Repository navigation
ci(renovate): pin the napi-rs toolchain and hold flate2 - #604
Merged
Merged
Conversation
The changes job runs every build target, and with them the release packaging dry run over all eight platform packages, only when a pull request touches crates/, npm/, scripts/, the Cargo files or the workflows. @napi-rs/cli drives every native build and the packaging, but its updates land in package.json and pnpm-lock.yaml, so they were built for Linux alone. Renovate's open PR #533 moves the CLI from 3.9.1 to 3.10.5 in the lockfile only; the 3.9.1 update itself broke the first two 2.0.2 publish attempts (#526, #529). Also run the full matrix when a changed line in package.json, pnpm-lock.yaml or pnpm-workspace.yaml names napi as a word: the @napi-rs packages, including those the CLI pulls in, and the napi scripts. Treating those files as native outright would send every npm update, the weekly Renovate group included, through eight builds and the macOS and Windows test legs, although nothing in them reaches a binary. The narrower check can miss a toolchain change that names no napi package, such as a transitive dependency of the CLI moving on its own, or an edit to the targets in the napi field, which comes with its npm/ package anyway. develop runs the full matrix after every merge, so such a change cannot reach a release untested. The diff is captured before grep -q reads it. Piped straight in, grep stops at the first match and, under pipefail, the git diff it cuts off would turn a match into a miss on a large lockfile diff. Refs #575 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DRi2Qu5rPjQSDBcR8xmkSS
Renovate treated the packages that build and package comprs like any other dependency. @napi-rs/cli sat behind a ^3.7.1 range in the automerged non-major npm group, so a new CLI arrived as a lockfile-only change and merged once CI passed; 3.9.1 came that way and broke the first two 2.0.2 publish attempts (#526, #529). Now that the napi crates are no longer held (#518), their minor and patch updates would be automerged with the other crates as well. The cargo automerge rule also overrode the deliberate flate2 =1.1.9 pin (#509): open PR #534 rewrites it to =1.1.10, and only a test that happens to catch another behaviour change in 1.1.10 keeps it from merging. - Group @napi-rs/* and the napi, napi-derive and napi-build crates as "napi-rs toolchain", majors included, and never automerge it. The rule follows the generic ones because later rules win. - Pin @napi-rs/cli to the locked 3.9.1 and keep the @napi-rs packages pinned, so a toolchain update shows in the reviewed package.json diff. The crates keep their major-version requirements; pinning them would turn "3" into "=3.13.0". - Allow flate2 only up to 1.1.9 until #509 is resolved. - Refresh the lock files once a month, without automerge. The workflow runs Renovate weekly, so the schedule covers the first seven days of the month; the built-in monthly schedule, before 4am on the 1st, would never coincide with a run. Cargo.lock gets its own PR through the rust-dependencies group. A refresh has no release timestamp to age, so it opts out of the minimum release age, which would keep its stability check pending for good. - Hold GitHub Actions updates, digests included, for 3 days instead of 0 (#385): retargeted tags are how the tj-actions/changed-files compromise reached even SHA-pinned workflows, as ordinary digest updates. Renovate ages a digest update by the release its tag resolves to, but the update carries no timestamp of its own, and with the default timestamp-required behaviour its branch would never pass the stability check or automerge. timestamp-optional keeps the 3-day hold at lookup time and lets the branch merge afterwards. renovate-config-validator 44.115.13, the Renovate release that last ran on this repository, accepts the config. A local lookup with it puts @napi-rs/cli 3.10.5 and napi 3.14.0, napi-derive 3.6.10 and napi-build 2.6.0 in the napi-rs toolchain branch and no longer proposes flate2 1.1.10, which the current config offers for both Cargo.toml and the fuzz crate. Closes #575 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DRi2Qu5rPjQSDBcR8xmkSS
