Skip to content

Releases: zsltg/iq

v0.38.0

Choose a tag to compare

@github-actions github-actions released this 30 Sep 14:04
7e760ef

iq v0.38.0

Fixes

  • Pushdown no longer drops matching records. A select() that came after a stage that changes the item, such as .[] | .b | select(.c == 2), was pushed down as a test on the whole item. The backend, or the raw prefilter of a dump file, could then drop records that the filter keeps, with no error. Pushdown now uses only the select() stages that test the item itself. The same bug affected a head such as .[].b | select(...), and a select() after map(...) or an object construction. If you ran such a filter with pushdown on, run it again.
  • DynamoDB parses integers at the size of int.

Changes

  • iq add stores a source password in the OS keyring by default. The saved URI keeps no password. When no keyring is available, for example on a server with no Secret Service, iq add keeps the password in the config file and prints one warning. Use --store inline to keep it in the config file without the warning, or --store keyring to make a missing keyring an error. iq add does not replace a password that the keyring already holds for the handle, because a source with the same handle in another config file can use it. Existing sources do not change: iq config keyring migrate moves their passwords to the keyring.

Project

  • Draft pull requests run only the fast CI jobs, and marking a pull request ready starts the full run.
  • A failed mutation check in CI uploads the ids of the escaped mutants.
  • Every Linux CI job runs StepSecurity Harden-Runner in audit mode.
  • The DCO check accepts a remediation commit for a missing sign-off.
  • CodeQL scans the Go code on every pull request.
  • The mutation baseline is being rebuilt for mutago v2.10.16: 9 packages are done.

The full list is in CHANGELOG.md.


Generated by Claude Code

v0.37.1

Choose a tag to compare

@github-actions github-actions released this 29 Sep 07:00
800f084

iq v0.37.1

Fixes

  • Negative zero keeps its sign. A -0 in a document now reads and prints as -0, as
    in jq, and a typed dump of -0.0 reads back unchanged. Before, it became 0.
  • Found by the new fuzz targets:
    • The raw prefilter could drop a record that the full jq filter keeps, when a JSON object
      repeats a key (for a field path, length, or a negated any) or a typed dump repeats its
      value field, also in another letter case.
    • A crafted BSON dump header could make the reader allocate up to 4 GiB. The frame length
      is now held to BSON's own limits.
    • A filter with no expression (a bare comment) caused a panic in the key selector.
    • A CBOR tag in the dump cache decoded to a value outside the cache's value set. A tagged
      cache now counts as corrupt.

Signed releases

This is the first release with a cosign signature and SLSA build provenance:

  • checksums.txt.sigstore.json: a keyless cosign signature of checksums.txt, made by the
    release workflow's GitHub identity.
  • multiple.intoto.jsonl: SLSA level 3 build provenance for every artifact.

See Verify a release for the commands.

Project

  • Go native fuzz targets run in CI on every change and weekly, and the Linux tests run with
    the race detector.
  • New commits carry a Developer Certificate of Origin sign-off, checked in CI.
  • CONTRIBUTING.md is now a short guide, with the full developer guide in DEVELOPMENT.md.

The full list is in CHANGELOG.md.


Generated by Claude Code

v0.37.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 17:02
21bd8f6

iq v0.37.0

Security

  • Dependency updates for three advisories: grpc v1.83.2 fixes
    GHSA-2v4p-qf9q-27wj, and
    x/crypto v0.56.0 fixes GO-2026-6354 and
    GO-2026-6355. iq does not reach the affected code
    (gRPC server paths and x/crypto/ssh), but the fixed versions are now in the binary.

New

  • Config file mode warning. If the config file holds an inline password and other users
    can access it (a mode wider than 0600), every command prints one warning to stderr with
    the chmod 600 fix and then runs as usual. See
    Configuration.

Documentation

  • The note on the home page now names iq exec as a command that can write, with no dry run.
  • iq mcp --help and the agent docs say that --allow exec lets an agent do anything the
    database account can do, and suggest a read-only database user.
  • New REVIEW.md with the review rules, and
    a written test policy in CONTRIBUTING.md.

Project

  • Every change now goes through a pull request with required CI, and releases are made
    through a release pull request.
  • New badges: OpenSSF Best Practices (passing) and CodeScene code health.

The full list is in CHANGELOG.md.


Generated by Claude Code

v0.36.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 07:58

iq v0.36.0

This is the first public release of iq.

iq runs jq filters to query, dump, copy, diff and write data across NoSQL
databases and their dump files. It is one static binary for Linux, macOS and Windows, on amd64
and arm64.

What it does

  • Query with jq. The filter is also the key selector. Its top-level paths name the keys to
    fetch, so a query reads only what it asks for.
  • Push filters to the server. A select(...) on a scan becomes a native server-side filter
    where the backend supports it. The full jq filter always runs again on the client, so the
    output does not change.
  • Copy, restore and migrate. Typed dumps carry native types from one store to another. A copy
    or a migration is one command.
  • Compare. iq diff compares two sources, also across different backends.
  • Read dump files. iq reads backup and export files (for example mongoexport, mongodump
    BSON, Redis RDB, DynamoDB JSON) without a running database.
  • Work with AI agents. iq mcp runs iq as an MCP server over stdio, and an Agent Skill
    teaches the workflow.

Queries are read-only. --insert, --replace, iq data clear, iq data drop and
iq data delete write to a target. iq exec forwards a native command to the database, so it
can write too. --explain shows the query plan, and --dry-run reports the effect of a write
without doing it. iq exec has no dry run.

Drivers

Apache Cassandra, Couchbase, Apache CouchDB, Amazon DynamoDB, Elasticsearch, OpenSearch,
Apache HBase, MongoDB, Neo4j, Redis, and local dump files. The
Drivers page lists the supported versions and what each
driver pushes to the server.

Install

# Linux (the script verifies the SHA-256 checksum)
curl -fsSL https://raw.githubusercontent.com/zsltg/iq/main/install.sh | sh

# macOS
brew install zsltg/tap/iq

# Windows
scoop bucket add zsltg https://github.com/zsltg/scoop-bucket
scoop install iq

# Go
go install github.com/zsltg/iq@latest

This release also contains .deb, .rpm and .apk packages, checksums.txt, and a CycloneDX
SBOM of the module (iq.cdx.json).

How it is built

iq is built with AI assistance. Every change passes the full test suite, container-backed
integration tests for every backend, and a mutation gate before it lands. See
CONTRIBUTING.md.

The full history is in CHANGELOG.md.
Feedback and bug reports are welcome. Use the issue forms, and report security problems
privately (see SECURITY.md).


Generated by Claude Code