NodeSource Weekly — Sept 29, 2026: ECMAScript Updates, AI Agents & NodeConf EU

👋 Welcome to This Week’s Edition!

Here’s what’s inside:

  • 🟢 Node.js & JavaScript Updates: New releases with Node.js 26.10.0 and Node.js 22.23.3, GitHub Actions moving away from Node.js 20, new investment in Node.js security from the OpenJS Foundation, and fresh ECMAScript progress with Iterator Chunking and Iterator Join reaching Stage 4.
  • 🚀 Featured from NodeSource: Our latest video walks through how to update Node.js on Windows using nvm-windows, the official installer, Winget, and Chocolatey, plus how to assess an upgrade before you start.
  • 🌎 Community & Events: NodeConf EU 2026 is happening now in Bologna, bringing the Node.js community together for two days of talks on performance, security, runtimes, observability, and production systems.
  • 🤖 AI Corner: The latest developments in coding agents, developer tooling, and safer agentic workflows, including new approaches to sandboxing AI agents working with local codebases.
  • 🛠️ Node.js Upgrade Program: Resources and expert support for teams moving from End-of-Life Node.js versions to supported releases.

Happy reading! 🚀


🟢 Last Week in Node.js

The Node.js and JavaScript ecosystem kept moving this week, with new runtime releases, changes across GitHub Actions, continued investment in Node.js security, and fresh progress at TC39.

  • Node.js 26.10.0 (Current) was released with several new runtime APIs, including crypto.parsePKCS12(), fs.openAsBlobSync(), a new SlidingWindowHistogram in perf_hooks, and new util.throttle() and util.debounce() utilities.

    Read the release notes →

  • Node.js 22.23.3 (LTS) landed with dependency and platform updates, including npm 10.9.9, Corepack 0.36.0, OpenSSL 3.5.8, Undici 6.28.1, ICU 78.3, and updated root certificates.

    Read the release notes →

  • GitHub Actions removed Node.js 20 support. JavaScript actions now run on Node.js 24, and the temporary opt-out for continuing to use Node.js 20 is no longer available. Action maintainers should migrate to runs.using: node24, while workflow users should make sure their actions are on versions that support the newer runtime.

    Read the announcement →

  • OpenJS Foundation launched its Security Stewardship Program, starting with Node.js. The initiative provides funding for vulnerability research, bug bounties, CVE coordination, security fixes, backports, and the maintainers responsible for keeping the ecosystem secure.

    Learn more →

JavaScript

  • ECMAScript iterators are getting more powerful. 🎉 At TC39, both Iterator Chunking and Iterator Join advanced to Stage 4.

Iterator Chunking introduces .chunks() and .windows() for processing iterator values in groups or overlapping windows:

[0, 1, 2, 3].values().chunks(2);
// [0, 1], [2, 3]

[0, 1, 2, 3].values().windows(2);
// [0, 1], [1, 2], [2, 3]

Iterator.prototype.join() makes it possible to turn an iterator directly into a string, similar to Array.prototype.join(), without converting it into an array first:

Iterator.from(["node", "js", "runtime"]).join(" ");
// "node js runtime"

Together, these additions continue expanding JavaScript's iterator APIs and make lazy data processing more expressive and convenient.


🚀 Featured from NodeSource

🪟 How to Update Node.js on Windows

Updating Node.js on Windows is easy. Making sure your application still works afterward is the part that requires more attention.

In our latest video, we walk through four ways to update Node.js on Windows — using nvm-windows, the official installer, Winget, and Chocolatey — plus the checks you should run before and after an upgrade.

We also show how to assess a Node.js upgrade before starting with:

npx @nodesource/upgrade

🎥 Watch the full video on YouTube →

👉 Read the guide →

🤖 Can AI Agents Safely Debug Production Node.js?

AI agents can already analyze code, trace performance issues, and suggest fixes. But production debugging requires something harder: runtime context and engineering judgment.

We explore what happens when AI agents gain access to real Node.js telemetry — including CPU, memory, and event loop data — and where human expertise still matters when a technically convincing diagnosis may be based on the wrong hypothesis.

The article also introduces our upcoming conversation with Matteo Collina and Bryce Baril on AI-assisted Node.js performance debugging, production incidents, flame graphs, memory leaks, and the evolving role of developers.

👉 Read the article →


🌎 Community & Events

🇮🇹 NodeConf EU 2026 is Happening Now

NodeConf EU 2026 is underway in Bologna, Italy, bringing the Node.js community together September 29–30 for two days and 24 talks focused on runtimes, performance, security, observability, architecture, and production systems.

Day one includes sessions on Node.js interoperability across JavaScript runtimes, debugging memory leaks, large-scale Node.js architecture at Supabase, and more.

Tomorrow, NodeSource’s Rafael Gonzaga, Principal Open Source Engineer and Node.js TSC member, joins Antoine du Hamel for:

“The New Node.js Release Model: Why Node 27 Changes Everything”

The session will explore why the Node.js release process is changing, the challenges of maintaining releases at ecosystem scale, and what the new model means for developers, maintainers, and companies building on Node.js.

👉 Explore the NodeConf EU 2026 program →


🤖 AI Corner

  • OpenAI introduced GPT-6 Sol and GPT-6 Luna. The new models bring improvements across coding, computer use, and agentic workflows while significantly reducing API costs compared with their GPT-5.6 predecessors. Both models are also now available in GitHub Copilot.

    👉 Explore GPT-6 Sol and Luna →

  • Anthropic launched Claude Opus 5.5, with a strong focus on long-running agentic coding and large software engineering tasks. Anthropic says the model is over 30% faster than Opus 5 and costs around 40% less on typical workloads, with improvements in tool use and resistance to prompt injection. It is also available through GitHub Copilot.

    👉 Read about Claude Opus 5.5 →

  • GitHub added local sandboxing to the Copilot app. Developers can now restrict an agent's access to files, network resources, and credentials on a per-project basis, reducing the potential impact of unintended commands when agents operate directly against a local codebase.

    👉 Learn about local sandboxing →


🚀 Node.js Upgrade Program

Free Expert Help for Your Next Node.js Upgrade

Still running an End-of-Life version of Node.js?

The Node.js Upgrade Program, developed in partnership with the OpenJS Foundation, helps organizations migrate to supported LTS releases with free expert guidance from the Node.js ecosystem.

You can follow the step-by-step upgrade process yourself using the program's resources, or request assistance from the Upgrade Program team to help plan and execute your migration.

The program is designed to help organizations:

  • ✅ Upgrade from End-of-Life Node.js versions
  • ✅ Reduce security and compliance risks
  • ✅ Plan migrations with confidence
  • ✅ Modernize production applications

Participation is completely free for organizations.

🔗 Learn more and get started:
https://nodesource.com/products/nodejs-upgrade


⚡ Stay Connected

The Node.js ecosystem never stands still—and neither do we.

Subscribe to stay up to date with future editions featuring the latest Node.js releases, AI-powered developer tools, observability, security, and community news.

Have questions, feedback, or ideas for a future edition? We'd love to hear from you.

📩 https://nodesource.com/pages/contact-us.html
📧 teffcode@nodesource.com

See you next month! 👋

The NodeSource platform offers a high-definition view of the performance, security and behavior of Node.js applications and functions.

Start for Free