Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESOPENJS FOUNDATIONVERIFIED

PUBLISHER UPDATE · NODEJS-26.8.2

NODEJS-26.8.2 release notes and known issues

2026-09-09, Version 26.8.2 (Current), @aduh95

Scope: Node.js. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

Notable Changes [ 616bd3fa26 ] - doc : deprecate Server.prototype._listen2 in node:net (Antoine du Hamel) #65593 [ ae1801eb55 ] - meta : refine the security vuln posture for experimental features (James M Snell) #65438 [ 09feba74c8 ] - deps : update Undici to 8.10.2 (Node.js GitHub Bot) #65788 [ 7efdbe3eb9 ] - deps : update OpenSSL to 3.5.8 (Node.js GitHub Bot) #65542 Commits [ d8aedd6584 ] - build : skip dockit on riscv64 (Stewart X Addison) #62251 [ 1899c274eb ] - build : activate correct default flags for riscv64 (Stewart X Addison) #65708 [ ec8a3be996 ] - build : derive NODE_ARCH from target_cpu in the GN build (Shelley Vohr) #65491 [ b73118a507 ] - build,win : remove LTO parallelisation limit (Stefan Stojanovic) #65535 [ 09feba74c8 ] - deps : update undici to 8.10.2 (Node.js GitHub Bot) #65788 [ e47c432dd6 ] - deps : upgrade npm to 11.19.1 (npm team) #65573 [ 2fd6ce36a9 ] - deps : update corepack to 0.36.0 (Node.js GitHub Bot) #65653 [ 49dec2767a ] - deps : update googletest to 36ba75f0ad5383a9759f17f3f72fd4661c72cb6d (Node.js GitHub Bot) #65654 [ 676174a071 ] - deps : update simdjson to 4.6.9 (Node.js GitHub Bot) #65655 [ 2f1b7fa0bb ] - deps : update perfetto to 58.2 (Node.js GitHub Bot) #65656 [ 12acd0ad15 ] - deps : update zlib to 1.3.2.1-motley-5eb4d7e (Node.js GitHub Bot) #65494 [ 48631c80fb ] - deps : update archs files for openssl-3.5.8 (Node.js GitHub Bot) #65542 [ 7efdbe3eb9 ] - deps : upgrade openssl sources to openssl-3.5.8 (Node.js GitHub Bot) #65542 [ bdc75900ee ] - doc : replace node:modules documentation header (René) #65800 [ 44c8a499ba ] - doc : clarify return type of fs.mkdtemp* (Antoine du Hamel) #65743 [ 025fb5eeb0 ] - doc : update changelog-maker instructions for releasing (Juan José) #65707 [ 5f64847afa ] - doc : add stability status to crypto.setEngine (Antoine du Hamel) #65746 [ 299dee0cb9 ] - doc : remove outdated TLS authorized warning (Tim Perry) #65597 [ e97dcc0278 ] - doc : fix broken using link in ffi.md (Soul Lee) #65632 [ 2c9cc7d237 ] - doc : fix some broken links (Antoine du Hamel) #65583 [ 0c330ec329 ] - doc : fix stale TOC in maintaining-dependencies (greenhead) #65523 [ 9c522a3a69 ] - doc : refactor the AI guidelines (Joyee Cheung) #65269 [ 46cbf1bf8c ] - doc : fix triggerAsyncId() comment in async_hooks example (soreavis) #64583 [ 788904ff78 ] - doc : fix fsPromises.watch overflow value (Matt Radbourne) #64605 [ 3d06ff19e8 ] - doc : clarify stream direction in options.stdio note (Avocado) #65236 [ d334838379 ] - doc : clarify signal listener behavior (Som Samantray) #65243 [ d55a2bd56a ] - doc : add test reporter event lifecycle diagram (sangwook) #63780 [ c17dfc87de ] - doc : discourage AbortSignal cleanup for long-lived resources (Efe Karasakal) #64342 [ 616bd3fa26 ] - doc : deprecate Server.prototype._listen2 in node:net (Antoine du Hamel) #65593 [ 4e6d7e0ca6 ] - meta : cleanup targos emeritus changes (Antoine du Hamel) #65738 [ a70cfe1747 ] - meta : bump github/codeql-action/init from 4.37.3 to 4.37.9 (dependabot[bot]) #65714 [ e43a0ad4ce ] - meta : bump github/codeql-action/autobuild from 4.37.3 to 4.37.9 (dependabot[bot]) #65717 [ 99e06288f1 ] - meta : bump actions/checkout from 7.0.0 to 7.0.1 (dependabot[bot]) #65718 [ 89662762b3 ] - meta : bump cachix/install-nix-action from 31.11.0 to 31.11.1 (dependabot[bot]) #65719 [ 6b8f078672 ] - meta : bump actions/setup-node from 6.4.0 to 7.0.0 (dependabot[bot]) #65720 [ 6c6fb18e63 ] - meta : bump step-security/harden-runner from 2.20.0 to 2.21.0 (dependabot[bot]) #65721 [ 0e002e859f ] - meta : bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.9 (dependabot[bot]) #65722 [ 98aaffe4b9 ] - meta : bump github/codeql-action/analyze from 4.37.3 to 4.37.9 (dependabot[bot]) #65723 [ d247cb2975 ] - meta : document collaborator automation (Filip Skokan) #65671 [ ae1801eb55 ] - meta : refine the security vuln posture for experimental features (James M Snell) #65438 [ fab81d15c3 ] - test : widen the gap in the resolver maxTimeout comparison

Improvements and security content

  • Notable Changes [ 616bd3fa26 ] - doc : deprecate Server.prototype._listen2 in node:net (Antoine du Hamel) #65593 [ ae1801eb55 ] - meta : refine the security vuln posture for experimental features (James M Snell) #65438 [ 09feba74c8 ] - deps : update Undici to 8.10.2 (Node.js GitHub Bot) #65788 [ 7efdbe3eb9 ] - deps : update OpenSSL to 3.5.8 (Node.js GitHub Bot) #65542 Commits [ d8aedd6584 ] - build : skip dockit on riscv64 (Stewart X Addison) #62251 [ 1899c274eb ] - build : activate correct default flags for riscv64 (Stewart X Addison) #65708 [ ec8a3be996 ] - build : derive NODE_ARCH from target_cpu in the GN build (Shelley Vohr) #65491 [ b73118a507 ] - build,win : remove LTO parallelisation limit (Stefan Stojanovic) #65535 [ 09feba74c8 ] - deps : update undici to 8.10.2 (Node.js GitHub Bot) #65788 [ e47c432dd6 ] - deps : upgrade npm to 11.19.1 (npm team) #65573 [ 2fd6ce36a9 ] - deps : update corepack to 0.36.0 (Node.js GitHub Bot) #65653 [ 49dec2767a ] - deps : update googletest to 36ba75f0ad5383a9759f17f3f72fd4661c72cb6d (Node.js GitHub Bot) #65654 [ 676174a071 ] - deps : update simdjson to 4.6.9 (Node.js GitHub Bot) #65655 [ 2f1b7fa0bb ] - deps : update perfetto to 58.2 (Node.js GitHub Bot) #65656 [ 12acd0ad15 ] - deps : update zlib to 1.3.2.1-motley-5eb4d7e (Node.js GitHub Bot) #65494 [ 48631c80fb ] - deps : update archs files for openssl-3.5.8 (Node.js GitHub Bot) #65542 [ 7efdbe3eb9 ] - deps : upgrade openssl sources to openssl-3.5.8 (Node.js GitHub Bot) #65542 [ bdc75900ee ] - doc : replace node:modules documentation header (René) #65800 [ 44c8a499ba ] - doc : clarify return type of fs.mkdtemp* (Antoine du Hamel) #65743 [ 025fb5eeb0 ] - doc : update changelog-maker instructions for releasing (Juan José) #65707 [ 5f64847afa ] - doc : add stability status to crypto.setEngine (Antoine du Hamel) #65746 [ 299dee0cb9 ] - doc : remove outdated TLS authorized warning (Tim Perry) #65597 [ e97dcc0278 ] - doc : fix broken using link in ffi.md (Soul Lee) #65632 [ 2c9cc7d237 ] - doc : fix some broken links (Antoine du Hamel) #65583 [ 0c330ec329 ] - doc : fix stale TOC in maintaining-dependencies (greenhead) #65523 [ 9c522a3a69 ] - doc : refactor the AI guidelines (Joyee Cheung) #65269 [ 46cbf1bf8c ] - doc : fix triggerAsyncId() comment in async_hooks example (soreavis) #64583 [ 788904ff78 ] - doc : fix fsPromises.watch overflow value (Matt Radbourne) #64605 [ 3d06ff19e8 ] - doc : clarify stream direction in options.stdio note (Avocado) #65236 [ d334838379 ] - doc : clarify signal listener behavior (Som Samantray) #65243 [ d55a2bd56a ] - doc : add test reporter event lifecycle diagram (sangwook) #63780 [ c17dfc87de ] - doc : discourage AbortSignal cleanup for long-lived resources (Efe Karasakal) #64342 [ 616bd3fa26 ] - doc : deprecate Server.prototype._listen2 in node:net (Antoine du Hamel) #65593 [ 4e6d7e0ca6 ] - meta : cleanup targos emeritus changes (Antoine du Hamel) #65738 [ a70cfe1747 ] - meta : bump github/codeql-action/init from 4.37.3 to 4.37.9 (dependabot[bot]) #65714 [ e43a0ad4ce ] - meta : bump github/codeql-action/autobuild from 4.37.3 to 4.37.9 (dependabot[bot]) #65717 [ 99e06288f1 ] - meta : bump actions/checkout from 7.0.0 to 7.0.1 (dependabot[bot]) #65718 [ 89662762b3 ] - meta : bump cachix/install-nix-action from 31.11.0 to 31.11.1 (dependabot[bot]) #65719 [ 6b8f078672 ] - meta : bump actions/setup-node from 6.4.0 to 7.0.0 (dependabot[bot]) #65720 [ 6c6fb18e63 ] - meta : bump step-security/harden-runner from 2.20.0 to 2.21.0 (dependabot[bot]) #65721 [ 0e002e859f ] - meta : bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.9 (dependabot[bot]) #65722 [ 98aaffe4b9 ] - meta : bump github/codeql-action/analyze from 4.37.3 to 4.37.9 (dependabot[bot]) #65723 [ d247cb2975 ] - meta : document collaborator automation (Filip Skokan) #65671 [ ae1801eb55 ] - meta : refine the security vuln posture for experimental features (James M Snell) #65438 [ fab81d15c3 ] - test : widen the gap in the resolver maxTimeout comparison

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Node.js

Affected versions

  • 26.8.2
  • 8.10.2
  • 3.5.8
  • 11.19.1
  • 0.36.0
  • 4.6.9
  • 58.2
  • 1.3.2.1-motley-5eb4d7e
  • 4.37.3
  • 4.37.9
  • 7.0.0
  • 7.0.1
  • 31.11.0
  • 31.11.1
  • 6.4.0
  • 2.20.0
  • 2.21.0

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

These links connect the publisher update to related Lifecycle records without treating the update publication date as an end-of-support date.

Official publisher evidence

OPENJS FOUNDATIONVERIFIED

2026-09-09, Version 26.8.2 (Current), @aduh95

Checked 28 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source