Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: networknt/json-schema-validator
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: 3.0.7
Choose a base ref
...
head repository: networknt/json-schema-validator
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: 3.0.8
Choose a head ref
  • 15 commits
  • 20 files changed
  • 5 contributors

Commits on Aug 20, 2026

  1. Configuration menu
    Copy the full SHA
    680d7b3 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    f8c7659 View commit details
    Browse the repository at this point in the history

Commits on Aug 26, 2026

  1. Allow apostrophe in uri-template literal (#1275)

    The uri-template format regex listed ' in its excluded character set, so
    "a'b" was reported invalid. An apostrophe in a literal is valid; remove it
    from the exclusion set.
    dngr2 authored Aug 26, 2026
    Configuration menu
    Copy the full SHA
    2a28f87 View commit details
    Browse the repository at this point in the history
  2. Reject empty labels in idn-hostname format (#1274)

    * Reject empty labels in idn-hostname format
    
    RFC5892.isValid skipped empty labels with continue, so a leading or interior
    empty label -- ".example" or "a..b" -- validated as a valid idn-hostname.
    String.split already drops trailing empty labels, so the skip only ever hit
    leading/interior empties, which are invalid. Reject them.
    
    * Reject a hostname made up only of label separators
    
    String.split returns an empty array for a value that is all separators
    ("..." or "。。"), so the loop was skipped and it validated as true. Reject
    when there are no labels; this also subsumes the single-separator case.
    
    * Fix comment wording to reference label separators generically, not just '.'
    dngr2 authored Aug 26, 2026
    Configuration menu
    Copy the full SHA
    a9c9638 View commit details
    Browse the repository at this point in the history

Commits on Aug 27, 2026

  1. Fix nullable allOf ref type check (#1279)

    * Fix nullable check for allOf + $ref compositions
    
    A property declared nullable: true and composed via allOf containing
    only a $ref (e.g. OpenAPI 3.0 style composition) incorrectly rejected
    null values. The schema owning the failing type keyword is resolved
    through $ref and is a cached object whose lexical parent reflects
    where it is declared in the document, not where it was referenced
    from, so the existing one-hop parent/grandparent nullable check never
    found the nullable declaration on the referencing schema.
    
    Walk the dynamic evaluation stack instead, following through any
    chain of $ref schemas, to find the referencing schema and check it
    (and its lexical parent) for nullable: true.
    
    Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
    
    * Add regression test confirming nullable allOf+$ref fix is dialect-scoped
    
    Confirms, per maintainer feedback on the upstream issue, that the
    dynamic evaluation stack walk added for nullable allOf + $ref
    compositions has no effect outside dialects that enable the nullable
    keyword (currently only OpenAPI 3.0.x) — null is still rejected for
    the same schema shape under draft-07.
    
    Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
    
    * Ignore nullable declared directly beside $ref
    
    Per PR review feedback (#1279), the
    dynamic evaluation stack walk added to support nullable allOf + $ref
    compositions incorrectly honored nullable: true declared as a direct
    sibling of $ref. That's a Reference Object, and the OpenAPI 3.0
    specification requires siblings of $ref to be ignored, so it must
    never grant nullability on its own.
    
    Track whether the current frame in the walk was reached via $ref and,
    if so, skip checking that frame's own nullable — only its lexical
    parent (the schema actually composing it, e.g. the allOf owner) is
    consulted. The allOf + $ref case that motivated the original fix
    still passes.
    
    Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
    
    ---------
    
    Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
    tomakehurst and claude authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    8716b5b View commit details
    Browse the repository at this point in the history

Commits on Sep 15, 2026

  1. Honor PathType when formatting DiscriminatorValidator schema locations (

    #1281)
    
    #1272 made SchemaException render the schema location with the configured
    PathType, through SchemaRegistry.formatSchemaLocation, and applied it to
    the two "Schema at ..." throws in that class. DiscriminatorValidator
    throws the same message at three sites and still concatenates the raw
    SchemaLocation.
    
    With pathType(PathType.JSON_PATH) the message mixes the two notations in
    one sentence, because instanceLocation is already a NodePath built from
    the configured PathType:
    
      Schema at #/allOf/1/discriminator is redefining the discriminator
      property that has already been set for at $
    
    Adds the same private helper the registry uses, so the default
    JSON_POINTER output is unchanged.
    youdie006 authored Sep 15, 2026
    Configuration menu
    Copy the full SHA
    81efb27 View commit details
    Browse the repository at this point in the history
  2. Add YAML non-finite number regression test for #1228 (#1282)

    Jackson 3.2 parses YAML .nan/.inf/-.inf as numeric values, and #1241
    already handles non-finite numbers during validation. Cover the default
    YAML mapper path so these inputs keep producing a type error instead of
    a parser exception.
    
    Test contributed by @patpatpat123 in #1228.
    
    
    Claude-Session: https://claude.ai/code/session_01XJ3SkCprrZVpASPFMADg1h
    
    Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
    stevehu and claude authored Sep 15, 2026
    Configuration menu
    Copy the full SHA
    3c433c4 View commit details
    Browse the repository at this point in the history

Commits on Sep 17, 2026

  1. Port the nullable ancestor walk from the 2.x branch (#1283)

    Resolves the OpenAPI nullable keyword by descending the engine's own
    evaluation stacks rather than reconstructing provenance from schema
    structure. The previous walk climbed lexical parents and sniffed for
    $ref members, which misattributed nullable across reference sites,
    was sensitive to schema-node identity, and missed $dynamicRef and
    $recursiveRef entirely.
    
    The walk pairs evaluationSchema with evaluationSchemaPath to recover
    the keyword each schema was entered by, propagating nullable through
    allOf/oneOf/anyOf, if/then/else and the three referencing keywords,
    and stopping at any keyword that moves to a different value. As a
    result nullable no longer leaks into a container's properties, items
    or additionalProperties children, and no longer reaches inside not.
    
    Applies the same walk to enum, which previously decided at
    construction time whether null was accepted, and relaxes only the
    oneOf cardinality check for a nullable null, leaving branch errors
    reported when nothing matches.
    
    Ported from #1280. Two adaptations
    were needed for this branch rather than a straight copy:
    
      - isNodeNullable now calls asBoolean(false). Jackson 3 throws on a
        node it cannot coerce where Jackson 2 returns false, and the walk
        reads nullable on every composing ancestor, so a malformed member
        anywhere in the chain would abort the validation.
    
      - The typeLoose enum change concerns the empty string here, not the
        string "null". NullNode.asString() is "" in Jackson 3, so that is
        the value the accepted set silently permitted.
    
    Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
    tomakehurst and claude authored Sep 17, 2026
    Configuration menu
    Copy the full SHA
    dc11f65 View commit details
    Browse the repository at this point in the history

Commits on Sep 18, 2026

  1. upgrade central-publishing-maven to 0.11.0 from 0.7.0

    Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
    stevehu and claude committed Sep 18, 2026
    Configuration menu
    Copy the full SHA
    4649209 View commit details
    Browse the repository at this point in the history
  2. upgrade actions/checkout

    stevehu committed Sep 18, 2026
    Configuration menu
    Copy the full SHA
    6f5d6c1 View commit details
    Browse the repository at this point in the history
  3. upgrade logback to 1.5.37

    stevehu committed Sep 18, 2026
    Configuration menu
    Copy the full SHA
    3d9971d View commit details
    Browse the repository at this point in the history
  4. Configuration menu
    Copy the full SHA
    2575a02 View commit details
    Browse the repository at this point in the history

Commits on Sep 28, 2026

  1. Configuration menu
    Copy the full SHA
    f26327c View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    759445b View commit details
    Browse the repository at this point in the history

Commits on Sep 30, 2026

  1. Configuration menu
    Copy the full SHA
    12596e6 View commit details
    Browse the repository at this point in the history
Loading