ci(rust): bump jaq-std from 2.1.2 to 3.0.1 - #4

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1
Closed

ci(rust): bump jaq-std from 2.1.2 to 3.0.1#4
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubJun 15, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-std from 2.1.2 to 3.0.1.

Release notes

Sourced from jaq-std's releases.

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

Changes since 3.0-gamma:

See the release notes for alpha, beta, and gamma for more details on all changes since jaq 2.3.

3.0 gamma

This release increases jq compatibility, introduces a new format (raw0), and decreases memory consumption.

A preliminary version of this release has received a security audit by @​dnet from Radically Open Security (ROS). This release addresses the raised concerns. Thanks a lot to NLnet for having funded the security audit!

With the security audit being done, this concludes the NLnet-funded project Polyglot jaq, meaning that all goals set out in the beginning were achieved. Again, thanks so much to NLnet for having supported jaq development for about two years!

jq features

Formats

Corrections

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot@github

dependabotBot commented on behalf of githubJun 15, 2026

Copy link
Copy Markdown
ContributorAuthor

Labels

The following labels could not be found: dependencies, rust. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Bumps [jaq-std](https://github.com/01mf02/jaq) from 2.1.2 to 3.0.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits)
---
updated-dependencies:
- dependency-name: jaq-std
dependency-version: 3.0.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@strandly-the-agent

Copy link
Copy Markdown

Triage: 🔴 DEFER — Dependency conflict

Status: Major version bump blocked by unresolved jaq-core/jaq-json coordination.

The blocker

This PR bumps jaq-std 2.1.2 → 3.0.1 in Cargo.toml ("2" → "3"), but leaves jaq-core = "2" pinned. Meanwhile, jaq-std 3.0.1 requires jaq-core 3.1.0. The Cargo.lock shows both versions in the dependency graph, and the test rollup fails.

Dependency state in PR:

jaq-std 3.0.1 (PR) — requires → jaq-core 3.1.0 ✓ in lock
jaq-json 1.1.3 (unchanged) — requires → jaq-core 2.2.1 ✓ in lock

So both jaq-core 2.2.1 and 3.1.0 are pulled in. Cargo allows semver-compatible coexistence, but the build still fails—likely API incompatibility or link issues.

What's needed

Before accept, resolve the dependency mismatch via one of:

  1. Also bump jaq-core in Cargo.toml ("2" → "3") if jaq-json 1.1.3 supports it
  2. Coordinate with jaq-json — wait for 1.2+ targeting jaq-core 3.x, or confirm 1.1.3 works with both
  3. Clarify coordination — does this depend on jaq-core ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15? If so, link and sequence.

Code review scope (once unblocked)

  • Correctness: Verify jaq-std 3.0.1 API stability (defs/funs signatures in src/commands/jq.rs:44-46, jaq_std::Filter, jaq_std::v(0))
  • Time handling: jaq 3.0 replaces chrono with jiff for dates; verify time-based filters still work
  • Test quality: Confirm existing tests pass; new multi-format features (YAML, CSV, etc.) if user-facing

Action

Reply with:

  1. Is this waiting on jaq ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15, or should jaq-core version also be bumped in this PR?
  2. Can jaq-json 1.1.3 work with jaq-core 3.1.0, or does it need an upgrade?
  3. Once resolved, push an updated Cargo.toml and re-run tests.

@dependabot@github

dependabotBot commented on behalf of githubAug 18, 2026

Copy link
Copy Markdown
ContributorAuthor

Superseded by #95.

@dependabotdependabotBot closed this Aug 18, 2026
@dependabot
dependabotBot deleted the dependabot/cargo/jaq-std-3.0.1 branch August 18, 2026 12:55
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@strandly-the-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

ci(rust): bump jaq-std from 2.1.2 to 3.0.1 - #4

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1
Closed

ci(rust): bump jaq-std from 2.1.2 to 3.0.1#4
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubJun 15, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-std from 2.1.2 to 3.0.1.

Release notes

Sourced from jaq-std's releases.

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

Changes since 3.0-gamma:

See the release notes for alpha, beta, and gamma for more details on all changes since jaq 2.3.

3.0 gamma

This release increases jq compatibility, introduces a new format (raw0), and decreases memory consumption.

A preliminary version of this release has received a security audit by @​dnet from Radically Open Security (ROS). This release addresses the raised concerns. Thanks a lot to NLnet for having funded the security audit!

With the security audit being done, this concludes the NLnet-funded project Polyglot jaq, meaning that all goals set out in the beginning were achieved. Again, thanks so much to NLnet for having supported jaq development for about two years!

jq features

Formats

Corrections

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot@github

dependabotBot commented on behalf of githubJun 15, 2026

Copy link
Copy Markdown
ContributorAuthor

Labels

The following labels could not be found: dependencies, rust. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Bumps [jaq-std](https://github.com/01mf02/jaq) from 2.1.2 to 3.0.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits)
---
updated-dependencies:
- dependency-name: jaq-std
dependency-version: 3.0.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@strandly-the-agent

Copy link
Copy Markdown

Triage: 🔴 DEFER — Dependency conflict

Status: Major version bump blocked by unresolved jaq-core/jaq-json coordination.

The blocker

This PR bumps jaq-std 2.1.2 → 3.0.1 in Cargo.toml ("2" → "3"), but leaves jaq-core = "2" pinned. Meanwhile, jaq-std 3.0.1 requires jaq-core 3.1.0. The Cargo.lock shows both versions in the dependency graph, and the test rollup fails.

Dependency state in PR:

jaq-std 3.0.1 (PR) — requires → jaq-core 3.1.0 ✓ in lock
jaq-json 1.1.3 (unchanged) — requires → jaq-core 2.2.1 ✓ in lock

So both jaq-core 2.2.1 and 3.1.0 are pulled in. Cargo allows semver-compatible coexistence, but the build still fails—likely API incompatibility or link issues.

What's needed

Before accept, resolve the dependency mismatch via one of:

  1. Also bump jaq-core in Cargo.toml ("2" → "3") if jaq-json 1.1.3 supports it
  2. Coordinate with jaq-json — wait for 1.2+ targeting jaq-core 3.x, or confirm 1.1.3 works with both
  3. Clarify coordination — does this depend on jaq-core ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15? If so, link and sequence.

Code review scope (once unblocked)

  • Correctness: Verify jaq-std 3.0.1 API stability (defs/funs signatures in src/commands/jq.rs:44-46, jaq_std::Filter, jaq_std::v(0))
  • Time handling: jaq 3.0 replaces chrono with jiff for dates; verify time-based filters still work
  • Test quality: Confirm existing tests pass; new multi-format features (YAML, CSV, etc.) if user-facing

Action

Reply with:

  1. Is this waiting on jaq ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15, or should jaq-core version also be bumped in this PR?
  2. Can jaq-json 1.1.3 work with jaq-core 3.1.0, or does it need an upgrade?
  3. Once resolved, push an updated Cargo.toml and re-run tests.

@dependabot@github

dependabotBot commented on behalf of githubAug 18, 2026

Copy link
Copy Markdown
ContributorAuthor

Superseded by #95.

@dependabotdependabotBot closed this Aug 18, 2026
@dependabot
dependabotBot deleted the dependabot/cargo/jaq-std-3.0.1 branch August 18, 2026 12:55
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@strandly-the-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(rust): bump jaq-std from 2.1.2 to 3.0.1 - #4

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1
Closed

ci(rust): bump jaq-std from 2.1.2 to 3.0.1#4
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubJun 15, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-std from 2.1.2 to 3.0.1.

Release notes

Sourced from jaq-std's releases.

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

Changes since 3.0-gamma:

See the release notes for alpha, beta, and gamma for more details on all changes since jaq 2.3.

3.0 gamma

This release increases jq compatibility, introduces a new format (raw0), and decreases memory consumption.

A preliminary version of this release has received a security audit by @​dnet from Radically Open Security (ROS). This release addresses the raised concerns. Thanks a lot to NLnet for having funded the security audit!

With the security audit being done, this concludes the NLnet-funded project Polyglot jaq, meaning that all goals set out in the beginning were achieved. Again, thanks so much to NLnet for having supported jaq development for about two years!

jq features

Formats

Corrections

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot@github

dependabotBot commented on behalf of githubJun 15, 2026

Copy link
Copy Markdown
ContributorAuthor

Labels

The following labels could not be found: dependencies, rust. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Bumps [jaq-std](https://github.com/01mf02/jaq) from 2.1.2 to 3.0.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits)
---
updated-dependencies:
- dependency-name: jaq-std
dependency-version: 3.0.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@strandly-the-agent

Copy link
Copy Markdown

Triage: 🔴 DEFER — Dependency conflict

Status: Major version bump blocked by unresolved jaq-core/jaq-json coordination.

The blocker

This PR bumps jaq-std 2.1.2 → 3.0.1 in Cargo.toml ("2" → "3"), but leaves jaq-core = "2" pinned. Meanwhile, jaq-std 3.0.1 requires jaq-core 3.1.0. The Cargo.lock shows both versions in the dependency graph, and the test rollup fails.

Dependency state in PR:

jaq-std 3.0.1 (PR) — requires → jaq-core 3.1.0 ✓ in lock
jaq-json 1.1.3 (unchanged) — requires → jaq-core 2.2.1 ✓ in lock

So both jaq-core 2.2.1 and 3.1.0 are pulled in. Cargo allows semver-compatible coexistence, but the build still fails—likely API incompatibility or link issues.

What's needed

Before accept, resolve the dependency mismatch via one of:

  1. Also bump jaq-core in Cargo.toml ("2" → "3") if jaq-json 1.1.3 supports it
  2. Coordinate with jaq-json — wait for 1.2+ targeting jaq-core 3.x, or confirm 1.1.3 works with both
  3. Clarify coordination — does this depend on jaq-core ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15? If so, link and sequence.

Code review scope (once unblocked)

  • Correctness: Verify jaq-std 3.0.1 API stability (defs/funs signatures in src/commands/jq.rs:44-46, jaq_std::Filter, jaq_std::v(0))
  • Time handling: jaq 3.0 replaces chrono with jiff for dates; verify time-based filters still work
  • Test quality: Confirm existing tests pass; new multi-format features (YAML, CSV, etc.) if user-facing

Action

Reply with:

  1. Is this waiting on jaq ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15, or should jaq-core version also be bumped in this PR?
  2. Can jaq-json 1.1.3 work with jaq-core 3.1.0, or does it need an upgrade?
  3. Once resolved, push an updated Cargo.toml and re-run tests.

@dependabot@github

dependabotBot commented on behalf of githubAug 18, 2026

Copy link
Copy Markdown
ContributorAuthor

Superseded by #95.

@dependabotdependabotBot closed this Aug 18, 2026
@dependabot
dependabotBot deleted the dependabot/cargo/jaq-std-3.0.1 branch August 18, 2026 12:55
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@strandly-the-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(rust): bump jaq-std from 2.1.2 to 3.0.1 - #4

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1
Closed

ci(rust): bump jaq-std from 2.1.2 to 3.0.1#4
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubJun 15, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-std from 2.1.2 to 3.0.1.

Release notes

Sourced from jaq-std's releases.

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

Changes since 3.0-gamma:

See the release notes for alpha, beta, and gamma for more details on all changes since jaq 2.3.

3.0 gamma

This release increases jq compatibility, introduces a new format (raw0), and decreases memory consumption.

A preliminary version of this release has received a security audit by @​dnet from Radically Open Security (ROS). This release addresses the raised concerns. Thanks a lot to NLnet for having funded the security audit!

With the security audit being done, this concludes the NLnet-funded project Polyglot jaq, meaning that all goals set out in the beginning were achieved. Again, thanks so much to NLnet for having supported jaq development for about two years!

jq features

Formats

Corrections

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot@github

dependabotBot commented on behalf of githubJun 15, 2026

Copy link
Copy Markdown
ContributorAuthor

Labels

The following labels could not be found: dependencies, rust. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Bumps [jaq-std](https://github.com/01mf02/jaq) from 2.1.2 to 3.0.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits)
---
updated-dependencies:
- dependency-name: jaq-std
dependency-version: 3.0.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@strandly-the-agent

Copy link
Copy Markdown

Triage: 🔴 DEFER — Dependency conflict

Status: Major version bump blocked by unresolved jaq-core/jaq-json coordination.

The blocker

This PR bumps jaq-std 2.1.2 → 3.0.1 in Cargo.toml ("2" → "3"), but leaves jaq-core = "2" pinned. Meanwhile, jaq-std 3.0.1 requires jaq-core 3.1.0. The Cargo.lock shows both versions in the dependency graph, and the test rollup fails.

Dependency state in PR:

jaq-std 3.0.1 (PR) — requires → jaq-core 3.1.0 ✓ in lock
jaq-json 1.1.3 (unchanged) — requires → jaq-core 2.2.1 ✓ in lock

So both jaq-core 2.2.1 and 3.1.0 are pulled in. Cargo allows semver-compatible coexistence, but the build still fails—likely API incompatibility or link issues.

What's needed

Before accept, resolve the dependency mismatch via one of:

  1. Also bump jaq-core in Cargo.toml ("2" → "3") if jaq-json 1.1.3 supports it
  2. Coordinate with jaq-json — wait for 1.2+ targeting jaq-core 3.x, or confirm 1.1.3 works with both
  3. Clarify coordination — does this depend on jaq-core ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15? If so, link and sequence.

Code review scope (once unblocked)

  • Correctness: Verify jaq-std 3.0.1 API stability (defs/funs signatures in src/commands/jq.rs:44-46, jaq_std::Filter, jaq_std::v(0))
  • Time handling: jaq 3.0 replaces chrono with jiff for dates; verify time-based filters still work
  • Test quality: Confirm existing tests pass; new multi-format features (YAML, CSV, etc.) if user-facing

Action

Reply with:

  1. Is this waiting on jaq ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15, or should jaq-core version also be bumped in this PR?
  2. Can jaq-json 1.1.3 work with jaq-core 3.1.0, or does it need an upgrade?
  3. Once resolved, push an updated Cargo.toml and re-run tests.

@dependabot@github

dependabotBot commented on behalf of githubAug 18, 2026

Copy link
Copy Markdown
ContributorAuthor

Superseded by #95.

@dependabotdependabotBot closed this Aug 18, 2026
@dependabot
dependabotBot deleted the dependabot/cargo/jaq-std-3.0.1 branch August 18, 2026 12:55
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@strandly-the-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

ci(rust): bump jaq-std from 2.1.2 to 3.0.1 - #4

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1
Closed

ci(rust): bump jaq-std from 2.1.2 to 3.0.1#4
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubJun 15, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-std from 2.1.2 to 3.0.1.

Release notes

Sourced from jaq-std's releases.

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

Changes since 3.0-gamma:

See the release notes for alpha, beta, and gamma for more details on all changes since jaq 2.3.

3.0 gamma

This release increases jq compatibility, introduces a new format (raw0), and decreases memory consumption.

A preliminary version of this release has received a security audit by @​dnet from Radically Open Security (ROS). This release addresses the raised concerns. Thanks a lot to NLnet for having funded the security audit!

With the security audit being done, this concludes the NLnet-funded project Polyglot jaq, meaning that all goals set out in the beginning were achieved. Again, thanks so much to NLnet for having supported jaq development for about two years!

jq features

Formats

Corrections

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot@github

dependabotBot commented on behalf of githubJun 15, 2026

Copy link
Copy Markdown
ContributorAuthor

Labels

The following labels could not be found: dependencies, rust. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Bumps [jaq-std](https://github.com/01mf02/jaq) from 2.1.2 to 3.0.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits)
---
updated-dependencies:
- dependency-name: jaq-std
dependency-version: 3.0.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@strandly-the-agent

Copy link
Copy Markdown

Triage: 🔴 DEFER — Dependency conflict

Status: Major version bump blocked by unresolved jaq-core/jaq-json coordination.

The blocker

This PR bumps jaq-std 2.1.2 → 3.0.1 in Cargo.toml ("2" → "3"), but leaves jaq-core = "2" pinned. Meanwhile, jaq-std 3.0.1 requires jaq-core 3.1.0. The Cargo.lock shows both versions in the dependency graph, and the test rollup fails.

Dependency state in PR:

jaq-std 3.0.1 (PR) — requires → jaq-core 3.1.0 ✓ in lock
jaq-json 1.1.3 (unchanged) — requires → jaq-core 2.2.1 ✓ in lock

So both jaq-core 2.2.1 and 3.1.0 are pulled in. Cargo allows semver-compatible coexistence, but the build still fails—likely API incompatibility or link issues.

