Dev News Daily ENDE

Node.js 26.11: Buffer.stringLength, --process-timeout and Alpine at tier 2

Node.js 26.11.0, a Current-line release, shipped on 7 October with a long list of minor features. A few hours later 26.11.1 followed, whose only changes are three reverts of the documentation-build move to the new docs redesign — so for application code the two are the same release.

What is new for application code.

  • Buffer.stringLength() (Matteo Collina) and buffer.isLatin1() (James M Snell) — size and encoding checks without allocating a buffer first.
  • http.isValidHeaderName() and isValidHeaderValue() — the validators Node uses internally, now public, so frameworks can reject bad headers before calling setHeader and catching the throw.
  • --process-timeout=N — a process-level timeout set from the command line; useful for scripts and CI jobs that must not hang.
  • process.ref() / process.unref() graduate to stable.
  • HTTP/2 gets a connectionWindowSize option (Tim Perry) for tuning connection-level flow control.
  • perf_hooks histograms gain snapshot() and diff(), can now record 0, and monitorEventLoopDelay() no longer truncates its resolution.
  • Heap profiles expose size and count.
Node.js 26.11: Buffer.stringLength, --process-timeout and Alpine at tier 2
Node.js 26.11: Buffer.stringLength, --process-timeout and Alpine at tier 2 — Dev News Daily

One rename to watch. The node:sqlite change list includes "rename DatabaseSync and StatementSync" as a semver-minor change. node:sqlite is still experimental, and the release notes list the rename without spelling out the new names in the notable-changes line, so anyone already using the synchronous API should read the module's docs for 26.11 before upgrading and check for deprecation warnings.

Platform and crypto. Alpine Linux is promoted to tier 2 support — relevant to the many container images built on musl. Under the hood, Filip Skokan's Web Crypto series tightens a dozen edge cases (PBKDF2 iteration limits, duplicate key usages, actual RSA modulus lengths, cSHAKE and KMAC from the crypto backend), and synchronous random-number generation is faster.

Current-line releases are not for production fleets on LTS; for teams testing ahead, 26.11.1 is the build to install.

Sources: Node.js blog, "Node.js 26.11.0 (Current)", 7 October 2026 — https://nodejs.org/en/blog/release/v26.11.0 ; "Node.js 26.11.1 (Current)" — https://nodejs.org/en/blog/release/v26.11.1

Written by Victoria Shinder.