-
-
Notifications
You must be signed in to change notification settings - Fork 6.5k
Description
https://nodejs.org/en/blog/vulnerability/december-2025-security-releases contains a link "January Security Release is available" which links to itself. This is confusing.
The advisory there also appears to be prepended to the previous pre-announcement, as it contains a "Summary" section "The Node.js project will release new versions of the 25.x, 24.x, 22.x, 20.x releases lines on or shortly after, Monday, December 15, 2025 in order to address:[...]"
I'd suggest to keep the December announcement on its own URL, place the January announcement on its own page (january-2025-security-releases) and then link from the December announcement to the January announcement.
(Having the link to the announcement posted to the nodejs-sec mailing list instead of just a short "new advisory just dropped" style message would also make it easier for users to get the details. Likewise, sending the full details to oss-security would also be a good way to ensure the information is shared widely.)
Metadata
Metadata
Assignees
Labels
Type
Projects
Status