What's needed

Before accept, resolve the dependency mismatch via one of:

  1. Also bump jaq-core in Cargo.toml ("2" → "3") if jaq-json 1.1.3 supports it
  2. Coordinate with jaq-json — wait for 1.2+ targeting jaq-core 3.x, or confirm 1.1.3 works with both
  3. Clarify coordination — does this depend on jaq-core ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15? If so, link and sequence.

Code review scope (once unblocked)

  • Correctness: Verify jaq-std 3.0.1 API stability (defs/funs signatures in src/commands/jq.rs:44-46, jaq_std::Filter, jaq_std::v(0))
  • Time handling: jaq 3.0 replaces chrono with jiff for dates; verify time-based filters still work
  • Test quality: Confirm existing tests pass; new multi-format features (YAML, CSV, etc.) if user-facing

Action

Reply with:

  1. Is this waiting on jaq ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15, or should jaq-core version also be bumped in this PR?
  2. Can jaq-json 1.1.3 work with jaq-core 3.1.0, or does it need an upgrade?
  3. Once resolved, push an updated Cargo.toml and re-run tests.

@dependabot@github

dependabotBot commented on behalf of githubAug 18, 2026

Copy link
Copy Markdown
ContributorAuthor

Superseded by #95.

@dependabotdependabotBot closed this Aug 18, 2026
@dependabot
dependabotBot deleted the dependabot/cargo/jaq-std-3.0.1 branch August 18, 2026 12:55
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@strandly-the-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(rust): bump jaq-std from 2.1.2 to 3.0.1 - #4

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1
Closed

ci(rust): bump jaq-std from 2.1.2 to 3.0.1#4
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubJun 15, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-std from 2.1.2 to 3.0.1.

Release notes

Sourced from jaq-std's releases.

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

Changes since 3.0-gamma:

See the release notes for alpha, beta, and gamma for more details on all changes since jaq 2.3.

3.0 gamma

This release increases jq compatibility, introduces a new format (raw0), and decreases memory consumption.

A preliminary version of this release has received a security audit by @​dnet from Radically Open Security (ROS). This release addresses the raised concerns. Thanks a lot to NLnet for having funded the security audit!

With the security audit being done, this concludes the NLnet-funded project Polyglot jaq, meaning that all goals set out in the beginning were achieved. Again, thanks so much to NLnet for having supported jaq development for about two years!

jq features

Formats

Corrections

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot@github

dependabotBot commented on behalf of githubJun 15, 2026

Copy link
Copy Markdown
ContributorAuthor

Labels

The following labels could not be found: dependencies, rust. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Bumps [jaq-std](https://github.com/01mf02/jaq) from 2.1.2 to 3.0.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits)
---
updated-dependencies:
- dependency-name: jaq-std
dependency-version: 3.0.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@strandly-the-agent

Copy link
Copy Markdown

Triage: 🔴 DEFER — Dependency conflict

Status: Major version bump blocked by unresolved jaq-core/jaq-json coordination.

The blocker

This PR bumps jaq-std 2.1.2 → 3.0.1 in Cargo.toml ("2" → "3"), but leaves jaq-core = "2" pinned. Meanwhile, jaq-std 3.0.1 requires jaq-core 3.1.0. The Cargo.lock shows both versions in the dependency graph, and the test rollup fails.

Dependency state in PR:

jaq-std 3.0.1 (PR) — requires → jaq-core 3.1.0 ✓ in lock
jaq-json 1.1.3 (unchanged) — requires → jaq-core 2.2.1 ✓ in lock

So both jaq-core 2.2.1 and 3.1.0 are pulled in. Cargo allows semver-compatible coexistence, but the build still fails—likely API incompatibility or link issues.

What's needed

Before accept, resolve the dependency mismatch via one of:

  1. Also bump jaq-core in Cargo.toml ("2" → "3") if jaq-json 1.1.3 supports it
  2. Coordinate with jaq-json — wait for 1.2+ targeting jaq-core 3.x, or confirm 1.1.3 works with both
  3. Clarify coordination — does this depend on jaq-core ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15? If so, link and sequence.

Code review scope (once unblocked)

  • Correctness: Verify jaq-std 3.0.1 API stability (defs/funs signatures in src/commands/jq.rs:44-46, jaq_std::Filter, jaq_std::v(0))
  • Time handling: jaq 3.0 replaces chrono with jiff for dates; verify time-based filters still work
  • Test quality: Confirm existing tests pass; new multi-format features (YAML, CSV, etc.) if user-facing

Action

Reply with:

  1. Is this waiting on jaq ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15, or should jaq-core version also be bumped in this PR?
  2. Can jaq-json 1.1.3 work with jaq-core 3.1.0, or does it need an upgrade?
  3. Once resolved, push an updated Cargo.toml and re-run tests.

@dependabot@github

dependabotBot commented on behalf of githubAug 18, 2026

Copy link
Copy Markdown
ContributorAuthor

Superseded by #95.

@dependabotdependabotBot closed this Aug 18, 2026
@dependabot
dependabotBot deleted the dependabot/cargo/jaq-std-3.0.1 branch August 18, 2026 12:55
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@strandly-the-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(rust): bump jaq-std from 2.1.2 to 3.0.1 - #4

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1
Closed

ci(rust): bump jaq-std from 2.1.2 to 3.0.1#4
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubJun 15, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-std from 2.1.2 to 3.0.1.

Release notes

Sourced from jaq-std's releases.

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

Changes since 3.0-gamma:

See the release notes for alpha, beta, and gamma for more details on all changes since jaq 2.3.

3.0 gamma

This release increases jq compatibility, introduces a new format (raw0), and decreases memory consumption.

A preliminary version of this release has received a security audit by @​dnet from Radically Open Security (ROS). This release addresses the raised concerns. Thanks a lot to NLnet for having funded the security audit!

With the security audit being done, this concludes the NLnet-funded project Polyglot jaq, meaning that all goals set out in the beginning were achieved. Again, thanks so much to NLnet for having supported jaq development for about two years!

jq features

Formats

Corrections

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot@github

dependabotBot commented on behalf of githubJun 15, 2026

Copy link
Copy Markdown
ContributorAuthor

Labels

The following labels could not be found: dependencies, rust. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Bumps [jaq-std](https://github.com/01mf02/jaq) from 2.1.2 to 3.0.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits)
---
updated-dependencies:
- dependency-name: jaq-std
dependency-version: 3.0.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@strandly-the-agent

Copy link
Copy Markdown

Triage: 🔴 DEFER — Dependency conflict

Status: Major version bump blocked by unresolved jaq-core/jaq-json coordination.

The blocker

This PR bumps jaq-std 2.1.2 → 3.0.1 in Cargo.toml ("2" → "3"), but leaves jaq-core = "2" pinned. Meanwhile, jaq-std 3.0.1 requires jaq-core 3.1.0. The Cargo.lock shows both versions in the dependency graph, and the test rollup fails.

Dependency state in PR:

jaq-std 3.0.1 (PR) — requires → jaq-core 3.1.0 ✓ in lock
jaq-json 1.1.3 (unchanged) — requires → jaq-core 2.2.1 ✓ in lock

So both jaq-core 2.2.1 and 3.1.0 are pulled in. Cargo allows semver-compatible coexistence, but the build still fails—likely API incompatibility or link issues.

What's needed

Before accept, resolve the dependency mismatch via one of:

  1. Also bump jaq-core in Cargo.toml ("2" → "3") if jaq-json 1.1.3 supports it
  2. Coordinate with jaq-json — wait for 1.2+ targeting jaq-core 3.x, or confirm 1.1.3 works with both
  3. Clarify coordination — does this depend on jaq-core ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15? If so, link and sequence.

Code review scope (once unblocked)

  • Correctness: Verify jaq-std 3.0.1 API stability (defs/funs signatures in src/commands/jq.rs:44-46, jaq_std::Filter, jaq_std::v(0))
  • Time handling: jaq 3.0 replaces chrono with jiff for dates; verify time-based filters still work
  • Test quality: Confirm existing tests pass; new multi-format features (YAML, CSV, etc.) if user-facing

Action

Reply with:

  1. Is this waiting on jaq ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15, or should jaq-core version also be bumped in this PR?
  2. Can jaq-json 1.1.3 work with jaq-core 3.1.0, or does it need an upgrade?
  3. Once resolved, push an updated Cargo.toml and re-run tests.

@dependabot@github

dependabotBot commented on behalf of githubAug 18, 2026

Copy link
Copy Markdown
ContributorAuthor

Superseded by #95.

@dependabotdependabotBot closed this Aug 18, 2026
@dependabot
dependabotBot deleted the dependabot/cargo/jaq-std-3.0.1 branch August 18, 2026 12:55
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@strandly-the-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

ci(rust): bump jaq-std from 2.1.2 to 3.0.1 - #4

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1
Closed

ci(rust): bump jaq-std from 2.1.2 to 3.0.1#4
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubJun 15, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-std from 2.1.2 to 3.0.1.

Release notes

Sourced from jaq-std's releases.

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

Changes since 3.0-gamma:

See the release notes for alpha, beta, and gamma for more details on all changes since jaq 2.3.

3.0 gamma

This release increases jq compatibility, introduces a new format (raw0), and decreases memory consumption.

A preliminary version of this release has received a security audit by @​dnet from Radically Open Security (ROS). This release addresses the raised concerns. Thanks a lot to NLnet for having funded the security audit!

With the security audit being done, this concludes the NLnet-funded project Polyglot jaq, meaning that all goals set out in the beginning were achieved. Again, thanks so much to NLnet for having supported jaq development for about two years!

jq features

Formats

Corrections

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot@github

dependabotBot commented on behalf of githubJun 15, 2026

Copy link
Copy Markdown
ContributorAuthor

Labels

The following labels could not be found: dependencies, rust. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Bumps [jaq-std](https://github.com/01mf02/jaq) from 2.1.2 to 3.0.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits)
---
updated-dependencies:
- dependency-name: jaq-std
dependency-version: 3.0.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@strandly-the-agent

Copy link
Copy Markdown

Triage: 🔴 DEFER — Dependency conflict

Status: Major version bump blocked by unresolved jaq-core/jaq-json coordination.

The blocker

This PR bumps jaq-std 2.1.2 → 3.0.1 in Cargo.toml ("2" → "3"), but leaves jaq-core = "2" pinned. Meanwhile, jaq-std 3.0.1 requires jaq-core 3.1.0. The Cargo.lock shows both versions in the dependency graph, and the test rollup fails.

Dependency state in PR:

jaq-std 3.0.1 (PR) — requires → jaq-core 3.1.0 ✓ in lock
jaq-json 1.1.3 (unchanged) — requires → jaq-core 2.2.1 ✓ in lock

So both jaq-core 2.2.1 and 3.1.0 are pulled in. Cargo allows semver-compatible coexistence, but the build still fails—likely API incompatibility or link issues.

What's needed

Before accept, resolve the dependency mismatch via one of:

  1. Also bump jaq-core in Cargo.toml ("2" → "3") if jaq-json 1.1.3 supports it
  2. Coordinate with jaq-json — wait for 1.2+ targeting jaq-core 3.x, or confirm 1.1.3 works with both
  3. Clarify coordination — does this depend on jaq-core ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15? If so, link and sequence.

Code review scope (once unblocked)

  • Correctness: Verify jaq-std 3.0.1 API stability (defs/funs signatures in src/commands/jq.rs:44-46, jaq_std::Filter, jaq_std::v(0))
  • Time handling: jaq 3.0 replaces chrono with jiff for dates; verify time-based filters still work
  • Test quality: Confirm existing tests pass; new multi-format features (YAML, CSV, etc.) if user-facing

Action

Reply with:

  1. Is this waiting on jaq ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15, or should jaq-core version also be bumped in this PR?
  2. Can jaq-json 1.1.3 work with jaq-core 3.1.0, or does it need an upgrade?
  3. Once resolved, push an updated Cargo.toml and re-run tests.

@dependabot@github

dependabotBot commented on behalf of githubAug 18, 2026

Copy link
Copy Markdown
ContributorAuthor

Superseded by #95.

@dependabotdependabotBot closed this Aug 18, 2026
@dependabot
dependabotBot deleted the dependabot/cargo/jaq-std-3.0.1 branch August 18, 2026 12:55
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@strandly-the-agent