NodeSource Weekly — July 28, 2026: Node.js Security, New API Docs & N|Solid AI DevTools
👋 Welcome to This Week’s Edition!
This edition brings together important security updates, new developer experiences, and community highlights from across the Node.js ecosystem. Here’s what we’ll cover:
🟢 The latest Node.js news, including July’s security releases and the beta launch of the redesigned Node.js API documentation.
🚀 New resources from NodeSource, including the N|Solid DevTools website, the open-source N|Solid Plugin for AI coding agents, and free expert guidance through the Node.js Upgrade Program.
🌎 Community highlights, celebrating the contributors behind the OpenJS ecosystem and looking ahead to NodeConf EU 2026 in Italy.
🤖 AI Corner, featuring Google’s latest Gemini models and DeepsecBench, Vercel’s benchmark for evaluating AI models in cybersecurity vulnerability detection.
Happy reading! 🚀

🟢 Last Week in Node.js
🔐 New Node.js security releases
The Node.js Project released security updates for the 26.x, 24.x, and 22.x release lines to address vulnerabilities with a maximum severity rating of HIGH.
All currently supported release lines were affected, and End-of-Life versions should also be considered vulnerable. Teams should update to the latest available version as soon as possible.
👉 Read the security announcement:
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases
📚 A new Node.js API documentation experience
The Node.js Project launched a beta preview of its redesigned API documentation, making it easier to find, navigate, and understand Node.js APIs.
The new documentation includes:
- Built-in API search
- Improved navigation and readability
- A responsive design for smaller screens
- ESM and CommonJS switching
- Structured access for AI tools through
llms.txt - Offline support and functionality without JavaScript
The content remains powered by the same Markdown files used by the existing documentation, while the experience has been rebuilt using the new doc-kit documentation generator.
👉 Explore the new documentation preview:
https://nodejs.org/en/blog/announcements/new-api-docs-beta

🚀 Featured from NodeSource
🤖 N|Solid DevTools for AI Coding Agents
We launched a new website dedicated to N|Solid developer tools, including the N|Solid Extension and the open-source N|Solid Plugin for AI coding agents.
👉 Explore the new website:
https://nodesource.com/products/nsolid/devtools

🤖 Bring production Node.js diagnostics to your AI agent
The N|Solid Plugin enables AI coding agents to access and analyze real runtime data, including:
- Heap snapshots
- CPU profiles
- Runtime telemetry
- Package security insights
- Application benchmarks
It works with Claude Code, Codex CLI, OpenCode, Antigravity CLI, Pi Agent, and other supported AI coding tools.
👉 Learn more about the N|Solid Plugin:
https://nodesource.com/blog/introducing-nsolid-plugin-ai-coding-agents
Get started with N|Solid DevTools:
VS Code Extension:
https://marketplace.visualstudio.com/items?itemName=nodesource-inc.nsolid
Windsurf, Cursor, and compatible editors:
https://marketplace.windsurf.com/extension/nodesource-inc/nsolid/1.0.2
N|Solid Plugin for AI coding agents:
https://www.npmjs.com/package/nsolid-plugin?activeTab=readme

🚀 Node.js Upgrade Program
Free Expert Help for Your Next Node.js Upgrade
Still running an End-of-Life version of Node.js?
The Node.js Upgrade Program, developed in partnership with the OpenJS Foundation, helps organizations migrate to supported LTS releases with free expert guidance from the Node.js ecosystem.
You can follow the step-by-step upgrade process yourself using the program's resources, or request assistance from the Upgrade Program team to help plan and execute your migration.
The program is designed to help organizations:
- ✅ Upgrade from End-of-Life Node.js versions
- ✅ Reduce security and compliance risks
- ✅ Plan migrations with confidence
- ✅ Modernize production applications
Participation is completely free for organizations.
🔗 Learn more and get started:
https://nodesource.com/products/nodejs-upgrade

🌎 Community & Events
💚 Celebrating the people behind the OpenJS ecosystem
Open source is built by people. The OpenJS Foundation contributor dashboard highlights the developers and organizations helping its projects grow through code, reviews, issues, documentation, and other community contributions.
Open source is built by people who consistently contribute code, review changes, fix bugs, improve documentation, and support the community.
A huge congratulations to everyone recognized among the top Node.js contributors—and a special shoutout to Ulises Gascón (@kom_256) and Rafael Gonzaga (@_rafaelgss) from NodeSource, who both ranked in the top 15 contributors over the past 12 months.
Their work continues to help move Node.js and the broader JavaScript ecosystem forward. We’re proud to have them on the NodeSource team. 💚
👉 View the OpenJS Foundation contributors:
https://insights.linuxfoundation.org/collection/details/ojsf/contributors?timeRange=past365days&start=2025-07-27&end=2026-07-27

🇮🇹 NodeConf EU 2026
NodeConf EU returns this September 29–30 in Italy.
If you're planning to attend one Node.js event this year, this is one of the best opportunities to meet maintainers, ecosystem contributors, and fellow Node.js developers.
🎟️ Tickets are still available:

🤖 AI Corner
Some AI resources we found particularly interesting this month:
⚡ Introducing Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber
Google introduced a new generation of Gemini models designed to make AI agents faster, more efficient, and more cost-effective.
Gemini 3.6 Flash improves coding, multimodal performance, and token efficiency, while Gemini 3.5 Flash-Lite is optimized for high-volume, low-latency workloads. Google also introduced Gemini 3.5 Flash Cyber, a specialized model for finding and fixing cybersecurity vulnerabilities.
👉 Explore the new Gemini models:
https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/
🛡️ DeepsecBench: Evaluating AI models for cybersecurity
Vercel introduced DeepsecBench, a benchmark designed to evaluate how effectively AI models can identify vulnerabilities in application code.
The benchmark compares models based on recall, precision, cost, and execution time, helping engineering and security teams understand which models offer the best balance of performance and cost for AI-powered security analysis.
👉 Explore the DeepsecBench results:
https://vercel.com/blog/deepsecbench-evaluating-model-performance-in-finding-cybersecurity-6O29ShaGQlHGINBsMEJSzR/21706b5aba

⚡ Stay Connected
The Node.js ecosystem never stands still—and neither do we.
Subscribe to stay up to date with future editions featuring the latest Node.js releases, AI-powered developer tools, observability, security, and community news.
Have questions, feedback, or ideas for a future edition? We'd love to hear from you.
📩 https://nodesource.com/pages/contact-us.html
📧 teffcode@nodesource.com
See you next month! 👋