Grounded on 2026-08-12. The links in this document point to the release channel or package record used for each decision.
| Choice | Selected version | Current stable or LTS | Release or support date | Decision | Source |
|---|---|---|---|---|---|
| Rust edition | 2024 | 2024 | Rust 1.85 stabilized it on 2025-02-20 | The repository edition pin wins. | Rust 2024 |
| Rust toolchain | 1.97.1 | 1.97.1 | 2026-07-16 | Rust has no LTS channel. Use the latest stable toolchain. Keep the repository MSRV at 1.88. | Stable channel |
| Node CI runtime | 24 LTS | 24 LTS | 24.19.0 released 2026-08-03; support ends 2028-04-30 | Use the current LTS in CI. | Official Node release schedule and 24.19.0 release record |
| Node consumer floor | >=20.17 | 24 LTS | Node 20 support ended 2026-04-30 | The existing public compatibility contract overrides an engine-floor raise. All shipped runtime dependencies must still load on 20.17. | Official Node release schedule and Node 20.17 API |
| pnpm | 11.21.0 | 11.21.0 | 2026-08-09 | Use the latest stable package manager. | npm package record |
| npm | 12.0.2 | 12.0.2 | 2026-07-29 | The release workflow exact-pins this stable version for publication and lockfile work. | npm package record |
| cargo-nextest | 0.9.143 | 0.9.143 | 2026-08-07 | The release workflow exact-pins this stable test runner. | upstream release |
| TypeScript | 7.0.2 | 7.0.2 | 2026-07-08 | Use the latest stable compiler. | npm package record |
| Vitest | 4.1.10 | 4.1.10 | 2026-07-06 | Use the latest stable release. Exclude Vitest 5 prereleases. | npm package record |
| oxlint | 1.78.0 | 1.78.0 | 2026-08-10 | This development-only tool requires Node 20.19. CI uses Node 24. It is not part of the published package or its Node 20.17 contract. | npm package record |
The default is the latest stable release. The N-API rows form one older stable generation because the latest generation requires prerelease Emnapi packages.
| Crate | Selected version | Current stable | Released | Decision | Source |
|---|---|---|---|---|---|
| serde | 1 / 1.0.229 | 1.0.229 | 2026-07-18 | Latest stable. | crates.io |
| sonic-rs | 0.5.8 | 0.5.8 | 2026-03-25 | Latest stable SIMD parser, writer, and value model. | crates.io |
| regex | 1.13.1 | 1.13.1 | 2026-07-15 | Latest stable. | crates.io |
| jiff | 0.2.35 | 0.2.35 | 2026-07-25 | Latest stable. | crates.io |
| memchr | 2.8.3 | 2.8.3 | 2026-07-08 | Latest stable. | crates.io |
| smallvec | 1.15.2 | 1.15.2 | 2026-06-11 | Latest stable. Exclude the 2.0 prerelease. | crates.io |
| compact_str | 0.10.0 | 0.10.0 | 2026-07-13 | Latest stable. | crates.io |
| slab | 0.4.12 | 0.4.12 | 2026-01-31 | Latest stable resolution. | crates.io |
| napi | 3.11.0 | 3.12.1 | 2026-07-21 | Exact pin. Version 3.11 accepts napi-build 2.3.2; version 3.12 raises that dependency to 2.4. |
3.11.0 manifest and 3.12.1 manifest |
| napi-derive | 3.5.10 | 3.6.3 | 2026-07-12 | Exact pin. Version 3.5.10 selects backend 5.1.2, which matches napi 3.11. | 3.5.10 manifest and changelog |
| napi-build | 2.3.2 | 2.4.1 | 2026-05-13 | Exact pin. Version 2.4 exports the native Emnapi-v2 environment functions that stable Emnapi 1.11 does not provide. | 2.3.2 WASI source and 2.4.1 WASI source |
| rstest | 0.26.1 | 0.26.1 | 2025-07-27 | Latest stable. | crates.io |
| Package | Selected version | Current stable | Released | Decision | Source |
|---|---|---|---|---|---|
| @napi-rs/cli | 3.8.6 | 3.8.6 | 2026-08-12 | Latest stable. Its peer ranges accept stable Emnapi 1.11.3; native and WASM artifact gates pass with that generation. | 3.8.6 package record |
| @emnapi/core | 1.11.3 | 1.11.3 stable | 2026-07-25 | Latest stable 1.x peer for the selected CLI and WASM runtime. | npm package record |
| @emnapi/runtime | 1.11.3 | 1.11.3 stable | 2026-07-25 | Latest stable 1.x peer for the selected CLI and WASM runtime. | npm package record |
| @napi-rs/wasm-runtime | 1.1.6 | 1.2.3 | 2026-06-24 | Version 1.1.6 is the newest stable line that supports Emnapi 1.x and does not raise the Node floor to 20.19. | npm package record |
| @types/node | 22.20.1 | 26.2.0 | 2026-07-08 | Keep the Node 22 type line. Newer types could admit APIs outside the public Node 20.17 contract. | npm package record |
| tsx | 4.23.12 | 4.23.12 | 2026-08-10 | Latest stable. | npm package record |
| zod | 4.4.3 | 4.4.3 | 2026-05-04 | Latest stable and the conformance oracle. | npm package record |
| arktype | 2.2.3 | 2.2.3 | 2026-07-07 | Latest stable resolution. | npm package record |
| valibot | 1.4.2 | 1.4.2 | 2026-06-28 | Latest stable resolution. | npm package record |
| tinybench | 6.1.3 | 6.1.3 | 2026-08-10 | Latest stable. It replaces dormant mitata. | npm package record |
| recheck | 4.5.0 | 4.5.0 stable | 2025-03-02 | Use the stable release instead of 4.6.0-beta.3. | npm package record |
| @seriousme/openapi-schema-validator | 2.9.1 | 2.9.1 | 2026-08-05 | Latest stable. | npm package record |
@web-std/file3.0.3 was last released on 2023-08-29. Node 20 provides the globalFileclass, so the platform API replaces it: Node 20.17 globals.mitata1.0.34 was last released on 2025-02-04.tinybench6.1.3 replaces it after passing the three-run performance gate: mitata package record.recheck4.6.0-beta.3 was replaced by stable 4.5.0: recheck package record.- Emnapi 2.0.0-alpha.3 was removed. The stable 1.11.3 generation passed native and WASM builds, installed-artifact checks, all backend conformance lanes, and a Node 20.17 WASM load.
sonic-rs 0.5.8 already parses deferred raw input and writes raw values. simd-json 0.17.3 parses through a mutable-byte API, which would force a copy at the immutable &[u8] zodrs boundary: simd-json from_slice.
sonic-rs is now the only JSON dependency. It provides the parser, the writer, and the value model. cargo-deny denies serde_json anywhere in the graph (deny.toml), so it cannot return.
Object ordering controls the design. In sonic-rs 0.5.8 a constructed sonic_rs::Object is an AHashMap. Mutation does not preserve insertion order. A parsed Sonic value preserves document order. The DOM stores it as a flat pair slice. The code therefore never builds ordered objects by mutation. The ordered Serialize writers (IssueWire and IssueList in crates/zodrs/src/issue.rs) produce the issue wire in field order. When a value tree is needed, the code parses that ordered serialized form back into a sonic_rs::Value.
sonic_rs::Value also cannot deserialize through Serde's internally-tagged
buffer. In sonic-rs 0.5.8 its Deserialize requests a private newtype token
that Sonic's own deserializer answers and Serde's buffered content
deserializer does not. PlanNode and Check are internally tagged, so Serde
buffers each node into Content before it reads the k or c tag, and a bare
Value field fails there. crates/zodrs/src/wire.rs writes the buffered value
back out as JSON text in visit order and parses it once. That solves the
ordering constraint above at the same time. crates/zodrs/tests/plan_wire.rs
pins both properties.
The streaming boundary measured real gains. The issue-heavy Rust probe improved from 77.15 ms to 22.6 ms, or 3.414x. The boundary preserves the old ordered-map behavior. This includes duplicate field replacement and path shadowing.