
Security News
/Company News
Socket Is Sponsoring Composer and Packagist
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.
@napi-rs/cli
Advanced tools
@napi-rs/cliCli tools for napi-rs
# or npm, pnpm
yarn add @napi-rs/cli -D
yarn napi build
@napi-rs/cli supports Node.js ^20.17.0, ^22.13.0, and >=23.5.0.
Earlier Node.js releases are no longer supported by the CLI runtime.
| Command | desc | docs |
|---|---|---|
| new | create new napi-rs project | ./docs/new.md |
| build | build napi-rs project | ./docs/build.md |
| create-npm-dirs | Create npm package dirs for different platforms | ./docs/create-npm-dirs |
| artifacts | Copy artifacts from Github Actions into specified dir | ./docs/artifacts.md |
| rename | Rename the napi-rs project | ./docs/rename.md |
| universalize | Combile built binaries into one universal binary | ./docs/universalize.md |
| version | Update version in created npm packages by create-npm-dirs | ./docs/version.md |
| pre-publish | Update package.json and copy addons into per platform packages | ./docs/pre-publish.md |
Generated WASI bindings expose deterministic cleanup through a non-enumerable symbol on the binding object:
const binding = require('<package>')
const dispose = binding[Symbol.for('napi.rs.wasi.dispose')]
if (dispose) {
await dispose()
}
The symbol is present only when the loaded binding is WASI. Browser WASI
loaders expose it on their default export. Disposal releases the instance: it
destroys the emnapi context and then terminates the workers owned by that
binding. Pending napi-rs runtime promises are settled or cancelled first only
when the binary exports the napi_prepare_wasm_env_cleanup preparation hook
(a planned napi-side follow-up); otherwise they may remain pending forever,
so settle in-flight work before disposing. Concurrent calls share one
promise, successful disposal is idempotent, and a failed cleanup phase can be
retried by calling the same function again. Do not call addon exports after
disposal completes.
See WASI targets and loaders for threaded, threadless, browser, and workerd packaging behavior.
DEBUG="napi:*" napi [command]
Neon is a similar tool that provides a CLI for creating and managing Node.js native addons using Rust. It offers a similar set of functionalities, such as project initialization, building, and testing. However, Neon focuses more on providing a seamless integration with Rust's ecosystem and offers additional features like automatic type conversion between Rust and JavaScript.
Node-gyp is a widely used tool for compiling native addon modules for Node.js. Unlike @napi-rs/cli, which is Rust-focused, node-gyp is more general-purpose and supports C/C++ addons. It is a lower-level tool that requires more manual configuration compared to the streamlined experience provided by @napi-rs/cli.
CMake.js is a tool that uses CMake to build native addons for Node.js. It is similar to node-gyp but leverages CMake's capabilities for cross-platform builds. While @napi-rs/cli is tailored for Rust and N-API, CMake.js is more versatile in terms of language support and build system integration.
FAQs
Cli tools for napi-rs
The npm package @napi-rs/cli receives a total of 809,950 weekly downloads. As such, @napi-rs/cli popularity was classified as popular.
We found that @napi-rs/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.

Research
/Security News
Benign-looking npm packages split malicious functionality across a dependency chain that deploys a cross-platform RAT targeting Alibaba developers.

Research
/Security News
Two Joyfill npm beta releases contain an import-time implant that uses blockchain transactions to retrieve a remote-access trojan.