Skip to content

chore: bump the napi group with 3 updates - #143

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/napi-3016fe80c1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/napi-3016fe80c1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 20, 2026

Copy link
Copy Markdown
Contributor

Bumps the napi group with 3 updates: napi, napi-derive and napi-build.

Updates napi from 3.12.2 to 3.12.4

Release notes

Sourced from napi's releases.

napi-v3.12.4

Security

  • Object::unwrap and Object::remove_wrapped (and the deprecated Env::unwrap / Env::drop_wrapped) read a TypeId out of a payload that is not a TaggedObject, giving a heap out-of-bounds read and a JavaScript-forgeable out-of-bounds write; payload provenance is now validated before dereferencing. See GHSA-rhpj-pggq-896v, fixed in #3506.
  • The serde deserializer reached unreachable!() on ordinary JavaScript values and aborted the process instead of returning an error. See GHSA-f334-75xc-qxv3, fixed in #3507.
  • ArrayBuffer::from_external, TypedArraySlice::from_external and Uint8ClampedSlice::from_external (plus the compat-mode Env::create_arraybuffer_with_borrowed_data) built their slice from freed memory on runtimes without external buffers. See GHSA-32mm-r9wp-hrvc, fixed in #3503.

Fixed

  • (napi) return errors from the serde deserializer for unexpected JS value shapes (#3507)
  • (napi) validate wrapped payload provenance in Object::unwrap/remove_wrapped (#3506)
  • (napi) point from_external slices at the engine-owned copy after finalize reclaims the source (#3503)

napi-v3.12.3

Fixed

  • CurrentThread waker-stack deadlocks and threadless-wasm Buffer detachment (#3489)
  • (napi) catch panics in closure trampolines instead of aborting (#3473)

Other

  • (napi) keep anyhow error cause when converting (#3477)
  • (napi) outline threadsafe callback dispatch (#3465)
  • (napi) outline class instance construction (#3464)
Commits
  • 1492b22 chore: release (#3502)
  • 828983a fix(napi): return errors from the serde deserializer for unexpected JS value ...
  • 606b142 fix(napi): validate wrapped payload provenance in Object::unwrap/remove_wrapp...
  • a75d89f fix(napi): point from_external slices at the engine-owned copy after finalize...
  • e414c8c fix(deps): update dependency obug to v3 (#3499)
  • a5fedde chore(deps): update release-plz/action action to v0.5.136 (#3505)
  • 31c27a1 chore: release (#3470)
  • 7e3f293 chore(release): publish
  • f772ee0 fix(cli): align generated file formats (#3501)
  • 1cf5ec5 fix(cli): use accessible WASI preopen root on Android (#3485)
  • Additional commits viewable in compare view

Updates napi-derive from 3.6.3 to 3.6.5

Release notes

Sourced from napi-derive's releases.

napi-derive-v3.6.5

Other

  • update Cargo.toml dependencies

napi-derive-v3.6.4

Fixed

  • (deps) update rust crate convert_case to 0.12 (#3469)
Commits
  • 1492b22 chore: release (#3502)
  • 828983a fix(napi): return errors from the serde deserializer for unexpected JS value ...
  • 606b142 fix(napi): validate wrapped payload provenance in Object::unwrap/remove_wrapp...
  • a75d89f fix(napi): point from_external slices at the engine-owned copy after finalize...
  • e414c8c fix(deps): update dependency obug to v3 (#3499)
  • a5fedde chore(deps): update release-plz/action action to v0.5.136 (#3505)
  • 31c27a1 chore: release (#3470)
  • 7e3f293 chore(release): publish
  • f772ee0 fix(cli): align generated file formats (#3501)
  • 1cf5ec5 fix(cli): use accessible WASI preopen root on Android (#3485)
  • Additional commits viewable in compare view

Updates napi-build from 2.4.1 to 2.4.4

Release notes

Sourced from napi-build's releases.

napi-build-v2.4.4

Fixed

  • (napi) guard AsyncTask completion against env teardown (#3536)

napi-build-v2.4.3

Fixed

  • (cli) drain outstanding async work before disposing a WASI binding (#3528)

napi-build-v2.4.2

Fixed

  • (cli,build) make wasm32-wasip1-threads link with wasi-sdk 34 and Rust nightly (#3492)
Commits
  • 38162bb chore: release (#3529)
  • ec3d8ea fix(napi): guard AsyncTask completion against env teardown (#3536)
  • 96ed267 chore(deps): update release-plz/action action to v0.5.139 (#3537)
  • b2c9f3b chore(deps): update release-plz/action action to v0.5.138 (#3533)
  • f31c887 fix(cli): skip the reconciliation heal test on hosts whose identity probes fa...
  • 34b8781 chore(release): publish
  • 5f5c289 fix(cli): derive WASI .d.cts from ESM sources when nothing blocks it (#3532)
  • 2733e5b chore(release): publish
  • 43ddfac fix(cli): retry a filesystem snapshot whose source only changed metadata and ...
  • e2f21c6 chore: release (#3525)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the napi group with 3 updates: [napi](https://github.com/napi-rs/napi-rs), [napi-derive](https://github.com/napi-rs/napi-rs) and [napi-build](https://github.com/napi-rs/napi-rs).


Updates `napi` from 3.12.2 to 3.12.4
- [Release notes](https://github.com/napi-rs/napi-rs/releases)
- [Commits](napi-rs/napi-rs@napi-v3.12.2...napi-v3.12.4)

Updates `napi-derive` from 3.6.3 to 3.6.5
- [Release notes](https://github.com/napi-rs/napi-rs/releases)
- [Commits](napi-rs/napi-rs@napi-derive-v3.6.3...napi-derive-v3.6.5)

Updates `napi-build` from 2.4.1 to 2.4.4
- [Release notes](https://github.com/napi-rs/napi-rs/releases)
- [Commits](napi-rs/napi-rs@napi-build-v2.4.1...napi-build-v2.4.4)

---
updated-dependencies:
- dependency-name: napi
  dependency-version: 3.12.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: napi
- dependency-name: napi-derive
  dependency-version: 3.6.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: napi
- dependency-name: napi-build
  dependency-version: 2.4.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: napi
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 20, 2026
@codspeed

codspeed Bot commented Sep 20, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 188 untouched benchmarks
⏩ 77 skipped benchmarks1


Comparing dependabot/cargo/napi-3016fe80c1 (ee4bba9) with main (f7baba3)

Open in CodSpeed

Footnotes

  1. 77 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants