Sponsor of the Day:
Jerkmate
https://openjsf.org/blog/openjs-security-checkpoint-2025-so-far
OpenJS Security Checkpoint: 2025 So Far | OpenJS Foundation
From vulnerability patching to release automation to better governance processes, here’s what’s been happening behind the scenes from January through June.
openjs securitycheckpoint2025farfoundation
https://openjsf.org/blog/openjs-security-update-oct-2025
OpenJS Security Update: October 2025 | OpenJS Foundation
From new threat modeling practices to ecosystem-wide coordination, npm security discussions, and major Node.js security enhancements, this update recaps the...
update october 2025openjs securityfoundation
https://openjsf.org/blog/openjs-security-update-marchapril-25
OpenJS Security Update: March–April 2025 | OpenJS Foundation
From critical security updates to improved automation, policy updates, and major release planning, this post covers the highlights from March and April 2025.
openjs security2025 foundationupdate
https://openjsf.org/blog/node-js-security-progress-report-17-reports-closed
Node.js Security Progress Report – 17 Reports Closed | OpenJS Foundation
In June, we saw all of our Node.js security metrics trending in the right direction.
node js securityprogress reportopenjs foundation17reports
https://openjsf.org/blog/openjs-security-annual-report-2025
OpenJS Foundation Security Program: Annual Report 2025 | OpenJS Foundation
The OpenJS Foundation, supported by generous funding from Alpha-Omega, made significant progress strengthening security for Node.js and the wider OpenJS...
program annual reportopenjs foundationsecurity2025
https://openjsf.org/blog/lodash-security-overhaul
Lodash Rolls Out Major Security Overhaul | OpenJS Foundation
With the release of Lodash 4.17.23 and the publication of CVE-2025-134655, the project is making visible progress in strengthening its security posture.
major securityopenjs foundationlodashrollsoverhaul
https://openjsf.org/blog/node-js-security-progress-report-improving-security-processes
Node.js Security Progress Report – Improving Security Processes | OpenJS Foundation
October saw steady improvements to Node.js security in multiple areas, assisted by the Open Source Security Foundation (OpenSSF) grant to the OpenJS Foundation.
node js securityprogress reportopenjs foundationimprovingprocesses