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
WASM Binary Size
|
This was referenced Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Problem (#575)
@napi-rs/clisat behind^3.7.1in the automerged non-major npm group. 3.9.1 arrived that way (chore(deps): update npm dependencies (non-major) #515) and broke the first two 2.0.2 publish attempts (fix(release): napi artifacts requires comprs.wasi.d.cts, which the WASI build job does not upload #526, fix(release): wasm32-wasi package manifest fails napi prepublish validation in @napi-rs/cli 3.9 #529). The open group PR chore(deps): update npm dependencies (non-major) #533 moves it to 3.10.5 as a lockfile-only change, with automerge enabled.flate2 = \"=1.1.9\"pin (perf(gzip): flate2 1.1.10 regresses gzip/deflate throughput with the zlib-rs backend #509). chore(deps): update rust-dependencies #534 rewrites it to=1.1.10. The only thing keeping it from merging is a test that happens to catch another behaviour change in 1.1.10.package.jsonorpnpm-lock.yaml, CLI updates included.Fix
renovate.json:@napi-rs/*plus thenapi,napi-deriveandnapi-buildcrates, major updates included, never automerged. It comes after the generic rules, because later rules win.@napi-rs/*stays at exact versions in package.json (rangeStrategy: pin, npm only), so a toolchain update shows in the reviewed diff. The crates keep their"3"and"2"requirements.<=1.1.9, with a description pointing at perf(gzip): flate2 1.1.10 regresses gzip/deflate throughput with the zlib-rs backend #509.* * 1-7 * *because the Renovate workflow runs once a week, on Sunday at 19:00 UTC. The built-in monthly schedule ("before 4am on the 1st") would never coincide with a run.minimumReleaseAge: null: a lock refresh has no release timestamp, so the inherited 3-day age would keep its stability check pending for good.minimumReleaseAgeBehaviour: "timestamp-optional".timestamp-required, the branch would never pass the stability check or automerge.timestamp-optional, the 3-day hold still applies at lookup time.package.json/pnpm-lock.yaml:@napi-rs/cliis pinned to the locked3.9.1. Only the specifier changes.ci.yml,changesjob: a pull request now also gets the full native matrix, and with it the all-targets Release Dry Run, when a changed line inpackage.json,pnpm-lock.yamlorpnpm-workspace.yamlnamesnapias a word. That covers the@napi-rspackages, including the ones the CLI pulls in, and the napi scripts.napi.targetslist is not matched either, but it always comes with itsnpm/package, which already counts as native. develop runs the full matrix after every merge, so such a change cannot reach a release untested.grep -qreads it, so the check keeps working if the step ever runs underpipefail.Tests
renovate-config-validator --strictpasses with Renovate 44.115.13, the release that last ran on this repository.renovate/napi-rs-toolchain.changesfilter was replayed old vs new on chore(deps): update github-actions (non-major) #532, chore(deps): update npm dependencies (non-major) #533, chore(deps): update rust-dependencies #534 and synthetic commits, under bothbash -eandbash -eo pipefail.Notes
@napi-rs/cli, which moves into a non-automerged "napi-rs toolchain" PR together with the napi crate updates.dependencyDashboardApproval: toolchain PRs now get the full matrix, so opening them for review is more useful than waiting for a dashboard tick.emnapi/@emnami/*: no longer direct dependencies.minimumReleaseAgesetting inpnpm-workspace.yamlcould close that gap.Related issue
Closes #575
Part of #535
Breaking changes / Deprecations
N/A
Checklist
pnpm run check)pnpm run typecheck)pnpm test)cargo test):cargo test --workspace;cargo fmt --all -- --checkpassescargo clippy): no warnings with--all-targets -- -W clippy::allpnpm run build): verified withpnpm run build:debug, no drift in generated files; cross-target builds and the Release Dry Run are left to CI, which runs the full matrix for this PRcrates/changed) — N/A,crates/is unchanged; CI and dev tooling only🤖 Generated with Claude Code
https://claude.ai/code/session_01DRi2Qu5rPjQSDBcR8xmkSS
Summary by CodeRabbit