Skip to content

chore(deps): bump jsonschema from 0.26.2 to 0.58.4 - #89

Merged
vyncint merged 2 commits into
mainfrom
dependabot/cargo/jsonschema-0.56.0
Oct 5, 2026
Merged

vyncint merged 2 commits into
mainfrom
dependabot/cargo/jsonschema-0.56.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Bumps jsonschema from 0.26.2 to 0.58.4.

Release notes

Sourced from jsonschema's releases.

[CLI] Release 0.58.4

No release notes provided.

[Python] Release 0.58.4

Fixed

  • repr of a validator_for validator naming the default draft instead of the one $schema declares.
  • unevaluatedProperties and unevaluatedItems beside a $recursiveRef ignoring what the reference target evaluates.
  • unevaluatedProperties ignoring the configured regex engine and its limits for patternProperties.
  • Absolute keyword location and schemaLocation of keywords a $ref JSON Pointer reaches through a subschema with its own $id.
  • type, minItems and maxItems ignored beside items when the applicator vocabulary is disabled.
  • Absolute keyword location and schemaLocation of keywords inside a nested $id resource counting from the document root.
  • required beside properties ignored when the applicator vocabulary is disabled, and required, minContains and maxContains applied when the validation vocabulary is disabled.
  • Absolute keyword location and evaluation output of type errors in a type-only items subschema pointing at items instead of the failing element's type.
  • Absolute keyword location of patternProperties annotations missing its JSON Pointer fragment.
  • Evaluation output of type: array beside schema-form items omitting passing type, minItems and maxItems units and nesting failing ones under items.
  • Evaluation output schemaLocation and absolute keyword location of $ref, $dynamicRef and $recursiveRef nodes not pointing at the reference target.
  • Evaluation output schemaLocation URIs not percent-encoding their fragment, such as a space in a property name.
  • Absolute keyword location of errors and annotations from a whole subschema, such as false, missing its JSON Pointer fragment.
  • Absolute keyword location of required, minContains and maxContains errors pointing at a sibling keyword.
  • Evaluation annotations from $ref siblings in Draft 4, 6 and 7 schemas.
  • Masked additionalItems messages counting allowed items instead of extra ones, and "1 items" in masked unevaluatedItems messages.
  • $dynamicRef and $recursiveRef resolving in the dynamic scope of another path to the same schema, depending on property order.
  • unevaluatedProperties and unevaluatedItems ignoring what then or else evaluates when if is true or false.
  • Stack overflow when building validators for long $ref chains.
  • format: "regex" and meta-schema validation rejecting escaped punctuation such as \- in patterns.
  • Build errors for an invalid patternProperties regex reporting the subschema instead of the pattern and its location.

[Ruby] Release 0.58.4

Fixed

  • inspect of a validator_for validator naming the default draft instead of the one $schema declares.
  • unevaluatedProperties and unevaluatedItems beside a $recursiveRef ignoring what the reference target evaluates.
  • unevaluatedProperties ignoring the configured regex engine and its limits for patternProperties.
  • Absolute keyword location and schemaLocation of keywords a $ref JSON Pointer reaches through a subschema with its own $id.
  • type, minItems and maxItems ignored beside items when the applicator vocabulary is disabled.
  • Absolute keyword location and schemaLocation of keywords inside a nested $id resource counting from the document root.
  • required beside properties ignored when the applicator vocabulary is disabled, and required, minContains and maxContains applied when the validation vocabulary is disabled.
  • Absolute keyword location and evaluation output of type errors in a type-only items subschema pointing at items instead of the failing element's type.
  • Absolute keyword location of patternProperties annotations missing its JSON Pointer fragment.
  • Evaluation output of type: array beside schema-form items omitting passing type, minItems and maxItems units and nesting failing ones under items.
  • Evaluation output schemaLocation and absolute keyword location of $ref, $dynamicRef and $recursiveRef nodes not pointing at the reference target.
  • Evaluation output schemaLocation URIs not percent-encoding their fragment, such as a space in a property name.
  • Absolute keyword location of errors and annotations from a whole subschema, such as false, missing its JSON Pointer fragment.
  • Absolute keyword location of required, minContains and maxContains errors pointing at a sibling keyword.
  • Evaluation annotations from $ref siblings in Draft 4, 6 and 7 schemas.
  • Masked additionalItems messages counting allowed items instead of extra ones, and "1 items" in masked unevaluatedItems messages.
  • $dynamicRef and $recursiveRef resolving in the dynamic scope of another path to the same schema, depending on property order.
  • unevaluatedProperties and unevaluatedItems ignoring what then or else evaluates when if is true or false.
  • Stack overflow when building validators for long $ref chains.

... (truncated)

Changelog

Sourced from jsonschema's changelog.

[0.58.4] - 2026-10-01

Fixed

  • Validator::draft returning the default draft instead of the one $schema declares.
  • unevaluatedProperties and unevaluatedItems beside a $recursiveRef ignoring what the reference target evaluates.
  • unevaluatedProperties ignoring the configured regex engine and its limits for patternProperties.
  • Absolute keyword location and schemaLocation of keywords a $ref JSON Pointer reaches through a subschema with its own $id.
  • type, minItems and maxItems ignored beside items when the applicator vocabulary is disabled.
  • Absolute keyword location and schemaLocation of keywords inside a nested $id resource counting from the document root.
  • required beside properties ignored when the applicator vocabulary is disabled, and required, minContains and maxContains applied when the validation vocabulary is disabled.
  • Absolute keyword location and evaluation output of type errors in a type-only items subschema pointing at items instead of the failing element's type.
  • Absolute keyword location of patternProperties annotations missing its JSON Pointer fragment.
  • Evaluation output of type: array beside schema-form items omitting passing type, minItems and maxItems units and nesting failing ones under items.
  • Evaluation output schemaLocation and absolute keyword location of $ref, $dynamicRef and $recursiveRef nodes not pointing at the reference target.
  • Evaluation output schemaLocation URIs not percent-encoding their fragment, such as a space in a property name.
  • Absolute keyword location of errors and annotations from a whole subschema, such as false, missing its JSON Pointer fragment.
  • Absolute keyword location of required, minContains and maxContains errors pointing at a sibling keyword.
  • Evaluation annotations from $ref siblings in Draft 4, 6 and 7 schemas.
  • Masked additionalItems messages counting allowed items instead of extra ones, and "1 items" in masked unevaluatedItems messages.
  • $dynamicRef and $recursiveRef resolving in the dynamic scope of another path to the same schema, depending on property order.
  • unevaluatedProperties and unevaluatedItems ignoring what then or else evaluates when if is true or false.
  • Stack overflow when building validators for long $ref chains.
  • format: "regex" and meta-schema validation rejecting escaped punctuation such as \- in patterns.
  • Build errors for an invalid patternProperties regex reporting the subschema instead of the pattern and its location.

[0.58.3] - 2026-09-30

Fixed

  • Keywords of a subschema declaring a Draft 2019-09+ $schema under a Draft 4, 6 or 7 root being ignored.
  • Evaluation annotations including those from subschemas of a failing schema (a failing schema produces no annotations).
  • Embedded resources declaring their own $schema being checked against the root's meta-schema.

[0.58.2] - 2026-09-28

Fixed

  • $dynamicRef targets in another document resolving relative references and reporting absolute keyword locations against the referencing document.
  • $ref to an $anchor or fragment $id validating against another anchor in the same document. #1668
  • schema_path of errors under a $ref or $dynamicRef to a named schema pointing at the resource root instead of that schema.

[0.58.1] - 2026-09-26

Fixed

  • Crash in Pyo3 validators when an Enum member's value override emptied a list or dict holding the instance being read.

Performance

... (truncated)

Commits
  • 22e9e39 chore(rust): Release 0.58.4
  • 8e57885 test: Cover malformed keyword values, masked messages and option paths in mod...
  • ccea405 build: Run each OS's Python tests as soon as its wheels are built
  • d94e107 build: Build the Python test wheels once per OS
  • d18ed08 build: Cache benchmark builds and install cargo-codspeed from a prebuilt binary
  • 91b39ce build: Drop the redundant wheel smoke test from Python release verification
  • 82b99f6 build: Cancel CI runs of closed pull requests
  • 1ae353d build: Speed up CI builds and fit Rust caches into the cache quota
  • 29bad0d build: Skip canonicalization tests on s390x
  • 0fda901 fix: Report required, minContains and maxContains errors at their own a...
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 22, 2026
@vyncint

vyncint commented Sep 22, 2026

Copy link
Copy Markdown
Owner

Holding this until after 2.3.0 ships, deliberately.

The release is being cut now, and each of these four changes a dependency that this repository cannot fully exercise on a plain runner:

  • sha2 0.10 → 0.11 feeds the candidate-id hash that appears in plan.v1, results.v1 and the committed fixtures. CI is green, which is real evidence the ids did not move — but that is worth landing on its own, after a release rather than inside one.
  • metal 0.29 → 0.33 is the Apple Silicon measurement backend. This PR's CI predates the Metal smoke step that test: cover the part that decides what the number is #94 added, so green here means it compiles, not that it dispatches. Rebasing it onto main will run a real dispatch on macos-latest and that is the check it needs.
  • jsonschema 0.26 → 0.56 and libloading 0.8 → 0.9 are red. libloading is the CUDA dlopen path, which nothing on a plain runner executes at all.

None of this is a judgement on the bumps. They land after the release, with the checks that can actually speak to them.

@dependabot
dependabot Bot force-pushed the dependabot/cargo/jsonschema-0.56.0 branch from 7eaeba5 to b2f74f2 Compare September 22, 2026 07:57
@dependabot
dependabot Bot requested a review from vyncint as a code owner September 22, 2026 07:57
@vyncint

vyncint commented Oct 5, 2026

Copy link
Copy Markdown
Owner

@dependabot rebase

@dependabot dependabot Bot changed the title chore(deps): bump jsonschema from 0.26.2 to 0.56.0 chore(deps): bump jsonschema from 0.26.2 to 0.58.4 Oct 5, 2026
Bumps [jsonschema](https://github.com/Stranger6667/jsonschema) from 0.26.2 to 0.58.4.
- [Release notes](https://github.com/Stranger6667/jsonschema/releases)
- [Changelog](https://github.com/Stranger6667/jsonschema/blob/master/CHANGELOG.md)
- [Commits](Stranger6667/jsonschema@rust-v0.26.2...cli-v0.58.4)

---
updated-dependencies:
- dependency-name: jsonschema
  dependency-version: 0.56.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/jsonschema-0.56.0 branch from b2f74f2 to 9cb6c44 Compare October 5, 2026 00:10
…e the golden depends on

The jsonschema bump (0.26 to 0.58) is used by one test, which validates a
report against schemas/report.v1.json through `validator_for`. That schema
has only local `#/definitions` references and a draft-07 `$schema`, so
nothing it does touches the network. jsonschema 0.58's default features
add an HTTP client and a TLS stack: this bump alone took the report
crate's dev tree from 140 packages to 168, with rustls, ring and aws-lc-sys
(a C build that needs cmake). `default-features = false` takes it to 93,
fewer than before the bump, with no HTTP or TLS at all; the lockfile ends
net smaller than main's. `cargo deny check` passes.

The bump also broke `report_validates_against_schema_and_matches_golden`.
The test writes a fixture, parses it back with serde_json, and snapshots
statistics computed from the parsed numbers, so its golden depends on
whether serde_json parses floats exactly, and jsonschema 0.58 turns that
on (`float_roundtrip`) where 0.26 did not. Five values moved in their last
digit. That dependence is now declared in the crate's dev-dependencies
instead of inherited from whatever a transitive crate enables, and the
snapshot is re-recorded: compared as JSON the structure is identical and
the five floats differ by at most 1.7e-16 relative.

Checked: the report crate's tests and clippy, rustfmt, cargo deny.
Signed-off-by: Vyncint Ng <115854244+vyncint@users.noreply.github.com>
@vyncint
vyncint merged commit 5050928 into main Oct 5, 2026
11 checks passed
@dependabot
dependabot Bot deleted the dependabot/cargo/jsonschema-0.56.0 branch October 5, 2026 00:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant