Rafael Gonzaga | Node.js's Avatar

Rafael Gonzaga | Node.js

@rafaelgss.dev

Node.js Technical Steering Committee member

726
Followers
56
Following
96
Posts
03.11.2024
Joined
Posts Following

Latest posts by Rafael Gonzaga | Node.js @rafaelgss.dev

Preview
Node.js — New HackerOne Signal Requirement for Vulnerability Reports Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

We have made our HackerOne policies even more strict. Now, if you don't have any Signal, you shouldn't be able to report through HackerOne. We advise you to contact any of the Security Release Stewards via OpenJS Slack.

nodejs.org/en/blog/anno...

19.02.2026 19:40 👍 8 🔁 1 💬 0 📌 0
Preview
Node Congress Want to master Fullstack: JS Backend, DevOps, Architecture? Join Node Congress on March 26-27, Online! Learn from industry professionals and community members, exchange ideas, interact, and collaborat...

My first talk of 2026 can now be shared!

I will join NodeCongress to present The State of Node.js Security

nodecongress.com#person-rafae...

30.01.2026 13:45 👍 3 🔁 0 💬 0 📌 0
Preview
Node.js — OpenSSL Security Advisory Assessment, January 2026 Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

🚨 Node.js assessment of the recent OpenSSL Security Release

TL;DR: We'll update OpenSSL versions through a regular release process.

nodejs.org/en/blog/vuln...

29.01.2026 12:53 👍 6 🔁 2 💬 0 📌 0
Preview
Node.js — New HackerOne Signal Requirement for Vulnerability Reports Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

We have increased the barrier to submit reports through HackerOne due to the amount of low-quality submissions we have received recently.

Please, see: nodejs.org/en/blog/anno...

22.01.2026 13:20 👍 6 🔁 1 💬 0 📌 0

This release contains a bunch of PRs I recently submitted to mark features I contributed to as stable/release candidate. Here is a thread about them 🧵:

19.01.2026 18:42 👍 53 🔁 8 💬 2 📌 1

Node.js v25.4.0 is out! 💚

• require(esm) now stable and a new CLI flag: --require-module
• http setGlobalProxyFromEnv() added
• Multiple APIs promoted to stable (heapsnapshot, build snapshot, v8.queryObjects)
• Root CAs updated to NSS 3.117

More in: nodejs.org/en/blog/rele...

19.01.2026 18:01 👍 36 🔁 7 💬 0 📌 2
Preview
Node.js — Thursday, January 8, 2026 Security Releases Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

Additionally, releasing on Tuesday rather than Friday helps ensure that security updates are available during regular business hours across all time zones, particularly for our users in the Asia-Pacific region.

nodejs.org/en/blog/vuln...

08.01.2026 21:50 👍 6 🔁 1 💬 0 📌 0
Preview
Node.js — Thursday, January 8, 2026 Security Releases Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

🚨Our team has decided to postpone the release to Tuesday, January 13th, 2026. This additional time will allow us to properly test all backports and re-run CITGM to ensure the highest quality for our users.

08.01.2026 21:50 👍 17 🔁 5 💬 1 📌 0

Node.s sec release

We are doing our best. We are ensuring test passes on all platforms and all active release lines (v20, v22, v24 and v25) - and they aren't currently.

Unfortunately, we don't have an ETA for that, and it's likely that this security release will be postponed one more time. Sorry.

08.01.2026 20:53 👍 7 🔁 4 💬 0 📌 0

That's how it works in Brazil. Holidays extend until the Carnival!

05.01.2026 16:20 👍 4 🔁 0 💬 1 📌 0
Video thumbnail

Oh hi. 👋 We're back with the latest Security Snapshot that covers how to publish to npm safely and with ease. ✨

@rafaelgss.dev breaks down why local publishing with 2FA gives you the safest setup right now.

05.01.2026 16:04 👍 8 🔁 5 💬 0 📌 0

* Add V8 code elimination detector - This should warn you when it believes your code is being JIT eliminated and the results aren't reliable.

* Add t-test feature - It enables a statistical significance test to compare how reliable your results are

And more!

17.12.2025 21:29 👍 3 🔁 0 💬 0 📌 0
Preview
Release v0.14.0 · RafaelGSS/bench-node 0.14.0 (2025-12-17) Features add dce detection plugin (#131) (2e2a6be) add t-test mode for statistical significance testing (#133) (53e20aa) Narrow the bar display by another couple of characters ...

New release of bench-node v0.14.0! Two important features were released:

github.com/RafaelGSS/be...

17.12.2025 21:29 👍 2 🔁 0 💬 1 📌 0
Post image

Right on time! Lovely @openjsf.org

15.12.2025 21:50 👍 8 🔁 0 💬 1 📌 0
Preview
Releasing Node.js v25.0.0! - rafaelgss on Twitch rafaelgss went live on Twitch. Catch up on their Software and Game Development VOD now.

Want to dive in further? Check out Rafael’s release of @nodejs.org 25: twitch.tv/videos/25925...

25.11.2025 19:06 👍 4 🔁 2 💬 0 📌 0
Video thumbnail

SEMVER MAJORS ARE BORING 🚨

Major releases mostly bring breaking changes, not shiny new features. The fun stuff? That’s hiding in the minors.

@rafaelgss.dev talks about why you should follow the minor releases in our latest JavaScript Security Snapshot.

25.11.2025 19:06 👍 11 🔁 2 💬 1 📌 0

I should get back to this platform. I’ve scrolled it for like 5 minutes and I found many interesting topics that I don’t see in one week of X.

22.11.2025 03:16 👍 24 🔁 0 💬 4 📌 0
Preview
JavaScript in Depth - James M. Snell Explore the inner workings of the world’s most popular programming language and enjoy the power and control that comes only from deep knowledge! In JavaScript in Depth, JavaScript and Node legend Jame...

ok so... I'm writing a book. It's called JavaScript In Depth (www.manning.com/books/javasc...) ... the first four chapters are available by Manning.

This has been a difficult project and will continue to be so. The reason is that it isn't a How To book that focuses only on how to use the langauge

20.11.2025 21:37 👍 30 🔁 5 💬 3 📌 0
Video thumbnail

Before automated workflows, releasing @nodejs.org meant 20 manual steps. Now it’s one command. 👀

@ulisesgascon.com and @rafaelgss.dev share how the Node.js build team went from a rack of Raspberry Pis in someone’s garage to full release automation.

👉Build Team on GitHub: github.com/nodejs/build

20.11.2025 15:29 👍 18 🔁 6 💬 0 📌 1

Live now!

14.11.2025 16:58 👍 1 🔁 0 💬 0 📌 0

It was great working with you on this! As much as I dislike that we had to do this work, I think it is important that we did it so there is a thorough and accurate resource about the current state of things.

14.11.2025 16:56 👍 2 🔁 1 💬 0 📌 0
Preview
Publishing More Securely on npm: Guidance from the OpenJS Security Collaboration Space | OpenJS Foundation The OpenJS Security Collaboration Space has been working closely with GitHub’s npm team to understand how new security features affect projects and maintainers, especially as threats and tools keep ev...

With npm supply chain attacks on the rise, secure publishing practices are becoming a pressing concern for anyone maintaining npm packages. ⚠️

We've released updated guidance to help maintainers reduce exposure, strengthen release processes, and protect the ecosystem: openjsf.org/blog/publish...

14.11.2025 16:02 👍 29 🔁 12 💬 1 📌 1

Thanks for your hard work on this @notwes.bsky.social

14.11.2025 16:53 👍 4 🔁 0 💬 1 📌 0
Video thumbnail

Too many @nodejs.org users are running old versions 😬 The team is exploring changes to the release schedule to fix that.

@rafaelgss.dev shares all the details in our latest JavaScript Security Snapshot.

Be a part of the conversation on releases: github.com/nodejs/lts-s...

13.11.2025 17:45 👍 16 🔁 5 💬 0 📌 0
Video thumbnail

Ever wonder why @nodejs.org drops new versions like clockwork? Here’s the scoop. ⏱️

@rafaelgss.dev shares all the details about the Node.js release schedule in our new series, JavaScript Security Snapshot.

11.11.2025 15:28 👍 25 🔁 6 💬 2 📌 0

Done

30.10.2025 13:42 👍 5 🔁 1 💬 0 📌 0

I’ll ping the team

29.10.2025 02:43 👍 1 🔁 0 💬 0 📌 0

i’m starting to get that “this word is weird now” feeling from hearing so many sentences like “releasers releasing releases” at the @nodejs.org collab summit

17.10.2025 16:18 👍 7 🔁 1 💬 0 📌 0
picture of a group exercise

picture of a group exercise

collab summit sign in the hallway

collab summit sign in the hallway

Starting the day at the Node.js Collab Summit #nodejs #javascript

17.10.2025 13:36 👍 20 🔁 2 💬 1 📌 0
Video thumbnail

Introducing 🥁🥁🥁 our JavaScriptLandia award recipients for this year!

Beyond building new features, our recipients guide others, maintain essential systems, document the hard parts, and strengthen the community every step of the way. 💙

Read more about our honorees here: hubs.la/Q03NQvx10

16.10.2025 14:19 👍 17 🔁 6 💬 0 📌 4