Profile avatar
ruyadorno.com
Node.js TSC • Founder Engineer at @vlt.sh • Previously Google, GitHub, npm Inc. Opinions are my own. 📍 Montreal 🇨🇦
414 posts 1,570 followers 789 following
Regular Contributor
Active Commenter

🚀 Help shape the future of Node.js! If you're a contributor or maintainer, the Next 10 Survey is your chance to make your voice heard. 🗳️ Take the survey + make a difference: linuxfoundation.research.net/r/2025nodene...

📅 Reminder: Node.js 18 is scheduled to reach End-of-Life on April 30, 2025. We recommend that you update to Node.js 20 or 22 as Node.js 18 will no longer receive security updates once it reaches End-of-Life.

🚀 Node.js v22.15.0 is out — with nearly 350 commits! Highlights: 🧪 assert upgrades 🔐 system cert support 🌐 TLSA record queries 💾 zstd in zlib 🧠 v8 heap stats Huge thanks to @rafaelgss.dev for prepping the release + all the heavy lifting! 🙌 nodejs.org/en/blog/rele...

We just bought a company. Why? Because vulnerability scanning is fundamentally broken. And I’m tired of pretending it’s fine. We acquired Coana, the best reachability analysis engine on the planet.

In partnership with @socket.dev we're bringing Socket Package Alerts to your local dependencies when using the vlt client. Introducing Package Insight Selectors, a powerful addition to our Dependency Selector Syntax that helps you understand and secure your node_modules folder. #js #nodejs #vlt

Node.js v20.19.1 is out! 🥳 Some highlights include: - Updated Undici to v6.21.2 - Bumped c-ares to v1.34.5 - Restored DNS query cache TTL - Minor doc, test, and tooling improvements Full changelog: nodejs.org/en/blog/rele...

vlt client: query package data for security information (provided by Socket) @ruyadorno.com @vlt.sh blog.vlt.sh/blog/insight... #ECMAScript #JavaScript

🚀 The @vlt.sh team just launched real-time dependency analysis powered by Socket! Developers can now explore supply chain risks directly in their graph, with rich security metadata from Socket built in. More on the integration → socket.dev/blog/vlt-lau... #JavaScript

We're excited to announce the new Insights Selectors to the @vlt.sh's Dependency Selector Syntax. This new information allows you to query packages based on a variety of security-focused metadata powered by @socket.dev! ⚡️

Plus que 2 jours avant notre mini-conférence gratuite sur Node.js à Paris, le 4 avril! ☕ Petit-déjeuner & déjeuner offerts 📍 Lieu : Auditorium Sanofi, Paris 🔗Inscription (gratuite): lu.ma/node-and-con... #nodejsparis

Node.js 23.11.0 is out, likely the last 23.x release. It adds `process.execve`, improvements to `assert.partialDeepStrictEqual`, and much more – full change log and download links can be found at nodejs.org/en/blog/rele...

Are you in Paris next week? 🇫🇷 If you are & you use @nodejs, I hope to see you at our free mini-conference, Node & Conquer! lu.ma/node-and-con...

New @nodejs.org 18.20.8 release. This is the last planned release of Node.js 18 before it reaches End-of-Life at the end of April 2025. You are recommended to update to Node.js 20 or 22 to continue to receive security updates after that date. nodejs.org/en/blog/rele...

The Node.js TSC officially voted to stop distributing Corepack. Future Node.js releases (i.e. 25+) won’t include it, but it will remain available separately. socket.dev/blog/node-js...

📌 Just hours ago, the Node.js TSC officially voted to stop distributing Corepack. Future Node.js releases (i.e. 25+) won’t include it, but it will remain available separately. socket.dev/blog/node-js... #nodejs #javascript

Node.js will no longer ship corepack starting from v25. This might make a lot of people sad, but it was a problem in terms of project maintainance. 🧵 github.com/nodejs/TSC/p...

This thing is so useful. Especially for security - ensuring the published package is actually what exists in the source

Node v23.10.0 is out 🎉 This release includes - --experimental-config-file aka node.config.json - changed the default glob for .ts files when running tests nodejs.org/en/blog/rele...

Node.js v20.19.0 is out 🤩 This is a special minor release ✨ Although v20 is in maintenance mode, meaning only patch releases are expected, an exception was made to backport require(esm) due to its importance and impact on the ecosystem. Full changelog 👇 nodejs.org/en/blog/rele...