
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
Prerequisites (Unix only):
* GCC 4.2 or newer
* G++ 4.2 or newer
* Python 2.6 or 2.7
* GNU Make 3.81 or newer
* libexecinfo (FreeBSD and OpenBSD only)
Unix/Macintosh:
./configure
make
make install
If your python binary is in a non-standard location or has a non-standard name, run the following instead:
export PYTHON=/path/to/python
$PYTHON ./configure
make
make install
Prerequisites (Windows only):
* Python 2.6 or 2.7
* Visual Studio 2010 or 2012
Windows:
vcbuild nosign
You can download pre-built binaries for various operating systems from http://nodejs.org/download/. The Windows and OS X installers will prompt you for the location in which to install. The tarballs are self-contained; you can extract them to a local directory with:
tar xzf /path/to/node-<version>-<platform>-<arch>.tar.gz
Or system-wide with:
cd /usr/local && tar --strip-components 1 -xzf \
/path/to/node-<version>-<platform>-<arch>.tar.gz
Unix/Macintosh:
make test
Windows:
vcbuild test
make doc
man doc/node.1
Intl (ECMA-402) support:Intl support is not enabled by default.
This option will build with "small" (English only) support, but
the full Intl (ECMA-402) APIs. With --download=all it will
download the ICU library as needed.
Unix/Macintosh:
./configure --with-intl=small-icu --download=all
Windows:
vcbuild small-icu download-all
The small-icu mode builds
with English-only data. You can add full data at runtime.
Note: more docs are on the wiki.
With the --download=all, this may download ICU if you don't
have an ICU in deps/icu.
Unix/Macintosh:
./configure --with-intl=full-icu --download=all
Windows:
vcbuild full-icu download-all
:-(The Intl object will not be available.
This is the default at present, so this option is not normally needed.
Unix/Macintosh:
./configure --with-intl=none
Windows:
vcbuild intl-none
pkg-config --modversion icu-i18n && ./configure --with-intl=system-icu
You can find other ICU releases at
the ICU homepage.
Download the file named something like icu4c-**##.#**-src.tgz (or
.zip).
Unix/Macintosh: from an already-unpacked ICU
./configure --with-intl=[small-icu,full-icu] --with-icu-source=/path/to/icu
Unix/Macintosh: from a local ICU tarball
./configure --with-intl=[small-icu,full-icu] --with-icu-source=/path/to/icu.tgz
Unix/Macintosh: from a tarball URL
./configure --with-intl=full-icu --with-icu-source=http://url/to/icu.tgz
Windows: first unpack latest ICU to deps/icu
icu4c-##.#-src.tgz (or .zip)
as deps/icu (You'll have: deps/icu/source/...)
vcbuild full-icu
FAQs
test Package
We found that derekjs demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.