ci(rust): bump jaq-core from 2.2.1 to 3.1.1 - #98

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-core-3.1.1
Closed

ci(rust): bump jaq-core from 2.2.1 to 3.1.1#98
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-core-3.1.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-core from 2.2.1 to 3.1.1.

Release notes

Sourced from jaq-core's releases.

3.1.1

This release features a new man page that is now generated by jaq itself. Apart from demonstrating jaq's XHTML processing capabilities, this serves to lift jaq's build dependency on Pandoc (01mf02/jaq#442). To quote@​alerque, jaq's Arch Linux package maintainer: "For any other project I'd say this was an absurd way to work around not wanting to use a standard tool. I guess for this project to dog food itself is ... chaotic genius?" This comment alone was nearly worth the endeavour.

Furthermore, this release makes it possible to disable a few dependencies when using jaq via its API (#448, thanks to @​kleinesfilmroellchen!), and handles broken pipes more gracefully 01mf02/jaq#445.

New Contributors

Full Changelog: 01mf02/jaq@v3.1.0...v3.1.1

3.1

This release adds support for jq's input_filename filter --- thanks to @​a-n-d-r-e-w-l01mf02/jaq#432! Furthermore, at places where jaq accepted filters like .a["b"], it now also accepts (equivalent) filters such as .a.["b"] (note the added dot after .a). 01mf02/jaq#423 Finally, this release corrects the indexing of arrays with an empty array, which previously panicked 01mf02/jaq#439. Thanks to @​leeewee for spotting this!

API

The biggest change in this release is that calls to halt in jq filters can now be handled by users of the jaq API, instead of forcing a termination of the process. Thanks to @​a-n-d-r-e-w-l01mf02/jaq#433! This has a few implications:

  • The signature of jaq_all::data::run had to be changed, resulting in a new major version of jaq-all.
  • To preserve semantic versioning stability guarantees, the jaq_core::unwrap_valr function still terminates the current process if halt is called, but only if the std feature is enabled --- otherwise, unwrap_valr panics! You need to take action to prevent panics if all of the following conditions hold:
    1. you use jaq_core::unwrap_valr,
    2. you have disabled the std feature in jaq_core, and
    3. you run filters that may call halt.

Furthermore, this version makes it possible to clone definitions, which can speed up compiling many different jq filters. 01mf02/jaq#430

Full Changelog: 01mf02/jaq@v3.0.0...v3.1.0

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [jaq-core](https://github.com/01mf02/jaq) from 2.2.1 to 3.1.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits/v3.1.1)
---
updated-dependencies:
- dependency-name: jaq-core
dependency-version: 3.1.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 1, 2026
@dependabot
dependabotBot requested a review from a team as a code ownerSeptember 1, 2026 12:58
@dependabotdependabotBot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 1, 2026
@opieter-aws

Copy link
Copy Markdown

@strandly-the-agent review this major version upgrade. Do we need or want this? Clearly it beaks CI.

@strandly-the-agentstrandly-the-agent left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: close this PR — it can never go green, and Dependabot can't fix it. Recommend @dependabot ignore this major version (reopenable later).

Answering your questions directly:

  • Need it? No. cargo audit is clean on jaq 2.2.1 (the Security-audit leg passes), and jaq 3's headline safety win — halt no longer killing the host process — is already covered by our sandbox stubs in src/commands/jq.rs:44.
  • Why CI breaks: the PR bumps only jaq-core → 3.1.1, but jaq-std 2.1.2 and jaq-json 1.1.3 still pin jaq-core ^2, so both 2.2.1 and 3.1.1 end up in the graph and jq.rs fails with 15 type-mismatch errors (reproduced locally). Same dead end as #15/#4, which this superseded — this will recur every jaq-core release until we ignore the major or migrate.
  • Want it? Mildly, eventually — upstream focus is 3.x and it brings jq-compat fixes. I tested the real path: a coordinated jaq-core 3 + jaq-std 3 + jaq-json 2 bump resolves cleanly but leaves ~22 compile errors, all confined to src/commands/jq.rs (258 lines). A small manual migration PR — happy to open it if you want jaq 3; otherwise ignoring the major costs us nothing today.
Evidence & migration details

Verification ledger

  • ✅ Reviewed head d7b6d59 vs base 6fecd79; diff is Cargo.toml (jaq-core = "2""3") + Cargo.lock only.
  • ✅ Lockfile on this PR contains bothjaq-core 2.2.1 (via jaq-std/jaq-json) and jaq-core 3.1.1 (via strands-shell) — the dual-version graph is visible in the Cargo.lock diff.
  • cargo check --workspace on the PR head: 15 errors, e.g. rustc: "there are multiple different versions of crate jaq_core in the dependency graph" (expected jaq_core 2.2.1::Native<Val>, found 3.1.1::Native<Val> at jq.rs:74).
  • cargo check with the coordinated bump (jaq-core = "3", jaq-std = "3", jaq-json = "2"): resolves and builds deps fine, 22 errors, all in src/commands/jq.rs — no other file in the workspace touches jaq.
  • ✅ crates.io index: the coherent jaq-3 stack is jaq-core 3.1.1 + jaq-std 3.0.3 + jaq-json 2.0.3.
  • ⚠️ Unchecked: whether the jaq#439 empty-array-indexing panic (fixed in 3.1) is reachable through our jq builtin on 2.2.1 — my repro build hit a sandbox disk limit. If it is reachable, it's a user-triggerable panic and would strengthen the "want" case.

What the migration actually involves (from the 22 errors)

  • jaq_core::Native<V>Native<D: DataT> (use JustLut<Val>); the halt_error/env stub plumbing and Compiler generics change accordingly.
  • jaq_json::Val: From<serde_json::Value> is gone in jaq-json 2 — the serde interop moved (feature renamed serde_jsonserde, now via serde_core), so input/output conversion needs rewriting.
  • filter.run(...) moved (compile::Filter now wraps it; roughly filter.id.run(lut, ...)).
  • All confined to run_filter() in src/commands/jq.rs; existing jq integration tests in tests/shell_integration.rs cover the behavior, so regressions would surface.

Config note (why this keeps happening)

dependabot.yml deliberately leaves majors ungrouped for attribution, which is right in general — but lockstep crate families like jaq-* can never pass CI solo. A cargo groups entry matching jaq-* for major updates would at least produce one coherent candidate PR; it still can't write the jq.rs code changes, so the manual migration PR remains the actual path either way.

