Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
20 commits
Select commit Hold shift + click to select a range
cce6008
ci: run the in-repo PR mirror job instead of skipping it
Shinrai Oct 2, 2026
b587fa8
ci: run the in-repo PR mirror job instead of skipping it (#78)
Shinrai Oct 3, 2026
4ab9ee8
chore: bump version to 1.1.3
cldmv-bot[bot] Oct 3, 2026
5fe45e9
deps: bump the minor group across 1 directory with 2 updates
dependabot[bot] Oct 3, 2026
2e82985
fix(cjs): make require() a synchronous wrapper around the ESM build
Shinrai Oct 3, 2026
ed3849d
fix(cjs): make require() a synchronous wrapper around the ESM build (…
Shinrai Oct 3, 2026
f128f02
deps: bump the minor group across 1 directory with 2 updates (#77)
Shinrai Oct 3, 2026
b0e625b
chore: bump version to 1.1.4
cldmv-bot[bot] Oct 3, 2026
8efb572
docs(changelog): backfill release notes for v1.0.0 through v1.1.3
Shinrai Oct 3, 2026
a5fb293
docs: add v1.1.4 release notes and restructure the README
Shinrai Oct 3, 2026
3348e9f
docs: add v1.1.4 release notes and restructure the README (#82)
Shinrai Oct 4, 2026
8a84d8b
deps: bump @cldmv/fix-headers to 2.1.4
Shinrai Oct 4, 2026
dc6cdb2
deps: bump @cldmv/fix-headers to 2.1.4 (#83)
Shinrai Oct 4, 2026
a729df6
docs: list the fix-headers 2.1.4 bump (#83) in the v1.1.4 notes
Shinrai Oct 4, 2026
14e71ff
docs: list the fix-headers 2.1.4 bump (#83) in the v1.1.4 notes (#84)
Shinrai Oct 4, 2026
34f5e25
deps: bump @cldmv/fix-headers to 2.2.0
Shinrai Oct 5, 2026
d514303
deps: bump @cldmv/configs to 1.2.4
Shinrai Oct 5, 2026
ddce07a
deps: bump @cldmv/configs to 1.2.4 (#85)
Shinrai Oct 5, 2026
143a50b
docs: update the v1.1.4 release notes
Shinrai Oct 5, 2026
9a403b6
docs: update the v1.1.4 release notes (#86)
Shinrai Oct 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
178 changes: 127 additions & 51 deletions README.md

Large diffs are not rendered by default.

67 changes: 67 additions & 0 deletions docs/changelog/v1/v1.0.0.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
# @cldmv/jsonv v1.0.0 Changelog

**Release Date**: January 2026
**Release Type**: Major (initial release)

---

## Overview

Version 1.0.0 is the first public release of `@cldmv/jsonv`, a hand-written, zero-dependency parser and serializer for **jsonv**: JSON5 extended with modern ECMAScript literals, internal references, and template interpolation, with features gated by ECMAScript year. jsonv is a static data format β€” it forbids executable syntax (no functions, classes, computed keys, or shorthand properties).

---

## ✨ Features

### JSON5 superset parser

`parse()` and `parseWithOptions()` accept everything JSON5 does (comments, trailing commas, single-quoted strings, unquoted keys, hex numbers) plus modern literals: binary and octal integers, BigInt (`9007199254740992n`), and numeric separators (`1_000_000`). `parse()` is signature-compatible with `JSON.parse(text, reviver)`.

`parseWithOptions()` takes a `ParseOptions` object:

- `year` β€” 2011 through 2025; defaults to the latest.
- `mode` β€” `"jsonv"`, `"json5"`, or `"json"`.
- `allowInternalReferences` β€” defaults to `true`.
- `strictBigInt` β€” require the `n` suffix for unsafe integers (default `false`).
- `strictOctal` β€” require `0o` and reject legacy `0755` (default `false`).
- `tolerant` β€” collect multiple errors instead of stopping at the first.
- `preserveComments` β€” keep comment nodes in results.

### Internal references and template interpolation

Values can refer to earlier or later keys in the same document, and template literals can interpolate them:

```jsonv
{ port: 8080, backup: port, url: `http://${host}:${port}` }
```

References are file-scoped only, forward references are supported, and circular references are rejected.

### Year-pinned APIs

Each ECMAScript year gates a feature set, exposed as its own entry point: `@cldmv/jsonv/2011` (JSON5 base), `@cldmv/jsonv/2015` (binary/octal literals and templates), `@cldmv/jsonv/2020` (BigInt), and `@cldmv/jsonv/2021` (numeric separators). Years 2022–2025 resolve to the 2021 module. `@cldmv/jsonv/loader` provides `loadYear()` and `getLoadedYear()` for dynamic loading, and `@cldmv/jsonv/year-resolver` provides `resolveYear()`, `isPublishedYear()`, and `getPublishedYears()`.

### Stringify

`stringify()` follows the `JSON.stringify(value, replacer, space)` signature; `stringifyWithOptions()` adds `mode` (`"jsonv"`, `"json5"`, `"json"`), a `bigint` strategy (`"native"`, `"string"`, `"object"`), `singleQuote`, `trailingComma`, `unquotedKeys`, and `preserveNumericFormatting`. `rawJSON()` and `isRawJSON()` implement raw-JSON passthrough compatible with the modern `JSON.rawJSON` API.

### Diagnostics

`diagnose()` reports the detected minimum year and features of a document plus `json` / `json5` compatibility flags. `info()` returns only the detected year and the parsed value.

### Packaging

Dual ESM/CJS build (the CommonJS entry exports a Promise of the ESM module, so CommonJS callers `await require("@cldmv/jsonv")`; v1.1.4 made it synchronous) with a `json-dev` export condition that resolves to `src/` for in-repo development, `.d.mts` type declarations, and a test suite with per-year `features/` and `violations/` fixtures run through Vitest.

---

## πŸ“š Documentation

- **NEW:** [docs/changelog/v1/v1.0.0.md](./v1.0.0.md) β€” this changelog.
- README, plus `docs/feature-matrix.md`, `docs/versioning-and-exports.md`, and `docs/json5-compatibility.md`.

---

## Upgrade notes

Initial release β€” nothing to migrate. Install with `npm install @cldmv/jsonv`.
40 changes: 40 additions & 0 deletions docs/changelog/v1/v1.0.1.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
# @cldmv/jsonv v1.0.1 Changelog

**Release Date**: April 2026
**Release Type**: Patch

---

## Overview

Version 1.0.1 fixes incorrect token start positions in the lexer for block comments and template literal tokens, and makes the parser skip comments that precede the root value. It also declares public publish access in `package.json`.

---

## πŸ› Bug Fixes

### Correct token start positions for block comments and templates

The lexer derived every token's start position by subtracting the raw text length from the end position. That is wrong for tokens that span lines β€” a multi-line block comment or template literal reported a start line, column, and offset that did not match where the token actually began. `createToken` now accepts an explicit start position, and the block-comment, `TemplateHead`, template-literal, `TemplateMiddle`, and `TemplateTail` scanners record the real start line, column, and offset before consuming the token.

### Parser skips leading comments before the root value

A document that began with a comment before its root value could fail to parse, because the parser went straight to the root value without consuming comment tokens first. The parser now skips leading comments before parsing the root value.

---

## πŸ”§ CI & tooling

- `package.json` gains `publishConfig.access: "public"` so the scoped package publishes publicly (introduced in the preceding "Update package privacy" commit and first shipped in this release).

---

## πŸ“š Documentation

- **NEW:** [docs/changelog/v1/v1.0.1.md](./v1.0.1.md) β€” this changelog.

---

## Upgrade notes

No breaking changes β€” drop-in for v1.0.0. Code that read token `loc`/offset values for multi-line block comments or templates will now see the corrected positions.
68 changes: 68 additions & 0 deletions docs/changelog/v1/v1.0.10.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,68 @@
# @cldmv/jsonv v1.0.10 Changelog

**Release Date**: September 2026
**Release Type**: Patch

---

## Overview

Version 1.0.10 gives parse errors a structured position. Every parse failure now throws `JsonvSyntaxError`, a `SyntaxError` subclass that carries `line`, `column`, `offset`, `code` and the full `loc` as properties, so tooling no longer has to pull the position out of the message text.

The release also moves the test suite onto the `@cldmv/vitest-runner` harness with coverage reporting, syncs the v4 workflows with the `CLDMV/.github` v4.29.0 templates, and restores the verbatim Apache-2.0 license text. `name` stays `"SyntaxError"` and the message text is unchanged, so existing error handling keeps working.

---

## πŸ› Bug Fixes

### Parse errors expose `line`, `column` and `offset` ([#31](https://github.com/CLDMV/jsonv/pull/31))

Parse failures used to throw a plain `SyntaxError` whose only position information was the `at line X, column Y` suffix in the message. They now throw `JsonvSyntaxError` (new in `src/errors.mts`), exported from the package root and from the `@cldmv/jsonv/parser` subpath. It exposes:

- `line` β€” 1-based line, matching the line in the message;
- `column` β€” the same column number the message reports;
- `offset` β€” 0-based character offset into the source;
- `code` β€” a machine-readable code such as `"PARSE_ERROR"` or `"UNTERMINATED_STRING"`;
- `loc` β€” the full start/end source location.

This applies to every parse entry point, year-pinned APIs included, and to both lexer-level errors (unterminated strings, invalid escapes, year-gated features) and parser-level errors (unexpected tokens, strict-mode violations). Because `JsonvSyntaxError` extends `SyntaxError` and keeps `name === "SyntaxError"`, `instanceof SyntaxError` and `error.name` checks are unaffected.

```js
import { parse, JsonvSyntaxError } from "@cldmv/jsonv";

try {
parse("{ a: 1, }");
} catch (err) {
if (err instanceof JsonvSyntaxError) {
console.log(err.line, err.column, err.offset);
}
}
```

---

## πŸ”§ CI & tooling

- **Test suite moved onto `@cldmv/vitest-runner`** ([#27](https://github.com/CLDMV/jsonv/pull/27)) β€” `npm test` now runs `tests/run-vitest.mjs`, test files were renamed from `*.test.ts` to `*.test.vitest.mjs` (TypeScript-only syntax stripped), and new `coverage`, `ci:coverage`, `test:types` and `build:ci` scripts were added. CI builds with `build:ci` in the publish and release workflows and turns on the coverage badge, the PR coverage comment and the type check.
- **v4 workflows synced with `CLDMV/.github` v4.29.0 templates** ([#26](https://github.com/CLDMV/jsonv/pull/26)), including corrected workflow header metadata and the new `provenance.yml` and `release-merge.yml` callers.

---

## πŸ“š Documentation

- **NEW:** [docs/changelog/v1/v1.0.10.md](./v1.0.10.md) β€” this changelog.
- README β€” new **Errors** section documenting `JsonvSyntaxError` and its position properties.
- LICENSE β€” restored to the verbatim Apache-2.0 text ([#25](https://github.com/CLDMV/jsonv/pull/25)).

---

## πŸ”§ Dependencies

- Added `@cldmv/vitest-runner` ^1.4.3 (dev).
- `vitest` and `@vitest/coverage-v8` ^5.0.0 β†’ ^5.0.2 (dev).

---

## Upgrade notes

No breaking changes β€” drop-in for v1.0.9. Errors keep their `SyntaxError` type, `name` and message text; code that parsed the position out of the message can switch to `err.line`, `err.column` and `err.offset`.
28 changes: 28 additions & 0 deletions docs/changelog/v1/v1.0.2.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
# @cldmv/jsonv v1.0.2 Changelog

**Release Date**: April 2026
**Release Type**: Patch

---

## Overview

Version 1.0.2 is a build-script-only patch. No runtime code changed.

---

## πŸ”§ CI & tooling

- The `build` script no longer runs `build:plugin`. The published package is built from `clean`, `build:ts`, `build:types`, `generate:years`, and `build:cjs`; `build:plugin` remains available as its own script.

---

## πŸ“š Documentation

- **NEW:** [docs/changelog/v1/v1.0.2.md](./v1.0.2.md) β€” this changelog.

---

## Upgrade notes

No breaking changes β€” drop-in for v1.0.1.
31 changes: 31 additions & 0 deletions docs/changelog/v1/v1.0.3.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
# @cldmv/jsonv v1.0.3 Changelog

**Release Date**: July 2026
**Release Type**: Patch

---

## Overview

Version 1.0.3 moves the repository's CI and release automation onto the `CLDMV/.github` v4 staging-branch workflows ([#2](https://github.com/CLDMV/jsonv/pull/2)). This version was tagged and released on GitHub but not published to npm; v1.0.2 remained the latest npm version until v1.0.7.

No runtime code changed.

---

## πŸ”§ CI & tooling

- **v4 workflow set adopted.** Added the `next` / `hotfixes` release-flow workflows (`feature-pr.yml`, `next-release.yml`, `hotfixes-release.yml`, `next-reset.yml`, `hotfix-redirector.yml`, `pr-title-normalizer.yml`, `master-commit-audit.yml`, `tag-health.yml`, `release-notify.yml`), plus `codeql.yml`, `scorecard.yml`, `dependency-review.yml`, `dependabot-auto-merge.yml`, `labeler.yml`, `stale.yml`, `welcome.yml`, `v4-bootstrap.yml`, and top-level `publish.yml` and `update-major-version-tags.yml`.
- **Removed the misplaced `.github/workflows/workflows/` directory** (stale `ci.yml`, `publish.yml`, `release.yml`, and `update-major-version-tags.yml` copies that GitHub never ran).

---

## πŸ“š Documentation

- **NEW:** [docs/changelog/v1/v1.0.3.md](./v1.0.3.md) β€” this changelog.

---

## Upgrade notes

No breaking changes β€” drop-in for v1.0.2.
30 changes: 30 additions & 0 deletions docs/changelog/v1/v1.0.4.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
# @cldmv/jsonv v1.0.4 Changelog

**Release Date**: August 2026
**Release Type**: Patch

---

## Overview

Version 1.0.4 changes the CI concurrency policy so release-relevant runs are never cancelled ([#4](https://github.com/CLDMV/jsonv/pull/4)). This version was released on GitHub but has no git tag and was not published to npm.

No runtime code changed.

---

## πŸ”§ CI & tooling

- **Never-supersede concurrency for release contexts.** `ci.yml` previously cancelled in-progress runs on every ref except `master`/`main`. Pushes to the release base branch (derived from the `CLDMV_RELEASE_BASE` variable, falling back to the repository's default branch), pushes to `next` / `hotfixes`, and the `next` / `hotfixes` release PRs now each get a unique concurrency group per run (`run_id` appended), so every run completes and posts its check instead of being cancelled into a red X on the release PR. Feature branches and feature PRs still cancel superseded runs.

---

## πŸ“š Documentation

- **NEW:** [docs/changelog/v1/v1.0.4.md](./v1.0.4.md) β€” this changelog.

---

## Upgrade notes

No breaking changes β€” drop-in for v1.0.3.
31 changes: 31 additions & 0 deletions docs/changelog/v1/v1.0.5.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
# @cldmv/jsonv v1.0.5 Changelog

**Release Date**: August 2026
**Release Type**: Patch

---

## Overview

Version 1.0.5 replaces the inlined release and feature-PR workflow logic with thin callers of the `CLDMV/.github` v4 reusable workflows ([#6](https://github.com/CLDMV/jsonv/pull/6)). This version was tagged and released on GitHub but not published to npm.

No runtime code changed.

---

## πŸ”§ CI & tooling

- **`feature-pr.yml`, `next-release.yml`, and `hotfixes-release.yml` reduced to thin callers** pinned at `@v4`; target detection, changelog body generation, and PR creation/refresh now live in the reusable workflows (about 500 fewer lines across the three files).
- **`deps/**` branches** now auto-open a PR into `next`, matching the current branch-naming convention.

---

## πŸ“š Documentation

- **NEW:** [docs/changelog/v1/v1.0.5.md](./v1.0.5.md) β€” this changelog.

---

## Upgrade notes

No breaking changes β€” drop-in for v1.0.4.
30 changes: 30 additions & 0 deletions docs/changelog/v1/v1.0.6.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
# @cldmv/jsonv v1.0.6 Changelog

**Release Date**: September 2026
**Release Type**: Patch

---

## Overview

Version 1.0.6 moves the hotfix redirector onto the v4 reusable workflow, which signs the security-fix cherry-pick ([#8](https://github.com/CLDMV/jsonv/pull/8)). This version was tagged and released on GitHub but not published to npm.

No runtime code changed.

---

## πŸ”§ CI & tooling

- **`hotfix-redirector.yml` is now a thin caller** of `workflow-hotfix-redirector.yml@v4`. The reusable checks out `hotfixes` (a trusted base-repo branch, never the PR head) and cherry-picks the fix there with the bot's signing identity, passing the bot app and `BOT_NAME` / `BOT_EMAIL` secrets through. The inline App-token and `redirect-hotfix-pr` steps are removed.

---

## πŸ“š Documentation

- **NEW:** [docs/changelog/v1/v1.0.6.md](./v1.0.6.md) β€” this changelog.

---

## Upgrade notes

No breaking changes β€” drop-in for v1.0.5.
53 changes: 53 additions & 0 deletions docs/changelog/v1/v1.0.7.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
# @cldmv/jsonv v1.0.7 Changelog

**Release Date**: September 2026
**Release Type**: Patch

---

## Overview

Version 1.0.7 fixes the development toolchain so it installs cleanly with Vitest 5 and uses the published ESLint plugin instead of a local checkout ([#14](https://github.com/CLDMV/jsonv/pull/14)). It is the first version published to npm since v1.0.2 (v1.0.3 through v1.0.6 were released on GitHub only).

No behavior of the published package changed; the only `src/` edit renames an unused `catch` binding.

---

## πŸ› Bug Fixes

### Dev install resolves with Vitest 5

`vitest` and `@vitest/coverage-v8` are bumped to `^5.0.0`, resolving the peer-dependency `ERESOLVE` on install. The unused `CustomReporter` (a `DefaultReporter` subclass imported from `vitest/reporters`, already commented out of the config) is removed from `.configs/vitest.config.mjs`.

### ESLint uses the published plugin

Both ESLint configs imported the plugin from a sibling `plugins/eslint-plugin-jsonv/dist/` checkout that does not exist in CI or fresh clones. They now import `@cldmv/eslint-plugin-jsonv`, added as a devDependency (`^1.0.3`). `plugins/` is gitignored for local co-development.

---

## πŸ”§ CI & tooling

- CI and publish workflows default the matrix floor (`min_node_version`) to `22.12.0`, the lowest Node release Vitest 5 runs on, and the ceiling (`max_node_major`) to `26`.
- `src/diagnose.mts`: the unused `catch (error)` binding is renamed `catch (_)` to satisfy lint.

---

## πŸ“š Documentation

- **NEW:** [docs/changelog/v1/v1.0.7.md](./v1.0.7.md) β€” this changelog.
- README β€” Tooling section now points to the separately published `@cldmv/eslint-plugin-jsonv` and `jsonv-vscode` repositories and describes local co-development under the gitignored `plugins/` folder.

---

## πŸ”§ Dependencies

- `vitest` ^4.0.17 β†’ ^5.0.0
- `@vitest/coverage-v8` ^4.0.17 β†’ ^5.0.0
- `@types/node` ^20.19.29 β†’ ^26.5.1
- `@cldmv/eslint-plugin-jsonv` ^1.0.3 (new devDependency)

---

## Upgrade notes

No breaking changes β€” drop-in for v1.0.2. All dependency changes are dev-only.
Loading
Loading