NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #337 by repository stars
Last release 2 days ago
06 Oct 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 29 of 29 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
783 releases · first in 2021
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
2017ff87 bson: support all non-deprecated types and fix int/uint bugs
Adds decoders for PostgreSQL btree, control and heap files. Thanks Pavel Safonov @pnsafonov and Michael Zhilin @mizhka
Adds new option skip gaps and output binary as hex string.
Make bits/bytes formats work a bit more intuitive.
Bug fixes to to_hex, to_base64 and trim functions.
Bug fixes and additions to bson, bitcoin_transaction, mp4, id3v2, html, and matroska formats.
bits,bytes now are real binaries and not raw decode value. This means they behave more like you would expect. #666# build your own strings(1)-like tool:
# scan matches range in a binary using a regexp and output ranges as new binaries
# \w\s looks for whitespace and alpha/numeric characters
# uses `...` raw string literal to not have to escape
# select/test to only include strings containing "thread"
# dd to display with no truncation
$ fq -d bytes 'scan(`[\w\s]{16,}`) | select(test("thread")) | dd' file.mp4
│00 01 02 03 04 05 06 07│01234567│
0x250│36 20 6c 6f 6f 6b 61 68│6 lookah│.: raw bits 0x250-0x262.7 (19)
0x258│65 61 64 5f 74 68 72 65│ead_thre│
0x260│61 64 73 │ads │
│00 01 02 03 04 05 06 07│01234567│
0x260│ 31 20 73 6c│ 1 sl│.: raw bits 0x264-0x273.7 (16)
0x268│69 63 65 64 5f 74 68 72│iced_thr│
0x270│65 61 64 73 │eads │
to_hex,to_base64 now correctly handles raw decode values, before the raw bits would be turned into codepoints and then binary UTF-8 possibly introducing invalid codepoints (0xfffd). Thanks @Rogach #672$ fq -r '.uncompressed | to_hex' file.gz
f6f2074cf77d449d
# with the change to add hex bits format you can also do this now
$ fq -Vr -o bits_format=hex .uncompressed file.gz
f6f2074cf77d449d
tovalue Now output a "deep" jq value, before it was shallowly a jq value which could be confusing, ex tovalue | .header could be a decode value.skip_gaps for -V/tovalue can be used to filter out gap fields when represented as JSON. Gaps are bit ranges that no decoder added any field for. #649
gap0 etc.bits_format=hex to represent raw bits as hex string in JSON. #673# output decode tree, JSON with binaries as strings and JSON with binaries as hex strings
$ fq '.packets[0].packet | ., tovalue, tovalue({bits_format:"hex"})' file.pcap
│00 01 02 03 04 05 06 07│01234567│.packets[0].packet{}: (ether8023_frame)
0x28│8c 85 90 74 b8 3b │...t.; │ destination: "8c:85:90:74:b8:3b" (0x8c859074b83b)
0x28│ e8 de│ ..│ source: "e8:de:27:c8:9a:6e" (0xe8de27c89a6e)
0x30│27 c8 9a 6e │'..n │
0x30│ 08 06 │ .. │ ether_type: "arp" (0x806) (Address Resolution Protocol)
0x30│ 00 01│ ..│ payload: raw bits
0x38│08 00 06 04 00 01 e8 de│........│
0x40│27 c8 9a 6e c0 a8 01 01│'..n....│
0x48│00 00 00 00 00 00 c0 a8│........│
0x50│01 e6 │.. │
{
"destination": "8c:85:90:74:b8:3b",
"ether_type": "arp",
"payload": "\u0000\u0001\b\u0000\u0006\u0004\u0000\u0001\ufffd\ufffd'Țn\ufffd\ufffd\u0001\u0001\u0000\u0000\u0000\u0000\u0000\u0000\ufffd\ufffd\u0001\ufffd",
"source": "e8:de:27:c8:9a:6e"
}
{
"destination": "8c:85:90:74:b8:3b",
"ether_type": "arp",
"payload": "0001080006040001e8de27c89a6ec0a80101000000000000c0a801e6",
"source": "e8:de:27:c8:9a:6e"
}
d/display on a binary will now always hexdump, this feels more intuitive. Before it could output raw binary as display is used as an implicit output function. Implicit (you don't mention d at all) can still output raw binary. #665# outputs raw binary (if stdout is not a tty)
$ fq -n '[1,2,3] | tobytes' | xxd
00000000: 0102 03
# outputs hexdump (even if stdout is not a tty) as we explicitly use d
$ fq -n '[1,2,3] | tobytes | d' | cat
|00 01 02 03 04 05 06 07|01234567|
0x0|01 02 03| |...| |.: raw bits 0x0-0x2.7 (3)
trim can now handle multi-line strings. #668bits,bytes Is a proper binary not a raw decode value. #666bitcoin_transaction Properly decode witness items array. #671 Thanks @Rogachbson Add javascript, decimal128, minkey and maxkey support. Fix decoding of datetime and use the correct size type for binary and document size. Thanks Matt Dale @matthewdale. #650id3v2
html Is now probeable. #667matroska Fallback raw is probe fail or file_data #645mp4
ctts,infe,iinf,trun more proper decoding based on version. #643pg_btree,pg_control,pg_heap Add PostgreSQL btree, control and heap support. Thanks Pavel Safonov @pnsafonov and Michael Zhilin @mizhka. #415Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Mostly a bug fix release but adds -V for easy JSON output.
Mostly a bug fix release but adds -V for easy JSON output.
Add -V argument to default output JSON instead of decode tree in case of decode value. #385 Thanks @peterwaller-arm for reminding me to merge this.
# default in case of decode value is to show a hexdump tree
$ fq '.headers | grep_by(.id=="TSSE").text' file.mp3
│00 01 02 03 04 05 06 07 08 09 0a 0b│0123456789ab│
0x0c│ 4c 61 76│ Lav│.headers[0].frames[0].text: "Lavf58.76.100"
0x18│66 35 38 2e 37 36 2e 31 30 30 00 │f58.76.100. │
# with -V an implicit "tovalue" is done
$ fq -V '.headers | grep_by(.id=="TSSE").text' file.mp3
"Lavf58.76.100"
# and in combination with -r will for strings output a "raw string" without quotes
# for other types like number, object, array etc -r makes not difference (same as jq)
$ fq -Vr '.headers | grep_by(.id=="TSSE").text' file.mp3
Lavf58.76.100
As a side note -V can be used with binary type also. Then the binary data will be interpreted as UTF-8 and turned into a string.
# trailing null terminator ends up as codepoint zero `\u0000`
$ fq -V '.headers | grep_by(.id=="TSSE").text | tobytes' file.mp3
"Lavf58.76.100\u0000"
# with -r null terminator and a new line is outputted
$ fq -Vr '.headers | grep_by(.id=="TSSE").text | tobytes' file.mp3 | hexdump -C
00000000 4c 61 76 66 35 38 2e 37 36 2e 31 30 30 00 0a |Lavf58.76.100..|
0000000f
# in contrast raw binary output has no new line separator
$ fq '.headers | grep_by(.id=="TSSE").text | tobytes' doc/file.mp3 | hexdump -C
00000000 4c 61 76 66 35 38 2e 37 36 2e 31 30 30 00 |Lavf58.76.100.|
0000000e
Fix issue using decode value in object passed as argument to internal function. #638
# this used to fail but now works
fq '.tracks[0].samples[10] | avc_au({length_size: <decode value>})' file.mp4
Some typo fixes. Thanks @retokromer and @peterwaller-arm
aiff Basic AIFF decoder added. #614matroska Update to latest specification. #640msgpack Fix bug decoding some fixstr lengths. #636 Thanks @schmee for reporting.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
TLS decode and decryption, better streaming matroska/webm support, support raw IP in PCAP and bug fixes.
TLS decode and decryption, better streaming matroska/webm support, support raw IP in PCAP and bug fixes.
-o name=value) to nested decoders. #589
-o name=@path fails to read file at path. #597id3v2 Properly decode CTOC subframes. #606matroska
decode_samples option. #574pcap,pcapng Support raw IPv4 and IPv6 link frames. #599 #590tls Add Transport layer security decoder and decryption. #603
# show first 50 bytes of decrypted client/server TLS application data stream
# -o keylog=@file.pcap.keylog is used to read keylog from a file
# first .stream is TCP stream, second .stream the application data stream
$ fq -o keylog=@file.pcap.keylog '.tcp_connections[0].["client", "server"].stream.stream | tobytes[0:50] | dd' file.pcap
│00 01 02 03 04 05 06 07 08 09 0a 0b│0123456789ab│
0x00│47 45 54 20 2f 64 75 6d 70 2f 6c 6f│GET /dump/lo│.: raw bits 0x0-0x31.7 (50)
0x0c│67 20 48 54 54 50 2f 31 2e 31 0d 0a│g HTTP/1.1..│
0x18│48 6f 73 74 3a 20 69 6e 77 61 64 65│Host: inwade│
0x24│72 2e 63 6f 6d 0d 0a 55 73 65 72 2d│r.com..User-│
0x30│41 67 │Ag │
│00 01 02 03 04 05 06 07 08 09 0a 0b│0123456789ab│
0x00│48 54 54 50 2f 31 2e 31 20 32 30 30│HTTP/1.1 200│.: raw bits 0x0-0x31.7 (50)
0x0c│20 4f 4b 0d 0a 41 63 63 65 70 74 2d│ OK..Accept-│
0x18│52 61 6e 67 65 73 3a 20 62 79 74 65│Ranges: byte│
0x24│73 0d 0a 43 6f 6e 74 65 6e 74 2d 4c│s..Content-L│
0x30│65 6e │en │
# show first TLS record from server
$ fq '.tcp_connections[0].server.stream.records[0] | d' file.pcap
│00 01 02 03 04 05 06 07 08 09 0a 0b│0123456789ab│.tcp_connections[1].server.stream.records[0]{}: record
0x00│16 │. │ type: "handshake" (22) (valid)
0x00│ 03 03 │ .. │ version: "tls1.2" (0x303) (valid)
0x00│ 00 40 │ .@ │ length: 64
│ │ │ message{}:
0x00│ 02 │ . │ type: "server_hello" (2)
0x00│ 00 00 3c │ ..< │ length: 60
0x00│ 03 03 │ .. │ version: "tls1.2" (0x303)
│ │ │ random{}:
0x00│ 86│ .│ gmt_unix_time: 2249760024 (2041-04-16T21:20:24Z)
0x0c│18 9d 18 │... │
0x0c│ 19 92 33 c2 21 ce 4f 97 30│ ..3.!.O.0│ random_bytes: raw bits
0x18│28 98 b3 fd 1e 15 f4 36 bb e9 14 f4│(......6....│
0x24│67 61 66 79 d5 3f 06 │gafy.?. │
0x24│ 00 │ . │ session_id_length: 0
│ │ │ session_id: raw bits
0x24│ c0 2f │ ./ │ cipher_suit: "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256" (0xc02f)
0x24│ 00 │ . │ compression_method: "null" (0x0)
0x24│ 00│ .│ extensions_length: 20
0x30│14 │. │
│ │ │ extensions[0:2]:
│ │ │ [0]{}: extension
0x30│ ff 01 │ .. │ type: "renegotiation_info" (65281)
0x30│ 00 01 │ .. │ length: 1
0x30│ 00 │ . │ data: raw bits
│ │ │ [1]{}: extension
0x30│ 00 10 │ .. │ type: "application_layer_protocol_negotiation" (16)
0x30│ 00 0b │ .. │ length: 11
0x30│ 00 09│ ..│ serer_names_length: 9
│ │ │ protocols[0:1]:
│ │ │ [0]{}: protocol
0x3c│08 │. │ length: 8
0x3c│ 68 74 74 70 2f 31 2e 31 │ http/1.1 │ name: "http/1.1"
# use ja3.jq to calculate ja3 TLS fingerprint
# https://github.com/wader/fq/blob/master/format/tls/testdata/ja3.jq
$ fq -L path/to/ja3 'include "ja3"; pcap_ja3' file.pcap
[
{
"client_ip": "192.168.1.193",
"client_port": 64126,
"ja3": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47-255,0-11-10-16-22-23-49-13-43-45-51-21,29-23-30-25-24,0-1-2",
"ja3_digest": "bc29aa426fc99c0be1b9be941869f88a",
"server_ip": "46.101.135.150",
"server_port": 443
}
]
toml Fail faster to speed up probe. Could in some cases read the whole file before failing. Thanks @0-wiz-0 for report. #594zip Properly decode EOCD record in zip64 files. Thanks @0-wiz-0 for report and spec interpretation. #586 #596xml Fail faster to speed up probe. Could in some cases read the whole file before failing. Thanks @0-wiz-0 for report. #594Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →