<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Node Weekly</title>
    <description>A free, once–weekly e-mail round-up of Node.js news and articles.</description>
    <link>https://nodeweekly.com/</link>
    <item>
      <title>Node.js 26.7, vlt 1.0, and Shai-Hulud Returns</title>
      <link>https://nodeweekly.com/issues/636</link>
      <description>

  

    
    
  




&lt;table border=0 cellpadding=0 cellspacing=0 align="center" border="0"&gt;
  &lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em;"&gt;
  &lt;div&gt;    
    &lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;
&lt;td align="left" style="padding-left: 4px; font-size: 15px; line-height: 1.48em;"&gt;&lt;p&gt;#​636 — August 6, 2026&lt;/p&gt;&lt;/td&gt;
&lt;td align="right" style="padding-right: 4px; font-size: 15px; line-height: 1.48em;"&gt;&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188934/rss" style=" color: #20824B;"&gt;Read on the Web&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;
&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em;"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border="0"&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em; margin: 0; padding: 0;"&gt;&lt;img src="https://res.cloudinary.com/cpress/image/upload/v1653576619/lgfqinzbdqttwmhvljxb.png" width="100%" style="    line-height: 100%; "&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em;"&gt;
  &lt;a href="https://nodeweekly.com/link/188890/rss" style=" color: #20824B;"&gt;&lt;img src="https://res.cloudinary.com/cpress/image/upload/w_1280,e_sharpen:60,q_auto/bc5keokbeeeetqnie36v.jpg" width="640" style="    line-height: 100%;    "&gt;&lt;/a&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188890/rss" title="nodejs.org" style=" color: #20824B;   "&gt;Node.js 26.7.0 (Current) Released&lt;/a&gt;&lt;/span&gt; — Landing just two days after &lt;a href="https://nodeweekly.com/link/188891/rss" style=" color: #20824B;   "&gt;26.6&lt;/a&gt;, coverage reports can now include files your tests didn't touch with &lt;a href="https://nodeweekly.com/link/188892/rss" style=" color: #20824B;   "&gt;&lt;code&gt;--test-coverage-include-all&lt;/code&gt;&lt;/a&gt;, FFI and SQLite pick up crash fixes, and Perfetto tracing support lands, though you'll need a custom build to use it.&lt;/p&gt;
  &lt;p&gt;Antoine du Hamel &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;&lt;p&gt;💡 &lt;a href="https://nodeweekly.com/link/188893/rss" style=" color: #20824B; font-weight: 600;"&gt;Node v24.19.0 (LTS)&lt;/a&gt; is also a noteworthy update, adding &lt;code&gt;--experimental-import-text&lt;/code&gt;, &lt;code&gt;fs.readFile()&lt;/code&gt; can reuse a buffer you supply, and &lt;code&gt;setKeepAlive&lt;/code&gt; exposes &lt;code&gt;TCP_KEEPINTVL&lt;/code&gt; and &lt;code&gt;TCP_KEEPCNT&lt;/code&gt;.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  &lt;a href="https://nodeweekly.com/link/188889/rss" style=" color: #20824B;   "&gt;&lt;img src="https://res.cloudinary.com/cpress/image/upload/c_limit,w_480,h_480,q_auto/copm/2fc0d85b.jpg" width="135" height="135" style="padding-top: 12px; padding-left: 12px;     line-height: 100%; "&gt;&lt;/a&gt;
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188889/rss" title="sentry.io" style=" color: #20824B;   "&gt;Join Sentry Live: How Etsy Stays Crash-Free&lt;/a&gt;&lt;/span&gt; — Sentry and Etsy break down how Etsy's engineering team preps for peak traffic, debugs in real time, and ties crashes to revenue impact. Real stories and practical takeaways for teams running services at scale.&lt;/p&gt;
  &lt;p&gt;Sentry &lt;span style="text-transform: uppercase; margin-left: 4px; font-size: 0.9em;   color: #997 !important; padding: 1px 4px; "&gt;sponsor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;span&gt;🚨&lt;/span&gt; &lt;a href="https://nodeweekly.com/link/188894/rss" title="research.jfrog.com" style=" color: #20824B;   "&gt;Shai-Hulud Strikes Again, Affecting &lt;code&gt;keyv&lt;/code&gt; and 400+ Packages&lt;/a&gt;&lt;/span&gt; — A credential-stealing worm was rolled out as part of a false &lt;a href="https://nodeweekly.com/link/188895/rss" style=" color: #20824B;   "&gt;keyv&lt;/a&gt; 6.0 release this week, and quickly spread. A reminder to check out &lt;a href="https://nodeweekly.com/link/188896/rss" style=" color: #20824B;   "&gt;npm v12&lt;/a&gt;, &lt;a href="https://nodeweekly.com/link/188897/rss" style=" color: #20824B;   "&gt;pnpm&lt;/a&gt;, or vlt (below), all of which block install scripts by default, the mechanism this worm relied on.&lt;/p&gt;
  &lt;p&gt;Shavit Satou (JFrog) &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188898/rss" title="www.vlt.io" style=" color: #20824B;   "&gt;vlt 1.0: An &lt;code&gt;npm&lt;/code&gt; Alternative With CSS-Like Selectors&lt;/a&gt;&lt;/span&gt; — After two years, Darcy Clarke's drop-in &lt;code&gt;npm&lt;/code&gt; alternative hits 1.0. A key draw is &lt;code&gt;vlt query&lt;/code&gt;, which lets you use 60+ CSS-like selectors over your dependency graph (half of which are security related). vlt also offers hosted private package registries.&lt;/p&gt;
  &lt;p&gt;Darcy Clarke &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;&lt;p&gt;💡 In 2023, Darcy wrote &lt;a href="https://nodeweekly.com/link/188899/rss" style=" color: #20824B; font-weight: 600;"&gt;"The massive bug at the heart of the npm ecosystem"&lt;/a&gt;, a post that was prescient of current packaging headaches.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;p&gt;&lt;strong&gt;IN BRIEF:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;⚠️ The Express team has &lt;a href="https://nodeweekly.com/link/188900/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;announced security releases for &lt;code&gt;body-parser&lt;/code&gt;&lt;/a&gt; to address a DoS vulnerability.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188901/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;&lt;code&gt;net.BlockList&lt;/code&gt;&lt;/a&gt;, used to prevent network access to/from specified IP addresses and ranges, is &lt;a href="https://nodeweekly.com/link/188902/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;gaining new methods and getting much faster&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;There's a proposal and initial implementation to &lt;a href="https://nodeweekly.com/link/188903/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;bring the HTML spec's &lt;em&gt;Web Worker API&lt;/em&gt; to Node&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188904/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;ZIP archive support is coming to &lt;code&gt;node:zlib&lt;/code&gt;&lt;/a&gt; in a future release.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;p&gt;📄 &lt;a href="https://nodeweekly.com/link/188905/rss" style=" color: #20824B; font-weight: 500 !important;"&gt;What's New in Mongoose 9.9: Major Performance Improvements&lt;/a&gt; – &lt;a href="https://nodeweekly.com/link/188906/rss" style=" color: #20824B; font-weight: 500 !important;"&gt;Mongoose&lt;/a&gt; is a popular MongoDB object modelling solution. &lt;cite&gt;Valeri Karpov&lt;/cite&gt;&lt;/p&gt;
&lt;p&gt;📄 &lt;a href="https://nodeweekly.com/link/188907/rss" style=" color: #20824B; font-weight: 500 !important;"&gt;Debugging Stuck Node.js Processes&lt;/a&gt; – A trick for catching event loop blockers that never yield. &lt;cite&gt;Winona Schroeer-Smith&lt;/cite&gt;&lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em;"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;&lt;p&gt;🛠 Code &amp;amp; Tools&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em;"&gt;
  &lt;a href="https://nodeweekly.com/link/188908/rss" style=" color: #20824B;"&gt;&lt;img src="https://res.cloudinary.com/cpress/image/upload/w_1280,e_sharpen:60,q_auto/kpdqracqa9nmngvovohb.jpg" width="640" style="    line-height: 100%;      "&gt;&lt;/a&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188908/rss" title="firecrawl.github.io" style=" color: #20824B;   "&gt;anydoc: Convert 14 Document Formats into Markdown&lt;/a&gt;&lt;/span&gt; — A Rust-powered library (with Node.js and WASM bindings) that converts Word, PowerPoint, Excel, OpenDocument, RTF, EPUB, CSV, and PDF documents into Markdown. I tried it on a 1,600 page PDF and it took less than 2 seconds. There's also an in-browser demo to try it out. &lt;a href="https://nodeweekly.com/link/188909/rss" style=" color: #20824B;   "&gt;GitHub repo&lt;/a&gt;.&lt;/p&gt;
  &lt;p&gt;Firecrawl &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;&lt;p&gt;💡 Firecrawl also has &lt;a href="https://nodeweekly.com/link/188910/rss" style=" color: #20824B; font-weight: 600;"&gt;pdf-inspector&lt;/a&gt; focused specifically on extracting text from PDFs (with positional awareness). &lt;a href="https://nodeweekly.com/link/188911/rss" style=" color: #20824B; font-weight: 600;"&gt;Liteparse&lt;/a&gt; is also worth considering if you want OCR for scanned / non-text PDFs.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188912/rss" title="www.tigerdata.com" style=" color: #20824B;   "&gt;You Added a Cache to Hide a Slow Query&lt;/a&gt;&lt;/span&gt; — TimescaleDB makes the query fast in Postgres, so you cache less and serve fresh data. &lt;a href="https://nodeweekly.com/link/188912/rss" style=" color: #20824B;   "&gt;Get $1000 credit to start&lt;/a&gt;.&lt;/p&gt;
  &lt;p&gt;Tiger Data (creators of TimescaleDB) &lt;span style="text-transform: uppercase; margin-left: 4px; font-size: 0.9em;   color: #997 !important; padding: 1px 4px; "&gt;sponsor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188913/rss" title="github.com" style=" color: #20824B;   "&gt;ioredis 6.0: Robust, Full-Featured Redis Client for Node&lt;/a&gt;&lt;/span&gt; — v6.0, the first major release in four years, adds &lt;a href="https://nodeweekly.com/link/188914/rss" style=" color: #20824B;   "&gt;RESP3&lt;/a&gt; and support for new &lt;a href="https://nodeweekly.com/link/188915/rss" style=" color: #20824B;   "&gt;Redis 8.10&lt;/a&gt; features.&lt;/p&gt;
  &lt;p&gt;The ioredis Team &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188916/rss" title="github.com" style=" color: #20824B;   "&gt;MicroDiff 1.6: Fast Object and Array Comparison Library&lt;/a&gt;&lt;/span&gt; — Given two objects or arrays, it returns the differences (think &lt;code&gt;diff&lt;/code&gt; but for JS objects). This week's release adds support for Temporal types.&lt;/p&gt;
  &lt;p&gt;Jacob Jackson &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188917/rss" title="github.com" style=" color: #20824B;   "&gt;Devalue 5.9: Get the Job Done When &lt;code&gt;JSON.stringify&lt;/code&gt; Can't&lt;/a&gt;&lt;/span&gt; — A library from the Svelte project that's like &lt;code&gt;JSON.stringify&lt;/code&gt; but can tackle cyclical and repeated references, regexes, &lt;code&gt;Map&lt;/code&gt;/&lt;code&gt;Set&lt;/code&gt;, and custom types. &lt;a href="https://nodeweekly.com/link/188918/rss" style=" color: #20824B;   "&gt;Try it here&lt;/a&gt;.&lt;/p&gt;
  &lt;p&gt;Svelte &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188919/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;node-x11 3.8&lt;/a&gt; – An X Window System protocol client library with no dependencies, GLX / OpenGL support, and even the ability to &lt;a href="https://nodeweekly.com/link/188920/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;work in the browser&lt;/a&gt; against a JavaScript X-server emulator.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188921/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;pnpm 11.20&lt;/a&gt; – Mostly security hardening, but also adds an &lt;code&gt;npmjs:&lt;/code&gt; prefix you can use to more succinctly pin a dependency to the public registry. Note that &lt;a href="https://nodeweekly.com/link/188922/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;pnpm 12.0&lt;/a&gt; has also reached RC stage.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188923/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Hono 4.13.0&lt;/a&gt; – The small, fast Web standards-based web framework focuses on performance and adds HTTP QUERY method support.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188924/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;graphql-upload 18.0&lt;/a&gt; – Middleware that adds support for GraphQL multipart requests to Node.js GraphQL servers.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188925/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;cron-parser 5.7&lt;/a&gt; – Library for parsing and manipulating &lt;code&gt;cron&lt;/code&gt; expressions.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px;"&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em;"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;p&gt;📰 Classifieds&lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;p&gt;⚡ &lt;a href="https://nodeweekly.com/link/188926/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Zuplo&lt;/a&gt; puts every API, AI, and MCP request behind one gateway. Route traffic, guard your MCP servers, and cap your AI costs. &lt;a href="https://nodeweekly.com/link/188926/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Try it free&lt;/a&gt;.&lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em;"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0;"&gt;&lt;p&gt;📢  Elsewhere in the ecosystem&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em;"&gt;
  &lt;a href="https://nodeweekly.com/link/188927/rss" style=" color: #20824B;"&gt;&lt;img src="https://res.cloudinary.com/cpress/image/upload/w_1280,e_sharpen:60,q_auto/rsttgpy4jk534dz2b9m8.jpg" width="640" style="    line-height: 100%;      "&gt;&lt;/a&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Did you know JavaScript supports a third type of comment (beyond &lt;code&gt;//&lt;/code&gt; and &lt;code&gt;/* */&lt;/code&gt;)? &lt;a href="https://nodeweekly.com/link/188927/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;▶️ Mat Marquis shows off hashbang comments&lt;/a&gt; in a short YouTube video. And yes, &lt;a href="https://nodeweekly.com/link/188928/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;they're in the language spec!&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🤖 Fred K. Schott, of &lt;a href="https://nodeweekly.com/link/188929/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Astro&lt;/a&gt; fame, has &lt;a href="https://nodeweekly.com/link/188930/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;unveiled Flue 2.0&lt;/a&gt;, the latest version of his TypeScript-based open agent framework.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;⚖️ The &lt;em&gt;Deno vs Oracle&lt;/em&gt; JavaScript™ trademark case rumbles on with &lt;a href="https://nodeweekly.com/link/188931/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Deno consenting to a &lt;em&gt;fifth&lt;/em&gt; extension request&lt;/a&gt; as discovery continues.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;📺 SQLite's Richard Hipp gave &lt;a href="https://nodeweekly.com/link/188932/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;▶️ a detailed 50-minute talk on SQLite's reliability&lt;/a&gt; and the tools, practices, and design choices that have given it its strong reputation.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;📊 The &lt;a href="https://nodeweekly.com/link/188933/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;results of the &lt;em&gt;State of CSS 2026&lt;/em&gt; survey&lt;/a&gt; have been released.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em;"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;


&lt;/div&gt;
  &lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;




&lt;img src="https://nodeweekly.com/open/636/rss" width="1" height="1" /&gt;</description>
      <pubDate>Thu, 6 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://nodeweekly.com/issues/636</guid>
    </item>
    <item>
      <title>npm to scan packages for malware at publish time</title>
      <link>https://nodeweekly.com/issues/635</link>
      <description>

  

    
    
  




&lt;table border=0 cellpadding=0 cellspacing=0 align="center" border="0"&gt;
  &lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em;"&gt;
  &lt;div&gt;    
    &lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;
&lt;td align="left" style="padding-left: 4px; font-size: 15px; line-height: 1.48em;"&gt;&lt;p&gt;#​635 — July 30, 2026&lt;/p&gt;&lt;/td&gt;
&lt;td align="right" style="padding-right: 4px; font-size: 15px; line-height: 1.48em;"&gt;&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188630/rss" style=" color: #20824B;"&gt;Read on the Web&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;
&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em;"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border="0"&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em; margin: 0; padding: 0;"&gt;&lt;img src="https://res.cloudinary.com/cpress/image/upload/v1653576619/lgfqinzbdqttwmhvljxb.png" width="100%" style="    line-height: 100%; "&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em;"&gt;
  &lt;a href="https://nodeweekly.com/link/188597/rss" style=" color: #20824B;"&gt;&lt;img src="https://res.cloudinary.com/cpress/image/upload/w_1280,e_sharpen:60,q_auto/un7lnngivo4dfpog3r24.jpg" width="640" style="    line-height: 100%;    "&gt;&lt;/a&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188597/rss" title="evilmartians.com" style=" color: #20824B;   "&gt;The Secure Way to Release an &lt;code&gt;npm&lt;/code&gt; Package in 2026&lt;/a&gt;&lt;/span&gt; — A practical guide to publishing &lt;code&gt;npm&lt;/code&gt; packages more safely in 2026, written by someone who's released several popular packages (like &lt;a href="https://nodeweekly.com/link/188598/rss" style=" color: #20824B;   "&gt;postcss&lt;/a&gt; and &lt;a href="https://nodeweekly.com/link/188599/rss" style=" color: #20824B;   "&gt;nanoid&lt;/a&gt;). As well as showing &lt;em&gt;how&lt;/em&gt; to use things like staged publishing and trusted publishing, he explains &lt;em&gt;why&lt;/em&gt; and the security benefits of doing so.&lt;/p&gt;
  &lt;p&gt;Andrey Sitnik &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  &lt;a href="https://nodeweekly.com/link/188596/rss" style=" color: #20824B;   "&gt;&lt;img src="https://res.cloudinary.com/cpress/image/upload/c_limit,w_480,h_480,q_auto/copm/d4838d18.jpg" width="160" height="110" style="padding-top: 12px; padding-left: 12px;     line-height: 100%; "&gt;&lt;/a&gt;
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188596/rss" title="dashboard.render.com" style=" color: #20824B;   "&gt;Ship Node and Bun Apps in Minutes&lt;/a&gt;&lt;/span&gt; — Link your repo and Render takes it from there, handling every build, deploy, and SSL cert. Loop in your agent with official Render &lt;code&gt;/plugins&lt;/code&gt; for Codex and Claude Code. Start free and scale from there.&lt;/p&gt;
  &lt;p&gt;Render &lt;span style="text-transform: uppercase; margin-left: 4px; font-size: 0.9em;   color: #997 !important; padding: 1px 4px; "&gt;sponsor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188600/rss" title="github.blog" style=" color: #20824B;   "&gt;npm to Scan Every Package For Malware at Publish Time&lt;/a&gt;&lt;/span&gt; — The npm registry is beginning to scan packages at publish time, meaning new versions can take several minutes to become installable, and &lt;em&gt;could&lt;/em&gt; be held or blocked.&lt;/p&gt;
  &lt;p&gt;GitHub &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;p&gt;&lt;strong&gt;IN BRIEF:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🔒 The &lt;a href="https://nodeweekly.com/link/188601/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Wednesday, July 29, 2026 Security Releases&lt;/a&gt; of Node are available as &lt;a href="https://nodeweekly.com/link/188602/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Node v26.5.1&lt;/a&gt;, &lt;a href="https://nodeweekly.com/link/188603/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;v24.18.1&lt;/a&gt; and &lt;a href="https://nodeweekly.com/link/188604/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;v22.23.2&lt;/a&gt;. 11 CVEs are tackled, including two HTTP/2 flaws, a Permission Model allowlist bypass, and more.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Microsoft is previewing &lt;a href="https://nodeweekly.com/link/188605/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;a way to call native Windows APIs from Node&lt;/a&gt; (and therefore Electron) &lt;em&gt;without&lt;/em&gt; native addons via a new dynamic Windows Runtime API (WinRT) projection.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188606/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Amazon's security team has narrowed down&lt;/a&gt; several npm supply chain attacks (such as those on &lt;code&gt;debug&lt;/code&gt; and &lt;code&gt;chalk&lt;/code&gt;) to a single North Korean-linked group.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Cloudflare's &lt;code&gt;wrangler&lt;/code&gt; can now &lt;a href="https://nodeweekly.com/link/188607/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;run integration tests against Workers from any Node.js test runner&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188608/rss" title="nodejs.org" style=" color: #20824B;   "&gt;Check Out Node's New API Documentation Preview&lt;/a&gt;&lt;/span&gt; — Node's official API docs have been getting redesigned (now sharing a design system with &lt;a href="https://nodeweekly.com/link/188609/rss" style=" color: #20824B;   "&gt;nodejs.org&lt;/a&gt; itself) and have a new built-in search feature. You're invited to &lt;a href="https://nodeweekly.com/link/188610/rss" style=" color: #20824B;   "&gt;try the preview here&lt;/a&gt; and report what breaks.&lt;/p&gt;
  &lt;p&gt;Guilherme Araújo (Node.js Team) &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188611/rss" title="github.blog" style=" color: #20824B;   "&gt;How GitHub Is Disrupting Supply Chain Attacks on npm and Actions&lt;/a&gt;&lt;/span&gt; — Separate to the scanning news above, GitHub's team explains recent npm and Actions changes designed to mitigate supply chain attack techniques.&lt;/p&gt;
  &lt;p&gt;Ose and Steindler (GitHub) &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;p&gt;📄 &lt;a href="https://nodeweekly.com/link/188612/rss" style=" color: #20824B; font-weight: 500 !important;"&gt;Finding Eight High-Severity Vulnerabilities in NodeBB in Six Hours&lt;/a&gt;  &lt;cite&gt;Jorian Woltjer (Aikido)&lt;/cite&gt;&lt;/p&gt;
&lt;p&gt;📄 &lt;a href="https://nodeweekly.com/link/188613/rss" style=" color: #20824B; font-weight: 500 !important;"&gt;Running &lt;code&gt;npm&lt;/code&gt; in a Separate Container When Using Claude&lt;/a&gt;  &lt;cite&gt;Bryan Hogan&lt;/cite&gt;&lt;/p&gt;
&lt;p&gt;📄 &lt;a href="https://nodeweekly.com/link/188614/rss" style=" color: #20824B; font-weight: 500 !important;"&gt;Integration Testing with Node and Testcontainers&lt;/a&gt;  &lt;cite&gt;Flavio Copes&lt;/cite&gt;&lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em;"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;&lt;p&gt;🛠 Code &amp;amp; Tools&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em;"&gt;
  &lt;a href="https://nodeweekly.com/link/188615/rss" style=" color: #20824B;"&gt;&lt;img src="https://res.cloudinary.com/cpress/image/upload/w_1280,e_sharpen:60,q_auto/q9tikaadsxmsj3f7vkpi.jpg" width="640" style="        line-height: 100%;  "&gt;&lt;/a&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em;"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188615/rss" title="scriptc.dev" style=" color: #20824B;   "&gt;scriptc: Vercel's New TypeScript-to-Native Compiler&lt;/a&gt;&lt;/span&gt; — A new entry into the growing field of JS/TS native ahead-of-time compilers that makes the promise that &lt;em&gt;"what compiles behaves byte-for-byte like Node."&lt;/em&gt; Static by default, but you can opt in to a &lt;code&gt;--dynamic&lt;/code&gt; mode which embeds a JavaScript engine for runtime dynamism. &lt;a href="https://nodeweekly.com/link/188616/rss" style=" color: #20824B;   "&gt;GitHub repo&lt;/a&gt;.&lt;/p&gt;
  &lt;p&gt;Vercel Labs &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188617/rss" title="www.tigerdata.com" style=" color: #20824B;   "&gt;Fast Endpoints Shouldn't Choke on Analytics&lt;/a&gt;&lt;/span&gt; — TimescaleDB extends Postgres so heavy queries stay fast at scale. One database, not two. &lt;a href="https://nodeweekly.com/link/188617/rss" style=" color: #20824B;   "&gt;Get $1000 credit to start&lt;/a&gt;.&lt;/p&gt;
  &lt;p&gt;Tiger Data (creators of TimescaleDB) &lt;span style="text-transform: uppercase; margin-left: 4px; font-size: 0.9em;   color: #997 !important; padding: 1px 4px; "&gt;sponsor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188618/rss" title="tslog.js.org" style=" color: #20824B;   "&gt;tslog 5: Zero-Dependency Logger for Node, Deno, Bun and Browsers&lt;/a&gt;&lt;/span&gt; — A ground-up rewrite that's now ESM-only. Pretty output by default, JSON optionally, plus middleware, file/HTTP/worker transports, secret masking, and error stacks that resolve through source maps to your &lt;code&gt;.ts&lt;/code&gt; code. &lt;a href="https://nodeweekly.com/link/188619/rss" style=" color: #20824B;   "&gt;GitHub repo&lt;/a&gt;.&lt;/p&gt;
  &lt;p&gt;Eugene Terehov &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188620/rss" title="github.com" style=" color: #20824B;   "&gt;npm-check-updates 23.0: Find Newer Versions of Dependencies&lt;/a&gt;&lt;/span&gt; — Find newer versions than your &lt;code&gt;package.json&lt;/code&gt; allows. Has a &lt;code&gt;-i&lt;/code&gt; interactive mode to look at upgrades and opt in to them one by one. Supports custom cooldown periods. &lt;a href="https://nodeweekly.com/link/188621/rss" style=" color: #20824B;   "&gt;v23&lt;/a&gt; is faster, smaller, and is now a pure ESM package.&lt;/p&gt;
  &lt;p&gt;Raine Revere &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188622/rss" title="github.com" style=" color: #20824B;   "&gt;jsdom 30.0: Pure JS Implementation of Web Standards for Node&lt;/a&gt;&lt;/span&gt; — The venerable browser-environment emulator used by countless test suites. v30.0 adds &lt;code&gt;CSS.escape()&lt;/code&gt;, &lt;code&gt;CSS.supports()&lt;/code&gt;, &lt;code&gt;background-position-x&lt;/code&gt;/&lt;code&gt;y&lt;/code&gt;, as well as some fixes.&lt;/p&gt;
  &lt;p&gt;Denicola, Insua, et al. &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188623/rss" title="github.com" style=" color: #20824B;   "&gt;crypto-random-string 6.0: Generate a Cryptographically Strong Random String&lt;/a&gt;&lt;/span&gt; — For example: &lt;code&gt;cryptoRandomString({length: 10})&lt;/code&gt; might return &lt;code&gt;2cf05d94db&lt;/code&gt;. v6.0 improves performance and removes &lt;code&gt;cryptoRandomStringAsync&lt;/code&gt;.&lt;/p&gt;
  &lt;p&gt;Sindre Sorhus &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188624/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Ada v4&lt;/a&gt; – The WHATWG-compliant URL parser used by Node is now even faster.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188625/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Wasp v0.25&lt;/a&gt; – The Rails-esque framework for building full-stack webapps with React &amp;amp; Node introduces Vite 8 and React Router 8.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188626/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;modern-tar 0.8&lt;/a&gt; – Zero-dependency streaming &lt;code&gt;tar&lt;/code&gt; parser and writer.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;📋 &lt;a href="https://nodeweekly.com/link/188627/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;tinyclip 1.0&lt;/a&gt; – Cross-platform clipboard utility library.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188628/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Nub 0.6&lt;/a&gt; – Fast all-in-one toolkit that augments Node.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188629/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Verdaccio 6.9&lt;/a&gt; – Self-hostable private npm registry.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em;"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;


&lt;/div&gt;
  &lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;




&lt;img src="https://nodeweekly.com/open/635/rss" width="1" height="1" /&gt;</description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://nodeweekly.com/issues/635</guid>
    </item>
    <item>
      <title>Domenic Denicola's modern dev setup</title>
      <link>https://nodeweekly.com/issues/634</link>
      <description>

  

    
    
  




&lt;table border=0 cellpadding=0 cellspacing=0 align="center" border="0"&gt;
  &lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em;"&gt;
  &lt;div&gt;    
    &lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;
&lt;td align="left" style="padding-left: 4px; font-size: 15px; line-height: 1.48em;"&gt;&lt;p&gt;#​634 — July 23, 2026&lt;/p&gt;&lt;/td&gt;
&lt;td align="right" style="padding-right: 4px; font-size: 15px; line-height: 1.48em;"&gt;&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188381/rss" style=" color: #20824B;"&gt;Read on the Web&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;
&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em;"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border="0"&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em; margin: 0; padding: 0;"&gt;&lt;img src="https://res.cloudinary.com/cpress/image/upload/v1653576619/lgfqinzbdqttwmhvljxb.png" width="100%" style="    line-height: 100%; "&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em;"&gt;
  &lt;a href="https://nodeweekly.com/link/188351/rss" style=" color: #20824B;"&gt;&lt;img src="https://res.cloudinary.com/cpress/image/upload/w_1280,e_sharpen:60,q_auto/phw1ia6ck6daytvjsy7q.jpg" width="640" style="    line-height: 100%;    "&gt;&lt;/a&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188351/rss" title="adventures.nodeland.dev" style=" color: #20824B;   "&gt;No, We Can't Harden Node.js Against Prototype Pollution&lt;/a&gt;&lt;/span&gt; — An explanation of why the Node team rejects prototype pollution reports against core: each assumes the attacker can already write to &lt;code&gt;Object.prototype&lt;/code&gt;, by which point the game is over. The true fix lives at the boundary where untrusted JSON becomes objects.&lt;/p&gt;
  &lt;p&gt;Matteo Collina &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  &lt;a href="https://nodeweekly.com/link/188350/rss" style=" color: #20824B;   "&gt;&lt;img src="https://res.cloudinary.com/cpress/image/upload/c_limit,w_480,h_480,q_auto/copm/9fdaa696.png" width="153" height="110" style="padding-top: 12px; padding-left: 12px;     line-height: 100%; "&gt;&lt;/a&gt;
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188350/rss" title="github.com" style=" color: #20824B;   "&gt;Full-Text Search in Drizzle Without a Second System&lt;/a&gt;&lt;/span&gt; — Try the official ParadeDB integration for Drizzle. Search your live Postgres tables. No stale results, no ETL, no Elasticsearch cluster.&lt;/p&gt;
  &lt;p&gt;ParadeDB &lt;span style="text-transform: uppercase; margin-left: 4px; font-size: 0.9em;   color: #997 !important; padding: 1px 4px; "&gt;sponsor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188352/rss" title="domenic.me" style=" color: #20824B;   "&gt;Domenic Denicola's Agentic Coding Setup&lt;/a&gt;&lt;/span&gt; — It's fascinating when a prolific developer (Domenic was a key figure in &lt;a href="https://nodeweekly.com/link/188353/rss" style=" color: #20824B;   "&gt;the adoption of promises in JavaScript&lt;/a&gt;, creating &lt;a href="https://nodeweekly.com/link/188354/rss" style=" color: #20824B;   "&gt;jsdom&lt;/a&gt;, and &lt;a href="https://nodeweekly.com/link/188382/rss" style=" color: #20824B;   "&gt;much more&lt;/a&gt;) shares their workflow. This is no exception, covering areas like disposable VMs, Tailscale, and worktrees.&lt;/p&gt;
  &lt;p&gt;Domenic Denicola &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;p&gt;&lt;strong&gt;IN BRIEF:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;⚠️ &lt;a href="https://nodeweekly.com/link/188355/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;A round of July 27 Node.js security releases&lt;/a&gt; has been announced, with Node 26.x, 24.x, 22.x being updated to resolve a HIGH severity issue.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🏆 The OpenJS Foundation is showcasing &lt;a href="https://nodeweekly.com/link/188356/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;a ranking of the top contributors to its projects&lt;/a&gt; (which &lt;a href="https://nodeweekly.com/link/188357/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;include&lt;/a&gt; Node, Express, and Electron) in the past year. Matteo Collina
leads the way…just!&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Over on 𝕏, &lt;a href="https://nodeweekly.com/link/188358/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;the Bun team is teasing&lt;/a&gt; the imminent release of &lt;a href="https://nodeweekly.com/link/188359/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Bun&lt;/a&gt; 1.4, which will have the &lt;em&gt;"biggest jump in Node.js compatibility since Bun v1.0".&lt;/em&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188376/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;pnpm has had a flurry of releases&lt;/a&gt; introducing native workspace release management, a &lt;code&gt;doctor&lt;/code&gt; command to diagnose installation issues, and more.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;ESLint now provides &lt;a href="https://nodeweekly.com/link/188360/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;official 'codemods' for automating ESLint version migrations&lt;/a&gt;, with v8→v9 and v9→v10 available.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188377/rss" title="github.com" style=" color: #20824B;   "&gt;better-sqlite3 13.0: The Popular SQLite Library Moves to N-API&lt;/a&gt;&lt;/span&gt; — The good news is prebuilt binaries should now work across different versions of Node and Electron. There's also a new &lt;code&gt;db.explain()&lt;/code&gt; method and a &lt;code&gt;preparedStatement.toString()&lt;/code&gt; method to get the expanded SQL of a prepared statement.&lt;/p&gt;
  &lt;p&gt;Joshua Wise &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188361/rss" title="www.tigerdata.com" style=" color: #20824B;   "&gt;High-Ingest Analytics, Still Just Postgres&lt;/a&gt;&lt;/span&gt; — TimescaleDB extends Postgres to ingest and query events at scale. One database, standard SQL. &lt;a href="https://nodeweekly.com/link/188361/rss" style=" color: #20824B;   "&gt;Get $1000 credit to start&lt;/a&gt;.&lt;/p&gt;
  &lt;p&gt;Tiger Data (creators of TimescaleDB) &lt;span style="text-transform: uppercase; margin-left: 4px; font-size: 0.9em;   color: #997 !important; padding: 1px 4px; "&gt;sponsor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;p&gt;📄 &lt;a href="https://nodeweekly.com/link/188378/rss" style=" color: #20824B; font-weight: 500 !important;"&gt;Unpacking the AsyncAPI npm Supply Chain Compromise&lt;/a&gt; – It seems attackers have already adapted to a world where post-install scripts are no longer run. &lt;cite&gt;Microsoft Security Research&lt;/cite&gt;&lt;/p&gt;
&lt;p&gt;📄 &lt;a href="https://nodeweekly.com/link/188379/rss" style=" color: #20824B; font-weight: 500 !important;"&gt;New Study Identifies 53 Slopsquatting Targets Across 5 Popular LLMs&lt;/a&gt; – LLMs continue to make up npm package names. &lt;cite&gt;Sarah Gooding&lt;/cite&gt;&lt;/p&gt;
&lt;p&gt;📄 &lt;a href="https://nodeweekly.com/link/188362/rss" style=" color: #20824B; font-weight: 500 !important;"&gt;Running Background Jobs in Node.js with BullMQ&lt;/a&gt;  &lt;cite&gt;Flavio Copes&lt;/cite&gt;&lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;&lt;p&gt;🛠 Code &amp;amp; Tools&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188365/rss" title="github.com" style=" color: #20824B;   "&gt;Execa 10.0: Better Process Execution from Node&lt;/a&gt;&lt;/span&gt; — A powerful way to run processes that makes passing in input, processing output, handling errors, piping things around, and handling streams easy. &lt;a href="https://nodeweekly.com/link/188366/rss" style=" color: #20824B;   "&gt;v10&lt;/a&gt; trims the API and adds new stream conversion powers and a &lt;code&gt;killDescendants&lt;/code&gt; option to terminate a subprocess's descendant processes.&lt;/p&gt;
  &lt;p&gt;Sindre Sorhus &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188363/rss" title="github.com" style=" color: #20824B;   "&gt;eslint-package-json: Powerful ESLint Rules for &lt;code&gt;package.json&lt;/code&gt;&lt;/a&gt;&lt;/span&gt; — An ESLint plugin that catches &lt;code&gt;package.json&lt;/code&gt; mistakes like invalid names, bad version ranges, broken &lt;code&gt;exports&lt;/code&gt;, redundant &lt;code&gt;files&lt;/code&gt; entries, and more, and fixes many of them automatically.&lt;/p&gt;
  &lt;p&gt;Sindre Sorhus &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;span&gt;🤖&lt;/span&gt; &lt;a href="https://nodeweekly.com/link/188364/rss" title="botkit.fedify.dev" style=" color: #20824B;   "&gt;BotKit: Build Standalone ActivityPub Bots&lt;/a&gt;&lt;/span&gt; — A way to run a bot (or multiple bots) that Mastodon users can see and follow but without needing an account anywhere. Write it all in JavaScript and self-host. I spun one up with Node (temporarily) and it worked well.&lt;/p&gt;
  &lt;p&gt;Fedify &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188367/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Nub 0.5&lt;/a&gt; – The &lt;a href="https://nodeweekly.com/link/188368/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;all-in-one toolkit&lt;/a&gt; that augments Node's feature set. v0.5 adds &lt;code&gt;nub init&lt;/code&gt; as a way to quickly scaffold new projects.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188369/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;odiff 4.5&lt;/a&gt; – Fast SIMD-powered image comparison library. Written in Zig with Node bindings.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188370/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;node-html-to-image 6.2&lt;/a&gt; – A function to generate images from HTML.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188371/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;find-my-way 9.7&lt;/a&gt; – Fast radix-tree based HTTP router used by Fastify.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188372/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Gitify 7.0&lt;/a&gt; – Electron-powered Git notifications menu bar app.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188380/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Verdaccio 6.8&lt;/a&gt; – Self-hostable Node.js private proxy registry.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188373/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Piscina 5.3&lt;/a&gt; – Popular worker thread pool implementation.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188374/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Prisma 7.9&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px;"&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em;"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;p&gt;📰 Classifieds&lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;p&gt;⚡ &lt;a href="https://nodeweekly.com/link/188375/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Zuplo&lt;/a&gt; puts every API, AI, and MCP request behind one gateway. Route traffic, guard your MCP servers, and cap your AI costs. &lt;a href="https://nodeweekly.com/link/188375/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Try it free&lt;/a&gt;.&lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em;"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;


&lt;/div&gt;
  &lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;




&lt;img src="https://nodeweekly.com/open/634/rss" width="1" height="1" /&gt;</description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://nodeweekly.com/issues/634</guid>
    </item>
    <item>
      <title>The life of a ~200ms HTTP request to a Node app</title>
      <link>https://nodeweekly.com/issues/633</link>
      <description>

  

    
    
  




&lt;table border=0 cellpadding=0 cellspacing=0 align="center" border="0"&gt;
  &lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em;"&gt;
  &lt;div&gt;    
    &lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;
&lt;td align="left" style="padding-left: 4px; font-size: 15px; line-height: 1.48em;"&gt;&lt;p&gt;#​633 — July 16, 2026&lt;/p&gt;&lt;/td&gt;
&lt;td align="right" style="padding-right: 4px; font-size: 15px; line-height: 1.48em;"&gt;&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188021/rss" style=" color: #20824B;"&gt;Read on the Web&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;
&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em;"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border="0"&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em; margin: 0; padding: 0;"&gt;&lt;img src="https://res.cloudinary.com/cpress/image/upload/v1653576619/lgfqinzbdqttwmhvljxb.png" width="100%" style="    line-height: 100%; "&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em;"&gt;
  &lt;a href="https://nodeweekly.com/link/187974/rss" style=" color: #20824B;"&gt;&lt;img src="https://res.cloudinary.com/cpress/image/upload/w_1280,e_sharpen:60,q_auto/dilnllzd34vzt8qhuhgu.jpg" width="640" style="    line-height: 100%;    "&gt;&lt;/a&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/187974/rss" title="200ms.thenodebook.com" style=" color: #20824B;   "&gt;Follow a Single HTTP Request Through Its ~200ms Life&lt;/a&gt;&lt;/span&gt; — From the creator of &lt;a href="https://nodeweekly.com/link/187975/rss" style=" color: #20824B;   "&gt;NodeBook&lt;/a&gt;, a thorough guide to Node's internals, comes a scroll-driven visualization following &lt;em&gt;every step&lt;/em&gt; a single HTTP POST request takes from the user's click to Node's event loop and on to a database behind it.&lt;/p&gt;
  &lt;p&gt;Ishtmeet Singh &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  &lt;a href="https://nodeweekly.com/link/187973/rss" style=" color: #20824B;   "&gt;&lt;img src="https://res.cloudinary.com/cpress/image/upload/c_limit,w_480,h_480,q_auto/copm/d17bc7e7.png" width="140" height="140" style="padding-top: 12px; padding-left: 12px;     line-height: 100%; "&gt;&lt;/a&gt;
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/187973/rss" title="master.dev" style=" color: #20824B;   "&gt;The Best Harness Wins, Not the Best Model. Learn Harness Engineering&lt;/a&gt;&lt;/span&gt; — Scott Moss (Netflix) teaches you to wrap an LLM in a production-grade harness. Learn durable execution, sandboxing, memory, and multi-agent orchestration.&lt;/p&gt;
  &lt;p&gt;Master.dev &lt;span style="text-transform: uppercase; margin-left: 4px; font-size: 0.9em;   color: #997 !important; padding: 1px 4px; "&gt;sponsor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/187976/rss" title="www.jasnell.me" style=" color: #20824B;   "&gt;Fetch Needs Error Codes&lt;/a&gt;&lt;/span&gt; — &lt;code&gt;e.cause.code&lt;/code&gt; lets you find out why a &lt;code&gt;fetch()&lt;/code&gt; failed in Node, but the spec says failures are just bare &lt;code&gt;TypeError&lt;/code&gt;s, so HTTP/2/3 typed signals like &lt;em&gt;"safe to retry this POST"&lt;/em&gt; go missing. James, who created Node's error code convention, is pushing a TC39 proposal to standardize a fix.&lt;/p&gt;
  &lt;p&gt;James M Snell &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;p&gt;&lt;strong&gt;IN BRIEF:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/187977/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Ant&lt;/a&gt; is a new entry to the growing field of JavaScript runtimes. This time, it's an independent engine written in C packed into a 9MB binary that boasts very low cold start times and can run Hono apps.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If you're considering using Go at all, &lt;a href="https://nodeweekly.com/link/187978/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;this 'from Express to Fiber' guide&lt;/a&gt; with examples in both JavaScript and Go (on the Express-inspired &lt;a href="https://nodeweekly.com/link/187979/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Fiber&lt;/a&gt; framework) could be helpful.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🇮🇹 &lt;a href="https://nodeweekly.com/link/187980/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;NodeConf EU 2026&lt;/a&gt; takes place this September 29-30 in Italy. &lt;a href="https://nodeweekly.com/link/187981/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Tickets&lt;/a&gt; are still available.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/187982/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Vercel is deprecating Node 20&lt;/a&gt; for &lt;em&gt;Builds&lt;/em&gt; and &lt;em&gt;Functions&lt;/em&gt; on October 1, 2026.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/187983/rss" title="piccalil.li" style=" color: #20824B;   "&gt;&lt;code&gt;Proxy&lt;/code&gt; and &lt;code&gt;Reflect&lt;/code&gt;: Redefining How Objects Fundamentally Work&lt;/a&gt;&lt;/span&gt; — A deep dive into intercepting the internal operations of JavaScript objects, covering why &lt;code&gt;Reflect&lt;/code&gt; exists at all, and ending with a small reactive state system.&lt;/p&gt;
  &lt;p&gt;Mat Marquis &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/187984/rss" title="core.telegram.org" style=" color: #20824B;   "&gt;Telegram Serverless: Run Telegram Bots on Telegram's Servers&lt;/a&gt;&lt;/span&gt; — Creating a bot for Telegram is easy (it has &lt;a href="https://nodeweekly.com/link/187985/rss" style=" color: #20824B;   "&gt;a &lt;em&gt;great&lt;/em&gt; API&lt;/a&gt;) with libraries like &lt;a href="https://nodeweekly.com/link/187986/rss" style=" color: #20824B;   "&gt;node-telegram-bot-api&lt;/a&gt;, but it's starting to support running them on its &lt;em&gt;own&lt;/em&gt; servers.&lt;/p&gt;
  &lt;p&gt;Telegram &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;&lt;p&gt;💡 The serverless program is in beta, so not all users will have access to it yet.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;p&gt;📄 &lt;a href="https://nodeweekly.com/link/187987/rss" style=" color: #20824B; font-weight: 500 !important;"&gt;A Gentle Introduction to Git Worktrees&lt;/a&gt; – For when you need to check out multiple branches into separate directories simultaneously. &lt;cite&gt;Nicholas C. Zakas&lt;/cite&gt;&lt;/p&gt;
&lt;p&gt;📄 &lt;a href="https://nodeweekly.com/link/187988/rss" style=" color: #20824B; font-weight: 500 !important;"&gt;Playwright on GitHub Actions: A Setup That Actually Runs Fast&lt;/a&gt; – How to cut Playwright CI time by caching browser binaries, lifting the scaffold's one-worker cap, and more. &lt;cite&gt;Jakob Norlin&lt;/cite&gt;&lt;/p&gt;
&lt;p&gt;📄 &lt;a href="https://nodeweekly.com/link/187989/rss" style=" color: #20824B; font-weight: 500 !important;"&gt;6 Security Settings Every GitHub Maintainer Should Enable This Week&lt;/a&gt;  &lt;cite&gt;Joseph Katsioloudes (GitHub)&lt;/cite&gt;&lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;&lt;p&gt;🛠 Code &amp;amp; Tools&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em;"&gt;
  &lt;a href="https://nodeweekly.com/link/187990/rss" style=" color: #20824B;"&gt;&lt;img src="https://res.cloudinary.com/cpress/image/upload/w_1280,e_sharpen:60,q_auto/p3ow0hsqzactzle7wsgv.jpg" width="640" style="    line-height: 100%;      "&gt;&lt;/a&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/187990/rss" title="github.com" style=" color: #20824B;   "&gt;LiteParse 2: Fast, Light PDF Document Parsing&lt;/a&gt;&lt;/span&gt; — A PDF parser built in Rust with bindings for Node (plus WASM, Rust, and Python) — it worked great in my testing. It includes OCR, handles layouts/is spatially aware, and is fast (a complex 140-page PDF took ~10 seconds). &lt;a href="https://nodeweekly.com/link/187991/rss" style=" color: #20824B;   "&gt;Here's how to get started from Node&lt;/a&gt;.&lt;/p&gt;
  &lt;p&gt;LlamaIndex &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/187994/rss" title="www.tigerdata.com" style=" color: #20824B;   "&gt;One Postgres for Your API and Your Analytics&lt;/a&gt;&lt;/span&gt; — TimescaleDB extends Postgres so your app and analytics run in one database at scale. &lt;a href="https://nodeweekly.com/link/187994/rss" style=" color: #20824B;   "&gt;Get $1000 credit to start&lt;/a&gt;.&lt;/p&gt;
  &lt;p&gt;Tiger Data (creators of TimescaleDB) &lt;span style="text-transform: uppercase; margin-left: 4px; font-size: 0.9em;   color: #997 !important; padding: 1px 4px; "&gt;sponsor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/187992/rss" title="github.com" style=" color: #20824B;   "&gt;&lt;code&gt;actions/setup-node@v7&lt;/code&gt;: Install Node in GitHub Actions&lt;/a&gt;&lt;/span&gt; — The popular way to set up an Actions workflow with a version of Node brings changes supporting GitHub's cache-poisoning defenses, inspired by recent exploits. There are also &lt;a href="https://nodeweekly.com/link/187993/rss" style=" color: #20824B;   "&gt;new docs&lt;/a&gt; on publishing to npm with Trusted Publisher (OIDC).&lt;/p&gt;
  &lt;p&gt;GitHub &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;span&gt;🎬&lt;/span&gt; &lt;a href="https://nodeweekly.com/link/187995/rss" title="mediabunny.dev" style=" color: #20824B;   "&gt;Mediabunny: A Full Media Toolkit for JavaScript&lt;/a&gt;&lt;/span&gt; — It's been a year since we mentioned this library for reading/writing/converting media formats (MP4, MP3, &lt;a href="https://nodeweekly.com/link/187996/rss" style=" color: #20824B;   "&gt;and more&lt;/a&gt;). Since then, it's added Apple ProRes, HLS read/write, and &lt;a href="https://nodeweekly.com/link/187997/rss" style=" color: #20824B;   "&gt;a new &lt;code&gt;server&lt;/code&gt; package&lt;/a&gt; that makes it all even easier to use from Node.&lt;/p&gt;
  &lt;p&gt;Vanilagy &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/187998/rss" title="www.tinbase.dev" style=" color: #20824B;   "&gt;Tinbase: A Supabase-Compatible Backend in a Single Binary&lt;/a&gt;&lt;/span&gt; — Provides a local Supabase-like dev experience using a JS backend built atop &lt;a href="https://nodeweekly.com/link/187999/rss" style=" color: #20824B;   "&gt;PGlite&lt;/a&gt; and &lt;a href="https://nodeweekly.com/link/188000/rss" style=" color: #20824B;   "&gt;pg-mem&lt;/a&gt;. A sort of mini, local-only Postgres wrapped in the same APIs as Supabase, so &lt;code&gt;supabase-js&lt;/code&gt; works unchanged.&lt;/p&gt;
  &lt;p&gt;Sanket Sahu &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;

&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
  
  &lt;p&gt;&lt;span style="font-weight: 500 !important; font-size: 18px !important; color: #000;"&gt;&lt;a href="https://nodeweekly.com/link/188001/rss" title="neon.com" style=" color: #20824B;   "&gt;&lt;code&gt;@neon/sdk&lt;/code&gt;: Neon's New TypeScript Client Library&lt;/a&gt;&lt;/span&gt; — For users of the &lt;a href="https://nodeweekly.com/link/188002/rss" style=" color: #20824B;   "&gt;Neon&lt;/a&gt; Postgres platform to manage projects, branches, and databases from code.&lt;/p&gt;
  &lt;p&gt;Andre Landgraf (Neon) &lt;/p&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188003/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Nano ID 6.0&lt;/a&gt; – Generate tiny URL-friendly unique string identifiers. Now 4x faster and drops Node 18/20 support.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188004/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;c8 12.0&lt;/a&gt; – Istanbul-compatible coverage reports using Node's built-in V8 data. Node's test runner also has its own &lt;a href="https://nodeweekly.com/link/188005/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;experimental code coverage reporting&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188006/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;np 12.0&lt;/a&gt; – Sindre Sorhus's "better &lt;code&gt;npm publish&lt;/code&gt;" adds support for npm 12 and staged publishing.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188007/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;HyperExpress 7.0&lt;/a&gt; – A high performance Node server powered by uWebSockets.js.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188008/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Helmet 8.3&lt;/a&gt; – HTTP security header hardening for Express apps.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188009/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;node-auth0 6.0&lt;/a&gt; – One for &lt;a href="https://nodeweekly.com/link/188010/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Auth0&lt;/a&gt; users.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188011/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;ESLint 10.7&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em;"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0;"&gt;&lt;p&gt;📢  Elsewhere in the ecosystem&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style="font-size: 15px; line-height: 1.48em; padding: 0px 15px;"&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;TypeScript-using AWS SDK for JavaScript v3 users need to be aware of &lt;a href="https://nodeweekly.com/link/188012/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;changes to the library's support for TypeScript versions&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;GitHub's &lt;a href="https://nodeweekly.com/link/188013/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Dependabot is now giving packages a three-day default cooldown&lt;/a&gt; before opening version update PRs, though security fixes are exempt.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;TC39's 115th meeting takes place next week. &lt;a href="https://nodeweekly.com/link/188014/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Here's the agenda&lt;/a&gt;, including &lt;a href="https://nodeweekly.com/link/188015/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Await Dictionary&lt;/a&gt; aiming for Stage 3, plus &lt;a href="https://nodeweekly.com/link/188016/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Decimal&lt;/a&gt;, Import Defer, and &lt;a href="https://nodeweekly.com/link/188017/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Map.take&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;📁 &lt;a href="https://nodeweekly.com/link/188018/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Cloudflare has launched 'Drop'&lt;/a&gt;, a way to quickly get a site live by dropping a folder or ZIP onto a page, similar to &lt;a href="https://nodeweekly.com/link/188019/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;Netlify's service of the same name&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://nodeweekly.com/link/188020/rss" style=" color: #20824B; font-weight: 500 !important;   "&gt;plx&lt;/a&gt; is a transpiler for Postgres stored functions that converts JavaScript, PHP, Python, Ruby, and even COBOL, to Postgres's own PL/pgSQL language.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;table border=0 cellpadding=0 cellspacing=0 border=0 cellpadding=0 cellspacing=0&gt;&lt;tr&gt;&lt;td style=" font-size: 15px; line-height: 1.48em;"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;


&lt;/div&gt;
  &lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;




&lt;img src="https://nodeweekly.com/open/633/rss" width="1" height="1" /&gt;</description>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://nodeweekly.com/issues/633</guid>
    </item>
  </channel>
</rss>
