datui

derekwisong·derekwisong.datui

Data Exploration in the Terminal

Datui is a high-performance terminal UI for exploring and analyzing datasets.

winget install --id derekwisong.datui --exact --source winget

Latest 0.3.2·September 11, 2026

Release Notes

What's changed This release fixes several bugs in the text fields, the load path and the parsers, and adds signatures to release artifacts. Fixed

  • Text input was rewritten on top of a new in-tree editor, replacing the two near-duplicate widgets that wrapped tui-textarea. Pressing / after Esc showed a blank query bar instead of the running query, and switching query tabs showed the last thing typed rather than that tab's query. Both are fixed. Readline keys (Ctrl-A, Ctrl-E, Ctrl-K, Ctrl-W, Ctrl-U) work as before. (#116)
  • Query history is merged rather than overwritten when two instances run at once. (#116)
  • Opening a second dataset left the first one on screen, under the incoming file's name and with its row count, for the whole load. The load now owns the screen from the keypress until its dataset is installed. (#113)
  • Ctrl+O reached the home screen mid-load but did not abandon the load, which ran to completion and swapped its dataset in underneath. Loads are now abandonable, and no phase of a load blocks the event thread. Declining "Continue with download?" exited the app; modals raised over the home screen could not be dismissed; a row count computed for one dataset could be applied to the next. (#109)
  • The home screen probes remote roots with a cap of four concurrent probes, but completed probes were never removed from the in-flight list. After four roots, no root was probed again for the rest of the session. (#110)
  • Three parser bugs found by fuzzing: the query parser recursed once per nested parenthesis and exhausted the stack at around two hundred, killing the process; hex colour parsing indexed at fixed byte offsets and panicked on a non-ASCII value; a literal * in a column name consumed a glob pattern's wildcard. (#114)
  • Builds without the sql feature, and cloud-only builds, did not compile. A cloud-only build also left downloaded data in the temp directory. (#114)
  • Homebrew refuses a third-party tap without brew trust, so the documented Homebrew install failed. The command is now in the README and the install guide. The one-line install was unaffected. (#108) Security
  • Cell values, column names, filenames and parser error messages containing terminal escape sequences reached the terminal intact. A spreadsheet cell could write to the clipboard or clear the screen. The rendered buffer is now swept before it is written out. (#80)
  • --generate-config wrote its template, which invites an S3 access key and secret, at 0644. It is now created 0600, and an existing 0644 file is corrected. (#82)
  • Releases now publish SHA256SUMS, and install.sh verifies what it downloaded before installing. Verification is skipped for releases that predate the file. (#106)
  • SHA256SUMS is signed with cosign, keyless via Sigstore, and the signature published alongside it. The identity is the release workflow's OIDC token. SECURITY.md carries the verification command. (#115)
  • calamine 0.36 moves off quick-xml 0.38, which carries two denial-of-service advisories reachable from any .xlsx opened. The Excel reader, previously the only input format with no test coverage, is now covered. (#79)
  • arrow and orc-rust upgraded together; both parse untrusted input. (#100)
  • ureq 3 bounds the whole HTTP exchange rather than individual socket operations, so a server that trickles bytes no longer hangs the TUI. (#101)
  • ratatui 0.30 resolves lru past two memory-corruption advisories that were unpatchable while ratatui 0.29 pinned it, and drops paste. (#116)
  • Added a security policy, security tooling in CI, and coverage-guided fuzzing of the five parsers that run on untrusted input. (#59, #78, #114)
  • The contributor requirements file floors filelock past two advisories it reached through pre-commit, and the security documentation was corrected where it had gone stale. Both are contributor-facing; nothing changes for anyone installing datui. (#117) Build
  • The dev profile emitted full DWARF for all dependencies, producing a 1.9 GB debug binary that was linked into 15 test binaries. Dependencies now build with no debuginfo; our own crates keep line tables. cargo test --no-run went from over ten minutes to 51 seconds, and target/debug from 185 GB to 7.2 GB. Plus dependency updates and CI fixes. Full changelog: v0.3.1...v0.3.2

Installer type: zip

x64—71D2B87941AD615DBAB8FB3B59392483A8ED6CA7BDB5DA4C63D4D065F818259B

Details

Homepage
https://github.com/derekwisong/datui
License
MIT
Publisher
derekwisong
Support
https://github.com/derekwisong/datui/issues

Tags

analysisclidataedaresearchtui

Older versions (13)

0.3.0
x64—F259CB741324447ED1535300AF3A4E2F71489CA68F22165262DF776AFBC579C2
0.2.56
x64—B0A4FEE8417E77A0DF55F3E667964534B426AF7683B1EA1ECD3C6B1D9B0F4D87
0.2.55
x64—A8B9DED8E2252930D510B07059D91AE8E63EED0DB70735F09C60680601AC64E1
0.2.54
x64—A4247EEA26BDCED72AF4E7CEA420539024CDDB7F44D0447B51AF359E6F1845C1
0.2.53
x64—2D1E7B6EEE92EAB5EFD43391100F80F33BD6FEBEB20E8552ACC131BA48E889EB
0.2.52
x64—DE23DB97604BF26A6C2FC7A730153C843B27ED9478F318450741C4E176C574C7
0.2.51
x64—841C5FA0CD3782DF1C0C3E4D850582C8AA6E6AFC08889818247989F3427D33D1
0.2.50
x64—915FE70DC4FCD04198CF0E2DAFFD46CF159D7210B6A90124808CE4C44C0A2AFF
0.2.49
x64—C2FEAF4C5E8D65F3C3A4CE93F338FB597C10A32696D506BA885681DECD36E8B6
0.2.48
x64—762854BCC32BB643D3F0DF8B0E3B53FB78E234C2B7F660DC83B522AF4A779B29
0.2.47
x64—BA52352853FFC3A63924048D3A955109EE28812EE03B7178B53146CE1023D16E
0.2.46
x64—1F5545F3636B4642690781BB00811B3CEF884E67DE9ADE23BFD0D9B0A01B3D2F
0.2.34
x64—22704caf0ed6e8324c5cd765fbc91b3b3b597784e967b7d62fac8eaadd6c4be3