THE LATEST
DENO 2.9 · EXPERIMENTAL DESKTOP APPS DEPLOY · GENERALLY AVAILABLE SANDBOX · UNTRUSTED CODE, CONTROLLED ACCESS

Company / Developer tools

Deno tried to leave Node behind. Its users brought npm.

The creator of Node.js built Deno to make JavaScript simpler. The revealing part is what his second act learned to keep - and why its next customer might be an AI agent.

In 2023, Ryan Dahl had to explain why his new JavaScript runtime was adopting something he had once regretted. The object was package.json, the little manifest that tells a project which packages it needs. Deno had offered a cleaner route: import code through web URLs. Yet the old arrangement kept returning, like a guest who knows where the spare key lives.

  • The tool: JavaScript and TypeScript execution, with development chores built in.
  • The reversal: supporting Node and npm made Deno easier to adopt.
  • The business: free runtime; paid hosting, isolated compute, and support.

The library that would not disappear

Dahl had created Node.js, which took JavaScript beyond the browser. He later introduced Deno while discussing Node’s design mistakes. The second attempt embraced newer language features, browser-standard APIs, TypeScript, and explicit permissions. A script would have to ask before reading files or opening network connections. The first stable release arrived in May 2020.

There was an awkward condition attached. The launch announcement acknowledged that many existing npm packages would not work. Developers could admire the architecture and still need yesterday’s database driver. The first obstacle was already waiting in their application.

Ryan DahlBert Belder
Two familiar faces, another runtime. Ryan Dahl, left, and co-founder Bert Belder had already spent years in the Node ecosystem.

Simplicity had acquired its own paperwork

URL imports looked pleasingly direct. But slightly different version URLs could pull two copies of essentially the same dependency into a program. Managing shared imports required conventions; services translating npm packages into web imports could stumble over accompanying data files. The attempt to remove ceremony had produced some ceremony of its own.

In March 2023, Dahl explained the package.json decision in unusually useful terms. The objective was easier programming, and the minimalist module system’s contribution to that objective had become less clear. Deno’s retrospective says 2022 survey responses had highlighted npm access. Users supplied the evidence; compatibility became a sustained engineering project.

“Deno’s main goal is to make programming both easy and fast.”Ryan Dahl, explaining package.json support, 2023

One executable, several ways in

Deno 2 arrived in October 2024 with expanded Node and npm compatibility, workspaces, and package management. Existing code no longer had to be discarded to try the new tools. A team could adopt the formatter or linter first, then consider the runtime. That is a considerably smaller request than asking a company to reconsider its entire software inheritance.

The underlying proposition remains practical. Deno runs TypeScript without a separate execution setup and supplies testing, formatting, linting, and other tools. Rust and V8 underpin the runtime; familiar web interfaces such as fetch reduce the distance between browser and server programming. Native execution does not mean automatic type checking: developers can run deno check separately.

Its surrounding projects address other chores. Fresh renders pages on the server and adds JavaScript where interaction needs it. JSR lets authors publish TypeScript packages while the registry handles documentation and distribution across runtimes. In 2025, JSR gained an independent governing board, including the creators of npm and Vue. A rival registry had invited the old establishment to the table.

The customer behind the customer

Some users want to build applications. Others want their customers to build applications. The latter group needs infrastructure that can execute strangers’ code without inviting those strangers into everyone else’s business.

Netlify chose Deno infrastructure for Edge Functions. A Deno-published April 2024 case study reported 255 million requests daily and 22,000 new edge functions deployed daily. Those are historical figures, but they show the scale of the platform customer. Slack had selected Deno for its next-generation developer platform in 2021, citing TypeScript, web APIs, and security defaults.

These relationships place Deno between developer tooling and cloud infrastructure. Node and Bun are runtime alternatives; Cloudflare Workers and AWS Lambda offer different hosting arrangements. Netlify illustrates how the categories overlap: a hosting alternative can also buy the machinery underneath.

The free tool and the paid machinery

Dahl and co-founder Bert Belder announced $4.9 million in seed funding in March 2021. A $21 million Series A led by Sequoia followed in June 2022. Their stated commercial plan kept the runtime MIT licensed rather than reserving features for paying users. The money would come from services built around the software.

Today, Deploy offers a free tier, a $20 monthly Pro plan, a $200 Builder plan, and custom enterprise arrangements. Included allowances and metered usage matter more than the headline subscription. Runtime enterprise support is another offering, with dedicated Slack access and response commitments. Free software still leaves plenty of operations somebody must perform.

Deno Deploy dashboard showing application build activity
The dashboard gets the paperwork. Deno Deploy’s build interface brings cloud operations into the same product as the code.

An agent with the keys

The newer Deploy platform reached general availability in February 2026, supporting Node projects as well as Deno applications. Alongside it came Sandbox, launched in beta: Linux microVMs for running untrusted code. Dahl described customers generating code with language models and executing it immediately, often with access to external APIs.

Sandbox adds a revealing detail. Through its protected-secret mechanism, code sees a placeholder rather than the actual key. An outbound proxy substitutes the real credential only when contacting an approved host. Network restrictions provide another boundary. The design puts enforcement outside the generated program, where a persuasive prompt cannot simply ask it to look away.

How a protected secret travels
Generated codeSees a placeholder
Outbound proxyChecks the destination
Approved API hostReceives the real credential

Configured secret binding and network policy work together. A microVM alone does not decide what an API request should be allowed to do.

The same concern reached Deno’s own operations. In May 2026, it introduced Claw Patrol, an open-source firewall for agents accessing production systems. June’s Deno 2.9 release pulled in another direction, adding experimental desktop application building and broader lockfile support. Together, the releases show the company extending both sides of its expertise: making familiar code easier to run and deciding what that code may touch.

Copy the experiment, keep the exit

Start with one script or one repetitive development task. Measure setup time and check the packages you actually use. Scope permissions deliberately; granting everything defeats their purpose. For generated workloads, test outbound policies and resource limits before handing over useful credentials.

A working Node service with specialized dependencies may gain little from a migration. Hosted compute introduces billing and platform constraints; it cannot repair an application’s authorization mistakes. Deno’s useful lesson is the willingness to revise a mechanism when it obstructs the mission. The spare key, inconveniently, belonged to the customer.