Skip to content

Bump the go group across 1 directory with 2 updates - #3635

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/go-b624269fdb
Open

Bump the go group across 1 directory with 2 updates#3635
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/go-b624269fdb

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the go group with 2 updates in the / directory: github.com/buger/jsonparser and github.com/jfrog/jfrog-cli-security.

Updates github.com/buger/jsonparser from 1.3.0 to 1.6.1

Release notes

Sourced from github.com/buger/jsonparser's releases.

v1.6.1 — Fastest across all payload sizes (now benchmarks vs gjson + sonic)

🔒 Covered by ReqProof — L3 Assurance (123 requirements, 0 errors, 0 warnings)

Performance — gjson-style fast-skip

Ported gjson's >'\\' single-comparison fast-skip to three hot loops. The trick skips all non-structural bytes (those > 0x5C) in one unsigned comparison per byte, reducing branch overhead.

Payload Before After Change
Small (190B) 382 ns 339 ns -11.3%
Medium (2.4kB) 3,899 ns 3,141 ns -19.4%
Large (24kB) 20,788 ns 20,114 ns -3.2%

Now benchmarks against gjson and sonic

Added tidwall/gjson (15.5k⭐) and bytedance/sonic (9.6k⭐) to the benchmark suite.

Large payload — the definitive ranking:

Library time/op allocs
jsonparser 20,114 ns 0
gjson 22,756 ns 2
easyjson 33,771 ns 134
sonic 41,053 ns 71
ffjson 59,063 ns 144
encoding/json 130,565 ns 147

jsonparser is the fastest across ALL payload sizes and the only zero-allocation parser.

Full changelog: CHANGELOG.md

v1.6.0 — Append function + zero open known issues

🔒 Covered by ReqProof — L3 Assurance (123 requirements, 0 errors, 0 warnings, 0 open known issues)

New API: Append

// Append to an array without knowing its length
data, _ = jsonparser.Append(data, []byte(`"new_item"`), "items")

Append(data, value, keys...) ([]byte, error) — clean array-append API. Works on top-level and nested arrays. Auto-creates missing paths as single-element arrays. No need for [N] path syntax.

Bug fixes — all known issues resolved

KI Fix
KI-2 ParseInt("-") now returns MalformedValueError (was returning 0, nil)
KI-3 Disposition corrected to fixed (auto-coerce was implemented in v1.3.0)

... (truncated)

Changelog

Sourced from github.com/buger/jsonparser's changelog.

[v1.6.1] — 2026-07-29

Covered by ReqProof — L3 Assurance (123 requirements, 0 errors, 0 warnings)

Performance — gjson-style fast-skip in hot loops

Ported gjson's >'\\' fast-skip trick to three inner loops in parser.go: stringEndConfig tail, blockEndConfig, and searchKeysConfig. The trick uses a single unsigned comparison (byte > 0x5C) to skip all non-structural bytes in bulk, reducing per-byte branch overhead.

Payload Before After Improvement
Small (190B) 382 ns 339 ns -11.3%
Medium (2.4kB) 3,899 ns 3,141 ns -19.4%
Large (24kB) 20,788 ns 20,114 ns -3.2%

Zero allocations maintained on all paths.

Benchmarks — now includes gjson and sonic

Added tidwall/gjson (15.5k⭐, path-based parser like jsonparser) and bytedance/sonic (9.6k⭐, SIMD-accelerated deserializer) to the benchmark suite.

Final leaderboard (large payload):

Library time/op bytes/op allocs/op
buger/jsonparser 20,114 0 0
tidwall/gjson 22,756 28,672 2
mailru/easyjson 33,771 4,016 134
bytedance/sonic 41,053 31,368 71
pquerna/ffjson 59,063 4,822 144
encoding/json 130,565 4,432 147

jsonparser is the fastest across all payload sizes and the only zero-allocation parser.


[v1.6.0] — 2026-07-29

Covered by ReqProof — L3 Assurance (123 requirements, 0 errors, 0 warnings)

New API — Append

// Append to an array without knowing its length
data, _ = jsonparser.Append(data, []byte(`"new_item"`), "items")

... (truncated)

Commits
  • 5663ba4 v1.6.1: gjson-style fast-skip optimization + benchmarks vs gjson/sonic
  • caa05b0 perf: gjson-style fast-skip in hot loops + benchmarks vs gjson/sonic
  • f1c83ac docs: remove anniversary article from repo (private draft)
  • 6c82735 docs: ten-year anniversary article with personal backstory and transitive deps
  • 3005d5b v1.6.0: Append function + all KI fixes (zero open known issues)
  • a55c29b v1.5.1: 6.1x large-payload speedup + fresh benchmarks
  • 09dbcf6 perf: SWAR string scan in stringEndConfig (8% large-payload speedup)
  • df5ae5b perf: bound stringEnd backslash scan to string body (5.8x large-payload speedup)
  • ae21251 Add MC/DC witnesses for SYS-REQ-115 (Config) and SYS-REQ-116 (ReaderParser)
  • dfb33c1 docs: complete CHANGELOG with v1.3.0–v1.5.0 entries, all mentioning ReqProof ...
  • Additional commits viewable in compare view

Updates github.com/jfrog/jfrog-cli-security from 1.31.4 to 1.32.0

Release notes

Sourced from github.com/jfrog/jfrog-cli-security's releases.

v1.32.0

What's Changed

Exciting New Features 🎉

Bug Fixes 🛠

Full Changelog: jfrog/jfrog-cli-security@v1.31.4...v1.32.0

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Aug 3, 2026
@ehl-jf ehl-jf added the ignore for release Automatically generated release notes label Aug 3, 2026
Bumps the go group with 2 updates in the / directory: [github.com/buger/jsonparser](https://github.com/buger/jsonparser) and [github.com/jfrog/jfrog-cli-security](https://github.com/jfrog/jfrog-cli-security).


Updates `github.com/buger/jsonparser` from 1.3.0 to 1.6.1
- [Release notes](https://github.com/buger/jsonparser/releases)
- [Changelog](https://github.com/buger/jsonparser/blob/master/CHANGELOG.md)
- [Commits](buger/jsonparser@v1.3.0...v1.6.1)

Updates `github.com/jfrog/jfrog-cli-security` from 1.31.4 to 1.32.0
- [Release notes](https://github.com/jfrog/jfrog-cli-security/releases)
- [Commits](jfrog/jfrog-cli-security@v1.31.4...v1.32.0)

---
updated-dependencies:
- dependency-name: github.com/buger/jsonparser
  dependency-version: 1.6.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/jfrog/jfrog-cli-security
  dependency-version: 1.32.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump the go group with 2 updates Bump the go group across 1 directory with 2 updates Aug 3, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/go-b624269fdb branch from 98cf63f to c9e1a76 Compare August 3, 2026 06:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code ignore for release Automatically generated release notes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant