Skip to content

Releases: faustbrian/go-wire

v3.0.1

Choose a tag to compare

@faustbrian faustbrian released this 08 Oct 02:53
0607913

Align the reusable CI workflow and bootstrap verifier sources so metadata-only verification uses the supported history scanner. This compatible maintenance release preserves the published v3 codec implementations, public API, Go minimum, and runtime dependency locks.

The module archive, CycloneDX SBOM, and maintainer-operated provenance are accompanied by signed checksums.

v3.0.0

Choose a tag to compare

@faustbrian faustbrian released this 06 Oct 12:29
7465778

[3.0.0] - 2026-10-06

Changed

  • Update the documentation TOML parser dependency to 1.9.0 to fix its
    reported resource-exhaustion issue without changing Go runtime dependencies.

  • Use the root module github.com/faustbrian/go-wire/v3 for the
    incompatible MessagePack option and accepted-input changes below. Migrate
    all Wire imports together and use keyed decode options; cross-major errors
    and sentinels have distinct identities. Version 2 remains available for
    consumers not migrating to the new major.

  • Determine recursive MessagePack key projection support before preparing
    reflected values or tuples. Unsupported components retain driver-owned
    decoding instead of uncharged projection preparation.

  • Admit aggregate MessagePack values and conservative raw/projected key work
    before generic materialization, with finite inclusive decode defaults and
    expanded built-in array-key preparation accounting. Limit refusal preserves
    the destination and does not invoke destination codecs. New option fields
    require keyed-literal migration and tighten acceptance in this major;
    final driver allocations and cancellation remain separate work.

  • Reject built-in MessagePack destination map-key collisions before decoding
    into the target, including numeric-width and string/binary projections in
    known map and unambiguous field shapes. Explicit duplicate-key opt-in remains
    last-key-wins. This major tightens acceptance;
    opaque codecs and ambiguous struct projections remain separate boundaries.

  • Adopt the go-library-tools v1.3.0 schema-v2 cohesion contract and local
    make cohesion gate without changing wire APIs or runtime behavior.

  • Pin reusable CI to the immutable v1.3.0 workflow and enforce cohesion
    metadata in the repository's required CI contract.

  • Adopt checksum-pinned go-library-tools v1.2.0 and its immutable workflow
    so CI executes specification governance while keeping format-specific
    conformance, interoperability, mutation, and benchmark evidence in this
    repository.

Documentation

  • Record reported RFC 9110 Errata ID 9164 as behavior-neutral because HTTP
    grammar remains caller-owned policy, while retaining the prior Errata ID
    9162 review and the immutable RFC 9110 source binding.

  • Link the support policy from the root documentation entry points.

  • Record the reviewed Go releases-feed representation change as
    behavior-neutral for the unchanged immutable Go 1.26.6 source contracts.

  • Replace commit-pinned installation and pre-v1 guidance with the published
    v1.0.0 release, exact Go 1.26.6 minimum, stable compatibility contract, and
    a package-level compiler-checked example.

  • Record the reviewed Go release-feed change through Go 1.27.1 as
    behavior-neutral for the pinned Go 1.26.6 JSON, XML, errors, and language
    contracts; Go 1.27 adoption remains a separate decision review.

  • Record the reviewed FIDO Alliance feed change as behavior-neutral for the
    pinned CTAP 2.2 deterministic-CBOR profile; replacing the general-news feed
    with a specification-specific release authority remains future maintenance.

  • Record reported RFC 9110 Errata ID 9162 as behavior-neutral because HTTP
    field combination remains caller-owned transport policy; re-review it if the
    erratum becomes verified or the package ownership boundary changes.

  • Publish the module's family, capabilities, ownership, lifecycle, supported
    environments, package selection, and delivery status, and link the README to
    the immutable v1.3.0 ecosystem index and family guidance.

  • Make the specification decision register
    machine-auditable with exact source and change-authority monitoring,
    attributable conformance evidence, classified maintained-peer results, and
    durable decision history.

    • WIRE-DEC-001 sha256:f1fc52ef8464874e7b8cebcae98161f7c9296128e9a8913fcf918b97fe2f0728
    • WIRE-DEC-002 sha256:f4dee326c94a5de595cbd5e0aea03414fd8ec444be92fd1ca25adcaef4a46f6d
    • WIRE-DEC-003 sha256:1dd67beed03dbeb91bdef10c77f6f8c21cd0c8326720861437f9ce1ae179ee98
    • WIRE-DEC-004 sha256:162b1cb67101d82b7732701b50193d49f2702908450227ecae9068777b5c91f5
    • WIRE-DEC-005 sha256:74528fbf1f9dae53b31e20152c679fe0614de1d4a3f45c1fa19179b6a99cb620
    • WIRE-DEC-006 sha256:a283308985c948563734b7f69e182e97ca844068e43e1cc9f5b09fcceb419e98
    • WIRE-DEC-007 sha256:c781bb6f45e052079ba1b1dbdb37b3184606c72abae012848ab23a1d7cc2d73c
    • WIRE-DEC-008 sha256:c5ce0457d9c8f828dfebef5c5d4467760836fcd58bb2b4b6291fe4bc76df4953
    • WIRE-DEC-009 sha256:3739785c9c34062134e2cbe7d38b974da151e1711ced5e16119184b7c0060e91
    • WIRE-DEC-010 sha256:57459c19b8ef283a3891ef4bc4d44efa1f1f4d211af4a9e74a533721c08f03f9
    • WIRE-DEC-011 sha256:78340a1b77fad0a94fdd12875dd851446ff46fea84d92f4eb1766f9fb6637909
    • WIRE-DEC-012 sha256:bbf48898109b852fe1b5784511c0bb5aa308162ceacd10b8777023fa391f9491
    • WIRE-DEC-013 sha256:4a7375048cd8a95c1b37ecaae2e5d21c7dbb97b5e95c544d12fd2db1ccb29b7b
    • WIRE-DEC-014 sha256:26d5aafc3d7e2bbf9304d04d9c0e1bf435968260b18dd05043fef4d1666596bd
    • WIRE-DEC-015 sha256:a78c203aaf7314a61baa093d7e80e87171e8695c570f7e0b443b4ddda227be66
    • WIRE-DEC-016 sha256:977cc72dfe7abd290dff31fa27f8150c26c0c27b4704e31427aabca3e7dffd52
  • Remove the archived monorepo documentation link; package guidance remains in
    the repository-owned documentation.

go-wire v2.0.0

Choose a tag to compare

@faustbrian faustbrian released this 04 Oct 07:25
12700f3

Fixed

  • Preserve YAML scalar values and mapping keys, including marker-like text
    inside block contents or multiline quoted strings. Explicit indentation
    follows the emitted mapping or sequence layout, including root and nested
    tab-leading block scalars.

  • Preserve blocks nested inside explicit collection keys and values. Keep
    plain scalar content unchanged at large configured byte limits rather
    than wrapping it into marker-like continuation lines.

  • Preserve marker-like scalar text inside inline flow collections and
    trailing comments while repairing real blocks after empty collection keys.

  • Preserve emitted carriage returns and Unicode line breaks in comments and
    scalar bodies while repairing subsequent tab-leading block values.

  • Preserve authored folded YAML values across ordinary and more-indented
    line transitions and trailing breaks. Admit the inclusive final byte quota
    after bounded provider-output normalization without repeating callbacks.

  • Upgrade CBOR decoding to reject dynamically uncomparable typed map keys
    as parse errors instead of panicking. Comparable keys and the default
    prohibition on tags remain unchanged.

Changed

  • Publish the major module as github.com/faustbrian/go-wire/v2. Update all
    Wire imports together; v1 and v2 error types and sentinels are distinct.

  • Harden XML and SOAP built-in charset conversion with bounded raw input and
    labels, pre-read allowlist rejection, and private categorical diagnostics.
    Add xmlwire.CharsetReaderWithLimit for explicit quotas. Custom charset callbacks remain caller-owned.

  • Make shared wire errors and SOAP fault errors render categorical text only,
    retaining original diagnostic fields, causes, and error classification.
    Use typed causes and fault fields instead of previous diagnostic text.
    WIRE-DEC-014 sha256:1238f483bf726688031a864be2082b503cdc4566830dc16ecbaf25f58d12bac9

  • Validate nested BSON structure and CodeWithScope scopes before decoding,
    retain structural checks with duplicate-key opt-in, and require consecutive
    array indices. Iterative raw validation permits 100 nested containers below
    the root; encoding checks output after codec work. These acceptance changes
    do not provide pre-encoding allocation protection.
    WIRE-DEC-012 sha256:bcc48febdf249b122ae7bbed2aff0ef5ba84ceeda0a501589276d6d673fec20c

  • Adopt MongoDB driver v2.9.1 while retaining external BSON driver aliases;
    driver network and GridFS operations remain outside the module's imported
    package boundary.

Documentation

  • Record the 2026-10-02 FIDO Alliance feed review while retaining the exact
    CTAP 2.2 normative PDF and deterministic-CBOR profile.

  • Align the codec dependency table with the CBOR v2.9.4 and BSON v2.9.1
    module pins.

v1.0.1

Choose a tag to compare

@faustbrian faustbrian released this 13 Sep 04:25
609cfd9

What's Changed

New Contributors

Full Changelog: v1.0.0...v1.0.1

github.com/faustbrian/go-wire v1.0.0

Choose a tag to compare

@faustbrian faustbrian released this 26 Aug 05:51

[1.0.0] - 2026-08-25

Changed

  • Validate action pinning from the standalone repository root and leave
    repository-foundation policy to the authoritative repository contract.

  • Exclude intentional nested modules from root local-proxy archives so local,
    bootstrap, CI, and public module checksums describe the same source
    boundary.

  • Track the pinned documentation-tool lockfile so clean CI checkouts install
    the exact validated cspell dependency.

  • Reconcile standalone dependency checksums against deterministic current
    module archives so CI, local verification, and release consumers resolve
    identical content.

  • Harden standalone documentation validation with deterministic spelling and
    link checks, package-specific documentation gates, and repository-local
    contributor guidance.

Documentation

  • Replace obsolete standalone-repository links and workflow claims with
    monorepo-canonical targets and current release guidance.

  • Link the package README to the repository-wide Golib documentation portal.

Compatibility

  • Added a pinned module export baseline so incompatible public API changes
    fail the canonical repository gate.

Changed

  • Publish the module from its standalone github.com/faustbrian/go-wire identity while preserving its documented API and behavior.
  • Hardened codec boundary coverage with exact byte, depth, numeric, charset,
    alias, fragment, and SOAP fault assertions, and bounded mutation execution
    for malformed XML and SOAP parser mutants.
  • Link the conformance source matrix directly to the canonical specification
    decision register.
  • Added the GO-SAFETY-1 ownership, concurrency, race, fuzz, resource, and
    benchmark standard with an executable make safety gate.
  • Moved AI planning and hardening briefs into .ai/ and clarified the
    separate purposes of project and third-party notice files.

Added

  • A specification decision register, pinned normative-source manifest, and
    executable conformance gate covering the observable JSON, XML, SOAP, YAML,
    TOML, MessagePack, CBOR, and BSON policy choices.
  • Opt-in recursive duplicate-name rejection for bounded JSON decoding before
    the destination value can be mutated.
  • A standardized OSS repository skeleton covering policy, documentation,
    legal notices, Go tooling, pinned CI, security, and release automation.
  • CI resolves the latest supported Go 1.25 patch while go.mod declares the
    portable Go 1.25 minimum.
  • Evidence-driven audit and hardening goal covering every supported format,
    parser resource safety, codec dependencies, and read/write boundaries.
  • A shared wire.Error model with parse, validation, unsupported-format,
    envelope, and SOAP-fault classifications.
  • Size-limit, invalid-target, and encoding classifications shared by every
    format package.
  • Explicit JSON, XML, SOAP, YAML, TOML, MessagePack, CBOR, and BSON format
    identifiers.
  • Opt-in JSON/XML format detection based on the first significant byte.
  • Bounded JSON byte-slice and reader decoding with optional unknown-field
    rejection and single-value enforcement.
  • Deterministic JSON encoding with configurable indentation and HTML escaping.
  • Explicit JSON normalization that strips a UTF-8 BOM, compacts whitespace,
    orders object keys, and preserves number lexemes.
  • JSON fixtures, malformed-input regression tests, fuzz seeds, and parse and
    encode benchmarks.
  • Bounded strict XML decoding, opt-in non-strict recovery, exact
    namespace-aware root validation, and resolved-root inspection.
  • Deterministic XML encoding with optional declaration and indentation.
  • Built-in, explicit charset conversion for UTF-8, US-ASCII, ISO-8859-1, and
    Windows-1252, including rejection of invalid or undefined bytes.
  • Namespace, malformed-document, charset, and trailing-root XML fixtures and
    regressions, plus fuzz seeds and parse and encode benchmarks.
  • Bounded SOAP 1.1 and 1.2 envelope parsing with exact raw envelope, header,
    and body access and namespace-preserving body decoding.
  • Typed SOAP 1.1 and 1.2 fault extraction, localized SOAP 1.2 reasons,
    subcodes, details, and errors.Is classification.
  • Deterministic envelope and fault serialization from validated raw fragments.
  • SOAP envelope, fault, malformed-input, structural-regression, fuzz, and
    benchmark coverage.
  • Compile-checked examples and adoption documentation covering quickstart,
    architecture, the complete public API, supported formats, behavioral
    guarantees, limitations, and rollout guidance.
  • End-to-end JSON, XML, and SOAP examples, a scenario cookbook, FAQ, and
    error-focused troubleshooting guide.
  • Migration, versioning, release, contribution, security, conduct, and roadmap
    documentation for open-source operation.
  • Reproducible local formatting, vet, lint, race-test, 100% coverage, fuzz,
    benchmark, documentation-link, and vulnerability quality gates.
  • GitHub Actions for the Go 1.25 and 1.26 build/race-test matrix,
    formatting, static analysis, lint, exact coverage, documentation, fuzz smoke,
    benchmark smoke, and vulnerability scanning.
  • Scheduled extended fuzzing and benchmark baselines, Dependabot configuration,
    and an interoperability-focused pull request template.
  • Tagged release automation that validates SemVer tags and changelog entries,
    reruns quality and security gates, creates a deterministic source archive and
    checksum, and publishes a GitHub Release with extracted notes.
  • Explicit method-level documentation for every exported error API.
  • JSON and XML writer APIs, typed SOAP header/body encoding, and SOAP envelope
    and fault writer APIs for symmetric input and output handling.
  • Bounded YAML read/write APIs with duplicate-key and multi-document policy,
    alias and merge controls, expansion limits, deterministic output, fixtures,
    fuzzing, and benchmarks.
  • Complete TOML document read/write APIs with strict-field metadata, native
    datetime handling, checked numeric conversion, deterministic output,
    fixtures, fuzzing, and benchmarks.
  • MessagePack read/write APIs with exact one-object enforcement, map-key and
    extension policy, checked numeric widths, timestamp support, deterministic
    map encoding, fixtures, fuzzing, and benchmarks.
  • Canonical, Core Deterministic, and CTAP2 CBOR read/write profiles with tag,
    indefinite-length, duplicate-key, and resource-limit policy, plus fixtures,
    fuzzing, and benchmarks.
  • BSON document read/write APIs with recursive duplicate-key rejection, exact
    length validation, ordered and raw document support, ObjectID and datetime
    aliases, checked numeric conversion, fixtures, fuzzing, and benchmarks.
  • Pinned, reviewed YAML, TOML, MessagePack, CBOR, and BSON codec dependencies
    with documented maintenance, security, and residual-risk rationale.
  • Compile-checked round-trip examples and full API, format, migration,
    adoption, security, troubleshooting, and dependency documentation for all
    eight supported formats.
  • A distinct wire.ErrWrite classification for destination failures.
  • Consistent repository automation for generated portable AI documentation,
    dependency review, and guarded semantic release commands.
  • Configurable output byte limits for every JSON, XML, SOAP, YAML, TOML,
    MessagePack, CBOR, and BSON byte and writer encoding path. Zero selects the
    safe 1 MiB default.
  • Size-bounded SOAP raw-envelope and fault APIs through MarshalOptions,
    MarshalWithOptions, MarshalWriterWithOptions,
    MarshalFaultWithOptions, and MarshalFaultWriterWithOptions.

Changed

  • The minimum supported Go version is Go 1.25.0; later Go 1.25 patch
    releases and newer language versions are supported.
  • Fuzz, benchmark, release, and documentation automation now covers YAML,
    TOML, MessagePack, CBOR, and BSON alongside JSON, XML, and SOAP.
  • Corrected codec troubleshooting and migration guidance to use the exported
    option and profile names, describe YAML's actual safe defaults, distinguish
    legacy size classifications, and document BSON double truncation as
    explicitly lossy.
  • MessagePack decoding now enforces configurable safe defaults of 32 nesting
    levels, 131,072 array elements, and 65,536 map pairs. Structural limit
    failures are classified as wire.ErrSizeLimit.
  • MessagePack decoding now rejects duplicate map keys recursively by default,
    with explicit last-key-wins compatibility through AllowDuplicateKeys.
  • BSON now re-exports the official array, raw value, Decimal128, binary, regex,
    timestamp, JavaScript, scoped code, sentinel, pointer, and symbol types.
  • Published the evidence-driven hardening report, threat model, per-format
    conformance matrix, allocation policy, dependency residual risks, and
    pre-v1 semantic-version recommendation.
  • Writer APIs now complete encoding within the configured output quota before
    writing, so an encode limit failure cannot emit a partial destination
    payload.

Fixed

  • Keep module-archive tests scoped to files shipped with the wire module;
    repository-root workflow policy remains owned by the root verification gate.
  • Bound fuzz-smoke concurrency to avoid deadline flakes on high-core hosts.
  • MessagePack now performs allocation-safe structural preflight for impossible
    collection lengths and composite map keys. Numeric preflight rejects
    narrowing overflow in typed maps, array-encoded structs, and automatically
    inlined embedded fields before the decoder can apply a lossy Go conversion.
  • MessagePack structural validation now stops recursive traversal and compact
    collection allocation amplification at explicit caller-configurable limits.
  • All typed encoders now reject cyclic values and nesting beyond 1,000
    traversed levels before recursive codecs can exhaust the process stack.
  • MessagePack numeric preflight now also prevents duplicate keys from being
    silently overwritten before assignment.
  • BSON documentation and tests now prove Decimal128, binary subtype, and regex
    interoperability instead of...
Read more