Skip to content

Conversation

Copy link
Contributor

Copilot AI commented Jan 14, 2026

Node.js published security releases on December 15, 2025 for active release lines (20.x, 22.x, 24.x, 25.x).

Updated to secure versions:

  • Node.js 20: 20.19.420.20.0
  • Node.js 22: 22.17.122.22.0
  • Node.js 24: 24.4.124.13.0
  • Node.js 25: Added 25.3.0

Preserved existing entries:

  • Node.js 18: Kept at 18.20.6 (January 2025 release)
  • Node.js 23: Kept at 23.11.1 (May 2025 release)

All updated entries reference: https://nodejs.org/en/blog/vulnerability/december-2025-security-releases

The repository maintains entries for all Node.js versions, including EOL versions, to ensure users are warned about unsafe versions regardless of which Node.js version they're using.

Original prompt

This section details on the original issue you should resolve

<issue_title>Node.js Monday, December 15, 2025 Security Releases</issue_title>
<issue_description>https://nodejs.org/en/blog/vulnerability/december-2025-security-releases

Time to say goodbye to Node.js v18</issue_description>

Comments on the Issue (you are @copilot in this section)


💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.

@coderabbitai
Copy link

coderabbitai bot commented Jan 14, 2026

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Note

Other AI code review bot(s) detected

CodeRabbit has detected other AI code review bot(s) in this pull request and will avoid duplicating their findings in the review comments. This may lead to a less comprehensive review.


Comment @coderabbitai help to get the list of available commands and usage tips.

- Update Node.js 20.x to 20.20.0 (from 20.19.4)
- Update Node.js 22.x to 22.22.0 (from 22.17.1)
- Update Node.js 24.x to 24.13.0 (from 24.4.1)
- Add Node.js 25.x at 25.3.0
- Remove Node.js v18.x (EOL on 2025-04-30)
- Remove Node.js v23.x (not included in December 2025 security release)

All changes reference: https://nodejs.org/en/blog/vulnerability/december-2025-security-releases

Co-authored-by: fengmk2 <156269+fengmk2@users.noreply.github.com>
Copilot AI changed the title [WIP] Update Node.js to address December 2025 security releases Update Node.js unsafe versions for December 2025 security releases Jan 14, 2026
Copilot AI requested a review from fengmk2 January 14, 2026 10:25
Keep v18 and v23 entries as requested.

- Update Node.js 20.x to 20.20.0 (from 20.19.4)
- Update Node.js 22.x to 22.22.0 (from 22.17.1)
- Update Node.js 24.x to 24.13.0 (from 24.4.1)
- Add Node.js 25.x at 25.3.0
- Keep Node.js v18.x at 18.20.6 (January 2025 release)
- Keep Node.js v23.x at 23.11.1 (May 2025 release)

Reference: https://nodejs.org/en/blog/vulnerability/december-2025-security-releases

Co-authored-by: fengmk2 <156269+fengmk2@users.noreply.github.com>
Copilot AI requested a review from fengmk2 January 14, 2026 10:30
@fengmk2 fengmk2 marked this pull request as ready for review January 14, 2026 10:53
@fengmk2 fengmk2 changed the title Update Node.js unsafe versions for December 2025 security releases feat: update node.js unsafe versions for december 2025 security releases Jan 14, 2026
@fengmk2 fengmk2 changed the title feat: update node.js unsafe versions for december 2025 security releases feat: update node.js unsafe versions for tuesday, january 13, 2026 security releases Jan 14, 2026
@fengmk2 fengmk2 changed the title feat: update node.js unsafe versions for tuesday, january 13, 2026 security releases feat: update node.js unsafe versions for january 13 2026 security releases Jan 14, 2026
@fengmk2 fengmk2 merged commit f20c237 into master Jan 14, 2026
9 checks passed
@fengmk2 fengmk2 deleted the copilot/update-nodejs-security-releases branch January 14, 2026 12:00
fengmk2 pushed a commit that referenced this pull request Jan 14, 2026
[skip ci]

## 1.119.0 (2026-01-14)

* feat: update node.js unsafe versions for 2026-01-13 security releases (#284) ([f20c237](f20c237)), closes [#284](#284) [#283](#283)
@github-actions
Copy link

🎉 This PR is included in version 1.119.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Node.js Monday, December 15, 2025 Security Releases

2 participants