Skip to main content

YAMLStar JSON Comments Plugin

This repository provides the experimental json-comments plugin API's sanitizer implementation. It recognizes JSON-style comments in UTF-8 YAML source, removes their text, preserves their line endings, and passes the transformed source to the parser selected by the host.

The sanitizer is independent of a particular YAML parser. It can be combined with go-yaml, the YAML reference parser, SnakeYAML, or another parser implementation supplied by the host. See the syntax rules for exact comment placement and scalar boundaries.

Go packages

The sanitizer package exposes the text transformation directly:

import "github.com/yamlstar/yamlstar-plugin-json-comments/sanitizer"

clean, err := sanitizer.Sanitize(
    []byte("a: true // comment\n"),
)

The parser package is a compatibility adapter for existing Go callers. It sanitizes the input and then uses github.com/yamlstar/yamlstar-plugin-parser-reference:

import "github.com/yamlstar/yamlstar-plugin-json-comments/parser"

events, err := parser.Parse([]byte("a: true // comment\n"))

New hosts should compose sanitizer.Sanitize with their selected parser instead of depending on the compatibility adapter. Both packages are safe for concurrent callers.

JVM artifact

Clojure and Java hosts use the Clojars artifact directly:

[org.yamlstar/yamlstar-plugin-json-comments "0.1.9"]

The artifact contains the Clojure sanitizer source. It does not need a native library or GraalVM. Build it locally with:

make jar

Publish it manually with configured Clojars credentials by running:

make deploy-clojars VERSION=0.1.9

Native shared plugin

The native plugin uses YAMLStar shared ABI version 2. Its manifest identifies plugin API json-comments, implementation sanitizer, version 0.1.9, and kind text-transform. The transform input and successful output are raw UTF-8 bytes. Only the manifest and options value use EDN.

Build the shared library with:

make build

Select it in YAMLStar after adding its directory to the library search path:

YAMLSTAR_LIBRARY_PATH=$PWD/lib \
  yaml --plugin=json-comments

Version 0.1 supports Unix shared libraries. Linux releases require glibc 2.28 or newer. The macOS artifacts are not Developer ID signed or notarized.

Binary releases

Release archives use YAMLStar platform names:

yamlstar-plugin-json-comments-VERSION-linux-x64.tar.xz
yamlstar-plugin-json-comments-VERSION-linux-aarch64.tar.xz
yamlstar-plugin-json-comments-VERSION-macos-x64.tar.xz
yamlstar-plugin-json-comments-VERSION-macos-arm64.tar.xz

Git tags and GitHub releases use only the vVERSION form starting with v0.1.9. Archive names and embedded manifest versions remain unprefixed. Old tags and assets remain available.

Install the library for the current user by copying it from the unpacked archive:

install -d "$HOME/.local/lib"
install -m 755 \
  lib/libyamlstar-plugin-json-comments.so \
  "$HOME/.local/lib/"

Use the .dylib filename on macOS.

Python wheels

Install the native plugin for the YAMLStar Python binding with:

pip install yamlstar-plugin-json-comments

The wheel registers the distribution through the yamlstar.plugins entry point and exposes library_path() and library_dir() from the yamlstar_plugin_json_comments module. Only platform wheels are published because an sdist would require compiling the plugin locally.

Release process

List the release steps with:

make release-list

After changing the source to the next version, run:

make release o=0.1.8 v=0.1.9

The command validates the source, commits the version bump, creates only the v0.1.9 tag, and starts the GitHub release workflow. The workflow publishes the JVM artifact to Clojars, native archives and wheels to GitHub, and wheels to PyPI. The repository must provide CLOJARS_USERNAME and CLOJARS_PASSWORD secrets. Use d=1 to preview the process. Use a=1 to release from a branch other than main.

Retry a failed workflow with:

make release-retry v=0.1.9

A published Go module tag must never be moved. Release a new version when tagged source needs a fix.

Metadata

Release files for yamlstar-plugin-json-comments 0.1.9

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for yamlstar-plugin-json-comments 0.1.9
File
yamlstar_plugin_json_comments-0.1.9-py3-none-manylinux_2_28_x86_64.whl Python 3 none Linux glibc 2.28+ x86-64 Details
yamlstar_plugin_json_comments-0.1.9-py3-none-manylinux_2_28_aarch64.whl Python 3 none Linux glibc 2.28+ ARM64 Details
yamlstar_plugin_json_comments-0.1.9-py3-none-macosx_15_0_x86_64.whl Python 3 none macOS 15.0+ x86-64 Details
yamlstar_plugin_json_comments-0.1.9-py3-none-macosx_14_0_arm64.whl Python 3 none macOS 14.0+ ARM64 Details

Total release size: 28.8 MB

Release files / yamlstar_plugin_json_comments-0.1.9-py3-none-manylinux_2_28_x86_64.whl

Download URL yamlstar_plugin_json_comments-0.1.9-py3-none-manylinux_2_28_x86_64.whl
Size 7.8 MB
Tags Linux glibc 2.28+ x86-64 Python 3
SHA-256 checksum
How to use checksums
669683c90574e6ca30c9b53be76d5822148927cbe8fb01b7d70559a2e0afbd97
BLAKE2b-256 checksum
How to use checksums
5b54538ed5b8136f455576e4a179c2cffab1a461bf76d9c137f42a19edef2277
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.

Transparency log

Release files / yamlstar_plugin_json_comments-0.1.9-py3-none-manylinux_2_28_aarch64.whl

Download URL yamlstar_plugin_json_comments-0.1.9-py3-none-manylinux_2_28_aarch64.whl
Size 6.9 MB
Tags Linux glibc 2.28+ ARM64 Python 3
SHA-256 checksum
How to use checksums
4ea9950a019779ed708eb7bff0edc13a4c16e074d8720923da85c4d8c64c1ce9
BLAKE2b-256 checksum
How to use checksums
e5b2af34d2117eb1b60fb66d1b0a1f5b093017626dd4bf3b686c70cf4981c8f9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.

Transparency log

Release files / yamlstar_plugin_json_comments-0.1.9-py3-none-macosx_15_0_x86_64.whl

Download URL yamlstar_plugin_json_comments-0.1.9-py3-none-macosx_15_0_x86_64.whl
Size 7.5 MB
Tags Python 3 macOS 15.0+ x86-64
SHA-256 checksum
How to use checksums
a68a1c1abbbbdb92ed291cc097bcf65c0e1bc7ea04bcafd4d45f4d867eb2b01c
BLAKE2b-256 checksum
How to use checksums
fa6eb1569f6e8ddf3b350e3096b335013803a38dcffc4590b604500ed40b6d07
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.

Transparency log

Release files / yamlstar_plugin_json_comments-0.1.9-py3-none-macosx_14_0_arm64.whl

Download URL yamlstar_plugin_json_comments-0.1.9-py3-none-macosx_14_0_arm64.whl
Size 6.7 MB
Tags Python 3 macOS 14.0+ ARM64
SHA-256 checksum
How to use checksums
c1ffb68a4e1d769970c590b5aa0c5e601eef1d5a26d9e5daa9cf46000babf686
BLAKE2b-256 checksum
How to use checksums
a544202c6de357e52a25147030e7facc96d0d16eb6b9ecec44b6c8f081aefdfa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.9 This release

4 release files

0.1.8

4 release files

0.1.7

4 release files

0.1.6

4 release files

0.1.5

4 release files

0.1.4

4 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page