
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
node-releases
Advanced tools
All data is located in data directory.
data/processed contains envs.json with node.js releases data preprocessed to be used by Browserslist and other projects. Each version in this file contains only necessary info: version, release date, LTS flag/name, and security flag.
data/release-schedule contains release-schedule.json with node.js releases date and end of life date.
npm install node-releases
// CommonJS
const envs = require('node-releases/data/processed/envs.json');
const schedule = require('node-releases/data/release-schedule/release-schedule.json');
// ESM (Node.js 22+)
import envs from 'node-releases/data/processed/envs.json' with { type: 'json' };
import schedule from 'node-releases/data/release-schedule/release-schedule.json' with { type: 'json' };
Releases are published automatically by a nightly GitHub Actions workflow whenever upstream Node.js release data changes. Publishing uses npm trusted publishing (OIDC, no long-lived tokens) and ships provenance attestations.
This package provides similar functionality to node-releases by offering data about Node.js versions. It includes release dates, version numbers, and more. However, it may not be as up-to-date or comprehensive as node-releases.
While not a direct alternative, nvm (Node Version Manager) allows you to manage multiple Node.js versions. It provides a way to switch between versions and download new ones, which indirectly gives you access to Node.js release information.
FAQs
Node.js releases data
The npm package node-releases receives a total of 0 weekly downloads. As such, node-releases popularity was classified as not popular.
We found that node-releases demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.