Skip to content

Bump jsonschema from 0.26.2 to 0.58.1 in /rust - #44

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/rust/jsonschema-0.58.1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/rust/jsonschema-0.58.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown

Bumps jsonschema from 0.26.2 to 0.58.1.

Release notes

Sourced from jsonschema's releases.

[Python] Release 0.58.1

Fixed

  • Crash in canonical.json.to_string on free-threaded Python when another thread resized a list or dict. #1664
  • Crash when an Enum member's value override, a custom keyword or a custom format emptied a list or dict holding the instance being read, during validation, schema conversion or canonical.json.to_string.

Performance

  • uri and uri-reference formats check the syntax directly instead of parsing each value into a URI.
  • Enum members read their stored value directly instead of calling the value property.

[Ruby] Release 0.58.1

Performance

  • uri and uri-reference formats check the syntax directly instead of parsing each value into a URI.

[Rust] Release 0.58.1

Fixed

  • Crash in Pyo3 validators when an Enum member's value override emptied a list or dict holding the instance being read.

Performance

  • uri and uri-reference formats check the syntax directly instead of parsing each value into a URI.
  • Enum members read their stored value directly instead of calling the value property in Pyo3 validators.

[Python] Release 0.58.0

Performance

  • oneOf and anyOf whose branches each require a property fixed to a distinct string validate only the branch matching the instance's value.
  • meta.is_valid and meta.validate check a schema against the bundled drafts without converting it first, about 2x faster on the benchmarked schemas.

Fixed

  • Crash on free-threaded Python when another thread resized a list or dict during validation.
  • find_unsatisfiable missing a oneOf over $ref branches beside a sibling none of them admits.

[Ruby] Release 0.58.0

Performance

  • oneOf and anyOf whose branches each require a property fixed to a distinct string validate only the branch matching the instance's value.
  • Meta.valid? and Meta.validate! check a schema against the bundled drafts without converting it first, 2 to 5x faster on the benchmarked schemas.

Fixed

  • Canonical.find_unsatisfiable missing a oneOf over $ref branches beside a sibling none of them admits.
  • A value with no JSON form nested under type: null failing validation silently (it should raise TypeError).

[Rust] Release 0.58.0

Added

... (truncated)

Changelog

Sourced from jsonschema's changelog.

[0.58.1] - 2026-09-26

Fixed

  • Crash in Pyo3 validators when an Enum member's value override emptied a list or dict holding the instance being read.

Performance

  • uri and uri-reference formats check the syntax directly instead of parsing each value into a URI.
  • Enum members read their stored value directly instead of calling the value property in Pyo3 validators.

[0.58.0] - 2026-09-25

Added

  • backend = Pyo3 on #[jsonschema::validator], generating a validator that reads Python objects in place.
  • backend = Magnus on #[jsonschema::validator], generating a validator that reads Ruby objects in place.
  • jsonschema::meta::pyo3, the bundled meta-schema validators for a schema held as a Python object.
  • jsonschema::meta::magnus, the bundled meta-schema validators for a schema held as a Ruby object.
  • methods = { ... } on #[jsonschema::validator], selecting which of is_valid, validate, and iter_errors are generated.
  • json::Jsonb, validating a Postgres jsonb value in place, behind the jsonb feature.

Performance

  • oneOf and anyOf whose branches each require a property fixed to a distinct string validate only the branch matching the instance's value.
  • Generated validate checks required in the same pass over an object as properties, instead of looking up each required name.

Fixed

  • A oneOf over $ref branches beside a sibling none of them admits, which canonicalized to an allOf instead of false.
  • multipleOf incorrectly accepted 1e-400 and other magnitudes below the smallest f64 subnormal with arbitrary-precision (they are not zero).
  • Numeric keywords panicked on a custom representation holding a number past f64 without arbitrary-precision.

[0.57.0] - 2026-09-22

Added

  • PreparedDocument::unsatisfiable, naming the keywords that leave each unsatisfiable subschema empty and where they are.

Changed

  • PreparedDocument::unsatisfiable_pointers is replaced by PreparedDocument::unsatisfiable.

Fixed

  • The instance path of a schema build error, which was empty instead of naming the keyword location that failed to compile.
  • PreparedDocument::unsatisfiable_pointers passed over a subschema that admits no value only once its references resolve, such as an allOf over two $refs.

Performance

... (truncated)

Commits
  • 397cd0a chore(ruby): Release 0.58.1
  • ee1fd05 chore(python): Release 0.58.1
  • a3033e5 chore(rust): Release 0.58.1
  • 108be08 fix(python): Use-after-free when Python code empties the instance mid-walk
  • 3051b06 fix(python): Concurrent mutation crash in canonical.json.to_string on free-th...
  • 29f6c5f perf: Check uri and uri-reference syntax without building a URI
  • 5a17d44 docs: Update changelog
  • 76516b2 chore(python): Release 0.58.0
  • 894beed chore(ruby): Release 0.58.0
  • ad33f36 chore(rust): Release 0.58.0
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [jsonschema](https://github.com/Stranger6667/jsonschema) from 0.26.2 to 0.58.1.
- [Release notes](https://github.com/Stranger6667/jsonschema/releases)
- [Changelog](https://github.com/Stranger6667/jsonschema/blob/master/CHANGELOG.md)
- [Commits](Stranger6667/jsonschema@rust-v0.26.2...ruby-v0.58.1)

---
updated-dependencies:
- dependency-name: jsonschema
  dependency-version: 0.58.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 1, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Author

Superseded by #47.

@dependabot dependabot Bot closed this Oct 8, 2026
@dependabot
dependabot Bot deleted the dependabot/cargo/rust/jsonschema-0.58.1 branch October 8, 2026 06:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants