ast-grep 0.50.0: Safer Custom Languages, Built-in Zig Support, and Better Outlines
We are excited to announce ast-grep 0.50.0!
This release introduces built-in Zig support, significantly expands Java and C/C++ outlines, and changes how native custom-language libraries are loaded. The custom-language change is important—and breaking—so let's start there.
Breaking Change: Custom-Language Loading Now Requires Opt-In
Native custom-language libraries are now ignored by default; use allow for one run or trust to remember a project you have reviewed.
Why Was Automatic Loading Dangerous?
Before 0.50.0, ast-grep automatically loaded native libraries listed in sgconfig.yml. For example, an untrusted repository could contain this configuration and a malicious native library:
customLanguages:
my-language:
libraryPath: ./malicious.so # can run anything!
extensions: [myext]A custom parser is a native dynamic library—such as a .so, .dll, or .dylib file—loaded directly into the ast-grep process, so it can execute arbitrary code with the same permissions.
Simply cloning that repository and running ast-grep scan could therefore allow the library to read credentials, modify files, or run other commands. Explicit opt-in prevents a routine scan from silently crossing that trust boundary.
Allow a Custom Language Once
Use allow when you want to load the configured libraries for a single invocation:
ast-grep scan --custom-languages allowThis is also the recommended option for trusted CI and other non-interactive environments:
ast-grep scan --custom-languages allowOnly enable it for repositories and native libraries you trust.
Trust a Project
trust is interactive and requires a human to review and approve the project. After reviewing its configuration and native libraries, run:
ast-grep scan --custom-languages trustast-grep will ask for confirmation, load the custom languages, and remember the project for future commands.
Trust Is Path-Based
Trust is associated with the canonical path of the project configuration—not its contents. If the configuration or referenced library changes later, the project remains trusted.
Please review those changes as carefully as you would any executable dependency.
Ignore or Revoke Trust
You can temporarily skip custom languages, including in a trusted project:
ast-grep scan --custom-languages ignoreTo remove previously granted trust:
ast-grep scan --custom-languages revokeThis policy change only affects custom-language loading in the ast-grep CLI. JavaScript and Python API usage is not affected because dynamic languages already require explicit registration in application code, such as registerDynamicLanguage in the JavaScript API. Built-in languages also continue to work without additional configuration.
You can find the implementation details in #2960, #2971, and #2972.
Built-in Zig Support
Zig is now a built-in ast-grep language. You no longer need to compile and register a custom Tree-sitter library to search Zig projects.
For example:
ast-grep run \
--lang zig \
--pattern 'const $A = @import($B);' \
.Zig support includes:
- The
ziglanguage name - Automatic detection of
.zigfiles - Structural pattern matching and rewriting
- Metavariable support
- A generated Zig rule schema for YAML rules
Patterns work with Zig constructs such as imports, functions, calls, struct literals, error handling, switch, catch, and try.
ast-grep run \
--lang zig \
--pattern 'pub fn $NAME($$$ARGS) $RET { $$$BODY }' \
.See #2942 for the full implementation and compatibility notes.
Richer Java Outlines
The ast-grep outline command can now describe more of a modern Java codebase.
Version 0.50.0 adds outline support for:
- Records and compact constructors
- Java modules
- Wildcard imports
- Enum constants
- Annotation types
- Annotation elements
- Private and protected fields
For example, annotation declarations such as this now appear in an outline with their elements:
public @interface Route {
String path();
String method() default "GET";
}Records are also represented with their methods, fields, regular constructors, and compact constructors.
These improvements make outlines more useful for quickly understanding unfamiliar Java projects and for tools that consume ast-grep's structural summaries.
Relevant changes include #2945, #2948, #2950, #2954, #2955, and #2956.
Better C and C++ Outlines
C and C++ declarations can contain deeply nested declarators, which previously made it difficult for the outline extractor to identify the correct symbol name.
Version 0.50.0 improves identifier extraction for declarations and fields, producing more accurate names for complex C and C++ code. See #2946.
Upgrading
Install or upgrade ast-grep with your preferred package manager:
npm install --global @ast-grep/cli@0.50.0pip install --upgrade ast-grep-cli==0.50.0cargo install ast-grep --version 0.50.0 --lockedIf your project uses customLanguages, update local workflows and CI commands to pass the appropriate --custom-languages policy.
Thank you to everyone who contributed code, reported issues, reviewed changes, and helped test this release. For the complete list of changes, see the ast-grep 0.50.0 release notes.
Happy grepping!