
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
@napi-rs/cli
Advanced tools
@napi-rs/cliCli tools for napi-rs
# or npm, pnpm
yarn add @napi-rs/cli -D
yarn napi build
@napi-rs/cli supports Node.js ^20.17.0, ^22.13.0, and >=23.5.0.
Earlier Node.js releases are no longer supported by the CLI runtime.
| Command | desc | docs |
|---|---|---|
| new | create new napi-rs project | ./docs/new.md |
| build | build napi-rs project | ./docs/build.md |
| create-npm-dirs | Create npm package dirs for different platforms | ./docs/create-npm-dirs |
| artifacts | Copy artifacts from Github Actions into specified dir | ./docs/artifacts.md |
| rename | Rename the napi-rs project | ./docs/rename.md |
| universalize | Combile built binaries into one universal binary | ./docs/universalize.md |
| version | Update version in created npm packages by create-npm-dirs | ./docs/version.md |
| pre-publish | Update package.json and copy addons into per platform packages | ./docs/pre-publish.md |
Generated WASI bindings expose deterministic cleanup through a non-enumerable symbol on the binding object:
const binding = require('<package>')
const dispose = binding[Symbol.for('napi.rs.wasi.dispose')]
if (dispose) {
await dispose()
}
The symbol is present only when the loaded binding is WASI. Browser WASI
loaders expose it on their default export. Disposal releases the instance: it
destroys the emnapi context and then terminates the workers owned by that
binding. Before that, the loader calls the binary's
napi_prepare_wasm_env_cleanup preparation hook, which shuts the addon's async
runtime down while the environment can still call into JavaScript. A registered
AsyncRuntime backend quiesces there and its cancelled tasks reject their
promises; the built-in Tokio runtime only starts draining, so with it a
promise whose task is still running can still be left pending. Settle in-flight
work before disposing if that matters. Concurrent calls share one
promise, successful disposal is idempotent, and a failed cleanup phase can be
retried by calling the same function again. Do not call addon exports after
disposal completes.
See WASI targets and loaders for threaded, threadless, browser, and workerd packaging behavior.
DEBUG="napi:*" napi [command]
Neon is a similar tool that provides a CLI for creating and managing Node.js native addons using Rust. It offers a similar set of functionalities, such as project initialization, building, and testing. However, Neon focuses more on providing a seamless integration with Rust's ecosystem and offers additional features like automatic type conversion between Rust and JavaScript.
Node-gyp is a widely used tool for compiling native addon modules for Node.js. Unlike @napi-rs/cli, which is Rust-focused, node-gyp is more general-purpose and supports C/C++ addons. It is a lower-level tool that requires more manual configuration compared to the streamlined experience provided by @napi-rs/cli.
CMake.js is a tool that uses CMake to build native addons for Node.js. It is similar to node-gyp but leverages CMake's capabilities for cross-platform builds. While @napi-rs/cli is tailored for Rust and N-API, CMake.js is more versatile in terms of language support and build system integration.
FAQs
Cli tools for napi-rs
The npm package @napi-rs/cli receives a total of 852,722 weekly downloads. As such, @napi-rs/cli popularity was classified as popular.
We found that @napi-rs/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.