Skip to content

ci(rust): bump jaq-std from 2.1.2 to 3.0.1#4

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1
Open

ci(rust): bump jaq-std from 2.1.2 to 3.0.1#4
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/jaq-std-3.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 15, 2026

Copy link
Copy Markdown
Contributor

Bumps jaq-std from 2.1.2 to 3.0.1.

Release notes

Sourced from jaq-std's releases.

3.0

jaq is a jq clone with focus on correctness, speed, and simplicity.

The most outstanding change in jaq 3.0 is its multi-format support, allowing you to read and write several data formats such as YAML, CBOR, TOML, XML, CSV, TSV, and of course JSON. That means that among others, jaq can convert data from one format into another, while transforming data with a jq filter. This effectively makes it into a "Pandoc for structured data". Achieving this has been the main focus of the NLnet-founded "Polyglot jaq" project, which has been successfully finished. A huge thanks to NLnet for supporting jaq and, more generally, free software!

Other large user-facing changes include:

  • Manual: jaq now has a full jq and jaq reference manual. This was a monumental effort into which I poured a lot of love, and I hope that you enjoy reading it as much as I enjoyed putting easter eggs into it. Bonus: You also get a man page. (For package maintainers: Man page build instructions can be found in docs/README.md.)
  • Byte strings: You can now read strings that contain arbitrary contents, including invalid UTF-8 sequences. (When a string is read from a file, this takes only constant time, thanks to memory mapping.) You can then mark these strings as byte strings via tobytes, allowing you to index/slice them in constant time. This allows you to process arbitrary binary data efficiently with jaq --- as proof of concept, I implemented a little TAR decoder.
  • Arbitrary values as object keys: Where jq supports only strings as object keys, jaq supports arbitrary values as object keys.
  • Compatibility improvements: Although this release adds many new features to jaq that do not exist in jq, this release still increases compatibility with jq. For example, jaq now supports path/1 and many other path-related filters.

API:

  • New jaq-all crate for easier "batteries-included" jaq usage
  • Passing arbitrary data to native filters
  • Optional thread-safe jaq_json::Val when enabling the sync feature, allowing for multithreaded usage of values, e.g. running multiple filters in parallel on the same value

Changes since 3.0-gamma:

See the release notes for alpha, beta, and gamma for more details on all changes since jaq 2.3.

3.0 gamma

This release increases jq compatibility, introduces a new format (raw0), and decreases memory consumption.

A preliminary version of this release has received a security audit by @​dnet from Radically Open Security (ROS). This release addresses the raised concerns. Thanks a lot to NLnet for having funded the security audit!

With the security audit being done, this concludes the NLnet-funded project Polyglot jaq, meaning that all goals set out in the beginning were achieved. Again, thanks so much to NLnet for having supported jaq development for about two years!

jq features

Formats

Corrections

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot @github

dependabot Bot commented on behalf of github Jun 15, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, rust. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Bumps [jaq-std](https://github.com/01mf02/jaq) from 2.1.2 to 3.0.1.
- [Release notes](https://github.com/01mf02/jaq/releases)
- [Commits](https://github.com/01mf02/jaq/commits)

---
updated-dependencies:
- dependency-name: jaq-std
  dependency-version: 3.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@strandly-the-agent

Copy link
Copy Markdown

Triage: 🔴 DEFER — Dependency conflict

Status: Major version bump blocked by unresolved jaq-core/jaq-json coordination.

The blocker

This PR bumps jaq-std 2.1.2 → 3.0.1 in Cargo.toml ("2" → "3"), but leaves jaq-core = "2" pinned. Meanwhile, jaq-std 3.0.1 requires jaq-core 3.1.0. The Cargo.lock shows both versions in the dependency graph, and the test rollup fails.

Dependency state in PR:

jaq-std 3.0.1 (PR) — requires → jaq-core 3.1.0 ✓ in lock
jaq-json 1.1.3 (unchanged) — requires → jaq-core 2.2.1 ✓ in lock

So both jaq-core 2.2.1 and 3.1.0 are pulled in. Cargo allows semver-compatible coexistence, but the build still fails—likely API incompatibility or link issues.

What's needed

Before accept, resolve the dependency mismatch via one of:

  1. Also bump jaq-core in Cargo.toml ("2" → "3") if jaq-json 1.1.3 supports it
  2. Coordinate with jaq-json — wait for 1.2+ targeting jaq-core 3.x, or confirm 1.1.3 works with both
  3. Clarify coordination — does this depend on jaq-core ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15? If so, link and sequence.

Code review scope (once unblocked)

  • Correctness: Verify jaq-std 3.0.1 API stability (defs/funs signatures in src/commands/jq.rs:44-46, jaq_std::Filter, jaq_std::v(0))
  • Time handling: jaq 3.0 replaces chrono with jiff for dates; verify time-based filters still work
  • Test quality: Confirm existing tests pass; new multi-format features (YAML, CSV, etc.) if user-facing

Action

Reply with:

  1. Is this waiting on jaq ci(rust): bump jaq-core from 2.2.1 to 3.1.0 #15, or should jaq-core version also be bumped in this PR?
  2. Can jaq-json 1.1.3 work with jaq-core 3.1.0, or does it need an upgrade?
  3. Once resolved, push an updated Cargo.toml and re-run tests.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant