Skip to content

January Security Release on December URL #8543

@jschauma

Description

@jschauma

https://nodejs.org/en/blog/vulnerability/december-2025-security-releases contains a link "January Security Release is available" which links to itself. This is confusing.

The advisory there also appears to be prepended to the previous pre-announcement, as it contains a "Summary" section "The Node.js project will release new versions of the 25.x, 24.x, 22.x, 20.x releases lines on or shortly after, Monday, December 15, 2025 in order to address:[...]"

I'd suggest to keep the December announcement on its own URL, place the January announcement on its own page (january-2025-security-releases) and then link from the December announcement to the January announcement.

(Having the link to the announcement posted to the nodejs-sec mailing list instead of just a short "new advisory just dropped" style message would also make it easier for users to get the details. Likewise, sending the full details to oss-security would also be a good way to ensure the information is shared widely.)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    📋 Backlog

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions