Skip to content

Bump github.com/tidwall/gjson from 1.19.0 to 1.20.0 in the go-dependencies group across 1 directory - #1476

Merged
bgentry merged 2 commits into
masterfrom
dependabot/go_modules/go-dependencies-286619ddd2
Oct 8, 2026
Merged

bgentry merged 2 commits into
masterfrom
dependabot/go_modules/go-dependencies-286619ddd2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-dependencies group with 1 update in the / directory: github.com/tidwall/gjson.

Updates github.com/tidwall/gjson from 1.19.0 to 1.20.0

Commits
  • 690362d Deprecate DisableModifiers and DisableEscapeHTML globals
  • b91555e nl at 80
  • b603eb1 Cleanup and modernize
  • 9378d3b Fix Result.Path panics
  • 8d89927 Ensure floating points are correctly being clipped
  • eaae8c6 Fix large number overflows for Int() and Uint()
  • 6ac9851 Change utf8 behavior for invalid codepoints
  • 5fc5c04 Update README.md
  • 7d8b382 Update README.md
  • 896d569 Update gjson.go
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-dependencies group with 1 update in the / directory: [github.com/tidwall/gjson](https://github.com/tidwall/gjson).


Updates `github.com/tidwall/gjson` from 1.19.0 to 1.20.0
- [Commits](tidwall/gjson@v1.19.0...v1.20.0)

---
updated-dependencies:
- dependency-name: github.com/tidwall/gjson
  dependency-version: 1.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 8, 2026

@bgentry bgentry left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Codex follow-up: Compatibility remains blocked on head 21f62407b0e0d9fa1cc94e7f653d7bd6330bd143.

Dependabot created this v1.20.0 update while processing the rebase request for #1470. The original dependency review covered GJSON v1.19.1, so its artifact/source security clearance does not cover the new v1.20.0 artifact.

The current conformance check fails in snooze_counter_matches_go_fixture, case fractional_string_is_zero: Rust produces 1, while the generated Go fixture expects 5. Reconcile Go/Rust/JavaScript snooze-counter coercion and fixtures before merging. This result comes from the hosted check; no local execution or full security review of v1.20.0 has been performed in this run.

This new minor update falls outside the frozen initial review queue and remains unapproved pending a fresh security delta review and successful compatibility checks.

@bgentry bgentry left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Codex review: Changes requested. Supply-chain security gate is clear; compatibility gate is blocked. This PR is not ready to merge.

Blocking finding — snooze counts diverge between clients

GJSON v1.20.0 changes Result.Int() to accept floating-point numeric strings and clamp integer overflow. River's Go executor reads snoozes with this method. For metadata {"snoozes":"4.5"}, NextSnoozeCount now returns 5, while Rust and JavaScript still return 1. The freshly generated fractional_string_is_zero fixture expects 5, and local Rust conformance plus hosted Rust and JavaScript tests fail on that mismatch.

Additional probes of the reviewed old/new artifacts show {"snoozes":"1e3"} changes the next count from 1 to 1001; signed integer boundary behavior also changes. Before merge, choose the intended coercion policy and implement it consistently across Go, Rust, and JavaScript, with conformance coverage for fractional/exponent strings and overflow boundaries. Update the fractional fixture's name if accepting fractional strings is intentional.

Upgrade

  • github.com/tidwall/gjson: v1.19.0 → v1.20.0.
  • Reviewed head: 21f62407b0e0d9fa1cc94e7f653d7bd6330bd143; base: 0be1dd97584bb019b451988404ba898a631ff4cb.
  • Scope: 15 Go manifest/sum files. Incidental churn adds conformance's indirect golang.org/x/tools v0.50.0 requirement and refreshes stale River v0.48.0 sums to the already-required v0.49.0 modules. No replace, exclude, Go/toolchain, workspace, vendored, or generated-source changes.

Security review

  • A delegated read-only review inspected the published artifacts, source delta, provenance, module graph changes, and advisory metadata before executable validation.
  • GJSON v1.20.0 module sum h1:+agJ3rEzKcCXKDKo0ml26UROcpcAlnZyjq+TjbY5Fto= and unchanged go.mod sum h1:V37/opeE/JbLUOfH0QTXiNez2l0RUjYUhpT4szFQAfc= were recomputed and matched the PR and sum.golang.org. All 10 published files match the canonical upstream tag at 690362d6edf4bcbde1e9f54d552d3814f1cd5bcb.
  • Reused exact-version/checksum evidence for GJSON v1.19.0, x/tools v0.49.0/v0.50.0, and River v0.49.0 modules; verified the current PR's identities and reviewed the new GJSON v1.20.0 artifact/source delta. No same-version checksum rewrite or unexplained source change was found.
  • Changes cover integer/string conversion, malformed-path handling, invalid UTF-8 output, modernization, and synchronized modifier/HTML-escape state. No new runtime network, credential/environment, filesystem, process, cgo, downloaded-binary, or build-hook behavior was found; existing unsafe string/byte conversions are unchanged.
  • DisableModifiers and DisableEscapeHTML become ineffective, and stock modifiers can no longer be overridden. River has no use of these globals or AddModifier at this head. Upstream dependency metadata and license remain unchanged.
  • Known Go advisory metadata shows no affected range for GJSON v1.20.0; historical GJSON advisories are fixed by v1.9.3. This is a routine upgrade, not a confirmed security update.

Compatibility verification

  • make tidy — passed across all 10 workspace modules; no tracked diff.
  • go mod verify in each workspace module — passed.
  • make test — passed with full permissions, including PostgreSQL/SQLite driver coverage and legacy transaction checks.
  • make lint — passed with full permissions, zero issues across all 10 modules; no tracked diff.
  • make generate/fixtures — passed; the current Go fixture records 5 for the fractional string case.
  • make test/rust/conformance — failed: 124 unit tests passed, one failed (snooze_counter_matches_go_fixture, fractional_string_is_zero, actual 1 / expected 5). The command stops before the protocol fixture binary.
  • Hosted Go CI, including race and database-version coverage, passed. All eight failed hosted Rust test jobs show the same snooze assertion; both JavaScript unit jobs fail the corresponding completion-command test. Hosted JavaScript build/lint/package/integration jobs and Rust quality passed.
  • Local tools: Go 1.27.1 and Rust 1.98.1 on macOS arm64. Local JavaScript execution was unavailable with Node 24.14.1 and no configured pnpm; exact-head hosted Node 26 results provide the JavaScript failure evidence. Broader local Rust/JavaScript checks were not repeated after the material conformance failure.

Residual risk

The lightweight GJSON tag and commit are unsigned; no signed release attestation or independent sumdb inclusion proof was verified. Checksum/source consistency establishes artifact identity, not publisher trust. Existing unsafe optimizations and ordinary third-party source-audit limits remain. Wider x/tools transitives received metadata review rather than a fresh exhaustive semantic audit; they are absent from River's imported runtime paths. Downstream applications sharing GJSON's deprecated global settings should assess the configuration changes. No blocking supply-chain issue was identified, but the reproducible cross-client compatibility regression blocks approval and merge.

A GJSON update changes how malformed `snoozes` values coerce to
integers, making cross-language fixtures fail while valid counters
continue to work. The ports carry custom parsing solely to match
those incidental conversions.

Limit shared fixtures to canonical non-negative integer counters and
absent values, retaining precision and int64 boundary coverage. Use
native integer decoding in Rust and the existing exact-number helper
in JavaScript, restarting invalid or overflowing counters safely.

Keep malformed-value safety coverage local to each implementation
without requiring an exact cross-language recovery result.
@bgentry

bgentry commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

@brandur The GJSON upgrade changed how malformed integer snooze counters like "4.5" are coerced, breaking conformance tests even though normal integer counters still worked. It made no sense to assert the specific parsed value of an invalid input IMO. Maybe if we were to enforce that it's an error of some kind that'd make sense, but it's not currently what happens.

I narrowed the shared fixtures to valid integer counters and missing values, while retaining local safety tests for malformed inputs without requiring identical recovery values. I also removed the custom GJSON-emulation parsers in Rust and JavaScript, using their existing integer readers instead.

@bgentry bgentry left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Codex review: Approved after dependency security and compatibility review. The earlier malformed-counter conformance blocker is resolved on this head.

Upgrade

  • github.com/tidwall/gjson: v1.19.0 → v1.20.0
  • Reviewed head: 21881d66f1c3ecb7b84902d5e2e9d4a0b05cafe0

Security review

  • Reused the delegated artifact/source review for the unchanged dependency identities from 21f62407b0e0d9fa1cc94e7f653d7bd6330bd143. Both GJSON module zips match their canonical upstream tags and independently recomputed module hashes/public checksum records. The new version resolves to upstream commit 690362d6edf4bcbde1e9f54d552d3814f1cd5bcb, with module sum h1:+agJ3rEzKcCXKDKo0ml26UROcpcAlnZyjq+TjbY5Fto=. No same-version checksum rewrite, source replacement, toolchain change, vendoring, or new lifecycle hook is introduced.
  • Inspected the complete GJSON source delta, including integer conversion, malformed-path bounds checks, UTF-8 encoding, modifier locking, and deprecated global settings. No new production network access, environment/credential reads, filesystem writes, process execution, cgo, or binary payload appears; existing unsafe conversions are unchanged. The known GJSON advisories checked do not affect either version. This is a regular version update, not an identified advisory fix.
  • Reviewed the incidental indirect golang.org/x/tools v0.49.0 → v0.50.0 selection and River v0.49.0 stale checksum refreshes. Published artifacts match canonical source/checksum records. The tools changes remain outside River's imported runtime package paths; no unexpected execution surface was identified in the reviewed delta.
  • Reviewed the seven-file delta on the current head: shared snooze fixtures now specify canonical non-negative integer counters and absent values, retain exact large-integer/int64 boundary coverage, and leave malformed-value recovery implementation-specific. Rust and JavaScript use their existing integer readers instead of custom GJSON emulation, with local malformed/overflow safety tests. The fix adds no dependency identity, manifest, lockfile, hook, or execution-context changes.

Compatibility verification

  • Current-head local make tidy — passed across all 10 Go modules, with no tracked changes. Prior go mod verify results are reused because all module manifests and sums are identical to the verified dependency head.
  • Current-head local make test, make lint, make generate/fixtures, and make test/rust/conformance — passed. Generated fixture bytes also match those produced with the pre-upgrade GJSON version after the same suite correction.
  • Full local JavaScript tests and lint passed for identical JavaScript source/manifests/lockfile and identical generated fixture inputs. Full Rust tests and lint also passed for the fix before applying it to this dependency head; the exact-head hosted Rust matrix supplies the combined-tree coverage.
  • All 40 hosted checks passed on the reviewed head, including Go PostgreSQL/SQLite/race tests and lint, fixture conformance, Rust versions 1.95–1.97 and PostgreSQL 14–18, JavaScript unit/build/lint/integration jobs, generation verification, CLI builds, and CodeQL. The formerly failing Rust and JavaScript conformance cases now pass.

Residual risk

  • No blocking issue identified. The upstream GJSON tag/commit is unsigned; no maintainer attestation or independent sumdb inclusion-proof verification was available. The wider tools module and metadata-only transitives were not exhaustively audited. GJSON's deprecated configuration globals and invalid-value coercions change upstream behavior; River does not use those globals, and exact malformed-counter coercion is intentionally outside the shared protocol.

@bgentry
bgentry merged commit 2a64484 into master Oct 8, 2026
40 checks passed
@bgentry
bgentry deleted the dependabot/go_modules/go-dependencies-286619ddd2 branch October 8, 2026 02:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant