Which Node versions to test the Sume SDK on: 22, 24 and 26

Node 26.10.0 is Current, 24.21.0 and 22.23.3 are LTS. A small CI matrix and smoke test for code that calls the Sume API with fetch and WebCrypto.

4 min readSume
All posts

Test on the two LTS lines the Node release page lists, 24.21.0 and 22.23.3, plus the Current line, 26.10.0. Sume's SDK docs say @sume-com/sdk needs only fetch and WebCrypto and states Node 18 or newer as the floor, so a matrix of 22, 24 and 26 sits comfortably above it.

This post gives a three-row matrix and a one-file smoke test that proves the runtime can reach the API, without spending any credits.

What the Node page lists

The versions below are as listed on the page.

Node.js release blog (read 2026-10-03)
LineVersion listedStatus
26v26.10.0Current
24v24.21.0LTS
22v22.23.3LTS

What the SDK needs

The SDK docs describe @sume-com/sdk@0.2.0 as MIT licensed with no runtime dependencies. It needs fetch and WebCrypto, so it runs on Node, Bun, Deno and Cloudflare Workers. The client sends x-api-key only, and the API rejects a request that carries both Authorization: Bearer and x-api-key.

Because there are no dependencies, a failure on one Node line is almost always your own code or a transitive package of yours, not the SDK.

The CI matrix

Pin the major lines and let the patch float, so the job picks up new releases without edits.

name: node-matrix
on: [push]
jobs:
  smoke:
    runs-on: ubuntu-latest
    strategy:
      fail-fast: false
      matrix:
        node: ["22", "24", "26"]
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
        with:
          node-version: ${{ matrix.node }}
      - run: node smoke.mjs
        env:
          SUME_API_KEY: ${{ secrets.SUME_API_KEY }}

A smoke test that costs nothing

GET /v1/me is a read call that confirms the key, the network path and the runtime together. It does not create a job, so it does not reserve or spend credits.

const key = process.env.SUME_API_KEY;
if (!key) throw new Error("SUME_API_KEY is not set");

const res = await fetch("https://api.sume.com/v1/me", {
  headers: { "x-api-key": key },
});
console.log(process.version, res.status);
if (!res.ok) process.exit(1);

// WebCrypto is what the SDK uses for webhook verification
console.log(typeof globalThis.crypto?.subtle?.importKey);

What to watch for

A few failure modes are worth checking in the matrix, each independent of Sume.

  • A key stored in a repository secret that is empty on forked pull requests; the smoke test fails loudly instead of sending a blank header.
  • A fetch wrapper in your code that adds Authorization on top of x-api-key, which Sume answers with 401 unauthorized.
  • Generation tests that wait on real jobs. Keep those out of the matrix; run them once on one line, with Idempotency-Key set.

Choosing what blocks a merge

Not every row needs to block a merge. A reasonable policy is to make the two LTS lines required and the Current line advisory, since Current is where behavior changes land first. If the advisory row fails and the LTS rows pass, open an issue rather than reverting a change. The reverse, an LTS failure with Current passing, usually means you used something newer than the oldest line you support.

Keep paid generation out of this job entirely. A matrix triples every call, and a retried CI run on a paid endpoint creates new jobs unless the Idempotency-Key is the same. The read-only call above gives you the runtime signal without that cost.

When to move the floor

The release page is the source for which lines are maintained. When a line drops off it, remove it from the matrix and raise the engines field in your own package. Sume's stated floor is a minimum for the SDK, not a recommendation to stay on an old runtime.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume