DEVWorld 2026

Matteo Collina - The Alleged 'End' of Node.js is Much Ado About Nothing

24:34 · 07 May 2026 – 08 May 2026 · YouTube

About this talk

This talk, presented by Matteo Collina, a member of the Node.js technical steering committee and CTO of Platformatic, addresses the misconception that Node.js is in decline. He emphasizes that contrary to popular belief, Node.js is thriving, citing its extensive usage and the vast number of downloads from the NPM ecosystem. Collina discusses various aspects of Node.js, including the importance of keeping up with updates and the notable challenges related to maintaining older versions with known vulnerabilities. He highlights the ongoing developments in the Node.js framework, such as ESM, multithreading capabilities, and integration of features like Fetch API and native WebSocket support. Additionally, he encourages community involvement and collaboration to improve the project's sustainability and innovation.

Full transcript

Is it actually true? Is Node.js actually in decline? Well, who else could tell us that better is someone who is part of the Node.js technical steering committee, the CTO of Platformatic, the author of Fastify, Pino, and other amazing open source libraries. He came here all the way from Italy. So, please give it up for the wonderful Matteo Collina, everybody. >> Hi, everyone. Let's plug in. Okay, here

we go. And magical magical. Here we go. Okay. Everyone. To the people inside, to the people outside, to the people sitting there in the corner. Hello. So, um couple of things about me. Um Okay. Hi, couple of things about me. I have been This light is very bright. Anyhow, um remember I'm vice chair of the Node.js technical steering committee. I'm also a board member of the Open

JS Foundation. It's the foundation that own that hold the copyrights and handles all the projects that you probably love most of the time. Created a few things like Fastify, Pino, worked as a consultant for a few years, then decided to try the startup world. Here I am, founded Platformatic in 2022. And we are still around, so I don't know, maybe we're doing something good. I also have

a newsletter if you want to check it out. So, cool. Um so, what are we talking today? Well, oh, one more thing. You're using my software, so right now one of my helpers will come around and collect some some change, spare change. I have 30 billion downloads on NPM. You're not paying for it at all. So, you should Okay, so this is the time of the offer.

Okay, so we are here to talk about these two sentences. Something XYZ will destroy Node.js and XYZ that XY Okay, whatever will flip the default beacon for JavaScript runtime from Node.js. Cool. this talk is born because of every single person around asked me one question all the time. And is Node.js dead yet? this talk more or less exist for this specific reason. So, I'm trying to give

an answer to this question. You may You may know the answer, but whatever. Anyway, no. The answer is no. It's not dead. Okay? But I'm going to also to tell you a secret. If you want to destroy another technology, okay? Well, okay. There is one technology that is born in 1959 that is still on that is on the rise. Do you know what it is? COBOL. COBOL

is on the rise, okay? So, you know, you after you reach a certain level of penetration, it's not you can destroy anything. Okay? Things become legacy over legacy over legacy forever, probably, but you you know, the destiny of successful technologies is to become the legacy of the next of the following generation. Okay? Not that, you know, COBOL is just under Rust. Okay? I don't know if And

over Ruby, which I don't know. You can decide. then let's talk about jQuery. How many of you wrote some jQuery this this this week? Well, it's still the most popular thing you can run on the web. By the way, jQuery is another open JS Foundation project. So, you know, if we keep that thing up, you don't you don't want to know how much it cost or how

much traffic that jQuery CDN generates every year because it's it's it's Okay? Anyhow, Bootstrap is there, okay? It's bigger than React. Sorry for for all of you that Um so, we're here to talk about Node.js, not these other technologies, okay? I made a few examples to say that, you know, maybe, you know, you don't want to destroy anybody. You want to build something else. Okay? Uh Node.js

is the most popular uh technology according to Stack Overflow, followed very shortly by Okay? Fine. Also, we had a massive explosion on the NPM ecosystem. One thing one problem that the Node.js plus NPM combo solved was uh reusing software at scale, and now it's a black hole. But, look, it's it's what it is, okay? Note that um one of my the modules I maintain, which is the

fourth most downloaded module on NPM, which is called readable-stream, you probably don't want to use it, by the way. Don't, okay? Uh it's being downloaded like it's a G, okay? It's not a billion. It's it's it's it's a G. Sorry. Anyhow, yeah. Um um uh Half of uh Node.js downloads are header files, okay? So, let's talk Oh, sorry. Let's talk a little bit about Node. Uh Node

uh downloads uh most Node downloads are header files, okay? What does it means? Half of them then are header files. Uh well, also, you see that there was a spike of downloads. We changed how the we count the numbers, so that we we were We're some in the past, so. But, half of them are header files. The others are Windows, Linux, and Mac. Um surprising surprise, um

header files are used to compile native addons. So, whenever you do npm install and you need to uh install a binary package, it downloads the header files and it compiles the thing on your machine. So, this means the people that are using compiling things on their machine on uh typically on CI or what whatever every time. Amazing, okay? Now, the important the one thing that you need

to know is um there's a lot of downloads from Windows. Uh yeah, I talked about this, okay? Um there's a massive amount of downloads from Windows. You don't even understand that I this is impressive to say, okay? So, Windows, lot of Linux, of course, CI, probably. And a lot of users, but you know, Windows. More than Mac. Would you have guessed? You know, I am Um yeah,

so Node.js is a 30 million monthly download on npm, the binary. And it grow to 60 for 60 million monthly downloads on 2024. Okay? It's growing. It's used everywhere, more or less. Now, big problem is Node 16, 14, and 12 that have known vulnerabilities are still massively downloaded. look at this. Node 14, it's still here. It's close to downloaded to 10 million times per month. I like

What I Are Are anybody here working on Node 14 today? Node 16? Uh okay, now you see somebody. Okay, you are in good company, anyhow. You're not updating Node, okay? The problem most of the time is not that Node is is is not progressing, is that you're not updating it. So, you probably should. you're also putting yourself at risk. So, there are vulnerabilities and stuff like that.

Now, you need to know that there is a thing called long-term support schedule, which is the most important thing that you need to know about Node.js, which shows that, you know, main is our uh GitHub main head, tip of tree, okay? Then, we have things that are either in maintenance or LTS active or just, you know, dead. Okay? Um you don't want to use the dead ones,

okay? The active lines catch uh continuous backports from tip of tree of uh fixes and things like that. Maintenance, when they are in maintenance, they only get, I don't whenever we want to do a release, you get a release and security fixes. Um so, most people most team update their Node.js version every two release. So, you're using Node 22, now you're using Node 20 They move from

Node 20 to Node 20 You don't move You move from Node 18 to Node 22, you skip Node 20 most of the time. I don't know why. This is what is happening. So, uh updating it every year is probably too much work. So, you need to update it every You update it all every 2 years, fine. It's also a very good strategy, by the way. You should

use this strategy because I recommend it. Um now, organization activity, this is a little bit of a sample. Uh we got some stars, okay? GitHub stars. We got a lot of pull requests. Uh I don't know, 5,000 pull requests in a year. I don't know. Is this Does this sound bad, by the way? How many are 5,000 pull requests in a year? Can you review all of

it? Okay, anyhow. Uh we got a little bit less reviews. So, basically, we are overwhelmed by the 5,000 PRs. We need more volunteers. We'll talk about that later. Uh Lot of issues. A lot of comments and pushes in the organization in the project. So, you can see it's we do a lot of comments and a few and blah blah blah. Pull requests, pretty good, pretty solid, going

up while it's stable more or less. The total number is is growing, but of course it cannot go down, right? So, we work hard to keep you all safe. uh had a lot of securities as a lot of security submissions, typically um between uh 10 and 20 10 and 30 per quarter. It's a lot. Okay. Most of the time they are uh completely bogus, okay? And nobody

see ever see the white spam. But even if they spam, you need to take it and evaluate and so on, otherwise they will claim a CVE to whatever uh external organization they can get a CVE from. So, you need to validate and and verify that those things are legit. Most of the time they are completely bogus. Okay. So, But anyhow, it's a lot of work, okay? Um

the first time after first response is usually very low. We typically triage them in a in a day, more or less. Which typically means we take a look in a day and we say it's spam. But sometimes it takes us longer because they are actually hard things to verify. Like some bugs are very very Some vulnerabilities are very odd sometimes. And you need identifying if it's actually

a vulnerability or no, it's actually a feature. It's it's very It's a very subtle line. So, this is pretty good. The numbers are are are good and so on. We got a lot of We got some funding for this. So, how much fund uh How many How much funding do you think Node.js has? How many people think Node.js has funds measured in millions? You wish. Yeah, that's

the truth. So, we got 300k at all last year only for doing security. That's the only thing that is funded by somebody and that's the only thing we got the money for. Okay? and that's it. There's nothing else. So, you can If you want, again, there is a a pub you can put some money in the pub. That that would be that will help to cut the

cost. Um so, what did we ship in the last few years with no money? Okay, and a lot of volunteer time. So, how do you work? Well, it's a volunteer-based organization. So, everybody is welcome to volunteer your time and your company to volunteer your your time, okay, to to do some work. Um what did we ship in the last few years? Well, first of all, we shipped

ESM. A lot of people didn't think we would ship ESM. Okay, we shipped ESM. We shipped threads. How many of you didn't you know that Node.js has threads, by the way? Not many. Okay, Node.js has threads now. So, I have another good talk about this. I don't know. But, it's Node.js has threads, okay? You can have fun with threads. It's a proper system now. Um we shipped

threads. we made fetch, which I don't know. I am proud of this because this was my plan. Took us like, you know, 5-6 years to get through, but it we got fetch. We also got a bunch of other web compatibility platform things happening, which, again, I don't know. You like them, so you can probably take them. Um well, promise-specific API because Node.js was born in the era

era of callbacks. We didn't have promises for a long time. So, now we have promises. And there are promise-based API that I use all the time, okay? We also decided that we wanted to have the prefixes for our more modules, so we stop polluting the global namespace. Otherwise, the name of the on NPM are gone. You probably are aware of that. We shipped watch mode. Do you

like watch mode? Do you like node man? Yes, okay. Now it's built in. We shipped something called a sync local storage. Now you probably should not use this API directly, but you probably use this API every day. If you are How many of you are using a react server components? You are using a sync local storage. It will not be possible without a sync local storage. Okay?

If you are using any APM like data dog, open telemetry, whatever, you're using a sync local storage. New relic, a sync local storage. Every Any of those things is built on a sync local storage these days. We shipped something called node crypto, which is very useful, too. Okay? Um And we parse the args. This This is one of the things they From time when I ship it's

very funny because we we were discussing, "Should we have these utilities that are available on NPM?" I said, "Yes, we should." Okay, so we added yeah, stupid utilities, which are good. I love them, but yeah. We started working on single executable application. You can take your node script, combine it with a node binary, and you get executable that you can send to your friends. Isn't this cool?

We shipped the permission system, which is now become stable in node 23, I think, or node 24 is going to become stable. Anyway, it's we shipped the permission system. Again, people said this will not possible not be possible. Node.js is insecure. Now we have a permission We have a test runner now. Again, I love this. This is one of my favorite new features of Node. Okay, it's

super fast. It's probably what you should be using if you're building stuff for Node. You can You can feel the difference, okay? I love this. This is really really nice, Uh we have web socket. Native web socket in Node.js, that is actually We were feeling We were We were a little bit behind. It took us a few years to get to this point, so I'm So, are

you using the new features of Node.js or are you stuck in 20 in 2015? >> 2015. >> 2015, yeah. Okay, great. Sorry, I'm sorry for you. There are new things from 20 Like all of this stuff is not covered by the tutorial that you've read from 2015. There is a one specific tutorial from 2015 that I'm referring to that everybody has read more or less, so anyway.

So, what's coming, okay? If you haven't updated to Node 22 yet, you probably should today because those things are in Node 22. The first one is require ESM. >> What? >> So, please a round of applause to Victor to all the guys that work on this. Okay, thank you all because uh I didn't I didn't do anything for this, so I'm not taking the credit, but I

am very happy to say that this is the thing, okay? Um it works, okay? You can require an ESM module from a common JS one and it just works out of the box. Thank you, Joey, and thank Bloomberg to sponsoring this work. This is how if you want a feature in Node, this is how things work. You You typically either you implement it yourself or you sponsor

a core contributor to implement it for you, okay? So, thanks Bloomberg to uh that foot the bill to get this done, So, yeah. Please. Okay? There is another one. Michael Jackson script, we can forget Michael Jackson script forever. Okay? Because it just works. It just works. You can it will automatically detect the thing that you're running. Okay? It will it will spit out a warning telling you

this is not optimal because it will cost us it it it will slow things down a tiny bit. So, you we want you to know. Okay? But it will work and you will not be in trouble. Again. Pretty good. Last but not least, the most wanted feature of all. Embedded TypeScript support. Thank you to Marco Ippolito that made this happen. Okay? I I'm he's not here, but

Marco is a friend and a great not not core collaborator that made it happen. It works beautifully. It's super fast. It feels from the future, more or less. Well, other runtimes have this, so we had to have this as well, probably. But it's really really cool. Okay? we need you. Okay? We need more collaborators. We need more volunteers. Again, we have and this year in 2025 we'll

only have 150. So, I can know how we're going to scrap with that. Okay? So, uh how do I how do we work? Well, let's talk a little bit about the project governance. Everything is run on the umbrella of the OpenJS Foundation. This is the organization. It's a branch of the uh it's a subsidiary of the um Linux Foundation and it holds, I don't know, jQuery, ESLint,

Electron, Webpack, Express, Fastify, a lot of open with project. It's 30-plus stuff. Node-RED, you probably heard of this guy, too. All of All things are inside Then we have the Node.js project. Node.js project is run by the Node.js collaborators. All the Node collaborators contribute and work, send PRs, review code, okay? If you do If you put in the work, you will become one. There is no obstacle

minus you being uh making code of conduct offense to and treating other people well, okay? From you becoming one if you put in the work. If you think you have put in the work, you can just contact any of us and we'll get to it. We'll we'll we'll we'll crown you. We'll we'll knight you. And um typically it's governed by open with a a consensus-seeking model, which

means that things move slowly. Sorry. It means that we cannot land things if somebody objects. Okay? If somebody If two people object strongly, then it involves the Node.js technical steering committee, which doesn't do much steering at all. It typically acts as a peacekeeping We are peace peacekeepers, okay? We try to keep the peace of the project. And we try to say, "Okay, this guy You know, these

two guys are fighting. Let's separate them and see who what we do in this in that case." that's what we do. Typically that goes to a vote, okay? We also do set release dates, other bunch of stuff. It is not much governance out of this, but we meet every week on and we publish all these videos on on YouTube. So, if you want to watch how we

do, you can watch our YouTube recording. We typically have maybe in between 10 to 50 watchers every time. So, you can you can be one of Um we vote. When there is disagreement in the project, we vote. Pretty cool. Uh Oh, yeah, one more thing. No more than 1/4 of the TSC members may be affiliated with the same employer. This pissed everybody off. Sorry. So, the Node.js

project have a had a history. You can a lot of it was covered by the documentary. So, there was a this very nice documentary. And because of that, we have this rule that no more than 1/3 of the TSC member can no more than 1/3 of people from the same employer can be in the TSC. So, essentially no one can control Node. Okay? You need to people

are forced to collaborate. This is great. Okay? It's something very good for all of you, for all the people using Node, but to some extent it slows things down a little So, this also means that each collaborator has to create a seek compromise and seek consensus to get things done. It's important. Okay? if you have a bug in Node, what do you do? Well, you should really

try to fix it. Because unfortunately, nobody's going to fix it for you most of the time. Okay? Either you fix it yourself or you find somebody else to to nag to say, "Uh can you fix it for me?" Okay? Unfortunately, there is no uh some people will fix bugs, fix fix bugs, but they are volunteers. So, it's not part of most of the time they are doing

it as a small part of their job. I don't know, half a day a week or a day a week. So, uh there's no QA or sub there's no support people. There's no support staff. Okay? If you want to have the support staff, be the support staff. We have a nice group of people called the triagers that help, you know, contribute and and help triaging the issues.

So, cool. Uh let's talk a little bit about uh Platformatic. Okay? Uh so, we try to be uh to help companies do Node and run Node in production and enterprise scales. Um we have a few bits. Last year I I shipped something called VAT. It's a um a a Node.js application server using multi-threading. You can we can run multiple Node.js application inside the same node process, completely

isolated using Come on, Node.js and threads. Um pretty cool. Um and all of these can be managed by our command center, which is uh a tool that you can deploy your system And you know, it has automatic ELU uh ELU event loop utilization uh auto-scaling and other things that are very hard usually to do in in Node.js environment. So, oh, uh we do also caching invalidation, which

is probably something very tough. And the next uh Next.js self-hosting on Kubernetes. I don't know if this is helpful for anybody, but if you are in trouble with Next uh and and Kubernetes, you can probably check talk to me because I have answers Okay. Um yeah, this is us. You can poke this if you want. You have a QR code. And uh yeah, I am done. Uh

is uh I think there are question time, right? I don't know if there is a question time a little bit. Hm? >> Yeah, of course. >> Thank you. >> Matteo, first of all, thank you so much for the talk.

From event

DEVWorld 2026

07 May 2026 – 08 May 2026

All event videos
Back to Watch