@dependabot@github

dependabotBot commented on behalf of githubSep 1, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabotBot deleted the dependabot/cargo/jaq-core-3.1.1 branch September 1, 2026 15:16
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filerustPull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@opieter-aws@strandly-the-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

ci(rust): bump jaq-core from 2.2.1 to 3.1.1 - #98

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-core-3.1.1
Closed

ci(rust): bump jaq-core from 2.2.1 to 3.1.1#98
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-core-3.1.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-core from 2.2.1 to 3.1.1.

Release notes

Sourced from jaq-core's releases.

3.1.1

This release features a new man page that is now generated by jaq itself. Apart from demonstrating jaq's XHTML processing capabilities, this serves to lift jaq's build dependency on Pandoc (01mf02/jaq#442). To quote@​alerque, jaq's Arch Linux package maintainer: "For any other project I'd say this was an absurd way to work around not wanting to use a standard tool. I guess for this project to dog food itself is ... chaotic genius?" This comment alone was nearly worth the endeavour.

Furthermore, this release makes it possible to disable a few dependencies when using jaq via its API (#448, thanks to @​kleinesfilmroellchen!), and handles broken pipes more gracefully 01mf02/jaq#445.

New Contributors

Full Changelog: 01mf02/jaq@v3.1.0...v3.1.1

3.1

This release adds support for jq's input_filename filter --- thanks to @​a-n-d-r-e-w-l01mf02/jaq#432! Furthermore, at places where jaq accepted filters like .a["b"], it now also accepts (equivalent) filters such as .a.["b"] (note the added dot after .a). 01mf02/jaq#423 Finally, this release corrects the indexing of arrays with an empty array, which previously panicked 01mf02/jaq#439. Thanks to @​leeewee for spotting this!

API

The biggest change in this release is that calls to halt in jq filters can now be handled by users of the jaq API, instead of forcing a termination of the process. Thanks to @​a-n-d-r-e-w-l01mf02/jaq#433! This has a few implications:

  • The signature of jaq_all::data::run had to be changed, resulting in a new major version of jaq-all.
  • To preserve semantic versioning stability guarantees, the jaq_core::unwrap_valr function still terminates the current process if halt is called, but only if the std feature is enabled --- otherwise, unwrap_valr panics! You need to take action to prevent panics if all of the following conditions hold:
    1. you use jaq_core::unwrap_valr,
    2. you have disabled the std feature in jaq_core, and
    3. you run filters that may call halt.

Furthermore, this version makes it possible to clone definitions, which can speed up compiling many different jq filters. 01mf02/jaq#430

Full Changelog: 01mf02/jaq@v3.0.0...v3.1.0

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [jaq-core](https://github.com/01mf02/jaq) from 2.2.1 to 3.1.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits/v3.1.1)
---
updated-dependencies:
- dependency-name: jaq-core
dependency-version: 3.1.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 1, 2026
@dependabot
dependabotBot requested a review from a team as a code ownerSeptember 1, 2026 12:58
@dependabotdependabotBot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 1, 2026
@opieter-aws

Copy link
Copy Markdown

@strandly-the-agent review this major version upgrade. Do we need or want this? Clearly it beaks CI.

@strandly-the-agentstrandly-the-agent left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: close this PR — it can never go green, and Dependabot can't fix it. Recommend @dependabot ignore this major version (reopenable later).

Answering your questions directly:

  • Need it? No. cargo audit is clean on jaq 2.2.1 (the Security-audit leg passes), and jaq 3's headline safety win — halt no longer killing the host process — is already covered by our sandbox stubs in src/commands/jq.rs:44.
  • Why CI breaks: the PR bumps only jaq-core → 3.1.1, but jaq-std 2.1.2 and jaq-json 1.1.3 still pin jaq-core ^2, so both 2.2.1 and 3.1.1 end up in the graph and jq.rs fails with 15 type-mismatch errors (reproduced locally). Same dead end as #15/#4, which this superseded — this will recur every jaq-core release until we ignore the major or migrate.
  • Want it? Mildly, eventually — upstream focus is 3.x and it brings jq-compat fixes. I tested the real path: a coordinated jaq-core 3 + jaq-std 3 + jaq-json 2 bump resolves cleanly but leaves ~22 compile errors, all confined to src/commands/jq.rs (258 lines). A small manual migration PR — happy to open it if you want jaq 3; otherwise ignoring the major costs us nothing today.
Evidence & migration details

Verification ledger

  • ✅ Reviewed head d7b6d59 vs base 6fecd79; diff is Cargo.toml (jaq-core = "2""3") + Cargo.lock only.
  • ✅ Lockfile on this PR contains bothjaq-core 2.2.1 (via jaq-std/jaq-json) and jaq-core 3.1.1 (via strands-shell) — the dual-version graph is visible in the Cargo.lock diff.
  • cargo check --workspace on the PR head: 15 errors, e.g. rustc: "there are multiple different versions of crate jaq_core in the dependency graph" (expected jaq_core 2.2.1::Native<Val>, found 3.1.1::Native<Val> at jq.rs:74).
  • cargo check with the coordinated bump (jaq-core = "3", jaq-std = "3", jaq-json = "2"): resolves and builds deps fine, 22 errors, all in src/commands/jq.rs — no other file in the workspace touches jaq.
  • ✅ crates.io index: the coherent jaq-3 stack is jaq-core 3.1.1 + jaq-std 3.0.3 + jaq-json 2.0.3.
  • ⚠️ Unchecked: whether the jaq#439 empty-array-indexing panic (fixed in 3.1) is reachable through our jq builtin on 2.2.1 — my repro build hit a sandbox disk limit. If it is reachable, it's a user-triggerable panic and would strengthen the "want" case.

What the migration actually involves (from the 22 errors)

  • jaq_core::Native<V>Native<D: DataT> (use JustLut<Val>); the halt_error/env stub plumbing and Compiler generics change accordingly.
  • jaq_json::Val: From<serde_json::Value> is gone in jaq-json 2 — the serde interop moved (feature renamed serde_jsonserde, now via serde_core), so input/output conversion needs rewriting.
  • filter.run(...) moved (compile::Filter now wraps it; roughly filter.id.run(lut, ...)).
  • All confined to run_filter() in src/commands/jq.rs; existing jq integration tests in tests/shell_integration.rs cover the behavior, so regressions would surface.

Config note (why this keeps happening)

dependabot.yml deliberately leaves majors ungrouped for attribution, which is right in general — but lockstep crate families like jaq-* can never pass CI solo. A cargo groups entry matching jaq-* for major updates would at least produce one coherent candidate PR; it still can't write the jq.rs code changes, so the manual migration PR remains the actual path either way.

@dependabot@github

dependabotBot commented on behalf of githubSep 1, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabotBot deleted the dependabot/cargo/jaq-core-3.1.1 branch September 1, 2026 15:16
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filerustPull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@opieter-aws@strandly-the-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(rust): bump jaq-core from 2.2.1 to 3.1.1 - #98

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-core-3.1.1
Closed

ci(rust): bump jaq-core from 2.2.1 to 3.1.1#98
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-core-3.1.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-core from 2.2.1 to 3.1.1.

Release notes

Sourced from jaq-core's releases.

3.1.1

This release features a new man page that is now generated by jaq itself. Apart from demonstrating jaq's XHTML processing capabilities, this serves to lift jaq's build dependency on Pandoc (01mf02/jaq#442). To quote@​alerque, jaq's Arch Linux package maintainer: "For any other project I'd say this was an absurd way to work around not wanting to use a standard tool. I guess for this project to dog food itself is ... chaotic genius?" This comment alone was nearly worth the endeavour.

Furthermore, this release makes it possible to disable a few dependencies when using jaq via its API (#448, thanks to @​kleinesfilmroellchen!), and handles broken pipes more gracefully 01mf02/jaq#445.

New Contributors

Full Changelog: 01mf02/jaq@v3.1.0...v3.1.1

3.1

This release adds support for jq's input_filename filter --- thanks to @​a-n-d-r-e-w-l01mf02/jaq#432! Furthermore, at places where jaq accepted filters like .a["b"], it now also accepts (equivalent) filters such as .a.["b"] (note the added dot after .a). 01mf02/jaq#423 Finally, this release corrects the indexing of arrays with an empty array, which previously panicked 01mf02/jaq#439. Thanks to @​leeewee for spotting this!

API

The biggest change in this release is that calls to halt in jq filters can now be handled by users of the jaq API, instead of forcing a termination of the process. Thanks to @​a-n-d-r-e-w-l01mf02/jaq#433! This has a few implications:

  • The signature of jaq_all::data::run had to be changed, resulting in a new major version of jaq-all.
  • To preserve semantic versioning stability guarantees, the jaq_core::unwrap_valr function still terminates the current process if halt is called, but only if the std feature is enabled --- otherwise, unwrap_valr panics! You need to take action to prevent panics if all of the following conditions hold:
    1. you use jaq_core::unwrap_valr,
    2. you have disabled the std feature in jaq_core, and
    3. you run filters that may call halt.

Furthermore, this version makes it possible to clone definitions, which can speed up compiling many different jq filters. 01mf02/jaq#430

Full Changelog: 01mf02/jaq@v3.0.0...v3.1.0

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [jaq-core](https://github.com/01mf02/jaq) from 2.2.1 to 3.1.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits/v3.1.1)
---
updated-dependencies:
- dependency-name: jaq-core
dependency-version: 3.1.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 1, 2026
@dependabot
dependabotBot requested a review from a team as a code ownerSeptember 1, 2026 12:58
@dependabotdependabotBot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 1, 2026
@opieter-aws

Copy link
Copy Markdown

@strandly-the-agent review this major version upgrade. Do we need or want this? Clearly it beaks CI.

@strandly-the-agentstrandly-the-agent left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: close this PR — it can never go green, and Dependabot can't fix it. Recommend @dependabot ignore this major version (reopenable later).

Answering your questions directly:

  • Need it? No. cargo audit is clean on jaq 2.2.1 (the Security-audit leg passes), and jaq 3's headline safety win — halt no longer killing the host process — is already covered by our sandbox stubs in src/commands/jq.rs:44.
  • Why CI breaks: the PR bumps only jaq-core → 3.1.1, but jaq-std 2.1.2 and jaq-json 1.1.3 still pin jaq-core ^2, so both 2.2.1 and 3.1.1 end up in the graph and jq.rs fails with 15 type-mismatch errors (reproduced locally). Same dead end as #15/#4, which this superseded — this will recur every jaq-core release until we ignore the major or migrate.
  • Want it? Mildly, eventually — upstream focus is 3.x and it brings jq-compat fixes. I tested the real path: a coordinated jaq-core 3 + jaq-std 3 + jaq-json 2 bump resolves cleanly but leaves ~22 compile errors, all confined to src/commands/jq.rs (258 lines). A small manual migration PR — happy to open it if you want jaq 3; otherwise ignoring the major costs us nothing today.
Evidence & migration details

Verification ledger

  • ✅ Reviewed head d7b6d59 vs base 6fecd79; diff is Cargo.toml (jaq-core = "2""3") + Cargo.lock only.
  • ✅ Lockfile on this PR contains bothjaq-core 2.2.1 (via jaq-std/jaq-json) and jaq-core 3.1.1 (via strands-shell) — the dual-version graph is visible in the Cargo.lock diff.
  • cargo check --workspace on the PR head: 15 errors, e.g. rustc: "there are multiple different versions of crate jaq_core in the dependency graph" (expected jaq_core 2.2.1::Native<Val>, found 3.1.1::Native<Val> at jq.rs:74).
  • cargo check with the coordinated bump (jaq-core = "3", jaq-std = "3", jaq-json = "2"): resolves and builds deps fine, 22 errors, all in src/commands/jq.rs — no other file in the workspace touches jaq.
  • ✅ crates.io index: the coherent jaq-3 stack is jaq-core 3.1.1 + jaq-std 3.0.3 + jaq-json 2.0.3.
  • ⚠️ Unchecked: whether the jaq#439 empty-array-indexing panic (fixed in 3.1) is reachable through our jq builtin on 2.2.1 — my repro build hit a sandbox disk limit. If it is reachable, it's a user-triggerable panic and would strengthen the "want" case.

What the migration actually involves (from the 22 errors)

  • jaq_core::Native<V>Native<D: DataT> (use JustLut<Val>); the halt_error/env stub plumbing and Compiler generics change accordingly.
  • jaq_json::Val: From<serde_json::Value> is gone in jaq-json 2 — the serde interop moved (feature renamed serde_jsonserde, now via serde_core), so input/output conversion needs rewriting.
  • filter.run(...) moved (compile::Filter now wraps it; roughly filter.id.run(lut, ...)).
  • All confined to run_filter() in src/commands/jq.rs; existing jq integration tests in tests/shell_integration.rs cover the behavior, so regressions would surface.

Config note (why this keeps happening)

dependabot.yml deliberately leaves majors ungrouped for attribution, which is right in general — but lockstep crate families like jaq-* can never pass CI solo. A cargo groups entry matching jaq-* for major updates would at least produce one coherent candidate PR; it still can't write the jq.rs code changes, so the manual migration PR remains the actual path either way.

@dependabot@github

dependabotBot commented on behalf of githubSep 1, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabotBot deleted the dependabot/cargo/jaq-core-3.1.1 branch September 1, 2026 15:16
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filerustPull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@opieter-aws@strandly-the-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(rust): bump jaq-core from 2.2.1 to 3.1.1 - #98

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-core-3.1.1
Closed

ci(rust): bump jaq-core from 2.2.1 to 3.1.1#98
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-core-3.1.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-core from 2.2.1 to 3.1.1.

Release notes

Sourced from jaq-core's releases.

3.1.1

This release features a new man page that is now generated by jaq itself. Apart from demonstrating jaq's XHTML processing capabilities, this serves to lift jaq's build dependency on Pandoc (01mf02/jaq#442). To quote@​alerque, jaq's Arch Linux package maintainer: "For any other project I'd say this was an absurd way to work around not wanting to use a standard tool. I guess for this project to dog food itself is ... chaotic genius?" This comment alone was nearly worth the endeavour.

Furthermore, this release makes it possible to disable a few dependencies when using jaq via its API (#448, thanks to @​kleinesfilmroellchen!), and handles broken pipes more gracefully 01mf02/jaq#445.

New Contributors

Full Changelog: 01mf02/jaq@v3.1.0...v3.1.1

3.1

This release adds support for jq's input_filename filter --- thanks to @​a-n-d-r-e-w-l01mf02/jaq#432! Furthermore, at places where jaq accepted filters like .a["b"], it now also accepts (equivalent) filters such as .a.["b"] (note the added dot after .a). 01mf02/jaq#423 Finally, this release corrects the indexing of arrays with an empty array, which previously panicked 01mf02/jaq#439. Thanks to @​leeewee for spotting this!

API

The biggest change in this release is that calls to halt in jq filters can now be handled by users of the jaq API, instead of forcing a termination of the process. Thanks to @​a-n-d-r-e-w-l01mf02/jaq#433! This has a few implications:

  • The signature of jaq_all::data::run had to be changed, resulting in a new major version of jaq-all.
  • To preserve semantic versioning stability guarantees, the jaq_core::unwrap_valr function still terminates the current process if halt is called, but only if the std feature is enabled --- otherwise, unwrap_valr panics! You need to take action to prevent panics if all of the following conditions hold:
    1. you use jaq_core::unwrap_valr,
    2. you have disabled the std feature in jaq_core, and
    3. you run filters that may call halt.

Furthermore, this version makes it possible to clone definitions, which can speed up compiling many different jq filters. 01mf02/jaq#430

Full Changelog: 01mf02/jaq@v3.0.0...v3.1.0

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [jaq-core](https://github.com/01mf02/jaq) from 2.2.1 to 3.1.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits/v3.1.1)
---
updated-dependencies:
- dependency-name: jaq-core
dependency-version: 3.1.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 1, 2026
@dependabot
dependabotBot requested a review from a team as a code ownerSeptember 1, 2026 12:58
@dependabotdependabotBot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 1, 2026
@opieter-aws

Copy link
Copy Markdown

@strandly-the-agent review this major version upgrade. Do we need or want this? Clearly it beaks CI.

@strandly-the-agentstrandly-the-agent left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: close this PR — it can never go green, and Dependabot can't fix it. Recommend @dependabot ignore this major version (reopenable later).

Answering your questions directly:

  • Need it? No. cargo audit is clean on jaq 2.2.1 (the Security-audit leg passes), and jaq 3's headline safety win — halt no longer killing the host process — is already covered by our sandbox stubs in src/commands/jq.rs:44.
  • Why CI breaks: the PR bumps only jaq-core → 3.1.1, but jaq-std 2.1.2 and jaq-json 1.1.3 still pin jaq-core ^2, so both 2.2.1 and 3.1.1 end up in the graph and jq.rs fails with 15 type-mismatch errors (reproduced locally). Same dead end as #15/#4, which this superseded — this will recur every jaq-core release until we ignore the major or migrate.
  • Want it? Mildly, eventually — upstream focus is 3.x and it brings jq-compat fixes. I tested the real path: a coordinated jaq-core 3 + jaq-std 3 + jaq-json 2 bump resolves cleanly but leaves ~22 compile errors, all confined to src/commands/jq.rs (258 lines). A small manual migration PR — happy to open it if you want jaq 3; otherwise ignoring the major costs us nothing today.
Evidence & migration details

Verification ledger

  • ✅ Reviewed head d7b6d59 vs base 6fecd79; diff is Cargo.toml (jaq-core = "2""3") + Cargo.lock only.
  • ✅ Lockfile on this PR contains bothjaq-core 2.2.1 (via jaq-std/jaq-json) and jaq-core 3.1.1 (via strands-shell) — the dual-version graph is visible in the Cargo.lock diff.
  • cargo check --workspace on the PR head: 15 errors, e.g. rustc: "there are multiple different versions of crate jaq_core in the dependency graph" (expected jaq_core 2.2.1::Native<Val>, found 3.1.1::Native<Val> at jq.rs:74).
  • cargo check with the coordinated bump (jaq-core = "3", jaq-std = "3", jaq-json = "2"): resolves and builds deps fine, 22 errors, all in src/commands/jq.rs — no other file in the workspace touches jaq.
  • ✅ crates.io index: the coherent jaq-3 stack is jaq-core 3.1.1 + jaq-std 3.0.3 + jaq-json 2.0.3.
  • ⚠️ Unchecked: whether the jaq#439 empty-array-indexing panic (fixed in 3.1) is reachable through our jq builtin on 2.2.1 — my repro build hit a sandbox disk limit. If it is reachable, it's a user-triggerable panic and would strengthen the "want" case.

What the migration actually involves (from the 22 errors)

  • jaq_core::Native<V>Native<D: DataT> (use JustLut<Val>); the halt_error/env stub plumbing and Compiler generics change accordingly.
  • jaq_json::Val: From<serde_json::Value> is gone in jaq-json 2 — the serde interop moved (feature renamed serde_jsonserde, now via serde_core), so input/output conversion needs rewriting.
  • filter.run(...) moved (compile::Filter now wraps it; roughly filter.id.run(lut, ...)).
  • All confined to run_filter() in src/commands/jq.rs; existing jq integration tests in tests/shell_integration.rs cover the behavior, so regressions would surface.

Config note (why this keeps happening)

dependabot.yml deliberately leaves majors ungrouped for attribution, which is right in general — but lockstep crate families like jaq-* can never pass CI solo. A cargo groups entry matching jaq-* for major updates would at least produce one coherent candidate PR; it still can't write the jq.rs code changes, so the manual migration PR remains the actual path either way.

@dependabot@github

dependabotBot commented on behalf of githubSep 1, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabotBot deleted the dependabot/cargo/jaq-core-3.1.1 branch September 1, 2026 15:16
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filerustPull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@opieter-aws@strandly-the-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

ci(rust): bump jaq-core from 2.2.1 to 3.1.1 - #98

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-core-3.1.1
Closed

ci(rust): bump jaq-core from 2.2.1 to 3.1.1#98
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-core-3.1.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-core from 2.2.1 to 3.1.1.

Release notes

Sourced from jaq-core's releases.

3.1.1

This release features a new man page that is now generated by jaq itself. Apart from demonstrating jaq's XHTML processing capabilities, this serves to lift jaq's build dependency on Pandoc (01mf02/jaq#442). To quote@​alerque, jaq's Arch Linux package maintainer: "For any other project I'd say this was an absurd way to work around not wanting to use a standard tool. I guess for this project to dog food itself is ... chaotic genius?" This comment alone was nearly worth the endeavour.

Furthermore, this release makes it possible to disable a few dependencies when using jaq via its API (#448, thanks to @​kleinesfilmroellchen!), and handles broken pipes more gracefully 01mf02/jaq#445.

New Contributors

Full Changelog: 01mf02/jaq@v3.1.0...v3.1.1

3.1

This release adds support for jq's input_filename filter --- thanks to @​a-n-d-r-e-w-l01mf02/jaq#432! Furthermore, at places where jaq accepted filters like .a["b"], it now also accepts (equivalent) filters such as .a.["b"] (note the added dot after .a). 01mf02/jaq#423 Finally, this release corrects the indexing of arrays with an empty array, which previously panicked 01mf02/jaq#439. Thanks to @​leeewee for spotting this!

API

The biggest change in this release is that calls to halt in jq filters can now be handled by users of the jaq API, instead of forcing a termination of the process. Thanks to @​a-n-d-r-e-w-l01mf02/jaq#433! This has a few implications:

  • The signature of jaq_all::data::run had to be changed, resulting in a new major version of jaq-all.
  • To preserve semantic versioning stability guarantees, the jaq_core::unwrap_valr function still terminates the current process if halt is called, but only if the std feature is enabled --- otherwise, unwrap_valr panics! You need to take action to prevent panics if all of the following conditions hold:
    1. you use jaq_core::unwrap_valr,
    2. you have disabled the std feature in jaq_core, and
    3. you run filters that may call halt.

Furthermore, this version makes it possible to clone definitions, which can speed up compiling many different jq filters. 01mf02/jaq#430

Full Changelog: 01mf02/jaq@v3.0.0...v3.1.0

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [jaq-core](https://github.com/01mf02/jaq) from 2.2.1 to 3.1.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits/v3.1.1)
---
updated-dependencies:
- dependency-name: jaq-core
dependency-version: 3.1.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 1, 2026
@dependabot
dependabotBot requested a review from a team as a code ownerSeptember 1, 2026 12:58
@dependabotdependabotBot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 1, 2026
@opieter-aws

Copy link
Copy Markdown

@strandly-the-agent review this major version upgrade. Do we need or want this? Clearly it beaks CI.

@strandly-the-agentstrandly-the-agent left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: close this PR — it can never go green, and Dependabot can't fix it. Recommend @dependabot ignore this major version (reopenable later).

Answering your questions directly:

  • Need it? No. cargo audit is clean on jaq 2.2.1 (the Security-audit leg passes), and jaq 3's headline safety win — halt no longer killing the host process — is already covered by our sandbox stubs in src/commands/jq.rs:44.
  • Why CI breaks: the PR bumps only jaq-core → 3.1.1, but jaq-std 2.1.2 and jaq-json 1.1.3 still pin jaq-core ^2, so both 2.2.1 and 3.1.1 end up in the graph and jq.rs fails with 15 type-mismatch errors (reproduced locally). Same dead end as #15/#4, which this superseded — this will recur every jaq-core release until we ignore the major or migrate.
  • Want it? Mildly, eventually — upstream focus is 3.x and it brings jq-compat fixes. I tested the real path: a coordinated jaq-core 3 + jaq-std 3 + jaq-json 2 bump resolves cleanly but leaves ~22 compile errors, all confined to src/commands/jq.rs (258 lines). A small manual migration PR — happy to open it if you want jaq 3; otherwise ignoring the major costs us nothing today.
Evidence & migration details

Verification ledger

  • ✅ Reviewed head d7b6d59 vs base 6fecd79; diff is Cargo.toml (jaq-core = "2""3") + Cargo.lock only.
  • ✅ Lockfile on this PR contains bothjaq-core 2.2.1 (via jaq-std/jaq-json) and jaq-core 3.1.1 (via strands-shell) — the dual-version graph is visible in the Cargo.lock diff.
  • cargo check --workspace on the PR head: 15 errors, e.g. rustc: "there are multiple different versions of crate jaq_core in the dependency graph" (expected jaq_core 2.2.1::Native<Val>, found 3.1.1::Native<Val> at jq.rs:74).
  • cargo check with the coordinated bump (jaq-core = "3", jaq-std = "3", jaq-json = "2"): resolves and builds deps fine, 22 errors, all in src/commands/jq.rs — no other file in the workspace touches jaq.
  • ✅ crates.io index: the coherent jaq-3 stack is jaq-core 3.1.1 + jaq-std 3.0.3 + jaq-json 2.0.3.
  • ⚠️ Unchecked: whether the jaq#439 empty-array-indexing panic (fixed in 3.1) is reachable through our jq builtin on 2.2.1 — my repro build hit a sandbox disk limit. If it is reachable, it's a user-triggerable panic and would strengthen the "want" case.

What the migration actually involves (from the 22 errors)

  • jaq_core::Native<V>Native<D: DataT> (use JustLut<Val>); the halt_error/env stub plumbing and Compiler generics change accordingly.
  • jaq_json::Val: From<serde_json::Value> is gone in jaq-json 2 — the serde interop moved (feature renamed serde_jsonserde, now via serde_core), so input/output conversion needs rewriting.
  • filter.run(...) moved (compile::Filter now wraps it; roughly filter.id.run(lut, ...)).
  • All confined to run_filter() in src/commands/jq.rs; existing jq integration tests in tests/shell_integration.rs cover the behavior, so regressions would surface.

Config note (why this keeps happening)

dependabot.yml deliberately leaves majors ungrouped for attribution, which is right in general — but lockstep crate families like jaq-* can never pass CI solo. A cargo groups entry matching jaq-* for major updates would at least produce one coherent candidate PR; it still can't write the jq.rs code changes, so the manual migration PR remains the actual path either way.

