64-bit
wixmachine scopenodejs.org · publisher-owned- SHA-256
- c9df873c4cf0463c63b79774d96b2e126ca6ba9d9f86529846864d41775101d6
- Product code
- {16ACB226-F825-4982-A438-4E2A4D52BC44}
by Node.js Foundation · MIT
Run JavaScript Everywhere
These URLs are the ones Node.js Foundation declares in its own manifest. We do not proxy or shorten them, and we do not host a copy.
Run this against the file on disk. If the output does not match the hash below, the file is not what Node.js Foundation published. Delete it.
Windows · PowerShell
Get-FileHash "node-v26.4.0-x64.msi" -Algorithm SHA256macOS · Linux
shasum -a 256 "node-v26.4.0-x64.msi"Expected output
c9df873c4cf0463c63b79774d96b2e126ca6ba9d9f86529846864d41775101d6
| Signal | Finding | Points |
|---|---|---|
| SHA-256 hash published | 4 of 4 installers ship a SHA-256 hashWithout a published hash there is no way to prove the file you downloaded is the file the publisher built. | 30 / 30 |
| Binary provenance | 4 on a domain owned by the publisherThe strongest signal against a repackaged installer: the file should come from the publisher, not from a mirror nobody vouches for. | 35 / 35 |
| Served over HTTPS | 4 of 4 over HTTPSAn installer fetched over plain HTTP can be modified in transit. | 15 / 15 |
| Release recency | last release about 1 months agoSoftware that has not shipped in years accumulates unpatched vulnerabilities. | 15 / 15 |
| Licence declared | MITA declared licence tells you what you are actually allowed to do with the software. | 5 / 5 |
Extensions Node.js registers itself to handle.
Every version with a published manifest, newest first. Useful when you need an older build for compatibility.