
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
node-releases
Advanced tools
All data is located in data directory.
data/processed contains envs.json with node.js releases data preprocessed to be used by Browserslist and other projects. Each version in this file contains only necessary info: version, release date, LTS flag/name, and security flag.
data/release-schedule contains release-schedule.json with node.js releases date and end of life date.
npm install node-releases
// CommonJS
const envs = require('node-releases/data/processed/envs.json');
const schedule = require('node-releases/data/release-schedule/release-schedule.json');
// ESM (Node.js 22+)
import envs from 'node-releases/data/processed/envs.json' with { type: 'json' };
import schedule from 'node-releases/data/release-schedule/release-schedule.json' with { type: 'json' };
Releases are published automatically by a nightly GitHub Actions workflow whenever upstream Node.js release data changes. Publishing uses npm trusted publishing (OIDC, no long-lived tokens) and ships provenance attestations.
This package provides similar functionality to node-releases by offering data about Node.js versions. It includes release dates, version numbers, and more. However, it may not be as up-to-date or comprehensive as node-releases.
While not a direct alternative, nvm (Node Version Manager) allows you to manage multiple Node.js versions. It provides a way to switch between versions and download new ones, which indirectly gives you access to Node.js release information.
FAQs
Node.js releases data
The npm package node-releases receives a total of 134,641,373 weekly downloads. As such, node-releases popularity was classified as popular.
We found that node-releases demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.