Nodejs fixed 8 vulnerabilities:

nodejs.org/en/blog/vulnerabili

There's a bunch of confusing things:
- the announcement is published today at a URL from last month with a link saying "January Security Release is available" linking to itself
- the 'release details' links in the advisory 404 (you want to go to the GitHub releases page instead)
- announcement to nodejs-sec mailing list is only a terse note saying "Security release is now available" with not even a link

0

If you have a fediverse account, you can quote this note from your own instance. Search https://mstdn.social/users/jschauma/statuses/115888432173862155 on your instance and quote it. (Note that quoting is not supported in Mastodon.)