Cloudflare is acquiring Deno, the startup founded by Node.js creator Ryan Dahl, and bringing its engineering team into Cloudflare Workers. The acquisition will wind down Deno’s standalone runtime and hosting service: the runtime will receive monthly maintenance and security updates for one more year before development ends, while Deno Deploy will shut down in six months. These deadlines create migration and support-lifecycle concerns for organizations relying on Deno applications or hosted workloads.
Cloudflare plans to merge Deno’s Celld project with its open-source Workers runtime, workerd, to improve support for distributed applications running on independently managed infrastructure. The JSR package registry will continue under Cloudflare, and paying Deno Deploy customers will receive migration assistance. Organizations using Deno should inventory affected workloads, plan hosting transitions before Deploy closes, and assess long-term runtime options before the announced maintenance and security-update period expires.

Map this exposure pattern across your cloud, code, and identities.
3 events from the most recent confirmed update back to the earliest known activity.
Cloudflare misidentified TypeScript files as video content and blocked Deno's website and module registry, forcing Deno to move infrastructure elsewhere.
Node.js creator Ryan Dahl introduced Deno, a JavaScript and TypeScript runtime, to address shortcomings in Node.js, particularly security and dependency management.
Cloudflare announced that Deno's entire team would join its Workers organization, with Ryan Dahl and Bert Belder leading a planned combination of Deno's Celld project and Cloudflare's workerd runtime. The announcement outlined another year of monthly maintenance and security updates before standalone Deno development ends, a Deno Deploy shutdown in six months with migration assistance for paying customers, and continued operation of the JSR package registry under Cloudflare.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.