{ "$schema": "deps.schema.json", "repositories": [ { "name": "ada-url", "type": "bazel_dep" }, // BoringSSL is more likely to break than other dependencies, because our downstream build uses // a custom-built version of BoringSSL in FIPS mode. { "name": "boringssl", "type": "github_release", "use_bazel_dep": true, "owner": "google", "repo": "boringssl", "repo_name": "ssl", "freeze_version": "0.20251002.0", "patches": [ "//:patches/boringssl/0001-Expose-libdecrepit-so-NodeJS-can-use-it-for-ncrypto.patch" ] }, { "name": "brotli", "type": "bazel_dep" }, { "name": "zstd", "type": "bazel_dep" }, { "name": "tcmalloc", "type": "bazel_dep" }, { "name": "capnp-cpp", "type": "github_tarball", "owner": "capnproto", "repo": "capnproto", "branch": "v2", "extra_strip_prefix": "/c++" }, // We want to avoid version skew with v8, so we use identical versions. { "name": "dragonbox", "type": "github_tarball", "build_file_content": "cc_library(name = 'dragonbox', hdrs = glob(['include/dragonbox/*.h']), visibility = ['//visibility:public'], include_prefix = 'third_party/dragonbox/src')", "owner": "jk-jeon", "repo": "dragonbox", "freeze_commit": "beeeef91cf6fef89a4d4ba5e95d47ca64ccb3a44" }, // We want to avoid version skew with v8, so we use identical versions. { "name": "fast_float", "type": "github_tarball", "use_bazel_dep": true, "owner": "fastfloat", "repo": "fast_float", "branch": "main", "freeze_commit": "cb1d42aaa1e14b09e1452cfdef373d051b8c02a4", "build_file_content": "cc_library(name = 'fast_float', hdrs = glob(['include/fast_float/*.h']), visibility = ['//visibility:public'], include_prefix = 'third_party/fast_float/src')", "use_module_bazel_from_bcr": "8.0.2" }, // We want to avoid version skew with v8, so we use identical versions. { "name": "fp16", "type": "github_tarball", "use_bazel_dep": true, "owner": "Maratyszcza", "repo": "FP16", "freeze_commit": "3d2de1816307bac63c16a297e8c4dc501b4076df", "build_file_content": "exports_files(glob(['**']))", "use_module_bazel_from_bcr": "0.0.0-20210320-0a92994" }, // We want to avoid version skew with v8, so we use identical versions. { "name": "highway", "type": "github_tarball", "use_bazel_dep": true, "owner": "google", "repo": "highway", "freeze_commit": "84379d1c73de9681b54fbe1c035a23c7bd5d272d", "use_module_bazel_from_bcr": "1.3.0" }, { "name": "nbytes", "type": "github_release", "owner": "nodejs", "repo": "nbytes", "build_file": "//:build/BUILD.nbytes" }, { "name": "ncrypto", "type": "github_release", "owner": "nodejs", "repo": "ncrypto" }, { "name": "perfetto", "type": "github_release", "use_bazel_dep": true, "owner": "google", "repo": "perfetto", "patches": [ "//:patches/perfetto/0001-Don-t-attempt-to-use-rules_android.patch", "//:patches/perfetto/0002-disable-info-level-logging.patch" ] }, { "name": "simdutf", "type": "github_release", "owner": "simdutf", "repo": "simdutf", "build_file": "//:build/BUILD.simdutf", "file_regex": "singleheader.zip" }, // In theory this should match the version specified in V8 DEPS, but in practice we should get // the latest commit – zlib is very stable and its API has not changed in a long time, but we // want to pick up any bug fixes, security patches and performance improvements more quickly // than we would through V8 updates. { "name": "zlib", "type": "git_clone", "use_bazel_dep": true, "url": "https://chromium.googlesource.com/chromium/src/third_party/zlib.git", "branch": "main", "build_file": "//:build/BUILD.zlib", "patches": ["//:patches/zlib/0001-Add-dummy-MODULE.bazel.patch"] }, { "name": "workerd-cxx", "type": "github_tarball", "owner": "cloudflare", "repo": "workerd-cxx", "branch": "master" } ] }