Skip to content

Update dependency Jint to 4.17.0 - #2393

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/jint-4.x
Oct 7, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/jint-4.x

Conversation

@renovate

@renovate renovate Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
Jint 4.16.4 → 4.17.0 age confidence

Release Notes

sebastienros/jint (Jint)

v4.17.0

Jint 4.17.0 is a release from the 4.x branch. It backports correctness and conformance fixes from main (four of them for scripts that could end the host process), linear string building, and two new opt-in APIs for hosts. That is why it is a minor release rather than a patch. Nothing in it changes an existing API or an existing default, so it is a drop-in update from 4.16.4.

Highlights

A pooled engine can let go of a finished request's objects. Hosts that reuse one engine across many evaluations (CaptureGlobalSnapshot once, RestoreGlobalSnapshot between runs) keep the interpreter's warmed caches, and that is the point of reusing it. But a warmed call site remembers the last function it called, and a warmed member read remembers the last object it read from. In a pooled web host, that can be a delegate built from a finished request's services, which then stay alive until the same script runs again. The new Engine.Advanced.DiscardInterpreterCaches() drops those caches, so the objects can be collected. The engine, its intrinsics and its global object stay as they are. The next run of each script rebuilds its cache, which costs roughly what a first run on a new engine costs, minus building the engine. A good place to call it is when an engine has been idle for a while, rather than after every use (#​4229, from #​4227).

A host can carry its own state across await. Jint now runs ECMAScript's HostMakeJobCallback and HostCallJobCallback steps for every promise reaction, every thenable job and the FinalizationRegistry cleanup callback. A host can take part through the new Options.Host.JobCallbacks, which accepts a JobCallbackHooks with Capture, Enter and Exit callbacks. That lets each branch of a Promise.all fan-out keep its own host context, such as a logging scope or ambient request data, through every await (#​4231, from #​4230; issue #​4200). The default is no hooks, in which case each promise registration costs one null check and nothing a script can observe changes.

Four more ways for a script to end the host process are closed.

  • ShadowRealm. A failure crossing a ShadowRealm boundary threw its TypeError copy from inside the catch that was handling the original failure. That added a nested exception dispatch at every hop, and no stack check could see it. Even with the stack-overflow guard on, a long chain of wrapped functions ended the process on the way back out, and a three-line script with a name getter needed no chain at all. Building that copy also ran script (toString, getters, proxy traps); it no longer does. A failed importValue now reports the import failure instead of an unrelated error (#​4220, from #​4176 and #​4183).
  • instanceof and eval. instanceof now checks the native stack before calling a custom Symbol.hasInstance method, and eval checks it before parsing. A self-referencing Symbol.hasInstance, or var s = 'eval(s)'; eval(s), now raises a RangeError the script can catch instead of ending the process. On the MaxExecutionStackCount path, eval also stopped hopping to a new thread at each overflow without ever throwing. instanceof over a bound function now consults every bound link's own Symbol.hasInstance, as the specification requires (#​4221, from #​4172, #​4184 and #​4187).
  • These checks follow 4.x's existing rule. Like every other stack check on 4.x, they are active only when Options.Constraints.StackOverflowGuard is on, so turn it on for any script you do not fully trust.

Building a string with s = s + x is linear. A + whose result reaches 512 characters now produces a deferred string instead of copying both sides. Building with s = s + x, s = x + s and s = s + a + b therefore becomes linear, as s += x already was. Short concatenations take a separate path and pay nothing for this. The deferred string is safe to read from several engines that share one Prepared<Script>, and it is charged to LimitMemory when it is built, so a memory limit still bounds it. Binding an already-bound function also no longer copies its whole "bound …" name at every level (#​4160, from #​3386, #​3571, #​4130, #​4164 and #​4173).

Array.prototype.concat spreads host arrays and lists. Since 4.14, CLR arrays and lists reach script as live views by default. concat added such a view as a single element instead of spreading its items, so a.concat(b) returned the two wrappers. It now spreads anything script sees as an array (#​4219, from #​4216; issue #​4201).

TypedArray.prototype.with survives a shrinking coercion. When converting the index or the value made a resizable buffer shorter, with copied past its new end and let a CLR ArgumentException escape. It now copies only what the buffer still holds (#​4218, from #​4157).

Verification

Every backport was verified failing-first: its tests were run against the unfixed 4.x tree on .NET 10 and .NET Framework 4.7.2, then with the change. The release candidate was measured against 4.16.4 on SunSpider and Dromaeo in six paired rounds, alternating which build ran first in each round. The four Dromaeo ObjectRegExp rows ran 12–15% faster and SunSpider's 3d-raytrace 2.3% faster. No row regressed by 1% or more; the two rows whose interval did not include zero (one Dromaeo Cube variant, +0.70%, and SunSpider's controlflow-recursive, +0.88%) are within this machine's run-to-run noise.

What's Changed

Full Changelog: sebastienros/jint@v4.16.4...v4.17.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Oct 7, 2026
@renovate
renovate Bot enabled auto-merge (squash) October 7, 2026 05:08
@renovate
renovate Bot merged commit 9992858 into main Oct 7, 2026
2 checks passed
@renovate
renovate Bot deleted the renovate/jint-4.x branch October 7, 2026 10:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

Development

Successfully merging this pull request may close these issues.

1 participant