NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #1243 most downloaded on crates.io
N-API bindings
Last release 2 days ago
06 Oct 2026
Ships fairly regularly
a new release about every 2 weeks
Most releases are documented
notes for 51 of the last 60 stable releases
4 versions withdrawn
withdrawn after publishing
9 years old
264 releases · first in 2017
(napi) register the wasm cleanup through the env cleanup hook
(napi) create objects with napi_define_properties on every Node version
One column per quarter.
(napi) lock the allocator on threaded WASI and never hang after a worker crash
(async-runtime) offer the MultiThread flavor on wasm32-wasip1-threads
(napi) guard AsyncTask completion against env teardown
(cli) drain outstanding async work before disposing a WASI binding
fatal_exception noop in optimized builds
Object::unwrap and Object::remove_wrapped (and the deprecated Env::unwrap / Env::drop_wrapped ) read a TypeId out of a payload that is not a TaggedObj…
Object::unwrap and Object::remove_wrapped (and the deprecated Env::unwrap / Env::drop_wrapped) read a TypeId out of a payload that is not a TaggedObject, giving a heap out-of-bounds read and a JavaScript-forgeable out-of-bounds write; payload provenance is now validated before dereferencing. See GHSA-rhpj-pggq-896v, fixed in #3506.unreachable!() on ordinary JavaScript values and aborted the process instead of returning an error. See GHSA-f334-75xc-qxv3, fixed in #3507.ArrayBuffer::from_external, TypedArraySlice::from_external and Uint8ClampedSlice::from_external (plus the compat-mode Env::create_arraybuffer_with_borrowed_data) built their slice from freed memory on runtimes without external buffers. See GHSA-32mm-r9wp-hrvc, fixed in #3503.CurrentThread waker-stack deadlocks and threadless-wasm Buffer detachment
BufferSlice::from_data, BufferSlice::copy_from and BufferSlice::from_external built their Deref/DerefMut slice over the napi_value handle instead of the buffer's bytes (OOB read into V8's handle scope, attacker-length OOB write). Fixed as part of #3489. See GHSA-3hv5-cch8-c72w.(napi) memory safety in PromiseRaw callbacks and AbortSignal conversion
(napi) stop unloading addons with live native code, preserve non-Error rejections, and add the wasm teardown barrier
*(cli)* support non-threaded WASI targets
Nothing published for this version
unforgeable #[napi] class identity via Node object type tags
#[napi] class identity via Node object type tags (#3405)*(napi)* release FunctionRef off the JS thread via the custom-GC TSFN
*(cli)* align build and project configuration
*(napi)* preserve the JS error object when cloning an Error off-thread
*(napi)* keep message and cause when cloning a JS-exception Error off-thread
*(napi)* release Error's exception reference via the custom GC when dropped off-thread.
*(napi)* implement To/FromNapiValue for OsString, OsStr, Path and PathBuf
*(napi-derive)* outline #[napi(object)] field-error decoration
*(napi)* sync referred flag when creating a weak ThreadsafeFunction
*(napi)* ReadableStream Reader loses chunks and aborts on errored streams
WASI threads builds on current toolchains ( #3492 ) wasm32-wasip1-threads was failing in two ways: wasi-sdk 34 changed the futex ABI, and Rust nightly
Patch over 3.9.0.
WASI threads builds on current toolchains (#3492)
wasm32-wasip1-threads was failing in two ways: wasi-sdk 34 changed the futex ABI, and Rust nightly started linking crt1-reactor.o itself (duplicate _initialize). The CLI now picks the matching emnapi archive; the build crate stops double-linking _initialize.
WASI on Android / Termux (#3485)
Generated Node loaders preopened /, which Termux cannot open (UVWASI_EACCES). Android now preopens the current working directory. Other platforms are unchanged.
Generated files share one format (#3501)
JSON / TOML / YAML, .d.ts, and JS / WASI loaders now use one house style (indent, trailing newline, quotes). Regenerating bindings may produce noisy diffs with no behavior change.
js-yaml 4 → 5 (#3344) — YAML dump formatting can change; loaded values should not.| Package | Version |
|---|---|
@napi-rs/triples |
2.1.23 |
@napi-rs/wasm-runtime |
1.2.4 |
*(napi)* add ThreadsafeFunction::call_async_catch to handle errors in callback functions
*(deps)* update rust crate ctor to 0.11.0
*(napi)* preserve generator class methods
*(deps)* update rust crate ctor to v0.8.0
*(napi)* prevent async iterator use-after-free during GC
*(napi)* memory leak in async fn
*(napi)* wasi debug compile error
*(napi)* support any object types in Stream
### Other - clippy fix for Rust 1.92.0
*(napi)* provide unsafe as_mut on ArrayBuffer
updated the following local packages: napi-sys
*(napi-derive)* add tracing feature for debug logging NAPI function calls
updated the following local packages: napi-build
*(napi)* TypedArraySlice creation
*(sys)* use libloading to load napi symbols at runtime on all platform
*(napi)* add on_abort for AbortSignal
*(napi)* implement from_static on JsStringLatin1 and JsStringUtf16
*(napi)* extends the Set types interoperability
*(napi)* link issue on cargo test --features noop
*(napi)* no need to cleanup thread_local stuff
*(napi)* ensure tokio runtime is initialized for dlopen
*(napi)* add ScopeGenerator trait
*(napi)* async task finally is not called
*(napi)* relax the lifetime restriction in PromiseRaw callbacks
*(napi)* the generic trait rectiction of Env::spawn should be ScopedTask
*(napi)* optimize HashMap allocation in FromNapiValue implementation for HashMap
*(napi)* use Vec with_capacity in FromNapiValue
Revert "fix(napi): callback should be Fn rather than FnOnce"
*(napi)* provide ScopedTask to resolve JsValue with lifetime
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →