Node.js 26.10 adds debounce and throttle to the runtime

A rocky Bermuda headland above a calm, glassy sea under thin cloud

Node.js 26.10.0 shipped on September 22, the last Current release before the 26 line becomes long-term support (LTS) this month. The list is modest and the pattern is the point. util.debounce and util.throttle arrive in the standard library. crypto.parsePKCS12 reads certificate bundles without a dependency. fs.openAsBlobSync joins its async sibling. There is a sliding window histogram in the performance hooks and a bound socket that can be handed to a worker thread.

Debounce and throttle are the ones I keep looking at. Every JavaScript codebase I have worked in has them, from a utility package, a copy-pasted implementation, or both. They are twenty lines that have been written ten thousand times, and they are now two function calls in the runtime.

That is the pattern Node has followed for years: fetch, the test runner, watch mode, SQLite, and now this. Each is a package, often a tree of them, that a team no longer needs. I think it is in core now should be treated as a trigger, with a standing task to find the dependency it replaces and delete it.

My reason is not tidiness. Every package removed is one fewer maintainer account, one fewer install script, one fewer thing that can be compromised in an afternoon, as several were this year. A scanner tells you a dependency is dangerous after the fact. Not having the dependency is the only control that works before it.

When a runtime adds something your codebase already imports, does anyone go back and remove the import?

Photo source: https://photos.robertstowe.com/bermuda