Skip to content

Releases: jqlang/jq

jq 1.8.2

Choose a tag to compare

@github-actions github-actions released this 20 Jun 14:11
34f7186

This is a patch release with security fixes and bug fixes since 1.8.1, along with new builds for Windows arm64 and Docker arm/v7.
Full commit log can be found at jq-1.8.1...jq-1.8.2.

Security fixes

  • CVE-2026-32316: Fix heap buffer overflow in jvp_string_append and jvp_string_copy_replace_bad. @itchyny e47e56d
  • CVE-2026-33947: Limit path depth to prevent stack overflow in jv_setpath, jv_getpath, jv_delpaths. @itchyny fb59f14
  • CVE-2026-33948: Fix NUL truncation in the JSON parser. @itchyny 6374ae0
  • CVE-2026-39956: Fix _strindices missing runtime type checks. @tlsbollei fdf8ef0
  • CVE-2026-39979: Fix out-of-bounds read in jv_parse_sized(). @wader 2f09060
  • CVE-2026-40164: Randomize hash seed to mitigate hash collision DoS attacks. @AsafMeizner @itchyny 0c7d133
  • CVE-2026-40612: Limit containment check depth to prevent stack overflow in contains. @itchyny d1a1256
  • CVE-2026-41256: Fix NUL truncation in program files loaded with -f. @itchyny 5a015de
  • CVE-2026-41257: Fix signed-int overflow in stack_reallocate. @itchyny 01b3cde
  • CVE-2026-43894: Reject numeric literals longer than DEC_MAX_DIGITS (999999999). @itchyny 9761ceb
  • CVE-2026-43895: Reject embedded NUL bytes in module import paths. @itchyny 9d223f1
  • CVE-2026-43896: Limit recursive object merge depth to prevent stack overflow. @itchyny 532ccea
  • CVE-2026-44777: Detect circular module imports to prevent stack overflow. @itchyny f58787c
  • CVE-2026-47770: Guard deep structural equality and comparison recursion. @fuyu0425 7122866
  • CVE-2026-49839: Fix heap-buffer-overflow in raw file loading. @itchyny e987df0
  • CVE-2026-54679: Tighten string length bounds and propagate invalid jv in implode. @itchyny 46d1da3
  • GHSA-gf4g-95wj-4q4r: Fix use-after-free in args2obj() array argument path. @sseal #3498
  • GHSA-hj52-j2c9-r8r4: Fix signed-int overflow in tokenadd to prevent buffer overflow. @itchyny 63751f8
  • Limit the number of function parameters and definitions to prevent SEGV. @OwenSanzas #3460
  • Pre-allocate tokenbuf for string parser to avoid undefined behavior. @fab1ano #3485
  • Avoid stack overflow when freeing deeply nested values. @itchyny 33d7bce
  • Fix memory leaks and double frees. @itchyny #3487

Releasing

  • Add builds for Windows arm64. @dennisameling #3376
  • Support arm/v7 architecture in Docker images. @itchyny #3463
  • Update GPG signing key. @itchyny 0ff997f
  • Add artifact-metadata permission for actions/attest. @itchyny #3530
  • Upload attestation bundle as a release artifact, allowing unauthenticated verification
    via gh attestation verify --bundle jq-attestation.json. @itchyny #3563

CLI changes

  • Improve error message truncation with closing delimiters. @itchyny #3478
  • Remove extra space from die function output. @krtk6160 #3391
  • Fix raw input flag not to corrupt multi-byte characters. @itchyny #3421
  • Fix crash when importing a module with errors twice. @itchyny #3497
  • Increase the maximum printing depth from 256 to 10000. @ishnagy #3414

Changes to existing functions

  • Fix rtrimstr("") always outputting "". @A4-Tacks #3415
  • Fix infinite loop and undefined behavior in del(.[nan]). @itchyny #3490
  • Refactor @uri and @urid to fix multi-byte UTF-8 corruption. @itchyny #3495
  • Fix tonumber and toboolean to reject strings with embedded null bytes. @itchyny #3496
  • Fix undefined behavior in modulo operator. @fab1ano #3486
  • Fix reversed pointer subtraction in f_env bounds check. @itchyny #3465
  • Fix missing validity check in f_strflocaltime after f_localtime. @itchyny #3491
  • Fix year 2038 problem on 32-bit platforms. @itchyny #3407
  • Use // instead of //= in from_entries definition. @itchyny #3516

Build and test changes

Documentation changes

jq 1.8.1

Choose a tag to compare

@github-actions github-actions released this 01 Jul 11:50
4467af7

This is a patch release to fix security, performance, and build issues found in 1.8.0.
Full commit log can be found at jq-1.8.0...jq-1.8.1.

Security fixes

CLI changes

  • Fix assertion failure when syntax error happens at the end of the query. @itchyny #3350

Changes to existing functions

  • Fix portability of strptime/1 especially for Windows. @itchyny #3342

Language changes

  • Revert the change of reduce/foreach state variable in 1.8.0 (#3205).
    This change was reverted due to serious performance regression. @itchyny #3349

Documentation changes

  • Add LICENSE notice of NetBSD's strptime() to COPYING. @itchyny #3344

Build improvements

jq 1.8.0

Choose a tag to compare

@github-actions github-actions released this 01 Jun 06:05
d23a7b9

We are pleased to announce the release of version 1.8.0.
This release includes a number of improvements since the last version.
Note that some changes may introduce breaking changes to existing scripts,
so be sure to read the following information carefully.
Full commit log can be found at jq-1.7.1...jq-1.8.0.

Releasing

  • Change the version number pattern to 1.X.Y (1.8.0 instead of 1.8). @itchyny #2999

  • Generate provenance attestations for release artifacts and docker image. @lectrical #3225

    gh attestation verify --repo jqlang/jq jq-linux-amd64
    gh attestation verify --repo jqlang/jq oci://ghcr.io/jqlang/jq:1.8.0

Security fixes

  • CVE-2024-23337: Fix signed integer overflow in jvp_array_write and jvp_object_rehash. @itchyny de21386
    • The fix for this issue now limits the maximum size of arrays and objects to 536870912 (2^29) elements.
  • CVE-2024-53427: Reject NaN with payload while parsing JSON. @itchyny a09a4df
    • The fix for this issue now drops support for NaN with payload in JSON (like NaN123).
      Other JSON extensions like NaN and Infinity are still supported.
  • CVE-2025-48060: Fix heap buffer overflow in jv_string_vfmt. @itchyny c6e0416
  • Fix use of uninitialized value in check_literal. @itchyny #3324
  • Fix segmentation fault on strftime/1, strflocaltime/1. @itchyny #3271
  • Fix unhandled overflow in @base64d. @emanuele6 #3080

CLI changes

  • Fix --indent 0 implicitly enabling --compact-output. @amarshall @gbrlmarn @itchyny #3232

    $ jq --indent 0 . <<< '{ "foo": ["hello", "world"] }'
    {
    "foo": [
    "hello",
    "world"
    ]
    }
    # Previously, this implied --compact-output, but now outputs with new lines.
  • Improve error messages to show problematic position in the filter. @itchyny #3292

    $ jq -n '1 + $foo + 2'
    jq: error: $foo is not defined at <top-level>, line 1, column 5:
        1 + $foo + 2
            ^^^^
    jq: 1 compile error
  • Include column number in parser and compiler error messages. @liviubobocu #3257

  • Fix error message for string literal beginning with single quote. @mattmeyers #2964

    $ jq .foo <<< "{'foo':'bar'}"
    jq: parse error: Invalid string literal; expected ", but got ' at line 1, column 7
    # Previously, the error message was Invalid numeric literal at line 1, column 7.
  • Improve JQ_COLORS environment variable to support larger escapes like truecolor. @SArpnt #3282

    JQ_COLORS="38;2;255;173;173:38;2;255;214;165:38;2;253;255;182:38;2;202;255;191:38;2;155;246;255:38;2;160;196;255:38;2;189;178;255:38;2;255;198;255" jq -nc '[null,false,true,42,{"a":"bc"}]'
  • Add --library-path long option for -L. @thaliaarchi #3194

  • Fix --slurp --stream when input has no trailing newline character. @itchyny #3279

  • Fix --indent option to error for malformed values. @thaliaarchi #3195

  • Fix option parsing of --binary on non-Windows platforms. @calestyo #3131

  • Fix issue with ~/.jq on Windows where $HOME is not set. @kirkoman #3114

  • Fix broken non-Latin output in the command help on Windows. @itchyny #3299

  • Increase the maximum parsing depth for JSON to 10000. @itchyny #3328

  • Parse short options in order given. @thaliaarchi #3194

  • Consistently reset color formatting. @thaliaarchi #3034

New functions

  • Add trim/0, ltrim/0 and rtrim/0 to trim leading and trailing white spaces. @wader #3056

    $ jq -n '" hello " | trim, ltrim, rtrim'
    "hello"
    "hello "
    " hello"
  • Add trimstr/1 to trim string from both ends. @gbrlmarn #3319

    $ jq -n '"foobarfoo" | trimstr("foo")'
    "bar"
  • Add add/1. Generator variant of add/0. @myaaaaaaaaa #3144

    $ jq -c '.sum = add(.xs[])' <<< '{"xs":[1,2,3]}'
    {"xs":[1,2,3],"sum":6}
  • Add skip/2 as the counterpart to limit/2. @itchyny #3181

    $ jq -nc '[1,2,3,4,5] | [skip(2; .[])]'
    [3,4,5]
  • Add toboolean/0 to convert strings to booleans. @brahmlower @itchyny #2098

    $ jq -n '"true", "false" | toboolean'
    true
    false
  • Add @urid format. Reverse of @uri. @fmgornick #3161

    $ jq -Rr '@urid' <<< '%6a%71'
    jq

Changes to existing functions

Language changes

  • Fix precedence of binding syntax against unary and binary operators.
    Also, allow some expressions as object values. @itchyny #3053 #3326

    • This is a breaking change that may change the output of filters with binding syntax as follows.
    $ jq -nc '[-1 as $x | 1,$x]'
    [1,-1]    # previously, [-1,-1]
    $ jq -nc '1 | . + 2 as $x | -$x'
    -3        # previously, -1
    $ jq -nc '{x: 1 + 2, y: false or true, z: null // 3}'
    {"x":3,"y":true,"z":3}    # previously, syntax error
  • Support Tcl-style multiline comments. @emanuele6 #2989

    #!/bin/sh --
    # Can be use to do shebang scripts.
    # Next line will be seen as a comment be of the trailing backslash. \
    exec jq ...
    # this jq expression will result in [1]
    [
      1,
      # \
      2
    ]
  • Fix foreach not to break init backtracking with DUPN. @kanwren #3266

    $ jq -n '[1, 2] | foreach .[] as $x (0, 1; . + $x)'
    1
    3
    2
    4
  • Fix reduce/foreach state variable should not be reset each iteration. @itchyny #3205

    $ jq -n 'reduce range(5) as $x (0; .+$x | select($x!=2))'
    8
    $ jq -nc '[foreach range(5) as $x (0; .+$x | select($x!=2); [$x,.])]'
    [[0,0],[1,1],[3,4],[4,8]]
  • Support CRLF line breaks in filters. @itchyny #3274

  • Improve performance of repeating strings. @itchyny #3272

Documentation changes

Build improvements

Test improvements

jq 1.7.1

Choose a tag to compare

@github-actions github-actions released this 13 Dec 19:56
71c2ab5

Security

  • CVE-2023-50246: Fix heap buffer overflow in jvp_literal_number_literal
  • CVE-2023-50268: fix stack-buffer-overflow if comparing nan with payload

CLI changes

Language changes

Documentation changes

libjq

Build and test changes

New Contributors

Full Changelog: jq-1.7...jq-1.7.1

jq 1.7

Choose a tag to compare

@github-actions github-actions released this 06 Sep 22:54

After a five year hiatus we're back with a GitHub organization, with new admins and new maintainers who have brought a great deal of energy to make a long-awaited and long-needed new release. We're very grateful for all the new owners, admins, and maintainers. Special thanks go to Owen Ou (@owenthereal) for pushing to set up a new GitHub organization for jq, Stephen Dolan (@stedolan) for transferring the jq repository to the new organization, @itchyny for doing a great deal of work to get the release done, Mattias Wadman (@wader) and Emanuele Torre (@emanuele6) for many PRs and code reviews. Many others also contributed PRs, issues, and code reviews as well, and you can find their contributions in the Git log and on the closed issues and PRs page.

What's Changed

Since the last stable release many things have happened:

  • jq now lives at https://github.com/jqlang
  • New maintainers, admins, and owners have been recruited.
  • NEWS file is replaced by NEWS.md with Markdown format. @wader #2599
  • CI, scan builds, release, website builds etc now use GitHub actions. @owenthereal @wader @itchyny #2596 #2603 #2620 #2723
  • Lots of documentation improvements and fixes.
  • Website updated with new section search box, better section ids for linking, dark mode, etc. @itchyny #2628
  • Release builds for:
    • Linux amd64, arm64, armel, armhf, i386, mips, mips64, mips64el, mips64r6, mips64r6el, mipsel, mipsr6, mipsr6el, powerpc, ppc64el, riscv64 and s390x
    • macOS amd64 and arm64
    • Windows i386 and amd64
    • Docker linux/386, linux/amd64, linux/arm64, linux/mips64le, linux/ppc64le, linux/riscv64 and linux/s390x
    • More details see @owenthereal #2665
  • Docker images are now available from ghcr.io/jqlang/jq instead of Docker Hub. @itchyny #2652 #2686
  • OSS-fuzz. @DavidKorczynski #2760 #2762

Full commit log can be found at jq-1.6...jq-1.7 but here are some highlights:

CLI changes

  • Make object key color configurable using JQ_COLORS environment variable. @itchyny @haguenau @ericpruitt #2703

    # this would make "field" bold yellow (`1;33`, the last value)
    $ JQ_COLORS="0;90:0;37:0;37:0;37:0;32:1;37:1;37:1;33" ./jq -n '{field: 123}'
    {
      "field": 123
    }
  • Change the default color of null to Bright Black. @itchyny #2824

  • Respect NO_COLOR environment variable to disable color output. See https://no-color.org for details. @itchyny #2728

  • Improved --help output. Now mentions all options and nicer order. @itchyny @wader #2747 #2766 #2799

  • Fix multiple issues of exit code using --exit-code/-e option. @ryo1kato #1697

    # true-ish last output value exits with zero
    $ jq -ne true ; echo $?
    true
    0
    # false-ish last output value (false and null) exits with 1
    $ jq -ne false ; echo $?
    false
    1
    # no output value exists with 4
    $ jq -ne empty ; echo $?
    4
  • Add --binary/-b on Windows for binary output. To get \n instead of \r\n line endings. @nicowilliams 0dab2b1

  • Add --raw-output0 for NUL (zero byte) separated output. @asottile @pabs3 @itchyny #1990 #2235 #2684

    # will output a zero byte after each output
    $ jq -n --raw-output0 '1,2,3' | xxd
    00000000: 3100 3200 3300                           1.2.3.
    # can be used with xargs -0
    $ jq -n --raw-output0 '"a","b","c"' | xargs -0 -n1
    a
    b
    c
    $ jq -n --raw-output0 '"a b c", "d\ne\nf"' | xargs -0 printf '[%s]\n'
    [a b c]
    [d
    e
    f]
    # can be used with read -d ''
    $ while IFS= read -r -d '' json; do
    >   jq '.name' <<< "$json"
    > done < <(jq -n --raw-output0 '{name:"a b c"},{name:"d\ne\nf"}')
    "a b c"
    "d\ne\nf"
    # also it's an error to output a string containing a NUL when using NUL separator
    $ jq -n --raw-output0 '"\u0000"'
    jq: error (at <unknown>): Cannot dump a string containing NUL with --raw-output0 option
  • Fix assert crash and validate JSON for --jsonarg. @wader #2658

  • Remove deprecated --argfile option. @itchyny #2768

  • Enable stack protection. @nicowilliams #2801

Language changes

  • Use decimal number literals to preserve precision. Comparison operations respects precision but arithmetic operations might truncate. @leonid-s-usov #1752

    # precision is preserved
    $ echo '100000000000000000' | jq .
    100000000000000000
    # comparison respects precision (this is false in JavaScript)
    $ jq -n '100000000000000000 < 100000000000000001'
    true
    # sort/0 works
    $ jq -n -c '[100000000000000001, 100000000000000003, 100000000000000004, 100000000000000002] | sort'
    [100000000000000001,100000000000000002,100000000000000003,100000000000000004]
    # arithmetic operations might truncate (same as JavaScript)
    $ jq -n '100000000000000000 + 10'
    100000000000000020
  • Adds new builtin pick(stream) to emit a projection of the input object or array. @pkoppstein #2656 #2779

    $ jq -n '{"a": 1, "b": {"c": 2, "d": 3}, "e": 4} | pick(.a, .b.c, .x)'
    {
      "a": 1,
      "b": {
        "c": 2
      },
      "x": null
    }
  • Adds new builtin debug(msgs) that works like debug but applies a filter on the input before writing to stderr. @pkoppstein #2710

    $ jq -n '1 as $x | 2 | debug("Entering function foo with $x == \($x)", .) | (.+1)'
    ["DEBUG:","Entering function foo with $x == 1"]
    ["DEBUG:",2]
    3
    $ jq -n '{a: 1, b: 2, c: 3} | debug({a, b, sum: (.a+.b)})'
    ["DEBUG:",{"a":1,"b":2,"sum":3}]
    {
      "a": 1,
      "b": 2,
      "c": 3
    }
  • Adds new builtin scan($re; $flags). Was documented but not implemented. @itchyny #1961

    # look for pattern "ab" in "abAB" ignoring casing
    $ jq -n '"abAB" | scan("ab"; "i")'
    "ab"
    "AB"
  • Adds new builtin abs to get absolute value. This potentially allows the literal value of numbers to be preserved as length and fabs convert to float. @pkoppstein #2767

  • Allow if without else-branch. When skipped the else-branch will be . (identity). @chancez @wader #1825 #2481

    # convert 1 to "one" otherwise keep as is
    $ jq -n '1,2 | if . == 1 then "one" end'
    "one"
    2
    # behaves the same as
    $ jq -n '1,2 | if . == 1 then "one" else . end'
    "one"
    2
    # also works with elif
    $ jq -n '1,2,3 | if . == 1 then "one" elif . == 2 then "two" end
    "one"
    "two"
    3
  • Allow use of $binding as key in object literals. @nicowilliams 8ea4a55

    $ jq -n '"a" as $key | {$key: 123}'
    {
      "a": 123
    }
    # previously parentheses were needed
    $ jq -n '"a" as $key | {($key): 123}'
    {
      "a": 123
    }
  • Allow dot between chained indexes when using .["index"] @nicowilliams #1168

    $ jq -n '{"a": {"b": 123}} | .a["b"]'
    123
    # now this also works
    $ jq -n '{"a": {"b": 123}} | .a.["b"]'
    123
  • Allow dot for chained value iterator .[], .[]? @wader #2650

    $ jq -n '{"a": [123]} | .a[]'
    123
    # now this also works
    $ jq -n '{"a": [123]} | .a.[]'
    123
  • Fix try/catch catches more than it should. @nicowilliams #2750

  • Speed up and refactor some builtins, also remove scalars_or_empty/0. @muhmuhten #1845

  • Now halt and halt_error exit immediately instead of continuing to the next input. @emanuele6 #2667

  • Fix issue converting string to number after previous convert error. @thalman #2400

  • Fix issue representing large numbers on some platforms causing invalid JSON output. @itchyny #2661

  • Fix deletion using assigning empty against arrays. @itchyny #2133

    # now this works as expected, filter out all values over 2 by assigning empty
    $ jq -c '(.[] | select(. >= 2)) |= empty' <<< '[1,5,3,0,7]'
    [1,0]
  • Allow keywords to be used as binding name in more places. @emanuele6 #2681

  • Allow using nan as NaN in JSON. @emanuele6 #2712

  • Expose a module's function names in modulemeta. @mrwilson #2837

  • Fix contains/1 to handle strings with NUL. @nicowilliams 61cd6db

  • Fix stderr/0 to output raw text without any decoration. @itchyny #2751

  • Fix nth/2 to emit empty on index out of range. @itchyny #2674

  • Fix implode to not assert and instead replace invalid unicode codepoints. @wader #2646

  • Fix indices/1 and rindex/1 in case of overlapping matches in strings. @emanuele6 #2718

  • Fix sub/3 to resolve issues involving global search-and-replace (gsub) operations. @pkoppstein #2641

  • Fix significand/0, gamma/0 and drem/2 to be available on macOS. @itchyny #2756 #2775

  • Fix empty regular expression matches. @itchyny #2677

  • Fix overflow exception of the modulo operator. @itchyny #2629

  • Fix string multiplication by 0 (and less than 1) to emit empty string. @itchyny #2142

  • Fix segfault when using libjq and threads. @thalman #2546

  • Fix constant folding of division and reminder with zero divisor. @itchyny #2797

  • Fix error/0, error/1 to throw null error. @emanuele6 #2823

  • Simpler and faster transpose. @pkoppstein #2758

  • Simple and efficient implementation of walk/1. @pkoppstein #2795

  • Remove deprecated filters leaf_paths, recurse_down. @itchyny #2666

Full Changelog: jq-1.7rc2...jq-1.7

jq 1.7rc2

jq 1.7rc2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 27 Aug 18:10

Note that this is a pre-release. Feedback is welcome #2862.


After a five year hiatus we're back with a GitHub organization, with new admins and new maintainers who have brought a great deal of energy to make a long-awaited and long-needed new release.

Since the last stable release many things have happened:

  • jq now lives at https://github.com/jqlang
  • New maintainers, admins, and owners have been recruited.
  • NEWS file is replaced by NEWS.md with Markdown format. @wader #2599
  • CI, scan builds, release, website builds etc now use GitHub actions. @owenthereal @wader @itchyny #2596 #2603 #2620 #2723
  • Lots of documentation improvements and fixes.
  • Website updated with new section search box, better section ids for linking, dark mode, etc. @itchyny #2628
  • Release builds for:
    • Linux amd64, arm64, armel, armhf, i386, mips, mips64, mips64el, mips64r6, mips64r6el, mipsel, mipsr6, mipsr6el, powerpc, ppc64el, riscv64 and s390x
    • macOS amd64 and arm64
    • Windows i386 and amd64
    • Docker linux/386, linux/amd64, linux/arm64, linux/mips64le, linux/ppc64le, linux/riscv64 and linux/s390x
    • More details see @owenthereal #2665
  • Docker images are now available from ghcr.io/jqlang/jq instead of Docker Hub. @itchyny #2652 #2686
  • OSS-fuzz. @DavidKorczynski #2760 #2762

Full commit log can be found at jq-1.6...jq-1.7rc2 but here are some highlights:

CLI changes

  • Make object key color configurable using JQ_COLORS environment variable. @itchyny @haguenau @ericpruitt #2703

    # this would make "field" bold yellow (`1;33`, the last value)
    $ JQ_COLORS="0;90:0;37:0;37:0;37:0;32:1;37:1;37:1;33" ./jq -n '{field: 123}'
    {
      "field": 123
    }
  • Change the default color of null to Bright Black. @itchyny #2824

  • Respect NO_COLOR environment variable to disable color output. See https://no-color.org for details. @itchyny #2728

  • Improved --help output. Now mentions all options and nicer order. @itchyny @wader #2747 #2766 #2799

  • Fix multiple issues of exit code using --exit-code/-e option. @ryo1kato #1697

    # true-ish last output value exits with zero
    $ jq -ne true ; echo $?
    true
    0
    # false-ish last output value (false and null) exits with 1
    $ jq -ne false ; echo $?
    false
    1
    # no output value exists with 4
    $ jq -ne empty ; echo $?
    4
  • Add --binary/-b on Windows for binary output. To get \n instead of \r\n line endings. @nicowilliams 0dab2b1

  • Add --raw-output0 for NUL (zero byte) separated output. @asottile @pabs3 @itchyny #1990 #2235 #2684

    # will output a zero byte after each output
    $ jq -n --raw-output0 '1,2,3' | xxd
    00000000: 3100 3200 3300                           1.2.3.
    # can be used with xargs -0
    $ jq -n --raw-output0 '"a","b","c"' | xargs -0 -n1
    a
    b
    c
    $ jq -n --raw-output0 '"a b c", "d\ne\nf"' | xargs -0 printf '[%s]\n'
    [a b c]
    [d
    e
    f]
    # can be used with read -d ''
    $ while IFS= read -r -d '' json; do
    >   jq '.name' <<< "$json"
    > done < <(jq -n --raw-output0 '{name:"a b c"},{name:"d\ne\nf"}')
    "a b c"
    "d\ne\nf"
    # also it's an error to output a string containing a NUL when using NUL separator
    $ jq -n --raw-output0 '"\u0000"'
    jq: error (at <unknown>): Cannot dump a string containing NUL with --raw-output0 option
  • Fix assert crash and validate JSON for --jsonarg. @wader #2658

  • Remove deprecated --argfile option. @itchyny #2768

  • Enable stack protection. @nicowilliams #2801

Language changes

  • Use decimal number literals to preserve precision. Comparison operations respects precision but arithmetic operations might truncate. @leonid-s-usov #1752

    # precision is preserved
    $ echo '100000000000000000' | jq .
    100000000000000000
    # comparison respects precision (this is false in JavaScript)
    $ jq -n '100000000000000000 < 100000000000000001'
    true
    # sort/0 works
    $ jq -n -c '[100000000000000001, 100000000000000003, 100000000000000004, 100000000000000002] | sort'
    [100000000000000001,100000000000000002,100000000000000003,100000000000000004]
    # arithmetic operations might truncate (same as JavaScript)
    $ jq -n '100000000000000000 + 10'
    100000000000000020
  • Adds new builtin pick(stream) to emit a projection of the input object or array. @pkoppstein #2656 #2779

    $ jq -n '{"a": 1, "b": {"c": 2, "d": 3}, "e": 4} | pick(.a, .b.c, .x)'
    {
      "a": 1,
      "b": {
        "c": 2
      },
      "x": null
    }
  • Adds new builtin debug(msgs) that works like debug but applies a filter on the input before writing to stderr. @pkoppstein #2710

    $ jq -n '1 as $x | 2 | debug("Entering function foo with $x == \($x)", .) | (.+1)'
    ["DEBUG:","Entering function foo with $x == 1"]
    ["DEBUG:",2]
    3
    $ jq -n '{a: 1, b: 2, c: 3} | debug({a, b, sum: (.a+.b)})'
    ["DEBUG:",{"a":1,"b":2,"sum":3}]
    {
      "a": 1,
      "b": 2,
      "c": 3
    }
  • Adds new builtin scan($re; $flags). Was documented but not implemented. @itchyny #1961

    # look for pattern "ab" in "abAB" ignoring casing
    $ jq -n '"abAB" | scan("ab"; "i")'
    "ab"
    "AB"
  • Adds new builtin abs to get absolute value. This potentially allows the literal value of numbers to be preserved as length and fabs convert to float. @pkoppstein #2767

  • Allow if without else-branch. When skipped the else-branch will be . (identity). @chancez @wader #1825 #2481

    # convert 1 to "one" otherwise keep as is
    $ jq -n '1,2 | if . == 1 then "one" end'
    "one"
    2
    # behaves the same as
    $ jq -n '1,2 | if . == 1 then "one" else . end'
    "one"
    2
    # also works with elif
    $ jq -n '1,2,3 | if . == 1 then "one" elif . == 2 then "two" end
    "one"
    "two"
    3
  • Allow use of $binding as key in object literals. @nicowilliams 8ea4a55

    $ jq -n '"a" as $key | {$key: 123}'
    {
      "a": 123
    }
    # previously parentheses were needed
    $ jq -n '"a" as $key | {($key): 123}'
    {
      "a": 123
    }
  • Allow dot between chained indexes when using .["index"] @nicowilliams #1168

    $ jq -n '{"a": {"b": 123}} | .a["b"]'
    123
    # now this also works
    $ jq -n '{"a": {"b": 123}} | .a.["b"]'
    123
  • Allow dot for chained value iterator .[], .[]? @wader #2650

    $ jq -n '{"a": [123]} | .a[]'
    123
    # now this also works
    $ jq -n '{"a": [123]} | .a.[]'
    123
  • Fix try/catch catches more than it should. @nicowilliams #2750

  • Speed up and refactor some builtins, also remove scalars_or_empty/0. @muhmuhten #1845

  • Now halt and halt_error exit immediately instead of continuing to the next input. @emanuele6 #2667

  • Fix issue converting string to number after previous convert error. @thalman #2400

  • Fix issue representing large numbers on some platforms causing invalid JSON output. @itchyny #2661

  • Fix deletion using assigning empty against arrays. @itchyny #2133

    # now this works as expected, filter out all values over 2 by assigning empty
    $ jq -c '(.[] | select(. >= 2)) |= empty' <<< '[1,5,3,0,7]'
    [1,0]
  • Allow keywords to be used as binding name in more places. @emanuele6 #2681

  • Allow using nan as NaN in JSON. @emanuele6 #2712

  • Expose a module's function names in modulemeta. @mrwilson #2837

  • Fix contains/1 to handle strings with NUL. @nicowilliams 61cd6db

  • Fix stderr/0 to output raw text without any decoration. @itchyny #2751

  • Fix nth/2 to emit empty on index out of range. @itchyny #2674

  • Fix implode to not assert and instead replace invalid unicode codepoints. @wader #2646

  • Fix indices/1 and rindex/1 in case of overlapping matches in strings. @emanuele6 #2718

  • Fix sub/3 to resolve issues involving global search-and-replace (gsub) operations. @pkoppstein #2641

  • Fix significand/0, gamma/0 and drem/2 to be available on macOS. @itchyny #2756 #2775

  • Fix empty regular expression matches. @itchyny #2677

  • Fix overflow exception of the modulo operator. @itchyny #2629

  • Fix string multiplication by 0 (and less than 1) to emit empty string. @itchyny #2142

  • Fix segfault when using libjq and threads. @thalman #2546

  • Fix constant folding of division and reminder with zero divisor. @itchyny #2797

  • Fix error/0, error/1 to throw null error. @emanuele6 #2823

  • Simpler and faster transpose. @pkoppstein #2758

  • Simple and efficient implementation of walk/1. @pkoppstein #2795

  • Remove deprecated filters leaf_paths, recurse_down. @itchyny #2666

jq 1.7rc1

jq 1.7rc1 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 31 Jul 23:04

Note that this is a pre-release. Feedback is welcome #2802.


After a five year hiatus we're back with a GitHub organization, with new admins and new maintainers who have brought a great deal of energy to make a long-awaited and long-needed new release.

Since the last stable release many things have happened:

  • jq now lives at https://github.com/jqlang
  • New maintainers, admins, and owners have been recruited.
  • CI, scan builds, release builds etc now use GitHub actions. @owenthereal #2596 #2620
  • Lots of documentation improvements and fixes.
  • Web site updated with new auto complete, better section ids for linking, dark mode, etc. @itchyny #2628
  • Release builds for:
    • Linux amd64, arm64, armel, armhf, i386, mips, mips64, mips64el, mips64r6, mips64r6el, mipsel, mipsr6, mipsr6el, powerpc, ppc64el, riscv64 and s390x
    • macOS amd64 and arm64
    • Windows i386 and amd64
    • Docker linux/386, linux/amd64, linux/arm64, linux/mips64le, linux/ppc64le, linux/riscv64 and linux/s390x
    • More details see @owenthereal #2665
  • Docker images are now available from ghcr.io/jqlang/jq instead of docker hub. @itchyny #2652
  • OSS-fuzz. @DavidKorczynski #2760 #2762

Full commit log can be found at jq-1.6...jq-1.7rc1 but here are some highlights:

CLI changes

  • Make object key color configurable using JQ_COLORS environment variable. @itchyny @haguenau @ericpruitt #2703

    # this would make "field" yellow (33, the last value)
    $ JQ_COLORS="1;30:0;37:0;37:0;37:0;32:1;37:1;37:1;33" ./jq -n '{field: 123}'
    {
      "field": 123
    }
  • Respect NO_COLOR environment variable to disable color output. See https://no-color.org for details. @itchyny #2728

  • Improved --help output. Now mentions all options and nicer order. @itchyny #2747 #2766

  • Last output value can now control exit code using --exit-code/-e. @ryo1kato #1697

    # true-ish last output value exits with zero
    $ jq -ne true ; echo $?
    true
    0
    # false-ish last output value (false and null) exits with 1
    $ jq -ne false ; echo $?
    false
    1
    # no output value exists with 4
    $ jq -ne empty ; echo $?
    4
  • Add --binary/-b on Windows for binary output. To get \n instead of \r\n line endings. 0dab2b1 @nicowilliams

  • Add --raw-output0 for NUL (zero byte) separated output. @asottile @pabs3 @itchyny #1990 #2235 #2684

    # will output a zero byte after each output
    $ jq -n --raw-output0 '1,2,3' | xxd
    00000000: 3100 3200 3300                           1.2.3.
    # can be used with xargs -0
    $ jq -n --raw-output0 '"a","b","c"' | xargs -0 -n1
    a
    b
    c
    $ jq -n --raw-output0 '"a b c", "d\ne\nf"' | xargs -0 printf '%q\n'
    'a b c'
    'd'$'\n''e'$'\n''f'
    # can be used with read -d ''
    $ while IFS= read -r -d '' json; do
    >   jq '.name' <<< "$json"
    > done < <(jq -n --raw-output0 '{name:"a b c"},{name:"d\ne\nf"}')
    "a b c"
    "d\ne\nf"
    # also it's an error to output a string containing a NUL when using NUL separator
    $ jq -n --raw-output0 '"\u0000"'
    jq: error (at <unknown>): Cannot dump a string containing NUL with --raw-output0 option
  • Fix assert crash and validate JSON for --jsonarg. @wader #2658

  • Remove deprecated --argfile option. @itchyny #2768

Language changes

  • Use decimal number literals to preserve precision. Comparison operations respects precision but arithmetic operations might truncate. @leonid-s-usov #1752

    # precision is preserved
    $ jq -n '100000000000000000'
    100000000000000000
    # comparison respects precision (this is false in JavaScript)
    $ jq -n '100000000000000000 < 100000000000000001'
    true
    # arithmetic operations might truncate (same as JavaScript)
    $ jq -n '100000000000000000+10'
    100000000000000020
  • Adds new builtin pick(stream) to emit a projection of the input object or array. @pkoppstein #2656

    $ jq -n '{"a": 1, "b": {"c": 2, "d": 3}, "e": 4} | pick(.a, .b.c, .x)'
    {
      "a": 1,
      "b": {
        "c": 2
      },
      "x": null
    }
  • Adds new builtin debug(msgs) that works like debug but applies a filter on the input before writing to stderr. @pkoppstein #2710

    $ jq -n '1 as $x | 2 | debug("Entering function foo with $x == \($x)", .) | (.+1)'
    ["DEBUG:","Entering function foo with $x == 1"]
    ["DEBUG:",2]
    3
    $ jq -n '{a: 1, b: 2, c: 3} | debug({a, b, sum: (.a+.b)})'
    ["DEBUG:",{"a":1,"b":2,"sum":3}]
    {
      "a": 1,
      "b": 2,
      "c": 3
    }
  • Adds new builtin scan($re; $flags). Was documented but not implemented. @itchyny #1961

    # look for pattern "ab" in "abAB" ignoring casing
    $ jq -n '"abAB" | scan("ab"; "i")'
    "ab"
    "AB"
  • Adds new builtin abs to get absolute value. This potentially allows the literal value of numbers to be preserved as length and fabs convert to float. @pkoppstein #2767

  • Allow if without else-branch. When skipped the else-branch will be . (identity). @chancez @wader #1825 #2481

    # convert 1 to "one" otherwise keep as is
    $ jq -n '1,2 | if . == 1 then "one" end'
    "one"
    2
    # behaves the same as
    $ jq -n '1,2 | if . == 1 then "one" else . end'
    "one"
    2
    # also works with elif
    $ jq -n '1,2,3 | if . == 1 then "one" elif . == 2 then "two" end
    "one"
    "two"
    3
  • Allow use of $binding as key in object literals. 8ea4a55 @nicowilliams

    $ jq -n '"a" as $key | {$key: 123}'
    {
      "a": 123
    }
    # previously parentheses were needed
    $ jq -n '"a" as $key | {($key): 123}'
    {
      "a": 123
    }
  • Allow dot between chained indexes when using .["index"] @nicowilliams #1168

    $ jq -n '{"a": {"b": 123}} | .a["b"]'
    123
    # now this works also
    $ jq -n '{"a": {"b": 123}} | .a.["b"]'
    123
  • Fix try/catch catches more than it should. @nicowilliams #2750

  • Speed up and refactor some builtins, also remove scalars_or_empty/0. @muhmuhten #1845

  • Now halt and halt_error exit immediately instead of continuing to the next input. @emanuele6 #2667

  • Fix issue converting string to number after previous convert error. @thalman #2400

  • Make 0 divided by 0 result in NaN consistently. @itchyny #2253

  • Fix issue representing large numbers on some platforms causing invalid JSON output. @itchyny #2661

  • Fix deletion using assigning empty against arrays. @itchyny #2133

    # now this works as expected, filter out all values over 2 by assigning empty
    $ jq -c '(.[] | select(. >= 2)) |= empty' <<< '[1,5,3,0,7]'
    [1,0]
  • Fix stderr/0 to output raw text without any decoration. @itchyny #2751

  • Fix nth/2 to emit empty on index out of range. @itchyny #2674

  • Fix implode to not assert and instead replace invalid unicode codepoints. @wader #2646

  • Simpler and faster transpose. @pkoppstein #2758

  • Allow keywords to be used as binding name in more places. @emanuele6 #2681

  • Allow using nan as NaN in JSON. @emanuele6 #2712

  • Fix indices/1 and rindex/1 in case of overlapping matches in strings. @emanuele6 #2718

  • Enable significand/0, gamma/0 and drem/2 on macOS. @itchyny #2756 #2775

  • Fix segfault when using libjq and threads. @thalman #2546

jq 1.6

Choose a tag to compare

@wtlangford wtlangford released this 02 Nov 01:54

New in this release since 1.5:

  • Destructuring Alternation
  • New Builtins:
    • builtins/0
    • stderr/0
    • halt/0, halt_error/1
    • isempty/1
    • walk/1
    • utf8bytelength/1
    • localtime/0, strflocaltime/1
    • SQL-style builtins
    • and more!
  • Add support for ASAN and UBSAN
  • Make it easier to use jq with shebangs (8f6f28c)
  • Add $ENV builtin variable to access environment
  • Add JQ_COLORS env var for configuring the output colors

Bug fixes:

  • Calling jq without a program argument now always assumes . for the program, regardless of stdin/stdout. (5fe0536)
  • Make sorting stable regardless of qsort. (7835a72)
  • Adds a local oniguruma submodule and the ./configure --with-oniguruma=builtin option to make it easier to build with oniguruma support on systems where you can't install system-level libraries. (c6374b6 and 02bad4b)
  • And much more!

jq 1.5

Choose a tag to compare

@nicowilliams nicowilliams released this 16 Aug 06:39

Thanks to the 20+ developers who have sent us PRs since 1.4, and the many contributors to issues and the wiki.

The manual for jq 1.5 can be found at https://stedolan.github.io/jq/manual/v1.5/

Salient new features since 1.4:

  • regexp support (using Oniguruma)!

  • a proper module system

    import "foo/bar" as bar; # import foo/bar.jq's defs into a bar::* namespace

    and

    include "foo/bar"; # import foo/bar.jq's defs into the top-level

  • destructuring syntax (. as [$first, $second, {$foo, $bar}] | ...)

  • math functions

  • an online streaming parser

  • minimal I/O builtions (inputs, debug)

    One can now write:

    jq -n 'reduce inputs as $i ( ... )'

    to reduce inputs in an online way without having to slurp them first! This works with streaming too.

  • try/catch, for catching and handling errors (this makes for a dynamic non-local exit system)

  • a lexical non-local exit system

    One can now say

    label $foo | ..... | break $foo

    where the break causes control to return to the label $foo, which
    then produces empty (backtracks). There's named and anonymous
    labels.

  • tail call optimization (TCO), which allows efficient recursion in jq

  • a variety of new control structure builtins (e.g., while(cond; exp), repeat(exp), until(cond; next)), many of which internally use TCO

  • an enhanced form of reduce: foreach exp as $name (init_exp; update_exp; extract_exp)

  • the ability to read module data files

    import "foo/bar" as $bar; # read foo/bar.json, bind to $bar::bar

  • --argjson var '<JSON text>'

    Using --arg var bit me too many times :)

  • --slurpfile var "filename"

    Replaces the --argfile form (which is now deprecated but remains for backward compatibility).

  • support for application/json-seq (RFC7464)

  • a large variety of new utility functions, many being community contributions (e.g., bsearch, for binary searching arrays)

  • datetime functions

  • a variety of performance enhancements

  • def($a): ...; is now allowed as an equivalent of def(a): a as $a | ...;

  • test and build improvements, including gcov support

Lastly, don't forget the wiki! The wiki has a lot of new content since 1.4, much of it contributed by the community.

jq 1.5 release candidate 2

Pre-release

Choose a tag to compare

@nicowilliams nicowilliams released this 27 Jul 04:14

Thanks to the 20+ developers who have sent us PRs since 1.4, and the many contributors to issues and the wiki. We're nearing a 1.5 release, finally.

Salient new features since 1.4:

  • regexp support (using Oniguruma)!

  • a proper module system

    import "foo/bar" as bar; # import foo/bar.jq's defs into a bar::* namespace

    and

    include "foo/bar"; # import foo/bar.jq's defs into the top-level

  • destructuring syntax (. as [$first, $second, {$foo, $bar}] | ...)

  • math functions

  • an online streaming parser

  • minimal I/O builtions (inputs, debug)

    One can now write:

    jq -n 'reduce inputs as $i ( ... )'

    to reduce inputs in an online way without having to slurp them first! This works with streaming too.

  • try/catch, for catching and handling errors (this makes for a dynamic non-local exit system)

  • a lexical non-local exit system

    One can now say

    label $foo | ..... | break $foo

    where the break causes control to return to the label $foo, which
    then produces empty (backtracks). There's named and anonymous
    labels.

  • tail call optimization (TCO), which allows efficient recursion in jq

  • a variety of new control structure builtins (e.g., while(cond; exp), repeat(exp), until(cond; next)), many of which internally use TCO

  • an enhanced form of reduce: foreach exp as $name (init_exp; update_exp; extract_exp)

  • the ability to read module data files

    import "foo/bar" as $bar; # read foo/bar.json, bind to $bar::bar

  • --argjson var '<JSON text>'

    Using --arg var bit me too many times :)

  • --slurpfile var "filename"

    Replaces the --argfile form (which is now deprecated but remains for backward compatibility).

  • support for application/json-seq (RFC7464)

  • a large variety of new utility functions, many being community contributions (e.g., bsearch, for binary searching arrays)

  • datetime functions

  • a variety of performance enhancements

  • def($a): ...; is now allowed as an equivalent of def(a): a as $a | ...;

  • test and build improvements, including gcov support

Lastly, don't forget the wiki! The wiki has a lot of new content since 1.4, much of it contributed by the community.