2cbd0b3350
fix: add least-privilege token permissions to GitHub workflows (OSSF)
...
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/1b5db5e2-af78-4289-a6e0-2e972fc68ef1
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
2026-04-13 08:56:13 +00:00
copilot-swe-agent[bot] and GitHub
e2feebb221
Initial plan
2026-04-13 08:53:42 +00:00
0e803833fb
chore: pin GitHub Actions and Docker base images to full-length hashes (OSSF scorecard) ( #2658 )
...
* Initial plan
* chore: pin GitHub Actions dependencies to specific commit SHAs (OSSF)
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/cbd03f0a-f2dc-4da4-b01c-7dd06ad83ee9
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* chore: pin Dockerfile base images to specific SHA digests (OSSF)
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/7a8f6690-37fb-42ab-b3dc-0dd23c270fbe
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* chore: revert yq pins in test-yq.yml; add release note for github-action/Dockerfile SHA
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/e1b35d79-92a3-47d5-b4ac-a2efe2fd58ce
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
2026-04-12 19:31:32 +10:00
30ca9ffde7
Add SECURITY.md security policy ( #2660 )
...
* Initial plan
* Add SECURITY.md with security policy
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/f9ff8a4c-addc-485b-abb8-4103394851a4
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
2026-04-12 18:57:11 +10:00
2927a28283
TOML encoder: prefer readable table sections over inline tables ( #2649 )
...
* Initial plan
* Fix TOML encoder to prefer readable table sections over inline tables
When converting from YAML/JSON to TOML, the encoder now always uses
readable TOML table section syntax ([section]) instead of compact inline
hash table syntax (key = { ... }), which better matches TOML's goal as
a human-focused configuration format.
Changes:
- decoder_toml.go: Mark inline TOML tables with FlowStyle so round-trips
can be distinguished from YAML flow mappings
- encoder_toml.go:
- encodeTopLevelEntry: use FlowStyle check instead of EncodeSeparate to
decide inline vs table section (all block mappings now become tables)
- encodeSeparateMapping: count FlowStyle children as attributes; use
recursive encodeSeparateMapping for nested non-flow mappings
- encodeMappingBodyWithPath: emit non-flow child mappings as sub-table
sections instead of inline tables
- toml_test.go: add encode (YAML→TOML) test scenarios, update roundtrip
expectations for inline tables (now expanded to table sections)
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/4824a219-6d5e-42e7-bca1-a8a277bf8c6a
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* Fix TOML roundtrip: use TomlInline flag instead of FlowStyle to preserve inline tables
FlowStyle affected YAML decode output (causing inline tables to appear as
YAML flow mappings). Replace it with a new TOML-specific TomlInline bool
on CandidateNode that:
- Is set by the TOML decoder for inline tables (not FlowStyle)
- Is copied by UpdateAttributesFrom so it survives DeeplyAssign merges
- Is checked by the TOML encoder alongside FlowStyle (for YAML flow maps)
- Has no effect on the YAML encoder, preserving existing TOML→YAML output
TOML roundtrip tests are restored to their original expected values (inline
tables stay inline, table sections stay as sections).
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/f59bdf62-6d16-4664-991b-38eb87c9d81c
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* Refactor EncodeSeparate+TomlInline into a single EncodeHint enum
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/24db9a8f-601d-4ccf-ada7-129ed3226bb6
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* Fix stale comment in hasStructuralChildren
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/24db9a8f-601d-4ccf-ada7-129ed3226bb6
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* Remove unused hasStructuralChildren method from tomlEncoder
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/2c234b77-28e9-4995-ba6f-9d213ec551a0
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
2026-04-12 18:36:43 +10:00
c47fe40a30
Fix TOML encoder to quote keys containing special characters ( #2648 )
...
* Initial plan
* Fix TOML encoder to quote keys with special characters
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/b2b52954-d13f-4e67-831a-16fdd3378de5
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* Add test for dotted table section header with special character key
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/12c783dd-8b7f-43bf-b71a-e7a0b5e55fea
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* Apply De Morgan's law to tomlKey condition to fix staticcheck QF1001
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/eeab0316-309f-418f-b357-11bbacffb471
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
2026-04-12 14:27:20 +10:00
44c55c8a54
Add system(command; args) operator (disabled by default) ( #2640 )
...
* Initial plan
* Add system(command; args) operator with --enable-system-operator flag
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/8a11e9a0-10d2-4f2a-ae29-4e9d0bfc266f
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* Update pkg/yqlib/operator_system.go
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
* Evaluate system command/args per matched node using SingleReadonlyChildContext
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/dca841eb-3f63-4f23-adeb-556431560420
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* Add yqFlags to expressionScenario for doc command snippets; fix system op docs
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/3f8a5375-25fd-4428-a8e6-b630194c36b2
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* Update pkg/yqlib/doc/operators/headers/system-operators.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
* Update pkg/yqlib/doc/operators/system-operators.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
* Validate command node type and handle multiple results with debug log
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/928aabc5-ad71-41d8-94ab-403942e3f92d
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
* Remove deprecated --enable-system-operator alias; use --security-enable-system-operator consistently
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/286b95e9-b6d7-4ab8-b401-2d7a03853922
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
* Address deep review feedback: error on disabled, strict arg/cmd validation, debug logs, docs
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/fbfba2db-60ea-4c20-a4c2-0fd396b80c81
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
Co-authored-by: Mike Farah <mikefarah@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-04-10 20:06:46 +10:00
3b2423e871
Add string slicing support ( #2639 )
...
* Initial plan
* Add string slicing support to yq
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/a8525fbb-77a7-4bb0-a3a7-b24f99ae8710
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* Fix sliceStringNode signature and fix test descriptions/expressions
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/58726b13-68ae-4f93-971f-eb70459edcf4
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* Update pkg/yqlib/operator_slice.go
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
* Fix array slice out-of-bounds panic with very negative indices
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/7c146762-d251-45fd-8555-2488f59fc57b
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* S2-S4: tighten lexer condition, fix doc header, add Unicode example
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/ec06083e-e20a-45d2-bf7e-4e1fa7be1073
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
* Fix spelling: multibyte -> multi-byte in Unicode test subdescription
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/6e7b304b-5b52-4e89-8bad-ba22813305c7
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
Co-authored-by: Mike Farah <mikefarah@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-04-06 19:29:07 +10:00
7d8d3ab902
Replace gopkg.in/op/go-logging.v1 with log/slog ( #2635 )
...
* Initial plan
* Replace gopkg.in/op/go-logging.v1 with log/slog
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
Agent-Logs-Url: https://github.com/mikefarah/yq/sessions/aa9c12f4-21b9-4633-9868-6b56585b247f
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
2026-03-26 20:41:54 +11:00
5d6c2047cf
Fix spelling: use British English Colourization
...
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
2025-12-20 15:55:17 +11:00
7f60daad20
Add test for string escape bug and implement fix
...
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
2025-12-20 15:55:17 +11:00
9fa353b123
Add test coverage for parent(0) and parent(-3) edge cases
...
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
2025-12-20 15:36:49 +11:00
copilot-swe-agent[bot]
1de4ec59f2
Merge remote-tracking branch 'origin/pr/2552' into copilot/sub-pr-2552
...
# Conflicts:
# pkg/yqlib/toml_test.go
2025-12-20 04:26:11 +00:00
copilot-swe-agent[bot] and mikefarah
c132c32731
Convert to UK English spelling (colourization, coloured)
...
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
2025-12-20 04:17:39 +00:00
copilot-swe-agent[bot] and mikefarah
aa5134e645
Add test case and fix colorization bug for inline arrays in TOML
...
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
2025-12-20 04:09:04 +00:00
copilot-swe-agent[bot]
c1b81f1a03
Initial plan
2025-12-20 04:04:24 +00:00
fd405749f9
Add build tag to hcl_test.go to skip tests when HCL is disabled
...
Co-authored-by: mikefarah <1151925+mikefarah@users.noreply.github.com >
2025-12-08 20:30:47 +11:00