
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
node-releases
Advanced tools
All data is located in data directory.
data/processed contains envs.json with node.js releases data preprocessed to be used by Browserslist and other projects. Each version in this file contains only necessary info: version, release date, LTS flag/name, and security flag.
data/release-schedule contains release-schedule.json with node.js releases date and end of life date.
npm install node-releases
// CommonJS
const envs = require('node-releases/data/processed/envs.json');
const schedule = require('node-releases/data/release-schedule/release-schedule.json');
// ESM (Node.js 22+)
import envs from 'node-releases/data/processed/envs.json' with { type: 'json' };
import schedule from 'node-releases/data/release-schedule/release-schedule.json' with { type: 'json' };
Releases are published automatically by a nightly GitHub Actions workflow whenever upstream Node.js release data changes. Publishing uses npm trusted publishing (OIDC, no long-lived tokens) and ships provenance attestations.
This package provides similar functionality to node-releases by offering data about Node.js versions. It includes release dates, version numbers, and more. However, it may not be as up-to-date or comprehensive as node-releases.
While not a direct alternative, nvm (Node Version Manager) allows you to manage multiple Node.js versions. It provides a way to switch between versions and download new ones, which indirectly gives you access to Node.js release information.
FAQs
Node.js releases data
The npm package node-releases receives a total of 154,813,940 weekly downloads. As such, node-releases popularity was classified as popular.
We found that node-releases demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.