@dependabot@github

dependabotBot commented on behalf of githubSep 1, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabotBot deleted the dependabot/cargo/jaq-core-3.1.1 branch September 1, 2026 15:16
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filerustPull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@opieter-aws@strandly-the-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(rust): bump jaq-core from 2.2.1 to 3.1.1 - #98

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-core-3.1.1
Closed

ci(rust): bump jaq-core from 2.2.1 to 3.1.1#98
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-core-3.1.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-core from 2.2.1 to 3.1.1.

Release notes

Sourced from jaq-core's releases.

3.1.1

This release features a new man page that is now generated by jaq itself. Apart from demonstrating jaq's XHTML processing capabilities, this serves to lift jaq's build dependency on Pandoc (01mf02/jaq#442). To quote@​alerque, jaq's Arch Linux package maintainer: "For any other project I'd say this was an absurd way to work around not wanting to use a standard tool. I guess for this project to dog food itself is ... chaotic genius?" This comment alone was nearly worth the endeavour.

Furthermore, this release makes it possible to disable a few dependencies when using jaq via its API (#448, thanks to @​kleinesfilmroellchen!), and handles broken pipes more gracefully 01mf02/jaq#445.

New Contributors

Full Changelog: 01mf02/jaq@v3.1.0...v3.1.1

3.1

This release adds support for jq's input_filename filter --- thanks to @​a-n-d-r-e-w-l01mf02/jaq#432! Furthermore, at places where jaq accepted filters like .a["b"], it now also accepts (equivalent) filters such as .a.["b"] (note the added dot after .a). 01mf02/jaq#423 Finally, this release corrects the indexing of arrays with an empty array, which previously panicked 01mf02/jaq#439. Thanks to @​leeewee for spotting this!

API

The biggest change in this release is that calls to halt in jq filters can now be handled by users of the jaq API, instead of forcing a termination of the process. Thanks to @​a-n-d-r-e-w-l01mf02/jaq#433! This has a few implications:

  • The signature of jaq_all::data::run had to be changed, resulting in a new major version of jaq-all.
  • To preserve semantic versioning stability guarantees, the jaq_core::unwrap_valr function still terminates the current process if halt is called, but only if the std feature is enabled --- otherwise, unwrap_valr panics! You need to take action to prevent panics if all of the following conditions hold:
    1. you use jaq_core::unwrap_valr,
    2. you have disabled the std feature in jaq_core, and
    3. you run filters that may call halt.

Furthermore, this version makes it possible to clone definitions, which can speed up compiling many different jq filters. 01mf02/jaq#430

Full Changelog: 01mf02/jaq@v3.0.0...v3.1.0

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [jaq-core](https://github.com/01mf02/jaq) from 2.2.1 to 3.1.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits/v3.1.1)
---
updated-dependencies:
- dependency-name: jaq-core
dependency-version: 3.1.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 1, 2026
@dependabot
dependabotBot requested a review from a team as a code ownerSeptember 1, 2026 12:58
@dependabotdependabotBot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 1, 2026
@opieter-aws

Copy link
Copy Markdown

@strandly-the-agent review this major version upgrade. Do we need or want this? Clearly it beaks CI.

@strandly-the-agentstrandly-the-agent left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: close this PR — it can never go green, and Dependabot can't fix it. Recommend @dependabot ignore this major version (reopenable later).

Answering your questions directly:

  • Need it? No. cargo audit is clean on jaq 2.2.1 (the Security-audit leg passes), and jaq 3's headline safety win — halt no longer killing the host process — is already covered by our sandbox stubs in src/commands/jq.rs:44.
  • Why CI breaks: the PR bumps only jaq-core → 3.1.1, but jaq-std 2.1.2 and jaq-json 1.1.3 still pin jaq-core ^2, so both 2.2.1 and 3.1.1 end up in the graph and jq.rs fails with 15 type-mismatch errors (reproduced locally). Same dead end as #15/#4, which this superseded — this will recur every jaq-core release until we ignore the major or migrate.
  • Want it? Mildly, eventually — upstream focus is 3.x and it brings jq-compat fixes. I tested the real path: a coordinated jaq-core 3 + jaq-std 3 + jaq-json 2 bump resolves cleanly but leaves ~22 compile errors, all confined to src/commands/jq.rs (258 lines). A small manual migration PR — happy to open it if you want jaq 3; otherwise ignoring the major costs us nothing today.
Evidence & migration details

Verification ledger

  • ✅ Reviewed head d7b6d59 vs base 6fecd79; diff is Cargo.toml (jaq-core = "2""3") + Cargo.lock only.
  • ✅ Lockfile on this PR contains bothjaq-core 2.2.1 (via jaq-std/jaq-json) and jaq-core 3.1.1 (via strands-shell) — the dual-version graph is visible in the Cargo.lock diff.
  • cargo check --workspace on the PR head: 15 errors, e.g. rustc: "there are multiple different versions of crate jaq_core in the dependency graph" (expected jaq_core 2.2.1::Native<Val>, found 3.1.1::Native<Val> at jq.rs:74).
  • cargo check with the coordinated bump (jaq-core = "3", jaq-std = "3", jaq-json = "2"): resolves and builds deps fine, 22 errors, all in src/commands/jq.rs — no other file in the workspace touches jaq.
  • ✅ crates.io index: the coherent jaq-3 stack is jaq-core 3.1.1 + jaq-std 3.0.3 + jaq-json 2.0.3.
  • ⚠️ Unchecked: whether the jaq#439 empty-array-indexing panic (fixed in 3.1) is reachable through our jq builtin on 2.2.1 — my repro build hit a sandbox disk limit. If it is reachable, it's a user-triggerable panic and would strengthen the "want" case.

What the migration actually involves (from the 22 errors)

  • jaq_core::Native<V>Native<D: DataT> (use JustLut<Val>); the halt_error/env stub plumbing and Compiler generics change accordingly.
  • jaq_json::Val: From<serde_json::Value> is gone in jaq-json 2 — the serde interop moved (feature renamed serde_jsonserde, now via serde_core), so input/output conversion needs rewriting.
  • filter.run(...) moved (compile::Filter now wraps it; roughly filter.id.run(lut, ...)).
  • All confined to run_filter() in src/commands/jq.rs; existing jq integration tests in tests/shell_integration.rs cover the behavior, so regressions would surface.

Config note (why this keeps happening)

dependabot.yml deliberately leaves majors ungrouped for attribution, which is right in general — but lockstep crate families like jaq-* can never pass CI solo. A cargo groups entry matching jaq-* for major updates would at least produce one coherent candidate PR; it still can't write the jq.rs code changes, so the manual migration PR remains the actual path either way.

@dependabot@github

dependabotBot commented on behalf of githubSep 1, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabotBot deleted the dependabot/cargo/jaq-core-3.1.1 branch September 1, 2026 15:16
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filerustPull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@opieter-aws@strandly-the-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(rust): bump jaq-core from 2.2.1 to 3.1.1 - #98

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-core-3.1.1
Closed

ci(rust): bump jaq-core from 2.2.1 to 3.1.1#98
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-core-3.1.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-core from 2.2.1 to 3.1.1.

Release notes

Sourced from jaq-core's releases.

3.1.1

This release features a new man page that is now generated by jaq itself. Apart from demonstrating jaq's XHTML processing capabilities, this serves to lift jaq's build dependency on Pandoc (01mf02/jaq#442). To quote@​alerque, jaq's Arch Linux package maintainer: "For any other project I'd say this was an absurd way to work around not wanting to use a standard tool. I guess for this project to dog food itself is ... chaotic genius?" This comment alone was nearly worth the endeavour.

Furthermore, this release makes it possible to disable a few dependencies when using jaq via its API (#448, thanks to @​kleinesfilmroellchen!), and handles broken pipes more gracefully 01mf02/jaq#445.

New Contributors

Full Changelog: 01mf02/jaq@v3.1.0...v3.1.1

3.1

This release adds support for jq's input_filename filter --- thanks to @​a-n-d-r-e-w-l01mf02/jaq#432! Furthermore, at places where jaq accepted filters like .a["b"], it now also accepts (equivalent) filters such as .a.["b"] (note the added dot after .a). 01mf02/jaq#423 Finally, this release corrects the indexing of arrays with an empty array, which previously panicked 01mf02/jaq#439. Thanks to @​leeewee for spotting this!

API

The biggest change in this release is that calls to halt in jq filters can now be handled by users of the jaq API, instead of forcing a termination of the process. Thanks to @​a-n-d-r-e-w-l01mf02/jaq#433! This has a few implications:

  • The signature of jaq_all::data::run had to be changed, resulting in a new major version of jaq-all.
  • To preserve semantic versioning stability guarantees, the jaq_core::unwrap_valr function still terminates the current process if halt is called, but only if the std feature is enabled --- otherwise, unwrap_valr panics! You need to take action to prevent panics if all of the following conditions hold:
    1. you use jaq_core::unwrap_valr,
    2. you have disabled the std feature in jaq_core, and
    3. you run filters that may call halt.

Furthermore, this version makes it possible to clone definitions, which can speed up compiling many different jq filters. 01mf02/jaq#430

Full Changelog: 01mf02/jaq@v3.0.0...v3.1.0

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [jaq-core](https://github.com/01mf02/jaq) from 2.2.1 to 3.1.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits/v3.1.1)
---
updated-dependencies:
- dependency-name: jaq-core
dependency-version: 3.1.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 1, 2026
@dependabot
dependabotBot requested a review from a team as a code ownerSeptember 1, 2026 12:58
@dependabotdependabotBot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 1, 2026
@opieter-aws

Copy link
Copy Markdown

@strandly-the-agent review this major version upgrade. Do we need or want this? Clearly it beaks CI.

@strandly-the-agentstrandly-the-agent left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: close this PR — it can never go green, and Dependabot can't fix it. Recommend @dependabot ignore this major version (reopenable later).

Answering your questions directly:

  • Need it? No. cargo audit is clean on jaq 2.2.1 (the Security-audit leg passes), and jaq 3's headline safety win — halt no longer killing the host process — is already covered by our sandbox stubs in src/commands/jq.rs:44.
  • Why CI breaks: the PR bumps only jaq-core → 3.1.1, but jaq-std 2.1.2 and jaq-json 1.1.3 still pin jaq-core ^2, so both 2.2.1 and 3.1.1 end up in the graph and jq.rs fails with 15 type-mismatch errors (reproduced locally). Same dead end as #15/#4, which this superseded — this will recur every jaq-core release until we ignore the major or migrate.
  • Want it? Mildly, eventually — upstream focus is 3.x and it brings jq-compat fixes. I tested the real path: a coordinated jaq-core 3 + jaq-std 3 + jaq-json 2 bump resolves cleanly but leaves ~22 compile errors, all confined to src/commands/jq.rs (258 lines). A small manual migration PR — happy to open it if you want jaq 3; otherwise ignoring the major costs us nothing today.
Evidence & migration details

Verification ledger

  • ✅ Reviewed head d7b6d59 vs base 6fecd79; diff is Cargo.toml (jaq-core = "2""3") + Cargo.lock only.
  • ✅ Lockfile on this PR contains bothjaq-core 2.2.1 (via jaq-std/jaq-json) and jaq-core 3.1.1 (via strands-shell) — the dual-version graph is visible in the Cargo.lock diff.
  • cargo check --workspace on the PR head: 15 errors, e.g. rustc: "there are multiple different versions of crate jaq_core in the dependency graph" (expected jaq_core 2.2.1::Native<Val>, found 3.1.1::Native<Val> at jq.rs:74).
  • cargo check with the coordinated bump (jaq-core = "3", jaq-std = "3", jaq-json = "2"): resolves and builds deps fine, 22 errors, all in src/commands/jq.rs — no other file in the workspace touches jaq.
  • ✅ crates.io index: the coherent jaq-3 stack is jaq-core 3.1.1 + jaq-std 3.0.3 + jaq-json 2.0.3.
  • ⚠️ Unchecked: whether the jaq#439 empty-array-indexing panic (fixed in 3.1) is reachable through our jq builtin on 2.2.1 — my repro build hit a sandbox disk limit. If it is reachable, it's a user-triggerable panic and would strengthen the "want" case.

What the migration actually involves (from the 22 errors)

  • jaq_core::Native<V>Native<D: DataT> (use JustLut<Val>); the halt_error/env stub plumbing and Compiler generics change accordingly.
  • jaq_json::Val: From<serde_json::Value> is gone in jaq-json 2 — the serde interop moved (feature renamed serde_jsonserde, now via serde_core), so input/output conversion needs rewriting.
  • filter.run(...) moved (compile::Filter now wraps it; roughly filter.id.run(lut, ...)).
  • All confined to run_filter() in src/commands/jq.rs; existing jq integration tests in tests/shell_integration.rs cover the behavior, so regressions would surface.

Config note (why this keeps happening)

dependabot.yml deliberately leaves majors ungrouped for attribution, which is right in general — but lockstep crate families like jaq-* can never pass CI solo. A cargo groups entry matching jaq-* for major updates would at least produce one coherent candidate PR; it still can't write the jq.rs code changes, so the manual migration PR remains the actual path either way.

@dependabot@github

dependabotBot commented on behalf of githubSep 1, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabotBot deleted the dependabot/cargo/jaq-core-3.1.1 branch September 1, 2026 15:16
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filerustPull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@opieter-aws@strandly-the-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

ci(rust): bump jaq-core from 2.2.1 to 3.1.1 - #98

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-core-3.1.1
Closed

ci(rust): bump jaq-core from 2.2.1 to 3.1.1#98
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-core-3.1.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-core from 2.2.1 to 3.1.1.

Release notes

Sourced from jaq-core's releases.

3.1.1

This release features a new man page that is now generated by jaq itself. Apart from demonstrating jaq's XHTML processing capabilities, this serves to lift jaq's build dependency on Pandoc (01mf02/jaq#442). To quote@​alerque, jaq's Arch Linux package maintainer: "For any other project I'd say this was an absurd way to work around not wanting to use a standard tool. I guess for this project to dog food itself is ... chaotic genius?" This comment alone was nearly worth the endeavour.

Furthermore, this release makes it possible to disable a few dependencies when using jaq via its API (#448, thanks to @​kleinesfilmroellchen!), and handles broken pipes more gracefully 01mf02/jaq#445.

New Contributors

Full Changelog: 01mf02/jaq@v3.1.0...v3.1.1

3.1

This release adds support for jq's input_filename filter --- thanks to @​a-n-d-r-e-w-l01mf02/jaq#432! Furthermore, at places where jaq accepted filters like .a["b"], it now also accepts (equivalent) filters such as .a.["b"] (note the added dot after .a). 01mf02/jaq#423 Finally, this release corrects the indexing of arrays with an empty array, which previously panicked 01mf02/jaq#439. Thanks to @​leeewee for spotting this!

API

The biggest change in this release is that calls to halt in jq filters can now be handled by users of the jaq API, instead of forcing a termination of the process. Thanks to @​a-n-d-r-e-w-l01mf02/jaq#433! This has a few implications:

  • The signature of jaq_all::data::run had to be changed, resulting in a new major version of jaq-all.
  • To preserve semantic versioning stability guarantees, the jaq_core::unwrap_valr function still terminates the current process if halt is called, but only if the std feature is enabled --- otherwise, unwrap_valr panics! You need to take action to prevent panics if all of the following conditions hold:
    1. you use jaq_core::unwrap_valr,
    2. you have disabled the std feature in jaq_core, and
    3. you run filters that may call halt.

Furthermore, this version makes it possible to clone definitions, which can speed up compiling many different jq filters. 01mf02/jaq#430

Full Changelog: 01mf02/jaq@v3.0.0...v3.1.0

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [jaq-core](https://github.com/01mf02/jaq) from 2.2.1 to 3.1.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits/v3.1.1)
---
updated-dependencies:
- dependency-name: jaq-core
dependency-version: 3.1.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 1, 2026
@dependabot
dependabotBot requested a review from a team as a code ownerSeptember 1, 2026 12:58
@dependabotdependabotBot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 1, 2026
@opieter-aws

Copy link
Copy Markdown

@strandly-the-agent review this major version upgrade. Do we need or want this? Clearly it beaks CI.

@strandly-the-agentstrandly-the-agent left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: close this PR — it can never go green, and Dependabot can't fix it. Recommend @dependabot ignore this major version (reopenable later).

Answering your questions directly:

  • Need it? No. cargo audit is clean on jaq 2.2.1 (the Security-audit leg passes), and jaq 3's headline safety win — halt no longer killing the host process — is already covered by our sandbox stubs in src/commands/jq.rs:44.
  • Why CI breaks: the PR bumps only jaq-core → 3.1.1, but jaq-std 2.1.2 and jaq-json 1.1.3 still pin jaq-core ^2, so both 2.2.1 and 3.1.1 end up in the graph and jq.rs fails with 15 type-mismatch errors (reproduced locally). Same dead end as #15/#4, which this superseded — this will recur every jaq-core release until we ignore the major or migrate.
  • Want it? Mildly, eventually — upstream focus is 3.x and it brings jq-compat fixes. I tested the real path: a coordinated jaq-core 3 + jaq-std 3 + jaq-json 2 bump resolves cleanly but leaves ~22 compile errors, all confined to src/commands/jq.rs (258 lines). A small manual migration PR — happy to open it if you want jaq 3; otherwise ignoring the major costs us nothing today.
Evidence & migration details

Verification ledger

  • ✅ Reviewed head d7b6d59 vs base 6fecd79; diff is Cargo.toml (jaq-core = "2""3") + Cargo.lock only.
  • ✅ Lockfile on this PR contains bothjaq-core 2.2.1 (via jaq-std/jaq-json) and jaq-core 3.1.1 (via strands-shell) — the dual-version graph is visible in the Cargo.lock diff.
  • cargo check --workspace on the PR head: 15 errors, e.g. rustc: "there are multiple different versions of crate jaq_core in the dependency graph" (expected jaq_core 2.2.1::Native<Val>, found 3.1.1::Native<Val> at jq.rs:74).
  • cargo check with the coordinated bump (jaq-core = "3", jaq-std = "3", jaq-json = "2"): resolves and builds deps fine, 22 errors, all in src/commands/jq.rs — no other file in the workspace touches jaq.
  • ✅ crates.io index: the coherent jaq-3 stack is jaq-core 3.1.1 + jaq-std 3.0.3 + jaq-json 2.0.3.
  • ⚠️ Unchecked: whether the jaq#439 empty-array-indexing panic (fixed in 3.1) is reachable through our jq builtin on 2.2.1 — my repro build hit a sandbox disk limit. If it is reachable, it's a user-triggerable panic and would strengthen the "want" case.

What the migration actually involves (from the 22 errors)

  • jaq_core::Native<V>Native<D: DataT> (use JustLut<Val>); the halt_error/env stub plumbing and Compiler generics change accordingly.
  • jaq_json::Val: From<serde_json::Value> is gone in jaq-json 2 — the serde interop moved (feature renamed serde_jsonserde, now via serde_core), so input/output conversion needs rewriting.
  • filter.run(...) moved (compile::Filter now wraps it; roughly filter.id.run(lut, ...)).
  • All confined to run_filter() in src/commands/jq.rs; existing jq integration tests in tests/shell_integration.rs cover the behavior, so regressions would surface.

Config note (why this keeps happening)

dependabot.yml deliberately leaves majors ungrouped for attribution, which is right in general — but lockstep crate families like jaq-* can never pass CI solo. A cargo groups entry matching jaq-* for major updates would at least produce one coherent candidate PR; it still can't write the jq.rs code changes, so the manual migration PR remains the actual path either way.

@dependabot@github

dependabotBot commented on behalf of githubSep 1, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabotBot deleted the dependabot/cargo/jaq-core-3.1.1 branch September 1, 2026 15:16
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filerustPull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@opieter-aws@strandly-the-agent