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,13 +20,13 @@ jobs:
run: |
echo "plusOne=$((${{ github.event.pull_request.commits }} + 1))" >> $GITHUB_OUTPUT
echo "minusOne=$((${{ github.event.pull_request.commits }} - 1))" >> $GITHUB_OUTPUT
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: ${{ steps.nb-of-commits.outputs.plusOne }}
persist-credentials: false
- run: git reset HEAD^2
- name: Install Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: ${{ env.NODE_VERSION }}
- name: Validate commit message
Expand Down
33 changes: 30 additions & 3 deletions .github/workflows/commit-queue.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ on:
# be read-only, and the Action won't have access to any other repository
# secrets, which it needs to access Jenkins API.
schedule:
- cron: '*/5 * * * *'
- cron: 3/5 * * * *

concurrency: ${{ github.workflow }}

Expand All @@ -28,6 +28,7 @@ jobs:
if: github.repository == 'nodejs/node'
runs-on: ubuntu-slim
outputs:
aged_prs: ${{ steps.get_candidate_prs.outputs.aged_prs }}
candidates: ${{ steps.get_candidate_prs.outputs.candidates }}
steps:
- name: Get Pull Request Candidates
Expand All @@ -50,6 +51,7 @@ jobs:
--search "-label:blocked")
candidates=$(printf '%s %s\n' "$fast_track_prs" "$aged_prs" |
jq -r -s 'reduce .[] as $pr ([]; if index($pr) then . else . + [$pr] end) | join(" ")')
echo "aged_prs=$aged_prs" >> "$GITHUB_OUTPUT"
echo "candidates=$candidates" >> "$GITHUB_OUTPUT"
env:
GH_TOKEN: ${{ github.token }}
Expand All @@ -64,7 +66,7 @@ jobs:
runs-on: ubuntu-slim
steps:
- name: Install Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: ${{ env.NODE_VERSION }}

Expand Down Expand Up @@ -93,6 +95,7 @@ jobs:
curl -fsSLo "$readme" "https://github.com/${GITHUB_REPOSITORY}/raw/${GITHUB_SHA}/README.md"

numbers=
lacks_second_approval_prs=
# shellcheck disable=SC2086
for pr in $CANDIDATES; do
metadata="${RUNNER_TEMP}/metadata-${pr}.json"
Expand Down Expand Up @@ -139,6 +142,14 @@ jobs:
if [ "$metadata_status" -ge 20 ] && [ "$metadata_status" -le 29 ]; then
echo "pr ${pr} skipped, not ready to land"
echo "reason codes: ${metadata_reason_codes}"
if jq -e '
(.reasonCodes | index("wait-time")) and
(.pullRequest.labels | index("lacks-second-approval") | not)
' "$metadata" > /dev/null; then
case " $AGED_PRS " in
*" $pr "*) lacks_second_approval_prs="$lacks_second_approval_prs $pr" ;;
esac
fi
continue
fi

Expand All @@ -148,12 +159,28 @@ jobs:
done

numbers=$(echo "$numbers" | xargs)
lacks_second_approval_prs=$(echo "$lacks_second_approval_prs" | xargs)
echo "numbers=$numbers" >> "$GITHUB_OUTPUT"
echo "lacks_second_approval_prs=$lacks_second_approval_prs" >> "$GITHUB_OUTPUT"
env:
AGED_PRS: ${{ needs.get_candidate_prs.outputs.aged_prs }}
CANDIDATES: ${{ needs.get_candidate_prs.outputs.candidates }}
GH_TOKEN: ${{ github.token }}

- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Label Pull Requests Lacking a Second Approval
if: steps.get_mergeable_prs.outputs.lacks_second_approval_prs != ''
run: |
# shellcheck disable=SC2086
for pr in $PULL_REQUESTS; do
if ! gh -R "$GITHUB_REPOSITORY" pr edit "$pr" --add-label 'lacks-second-approval'; then
echo "::warning::Failed to add lacks-second-approval to PR ${pr}"
fi
done
env:
GH_TOKEN: ${{ secrets.GH_USER_TOKEN }}
PULL_REQUESTS: ${{ steps.get_mergeable_prs.outputs.lacks_second_approval_prs }}

- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
if: steps.get_mergeable_prs.outputs.numbers != ''
with:
# A personal token is required because pushing with GITHUB_TOKEN will
Expand Down
147 changes: 147 additions & 0 deletions .github/workflows/contributor-guidance.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,147 @@
name: Contributor guidance

on:
pull_request_target:
types: [opened]

permissions: {}

jobs:
contributor:
name: Resolve contributor status
# Use the event only to exclude trusted associations, mannequins, and bots.
# Resolve every potentially external contributor with a privileged API request.
if: >-
github.run_attempt == 1 &&
github.repository == 'nodejs/node' &&
github.event.pull_request.user.type != 'Bot' &&
(github.event.pull_request.author_association == 'CONTRIBUTOR' ||
github.event.pull_request.author_association == 'FIRST_TIMER' ||
github.event.pull_request.author_association == 'FIRST_TIME_CONTRIBUTOR' ||
github.event.pull_request.author_association == 'NONE')
runs-on: ubuntu-slim
outputs:
is_first_time: ${{ steps.resolve.outputs.is_first_time }}
should_scan: ${{ steps.resolve.outputs.should_scan }}
steps:
- name: Check author association
id: resolve
env:
GH_TOKEN: ${{ secrets.GH_USER_TOKEN }}
NUMBER: ${{ github.event.pull_request.number }}
run: |
started_at=$SECONDS
# TODO: Remove the retries once privileged API requests are confirmed
# to return the association immediately.
for delay in 0 15 30 60; do
sleep "$delay"
association=$(gh api "/repos/$GITHUB_REPOSITORY/pulls/$NUMBER" \
--jq '.author_association')
elapsed=$((SECONDS - started_at))
echo "Author association after ${elapsed}s: $association"

case "$association" in
FIRST_TIMER|FIRST_TIME_CONTRIBUTOR)
echo 'is_first_time=true' >> "$GITHUB_OUTPUT"
echo 'should_scan=true' >> "$GITHUB_OUTPUT"
exit 0
;;
CONTRIBUTOR)
echo 'is_first_time=false' >> "$GITHUB_OUTPUT"
echo 'should_scan=true' >> "$GITHUB_OUTPUT"
exit 0
;;
NONE)
;;
COLLABORATOR|MANNEQUIN|MEMBER|OWNER)
echo 'is_first_time=false' >> "$GITHUB_OUTPUT"
echo 'should_scan=false' >> "$GITHUB_OUTPUT"
exit 0
;;
*)
echo "Unexpected author association: $association" >&2
exit 1
;;
esac
done

# NONE is unresolved, not trusted. Scan without posting the welcome.
echo 'is_first_time=false' >> "$GITHUB_OUTPUT"
echo 'should_scan=true' >> "$GITHUB_OUTPUT"

guidance:
name: Apply contributor guidance
needs: contributor
if: needs.contributor.outputs.should_scan == 'true'
runs-on: ubuntu-slim
permissions:
contents: read
pull-requests: write
steps:
- name: Scan contributor activity
id: agentscan
# The welcome should still be posted if this advisory scan fails.
continue-on-error: true
uses: MatteoGabriele/agentscan-action@8112fb79b33fafb8506159df20129a34209ac410 # v2.5.0
with:
github-token: ${{ github.token }}
mode: labels
scan-pull-requests: true
scan-issues: false
auto-close: false
honeypot: false

- name: Comment with contributor guidance
env:
ADD_CAUTION: >-
${{
steps.agentscan.outputs.classification == 'mixed' ||
steps.agentscan.outputs.classification == 'automation' ||
steps.agentscan.outputs['community-flagged'] == 'true'
}}
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
IS_FIRST_TIME: ${{ needs.contributor.outputs.is_first_time }}
NUMBER: ${{ github.event.pull_request.number }}
WELCOME_MESSAGE: >2-
Welcome to Node.js, and thank you for your first contribution!

Before review, please take a moment to read:

* the [guide for first-time contributors](https://github.com/nodejs/node/blob/HEAD/doc/contributing/first-contributions.md)
* the [contribution and automation policies](https://github.com/nodejs/node/blob/HEAD/CONTRIBUTING.md)
* the [pull request guide](https://github.com/nodejs/node/blob/HEAD/doc/contributing/pull-requests.md)
* the [AI use policy](https://github.com/nodejs/node/blob/HEAD/doc/contributing/ai-guidelines.md)
* the [Code of Conduct](https://github.com/nodejs/admin/blob/HEAD/CODE_OF_CONDUCT.md)

Please make sure every commit is
[signed off](https://github.com/nodejs/node/blob/HEAD/doc/contributing/pull-requests.md#step-4-commit).
For a first pull request, GitHub Actions require collaborator
approval and Jenkins CI must be started by a collaborator or triager,
so an initial wait is normal.
CAUTION_MESSAGE: >-
> [!CAUTION]

> AgentScan found account activity patterns that may be consistent with
automation. This is a heuristic, not proof that this pull request was
opened by an agent or violates policy. AI-assisted contributions are
permitted, but automated tooling must not open pull requests without
advance approval, and contributors must personally understand, test,
verify, and take responsibility for every submitted change. See the
[AgentScan analysis](https://agentscan.tools/user/${{ github.event.pull_request.user.login }}),
[AI use policy](https://github.com/nodejs/node/blob/HEAD/doc/contributing/ai-guidelines.md),
and
[automation policy](https://github.com/nodejs/node/blob/HEAD/CONTRIBUTING.md#automation-and-bots)
for additional context.
run: |
if [[ "$IS_FIRST_TIME" == "true" && "$ADD_CAUTION" == "true" ]]; then
body="$WELCOME_MESSAGE"$'\n\n'"$CAUTION_MESSAGE"
elif [[ "$IS_FIRST_TIME" == "true" ]]; then
body="$WELCOME_MESSAGE"
elif [[ "$ADD_CAUTION" == "true" ]]; then
body="$CAUTION_MESSAGE"
else
exit 0
fi

printf '%s\n' "$body" |
gh pr comment "$NUMBER" --repo "$GITHUB_REPOSITORY" --body-file -
2 changes: 1 addition & 1 deletion .github/workflows/coverage-linux-without-intl.yml
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ jobs:
if: github.event.pull_request.draft == false
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install Clang ${{ env.CLANG_VERSION }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/coverage-linux.yml
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ jobs:
if: github.event.pull_request.draft == false
runs-on: ubuntu-24.04-arm
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install Clang ${{ env.CLANG_VERSION }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/coverage-windows.yml
Original file line number Diff line number Diff line change
Expand Up @@ -72,7 +72,7 @@ jobs:
if: github.event.pull_request.draft == false
runs-on: windows-2025
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Set up Python ${{ env.PYTHON_VERSION }}
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/create-release-proposal.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,14 +33,14 @@ jobs:
RELEASE_LINE: ${{ inputs.release-line }}
runs-on: ubuntu-slim
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ env.STAGING_BRANCH }}
persist-credentials: false

# Install dependencies
- name: Install Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: ${{ env.NODE_VERSION }}

Expand Down
Loading
Loading