github vektah/gqlparser v2.5.59

2 hours ago

Changelog

  • 7bd8ce2 Avoid iterator allocations in overlapping field validator (#481)
  • 3ccd437 Benchmarks, a benchmark gate, property tests and mutation testing (#482)
  • 6ddb710 Index fragments by name in the validator walker (#472)
  • b312a14 build(deps): bump brace-expansion in /validator/imported (#480)
  • dce6e66 build(deps-dev): bump prettier (#473)
  • 3e25eab feat(validator): Add new validator.EmptyDefinitionError (#474)
  • eaee109 lexer: combine surrogate pair escapes in string literals (#476)
  • 1c204b4 validator: make MaxIntrospectionDepth linear in fragment spreads (#471)
  • b99f91a validator: stop OverlappingFieldsCanBeMerged recursing forever on fragment cycles (revised #477) (#478)

Verifying this release

# 1. cosign signature over the checksum file (identity = the release workflow).
cosign verify-blob \
  --bundle checksums.txt.sigstore.json \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  --certificate-identity 'https://github.com/StevenACoffman/gqlparser/.github/workflows/release.yml@refs/tags/v2.5.59' \
  checksums.txt

# 2. source tarball + SBOM hash to the now-trusted checksums.
shasum -a 256 -c checksums.txt

# 3. GitHub build provenance.
gh attestation verify gqlparser_2.5.59_source.tar.gz --repo StevenACoffman/gqlparser

The SBOM is gqlparser_2.5.59_source.tar.gz.sbom.json (SPDX-2.3).


Released by GoReleaser.

Don't miss a new gqlparser release

NewReleases is sending notifications on new releases.