Repository navigation
Releases: faustbrian/go-wire
Release list
v3.0.1
Align the reusable CI workflow and bootstrap verifier sources so metadata-only verification uses the supported history scanner. This compatible maintenance release preserves the published v3 codec implementations, public API, Go minimum, and runtime dependency locks.
The module archive, CycloneDX SBOM, and maintainer-operated provenance are accompanied by signed checksums.
v3.0.0
[3.0.0] - 2026-10-06
Changed
-
Update the documentation TOML parser dependency to 1.9.0 to fix its
reported resource-exhaustion issue without changing Go runtime dependencies. -
Use the root module
github.com/faustbrian/go-wire/v3for the
incompatible MessagePack option and accepted-input changes below. Migrate
all Wire imports together and use keyed decode options; cross-major errors
and sentinels have distinct identities. Version 2 remains available for
consumers not migrating to the new major. -
Determine recursive MessagePack key projection support before preparing
reflected values or tuples. Unsupported components retain driver-owned
decoding instead of uncharged projection preparation. -
Admit aggregate MessagePack values and conservative raw/projected key work
before generic materialization, with finite inclusive decode defaults and
expanded built-in array-key preparation accounting. Limit refusal preserves
the destination and does not invoke destination codecs. New option fields
require keyed-literal migration and tighten acceptance in this major;
final driver allocations and cancellation remain separate work. -
Reject built-in MessagePack destination map-key collisions before decoding
into the target, including numeric-width and string/binary projections in
known map and unambiguous field shapes. Explicit duplicate-key opt-in remains
last-key-wins. This major tightens acceptance;
opaque codecs and ambiguous struct projections remain separate boundaries. -
Adopt the
go-library-toolsv1.3.0 schema-v2 cohesion contract and local
make cohesiongate without changing wire APIs or runtime behavior. -
Pin reusable CI to the immutable v1.3.0 workflow and enforce cohesion
metadata in the repository's required CI contract. -
Adopt checksum-pinned
go-library-toolsv1.2.0 and its immutable workflow
so CI executes specification governance while keeping format-specific
conformance, interoperability, mutation, and benchmark evidence in this
repository.
Documentation
-
Record reported RFC 9110 Errata ID 9164 as behavior-neutral because HTTP
grammar remains caller-owned policy, while retaining the prior Errata ID
9162 review and the immutable RFC 9110 source binding. -
Link the support policy from the root documentation entry points.
-
Record the reviewed Go releases-feed representation change as
behavior-neutral for the unchanged immutable Go 1.26.6 source contracts. -
Replace commit-pinned installation and pre-v1 guidance with the published
v1.0.0 release, exact Go 1.26.6 minimum, stable compatibility contract, and
a package-level compiler-checked example. -
Record the reviewed Go release-feed change through Go 1.27.1 as
behavior-neutral for the pinned Go 1.26.6 JSON, XML, errors, and language
contracts; Go 1.27 adoption remains a separate decision review. -
Record the reviewed FIDO Alliance feed change as behavior-neutral for the
pinned CTAP 2.2 deterministic-CBOR profile; replacing the general-news feed
with a specification-specific release authority remains future maintenance. -
Record reported RFC 9110 Errata ID 9162 as behavior-neutral because HTTP
field combination remains caller-owned transport policy; re-review it if the
erratum becomes verified or the package ownership boundary changes. -
Publish the module's family, capabilities, ownership, lifecycle, supported
environments, package selection, and delivery status, and link the README to
the immutable v1.3.0 ecosystem index and family guidance. -
Make the specification decision register
machine-auditable with exact source and change-authority monitoring,
attributable conformance evidence, classified maintained-peer results, and
durable decision history.- WIRE-DEC-001 sha256:f1fc52ef8464874e7b8cebcae98161f7c9296128e9a8913fcf918b97fe2f0728
- WIRE-DEC-002 sha256:f4dee326c94a5de595cbd5e0aea03414fd8ec444be92fd1ca25adcaef4a46f6d
- WIRE-DEC-003 sha256:1dd67beed03dbeb91bdef10c77f6f8c21cd0c8326720861437f9ce1ae179ee98
- WIRE-DEC-004 sha256:162b1cb67101d82b7732701b50193d49f2702908450227ecae9068777b5c91f5
- WIRE-DEC-005 sha256:74528fbf1f9dae53b31e20152c679fe0614de1d4a3f45c1fa19179b6a99cb620
- WIRE-DEC-006 sha256:a283308985c948563734b7f69e182e97ca844068e43e1cc9f5b09fcceb419e98
- WIRE-DEC-007 sha256:c781bb6f45e052079ba1b1dbdb37b3184606c72abae012848ab23a1d7cc2d73c
- WIRE-DEC-008 sha256:c5ce0457d9c8f828dfebef5c5d4467760836fcd58bb2b4b6291fe4bc76df4953
- WIRE-DEC-009 sha256:3739785c9c34062134e2cbe7d38b974da151e1711ced5e16119184b7c0060e91
- WIRE-DEC-010 sha256:57459c19b8ef283a3891ef4bc4d44efa1f1f4d211af4a9e74a533721c08f03f9
- WIRE-DEC-011 sha256:78340a1b77fad0a94fdd12875dd851446ff46fea84d92f4eb1766f9fb6637909
- WIRE-DEC-012 sha256:bbf48898109b852fe1b5784511c0bb5aa308162ceacd10b8777023fa391f9491
- WIRE-DEC-013 sha256:4a7375048cd8a95c1b37ecaae2e5d21c7dbb97b5e95c544d12fd2db1ccb29b7b
- WIRE-DEC-014 sha256:26d5aafc3d7e2bbf9304d04d9c0e1bf435968260b18dd05043fef4d1666596bd
- WIRE-DEC-015 sha256:a78c203aaf7314a61baa093d7e80e87171e8695c570f7e0b443b4ddda227be66
- WIRE-DEC-016 sha256:977cc72dfe7abd290dff31fa27f8150c26c0c27b4704e31427aabca3e7dffd52
-
Remove the archived monorepo documentation link; package guidance remains in
the repository-owned documentation.
go-wire v2.0.0
Fixed
-
Preserve YAML scalar values and mapping keys, including marker-like text
inside block contents or multiline quoted strings. Explicit indentation
follows the emitted mapping or sequence layout, including root and nested
tab-leading block scalars. -
Preserve blocks nested inside explicit collection keys and values. Keep
plain scalar content unchanged at large configured byte limits rather
than wrapping it into marker-like continuation lines. -
Preserve marker-like scalar text inside inline flow collections and
trailing comments while repairing real blocks after empty collection keys. -
Preserve emitted carriage returns and Unicode line breaks in comments and
scalar bodies while repairing subsequent tab-leading block values. -
Preserve authored folded YAML values across ordinary and more-indented
line transitions and trailing breaks. Admit the inclusive final byte quota
after bounded provider-output normalization without repeating callbacks. -
Upgrade CBOR decoding to reject dynamically uncomparable typed map keys
as parse errors instead of panicking. Comparable keys and the default
prohibition on tags remain unchanged.
Changed
-
Publish the major module as
github.com/faustbrian/go-wire/v2. Update all
Wire imports together; v1 and v2 error types and sentinels are distinct. -
Harden XML and SOAP built-in charset conversion with bounded raw input and
labels, pre-read allowlist rejection, and private categorical diagnostics.
Addxmlwire.CharsetReaderWithLimitfor explicit quotas. Custom charset callbacks remain caller-owned. -
Make shared wire errors and SOAP fault errors render categorical text only,
retaining original diagnostic fields, causes, and error classification.
Use typed causes and fault fields instead of previous diagnostic text.
WIRE-DEC-014 sha256:1238f483bf726688031a864be2082b503cdc4566830dc16ecbaf25f58d12bac9 -
Validate nested BSON structure and CodeWithScope scopes before decoding,
retain structural checks with duplicate-key opt-in, and require consecutive
array indices. Iterative raw validation permits 100 nested containers below
the root; encoding checks output after codec work. These acceptance changes
do not provide pre-encoding allocation protection.
WIRE-DEC-012 sha256:bcc48febdf249b122ae7bbed2aff0ef5ba84ceeda0a501589276d6d673fec20c -
Adopt MongoDB driver v2.9.1 while retaining external BSON driver aliases;
driver network and GridFS operations remain outside the module's imported
package boundary.
Documentation
-
Record the 2026-10-02 FIDO Alliance feed review while retaining the exact
CTAP 2.2 normative PDF and deterministic-CBOR profile. -
Align the codec dependency table with the CBOR v2.9.4 and BSON v2.9.1
module pins.
v1.0.1
What's Changed
- chore: use shared library tooling by @faustbrian in #7
- docs: remove archived monorepo link by @faustbrian in #8
- chore: update golib to v1.0.14 by @faustbrian in #9
- docs: record shared tooling adoption by @faustbrian in #10
- Adopt v1.2.0 specification governance by @faustbrian in #11
- chore(cohesion): publish wire adoption metadata by @faustbrian in #13
- chore(cohesion): adopt v1.4.0 tooling by @faustbrian in #14
- docs: align stable guidance and monitoring by @faustbrian in #15
- docs: link support guidance by @faustbrian in #16
- docs: pin stable wire installation by @faustbrian in #17
- chore: adopt proportional assurance policy by @faustbrian in #19
- chore: target Go 1.27.0 toolchain by @faustbrian in #21
- docs(go): align current wire support claims with Go 1.27 by @faustbrian in #22
- chore: publish compatibility remediation by @faustbrian in #24
- build(deps): bump go.mongodb.org/mongo-driver/v2 in / by @dependabot[bot] in #12
- build(deps): bump faustbrian/go-library-tools/.github/workflows/library-ci.yml from 1.4.0 to 1.5.4 in the github-actions group by @dependabot[bot] in #18
- build(deps): bump github.com/fxamacker/cbor/v2 in / by @dependabot[bot] in #6
New Contributors
- @faustbrian made their first contribution in #7
- @dependabot[bot] made their first contribution in #12
Full Changelog: v1.0.0...v1.0.1
github.com/faustbrian/go-wire v1.0.0
[1.0.0] - 2026-08-25
Changed
-
Validate action pinning from the standalone repository root and leave
repository-foundation policy to the authoritative repository contract. -
Exclude intentional nested modules from root local-proxy archives so local,
bootstrap, CI, and public module checksums describe the same source
boundary. -
Track the pinned documentation-tool lockfile so clean CI checkouts install
the exact validated cspell dependency. -
Reconcile standalone dependency checksums against deterministic current
module archives so CI, local verification, and release consumers resolve
identical content. -
Harden standalone documentation validation with deterministic spelling and
link checks, package-specific documentation gates, and repository-local
contributor guidance.
Documentation
-
Replace obsolete standalone-repository links and workflow claims with
monorepo-canonical targets and current release guidance. -
Link the package README to the repository-wide Golib documentation portal.
Compatibility
- Added a pinned module export baseline so incompatible public API changes
fail the canonical repository gate.
Changed
- Publish the module from its standalone
github.com/faustbrian/go-wireidentity while preserving its documented API and behavior. - Hardened codec boundary coverage with exact byte, depth, numeric, charset,
alias, fragment, and SOAP fault assertions, and bounded mutation execution
for malformed XML and SOAP parser mutants. - Link the conformance source matrix directly to the canonical specification
decision register. - Added the
GO-SAFETY-1ownership, concurrency, race, fuzz, resource, and
benchmark standard with an executablemake safetygate. - Moved AI planning and hardening briefs into
.ai/and clarified the
separate purposes of project and third-party notice files.
Added
- A specification decision register, pinned normative-source manifest, and
executable conformance gate covering the observable JSON, XML, SOAP, YAML,
TOML, MessagePack, CBOR, and BSON policy choices. - Opt-in recursive duplicate-name rejection for bounded JSON decoding before
the destination value can be mutated. - A standardized OSS repository skeleton covering policy, documentation,
legal notices, Go tooling, pinned CI, security, and release automation. - CI resolves the latest supported Go 1.25 patch while
go.moddeclares the
portable Go 1.25 minimum. - Evidence-driven audit and hardening goal covering every supported format,
parser resource safety, codec dependencies, and read/write boundaries. - A shared
wire.Errormodel with parse, validation, unsupported-format,
envelope, and SOAP-fault classifications. - Size-limit, invalid-target, and encoding classifications shared by every
format package. - Explicit JSON, XML, SOAP, YAML, TOML, MessagePack, CBOR, and BSON format
identifiers. - Opt-in JSON/XML format detection based on the first significant byte.
- Bounded JSON byte-slice and reader decoding with optional unknown-field
rejection and single-value enforcement. - Deterministic JSON encoding with configurable indentation and HTML escaping.
- Explicit JSON normalization that strips a UTF-8 BOM, compacts whitespace,
orders object keys, and preserves number lexemes. - JSON fixtures, malformed-input regression tests, fuzz seeds, and parse and
encode benchmarks. - Bounded strict XML decoding, opt-in non-strict recovery, exact
namespace-aware root validation, and resolved-root inspection. - Deterministic XML encoding with optional declaration and indentation.
- Built-in, explicit charset conversion for UTF-8, US-ASCII, ISO-8859-1, and
Windows-1252, including rejection of invalid or undefined bytes. - Namespace, malformed-document, charset, and trailing-root XML fixtures and
regressions, plus fuzz seeds and parse and encode benchmarks. - Bounded SOAP 1.1 and 1.2 envelope parsing with exact raw envelope, header,
and body access and namespace-preserving body decoding. - Typed SOAP 1.1 and 1.2 fault extraction, localized SOAP 1.2 reasons,
subcodes, details, anderrors.Isclassification. - Deterministic envelope and fault serialization from validated raw fragments.
- SOAP envelope, fault, malformed-input, structural-regression, fuzz, and
benchmark coverage. - Compile-checked examples and adoption documentation covering quickstart,
architecture, the complete public API, supported formats, behavioral
guarantees, limitations, and rollout guidance. - End-to-end JSON, XML, and SOAP examples, a scenario cookbook, FAQ, and
error-focused troubleshooting guide. - Migration, versioning, release, contribution, security, conduct, and roadmap
documentation for open-source operation. - Reproducible local formatting, vet, lint, race-test, 100% coverage, fuzz,
benchmark, documentation-link, and vulnerability quality gates. - GitHub Actions for the Go 1.25 and 1.26 build/race-test matrix,
formatting, static analysis, lint, exact coverage, documentation, fuzz smoke,
benchmark smoke, and vulnerability scanning. - Scheduled extended fuzzing and benchmark baselines, Dependabot configuration,
and an interoperability-focused pull request template. - Tagged release automation that validates SemVer tags and changelog entries,
reruns quality and security gates, creates a deterministic source archive and
checksum, and publishes a GitHub Release with extracted notes. - Explicit method-level documentation for every exported error API.
- JSON and XML writer APIs, typed SOAP header/body encoding, and SOAP envelope
and fault writer APIs for symmetric input and output handling. - Bounded YAML read/write APIs with duplicate-key and multi-document policy,
alias and merge controls, expansion limits, deterministic output, fixtures,
fuzzing, and benchmarks. - Complete TOML document read/write APIs with strict-field metadata, native
datetime handling, checked numeric conversion, deterministic output,
fixtures, fuzzing, and benchmarks. - MessagePack read/write APIs with exact one-object enforcement, map-key and
extension policy, checked numeric widths, timestamp support, deterministic
map encoding, fixtures, fuzzing, and benchmarks. - Canonical, Core Deterministic, and CTAP2 CBOR read/write profiles with tag,
indefinite-length, duplicate-key, and resource-limit policy, plus fixtures,
fuzzing, and benchmarks. - BSON document read/write APIs with recursive duplicate-key rejection, exact
length validation, ordered and raw document support, ObjectID and datetime
aliases, checked numeric conversion, fixtures, fuzzing, and benchmarks. - Pinned, reviewed YAML, TOML, MessagePack, CBOR, and BSON codec dependencies
with documented maintenance, security, and residual-risk rationale. - Compile-checked round-trip examples and full API, format, migration,
adoption, security, troubleshooting, and dependency documentation for all
eight supported formats. - A distinct
wire.ErrWriteclassification for destination failures. - Consistent repository automation for generated portable AI documentation,
dependency review, and guarded semantic release commands. - Configurable output byte limits for every JSON, XML, SOAP, YAML, TOML,
MessagePack, CBOR, and BSON byte and writer encoding path. Zero selects the
safe 1 MiB default. - Size-bounded SOAP raw-envelope and fault APIs through
MarshalOptions,
MarshalWithOptions,MarshalWriterWithOptions,
MarshalFaultWithOptions, andMarshalFaultWriterWithOptions.
Changed
- The minimum supported Go version is Go 1.25.0; later Go 1.25 patch
releases and newer language versions are supported. - Fuzz, benchmark, release, and documentation automation now covers YAML,
TOML, MessagePack, CBOR, and BSON alongside JSON, XML, and SOAP. - Corrected codec troubleshooting and migration guidance to use the exported
option and profile names, describe YAML's actual safe defaults, distinguish
legacy size classifications, and document BSON double truncation as
explicitly lossy. - MessagePack decoding now enforces configurable safe defaults of 32 nesting
levels, 131,072 array elements, and 65,536 map pairs. Structural limit
failures are classified aswire.ErrSizeLimit. - MessagePack decoding now rejects duplicate map keys recursively by default,
with explicit last-key-wins compatibility throughAllowDuplicateKeys. - BSON now re-exports the official array, raw value, Decimal128, binary, regex,
timestamp, JavaScript, scoped code, sentinel, pointer, and symbol types. - Published the evidence-driven hardening report, threat model, per-format
conformance matrix, allocation policy, dependency residual risks, and
pre-v1 semantic-version recommendation. - Writer APIs now complete encoding within the configured output quota before
writing, so an encode limit failure cannot emit a partial destination
payload.
Fixed
- Keep module-archive tests scoped to files shipped with the wire module;
repository-root workflow policy remains owned by the root verification gate. - Bound fuzz-smoke concurrency to avoid deadline flakes on high-core hosts.
- MessagePack now performs allocation-safe structural preflight for impossible
collection lengths and composite map keys. Numeric preflight rejects
narrowing overflow in typed maps, array-encoded structs, and automatically
inlined embedded fields before the decoder can apply a lossy Go conversion. - MessagePack structural validation now stops recursive traversal and compact
collection allocation amplification at explicit caller-configurable limits. - All typed encoders now reject cyclic values and nesting beyond 1,000
traversed levels before recursive codecs can exhaust the process stack. - MessagePack numeric preflight now also prevents duplicate keys from being
silently overwritten before assignment. - BSON documentation and tests now prove Decimal128, binary subtype, and regex
interoperability instead of...