Carlos Fuentes

@metcoder.dev

Node.js Collaborator | Open Source Maintainer | Currently Auth0/Okta Just another guy playing to be a software engineer 🇳🇱 Amsterdam

Excited to share vlt 1.0 along with our hosted registries & ecosystem mirrors now GA! A drop-in npm replacement, built so nothing runs on your machine just because you typed install. → faster delivery → malware blocking at the registry layer → graph-native querying

🥁 𝐒𝐩𝐞𝐚𝐤𝐞𝐫 𝐀𝐧𝐧𝐨𝐮𝐧𝐜𝐞𝐦𝐞𝐧𝐭🎙️ Thrilled to have Filip Skokan on the NodeConf EU 2026 stage! He'll tell us the story of "𝐏𝐨𝐬𝐭-𝐐𝐮𝐚𝐧𝐭𝐮𝐦 𝐂𝐫𝐲𝐩𝐭𝐨𝐠𝐫𝐚𝐩𝐡𝐲 𝐢𝐧 𝐍𝐨𝐝𝐞.𝐣𝐬". 🎟️Don't miss it out, secure your tickets www.nodeconf.eu

Bild

Don't forget! Tickets are on sale now for @nodeconf.eu The conference is being held in beautiful Bologna, Italy on September 29th and 30th We've got a fantastic agenda, wonderful sponsors, and Italian food. The food alone is worth the trip.

Did you know Node.js is redesigning its API documentation? The new beta brings faster navigation, improved search, richer type information, better mobile support, version switching, and so much more. Learn more & preview today at nodejs.org/en/blog/anno...

Node.js — Check out the New Node.js API Documentation Preview

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

nodejs.org

Have been thinking recently about adding `diagnostics_channel` support to Piscina as part of v6, and possibly dropping the `histogram` support from the instance. Wondering if there are thoughts wether this can or cannot be a good idea or something appealing to be used. github.com/piscinajs/pi...

Use `diagnostics_channel` for Histograms · Issue #1116 · piscinajs/piscina

Goal Deliver metadata around pool performance using diagnostics_channel Proposal Instead of directly accessing pool performance metadata from Piscina#<histogram|utilization> provide it as a diagnos...

github.com

Using Ai as a “reference” sucks because it’s a dead end to learning and curiosity. There are more artists and writers whose work I can be inspired by and I can always dig deeper into them to learn more, but Ai flattens it to the result with no way to find out what parts were stolen from who.

Nearly 5 years of work later, I've successfully closed the Node.js TLS fingerprinting issue: github.com/nodejs/node/.... As of Node 26.4.0, it's possible to match most common TLS fingerprints in Node directly. I've published a library to do all the hard work here: github.com/httptoolkit/...

GitHub - httptoolkit/node-tls-impersonate: TLS fingerprint control within Node.js's normal networking APIs

TLS fingerprint control within Node.js's normal networking APIs - httptoolkit/node-tls-impersonate

github.com

A

High Severity Vulnerability fix for Piscina landed - github.com/piscinajs/pi... Prototype pollution upon constructor params and function params when executing a task can lead to arbitrary RCE. Fixed on: - >=5.2.0 - >=4.9.3 - >= piscina@6.0.0-rc.2

Prototype Pollution Gadget → RCE via inherited options.filename

## Summary Sister bug to the prototype-pollution-gadget I reported against pino earlier today; same root-cause class, different library. **Filing as a separate PSA because the fix lives in pisci...

github.com

Hello, World! Yes it's actually me - just a few years late to the party. Not sure exactly how much I will participate here; I'm still avoiding unnecessary scrolling and reducing my screen time. The best way to keep up with and contact me is at my personal site: ethanarrowood.com 🏔️⛷️🚀

Ethan Arrowood

Personal website for Ethan Arrowood. Head of Open Source Engineering at Harper. Node.js contributor. OpenJS Foundation and WinterTC collaborator. Breckenridge ski instructor.

ethanarrowood.com

I suppose, if the only thing you've ever experienced is chaos, SDD seems like an improvement, but believe me, it's not. In my experience, incremental feedback-driven approaches always yield better outcomes. 6/7

Everyone setting --max-old-space-size in Kubernetes is doing it wrong. Here's why your Node.js app keeps getting OOMKilled despite your "careful" heap tuning 🧵

The Axios npm compromise was a social engineering attack — not a leaked password, not a stolen key. The attacker hijacked the maintainer's *live browser session*. As far as npm was concerned, they *were* the maintainer. This exposes a dangerous gap in how we think about supply chain security. 👇

The hidden gem is that @nodejs.org majors and LTS cycles got WAY easier to understand: 2026 -> v26 2027 -> v27 2028 -> v28 ... Aall of them go LTS for 18 months meaning each major is supported for 2 years. The new graphic tells the best story here: nodejs.org/en/blog/anno...

nodejs release schedule chat. Bars for each major showing 6mo unstable, 6mo current, then 18mo LTS for each major. The best interpretation is that each yearly release is stable and supported for 2 full years.
Rafael Gonzaga | Node.js@rafaelgss.dev · 3mo ago

Node.js v26.0.0 is out 💚 Temporal API enabled by default, V8 14.6, Undici 8, and key deprecations as we keep modernizing the platform. Check it out nodejs.org/en/blog/rele...

Do not unleash your AI-powered bot into people's GitHub repos without asking first. If you do that on any of the repos I maintain, your bot is likely to get banned. (I've already banned a few).