Skip to content

[Due for payment 2026-10-01] chore(deps): Upgrade NitroModules from 0.36.3 to 0.37.1 #101472

Description

@MelvinBot

Summary

Update react-native-nitro-modules from 0.36.3 to the latest release (0.37.1), bump the packages that peer-depend on it, and refresh the generated and version-pinned code that follows from the bump.

Why update

  • NewDot is a minor behind the Nitro native runtime. 0.37.1 is the current published release; main is still on 0.36.3.
  • NitroFetch is blocked by the old pin. react-native-nitro-fetch@1.5.4 declares react-native-nitro-modules: ^0.36.1, so it cannot resolve against 0.37.x. 1.6.2 widens that range to >=0.36.1, which unblocks the runtime bump.
  • Nitrogen must track NitroModules exactly. The nitrogen codegen dependency ships in lockstep with the runtime, and nitrogen@0.37.1 depends on react-native-nitro-modules: ^0.37.1. Leaving the codegen behind produces bindings that don't match the runtime.

Scope

  • Bump in package.json:
    • react-native-nitro-modules 0.36.3 → 0.37.1
    • nitrogen (devDependency) 0.36.3 → 0.37.1
    • react-native-nitro-fetch 1.5.4 → 1.6.2 (the version whose peer range accepts 0.37.1)
  • Regenerate the local Nitro bindings for modules/ExpensifyNitroUtils. Nitrogen 0.37.1 adds a @FastNative annotation to the generated Android initHybrid() declarations for the contacts and app-start-time modules.
  • Rename Expensify's Android Cronet certificate-pinning patch to the new NitroFetch version so patch-package still applies it, and update the two places that reference the versioned filename:
  • Update the NitroModules and NitroFetch entries plus their checksums in ios/Podfile.lock.
  • Pin the same native versions in HybridApp's own lockfile in Mobile-Expensify via a companion PR, so standalone NewDot and HybridApp build against one runtime.

Out of scope

react-native-nitro-sqlite is tracked separately in chore(deps): Update NitroSQLite from 9.6.0 to 9.8.0 so the two dependency updates can be reviewed independently. The NitroModules bump should land after that one, keeping the SQLite changes out of its diff.

Testing

The change is native-runtime and lockfile only, so it needs real device builds on iOS and Android — chat send plus relaunch persistence, the contacts-backed participant search with permission granted and denied, and an offline/reconnect pass confirming no certificate-pinning errors.

Follow-up

react-native-nitro-fetch@1.7.0 is already published and its peer range (react-native-nitro-modules: >=0.36.1) also accepts 0.37.1. Decide whether to take 1.7.0 in this update or move to it separately afterwards.

Issue OwnerCurrent Issue Owner: @mallenexpensify

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Awaiting PaymentAuto-added when associated PR is deployed to productionDailyKSv2

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions