Skip to content

deps(go): bump modernc.org/sqlite from 1.58.0 to 1.59.0 - #1934

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/modernc.org/sqlite-1.59.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/modernc.org/sqlite-1.59.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Bumps modernc.org/sqlite from 1.58.0 to 1.59.0.

Changelog

Sourced from modernc.org/sqlite's changelog.

Changelog

Entries for v1.38.1 through v1.44.1 and for v1.49.1 were added on 2026-09-05, reconstructed from the git history and the merge requests they cite; they were missing at release time.

  • 2026-09-29 v1.60.1:

    • Binding arguments to a statement is no longer quadratic in the number of its parameters, which made multi-row INSERTs with thousands of ? parameters slow. Resolves [GitHub issue #8](modernc-org/sqlite#8), thanks wencycool!
  • 2026-09-28 v1.60.0:

    • A fault while reading the memory-mapped -shm file of a WAL database no longer crashes the process. The statement fails with a disk I/O error, extended code SQLITE_IOERR_IN_PAGE (8714), and the connection stays usable, as in MSVC builds of SQLite. On by default on every platform and not switchable; lib.SehInject and lib.SehPending inject such a fault for tests. Resolves [GitLab issue #221](https://gitlab.com/cznic/sqlite/-/issues/221), thanks Roman (@​requilence) for the report, and supersedes libsqlite3!4 and [GitHub pull request #7](modernc-org/sqlite#7), thanks hazyhaar for the two rounds, the ccgo finding and the Windows Server runs!
    • Re-vendor lib/ from modernc.org/libsqlite3 v1.15.0 and vec/ from modernc.org/libsqlite_vec v0.6.0; SQLite stays 3.53.4 and sqlite-vec v0.1.9. Go 1.26 is now required, and the pinned modernc.org/libc becomes v1.77.1; as always, downstream go.mod files must pin the same modernc.org/libc version this repository's go.mod does, see [GitLab issue #177](https://gitlab.com/cznic/sqlite/-/issues/177).
    • Nine exported lib constants that never had a meaningful value are gone: INFINITY, MB_CUR_MAX, NAN, RESERVED_BYTE, SHARED_FIRST, SQLITE_CANTOPEN_BKPT, SQLITE_CORRUPT_BKPT, SQLITE_DEFAULT_LOOKASIDE and SQLITE_MISUSE_BKPT. The transpiler now evaluates object-like macros as C expressions, so other constants take their C value (lib.WALINDEX_PGSZ is 32768, not 0) and some appear; the full list is in libsqlite3's CHANGELOG under 2026-09-19.
    • make vendor now writes vendor.json, the modernc.org/libsqlite3 and modernc.org/libsqlite_vec commits and the Go toolchain lib/ and vec/ were vendored with, so git show vX.Y.Z:vendor.json says which revisions a release carries; the test suite fails when they no longer match. Tooling only. See [GitLab merge request #140](https://gitlab.com/cznic/sqlite/-/merge_requests/140).
    • vfs.FS.Close now refuses while a database opened through it is still open, returning an error that wraps the new vfs.ErrInUse and leaving the VFS registered. It used to free the VFS the open connection still called through, so the next query crashed the process or read through freed memory. Close the databases first, then the FS.
    • Fix handle reuse in modernc.org/sqlite/vfs on 32-bit targets: after 2^32 file opens in one process the handle counter wrapped and could overwrite a live entry, such as a file system registered at start-up, and crash. 64-bit targets were not affected.
    • The pluggable page cache now panics when a Cache breaks its contract by returning nil, or a different Page, from Fetch for a page SQLite still holds pinned. It used to free memory SQLite was still using, corrupting the database without an error. Only a Cache implementation with that bug is affected; modernc.org/sqlite/pcache is not.
    • Document three limits of the pluggable page cache on RegisterPageCache and Cache: it cannot be combined with modernc.org/sqlite/vec, PageCache.Create may be called concurrently, and under cache=shared a Cache is called from several goroutines. Documentation only.
    • Document in the package documentation that state set on a pooled connection is inherited by the next caller to borrow it, and that a connection reached through sql.Conn.Raw is not safe for concurrent use. Documentation only.
    • Add StrictPragmas, opt-in and off by default: once enabled, a connection whose _pragma DSN value holds more than one SQL statement fails to open with ErrMultiStatementPragma, before any DSN parameter is applied. A _pragma value runs as SQL text, so anything after a ; runs too. Recommended for any application whose DSN is not a compile-time constant.
    • Document SQLite's own URI query parameters on Driver.Open: mode, cache, immutable, nolock, psow and modeof, which have always worked in a DSN starting with file:, and the trap that a plain file name has its query stripped before SQLite sees it, so /path/to.db?mode=ro opens read-write. Resolves [GitLab issue #257](https://gitlab.com/cznic/sqlite/-/issues/257). Documentation only.
    • Add SECURITY.md, the vulnerability reporting policy: three private channels, what is in scope, that only the latest release is supported, and how a confirmed report is disclosed, including an entry in the Go vulnerability database so govulncheck reports it. IRP.md, linked from it, is the maintainers' incident response plan. Documentation only.
    • Add CONTRIBUTING.md: where to send a merge request, which files are generated and must not be edited by hand, how to build and test across the 20 supported targets, and the AUTHORS/CONTRIBUTORS convention. Documentation only.
    • Ship LICENSE-3RD-PARTY.md, a transitively flattened inventory of every third-party component this module carries with all seventeen license texts in full, and a Software Bill of Materials, sbom.cdx.json (CycloneDX 1.6) and sbom.spdx.json (SPDX 2.3), explained in SBOM.md. Both cover what a module-graph tool cannot see: the transpiled SQLite and sqlite-vec C, and the upstreams modernc.org/libc carries, musl among them. Documentation only.
  • 2026-09-15 v1.59.0:

    • Bump the pinned modernc.org/libc to v1.75.7 and re-vendor lib/ and vec/. The transpiled SQLite is unchanged, still 3.53.4. On the Linux targets the new libc replaces transpiled musl memcpy, memmove, memset, memcmp and strlen with native Go, cutting CPU time on query-heavy workloads by up to a third; see the new Performance section below. As always, downstream go.mod files must pin the same modernc.org/libc version this repository's go.mod does; see [GitLab issue #177](https://gitlab.com/cznic/sqlite/-/issues/177).
    • Hand user-defined function and aggregate callbacks a pooled *FunctionContext instead of allocating a fresh one per call, removing the last driver-side allocation per invocation. Like the argument slice, it is valid only for the duration of the callback and must not be retained past its return. Updates [GitLab issue #226](https://gitlab.com/cznic/sqlite/-/issues/226). See [GitLab merge request #137](https://gitlab.com/cznic/sqlite/-/merge_requests/137).
    • Add regression tests pinning the identity and the pooling of that context. See [GitLab merge request #138](https://gitlab.com/cznic/sqlite/-/merge_requests/138), thanks Ian Chechin!
    • Add a Performance section to the package documentation: measured CPU-time ratios of this driver against the same SQLite compiled from C, where the gap comes from, and the two consequences for applications — index the columns that ORDER BY, GROUP BY and WHERE use, and bound the database/sql pool with SetMaxOpenConns.
  • 2026-09-01 v1.58.0:

    • Upgrade to SQLite 3.53.4. It carries upstream's own fix for the journal-rollback data-corruption bug, so the local super-journal patch v1.56.0 introduced is dropped; recovery behavior is unchanged. Also bumps the pinned modernc.org/libc to v1.75.6; as always, downstream modules must pin the same version this one does, see [GitLab issue #177](https://gitlab.com/cznic/sqlite/-/issues/177).
    • Add opt-in support for Linux Open File Description (OFD) locks on database files, off by default; without opting in, locking behavior is byte-for-byte that of previous releases. A POSIX record lock is owned by the (process, inode) pair, so any Close of any descriptor of the database file anywhere in the process silently strips SQLite's locks; OFD locks survive that. Enable it process-wide with MODERNC_SQLITE_OFD_LOCK=1 in the environment, or with the new OFDLocking(true) before the first connection is opened; OFDLockingEnabled reports the mode in effect, and the new ErrOFDLockingTooLate and ErrOFDLockingUnavailable report a switch attempted too late and a platform or filesystem without the feature. Why it is process-wide rather than a DSN parameter, what WAL's -shm coordination still uses, and the /proc/locks measurements behind the design are in [GitLab issue #255](https://gitlab.com/cznic/sqlite/-/issues/255).
    • Resolves [GitLab issue #255](https://gitlab.com/cznic/sqlite/-/issues/255). See [GitLab merge request #136](https://gitlab.com/cznic/sqlite/-/merge_requests/136), thanks Nathan Herring (@​technosloth), and thanks Gani Georgiev (@​ganigeorgiev) for pressing the opt-in default!
  • 2026-08-19 v1.57.0:

    • Add an opt-in _defensive DSN query parameter turning on SQLite's defensive mode for the connection. On such a connection PRAGMA writable_schema=ON, PRAGMA journal_mode=OFF and PRAGMA schema_version=N become silent no-ops, and writes to a virtual table's shadow tables and to sqlite_dbpage fail. It is a hardening measure, not a sandbox for hostile database files, for which it is only one of the steps SQLite recommends, and it is a property of the connection, not of the file. Absent, or _defensive=0, nothing changes.
    • Reject _defensive=1 together with _journal_mode=OFF (or _journal=OFF) instead of opening a connection in which neither was honoured: SQLite turns that PRAGMA into a no-op that still reports success. Only DSNs using the new parameter can be affected. See [GitHub pull request #6](modernc-org/sqlite#6), thanks wsman!
    • Ship the sqlite-vec license notice this module has been missing since vec/ arrived in v1.47.0. sqlite-vec is Copyright (c) 2024 Alex Garcia, dual-licensed Apache-2.0 OR MIT and used here under MIT; the text now ships as LICENSE-SQLITE_VEC, and make vendor fails rather than quietly dropping it.
    • The SQLite notice is renamed from SQLITE-LICENSE to LICENSE-SQLITE; update any direct links to it. Its contents are unchanged. The rename is what makes go mod vendor carry both notices into downstream vendor/ trees: it selects license files by name prefix, so a name merely ending in LICENSE was never propagated.
    • Let a caller-constructed Driver register its own functions, collations and virtual table modules, through new RegisterFunction, RegisterScalarFunction, RegisterDeterministicScalarFunction, RegisterCollationUtf8 and RegisterModule methods plus Must* variants, and let vtab.RegisterModule honour its db argument. Behavior change: vtab.RegisterModule(db, ...) where db was opened on a caller-constructed Driver used to discard db and land on the registered sqlite driver, reaching every connection in the process; it now lands on that Driver alone, so a sql.Open("sqlite") connection that used to resolve such a module gets no such module. Everything else is additive, and the isolating change discussed in [GitLab issue #254](https://gitlab.com/cznic/sqlite/-/issues/254) is deliberately not made here. See [GitLab merge request #135](https://gitlab.com/cznic/sqlite/-/merge_requests/135), thanks Ian Chechin!
    • Promote freebsd/386, freebsd/arm and netbsd/amd64 from experimental to fully supported. The package documentation's platform table had carried seventeen entries while this module shipped, cross-built and tested twenty; all three have been in the builder matrix since v1.53.0 and pass the full suite on this release's commit. Documentation only — lib/ is byte-for-byte what v1.56.0 shipped.
  • 2026-08-03 v1.56.0:

    • Re-vendor the transpiled sources, picking up modernc.org/libsqlite3's patch for an upstream data-corruption bug in SQLite 3.53.3's journal rollback. A crash during the commit of a multi-database (ATTACH) transaction can leave a hot journal whose zeroed super-journal name still validates, so pager_playback() deletes it without playing it back and leaves the database corrupted. Not a transpilation artifact: a plain gcc build of stock 3.53.3 fails on the same bytes. The SQLite version is unchanged at 3.53.3, every supported target carries the patch, and it will be dropped once upstream ships its own fix.
    • Two targets change beyond that patch. linux/s390x now allocates C bit-fields MSB-first as the big-endian ABI requires, from modernc.org/cc/v4 v4.29.1. linux/riscv64 was regenerated on a host running GCC 11.4.0 rather than 13.3.0, which drops some unreferenced compiler-predefined macro constants and changes what PRAGMA compile_options reports; no SQLite code generation differs. Every other target is byte-identical to v1.55.0 apart from the patch above.
    • Bump the pinned modernc.org/libc to v1.74.4 and the remaining dependencies to their current releases. v1.74.2 and v1.74.3 are retracted upstream over a freeaddrinfo lock leak that deadlocks name resolution, and v1.74.4 is the fix. As always, downstream modules must pin the same modernc.org/libc version this one does, see [GitLab issue #177](https://gitlab.com/cznic/sqlite/-/issues/177).
    • Add NewConnector, returning a database/sql/driver.Connector for use with sql.OpenDB. It opens the same connections sql.Open("sqlite", dsn) does, from the same registered driver, so every function, collation, connection hook and virtual table module registered through this package applies to them. It exists for callers that need to interpose on the physical connections database/sql opens — tracing, metrics, connection-scoped setup — for which the alternative was sql.Register, which is process-global, panics on a repeated name and cannot be undone. A runnable sample is in examples/connector. Resolves [GitLab issue #253](https://gitlab.com/cznic/sqlite/-/issues/253), thanks Alessandro Segala (@​ItalyPaleAle)!
    • Documentation sweep. openbsd/amd64 and openbsd/arm64 join the supported platforms table, the vfs DSN query parameter is documented alongside the others on Driver.Open, the stale go generate and GO_GENERATE instructions are replaced by modernc.org/libsqlite3 and make vendor, and vec and vfs gained the package doc comments they were missing. A caller-constructed sqlite.Driver is now documented as not being the driver this package registers as "sqlite": it carries none of the package-level functions and collations, so it can evaluate upper(x) or date(x) differently. Documentation only.
  • 2026-07-20 v1.55.0:

... (truncated)

Commits
  • c96a4e6 CHANGELOG.md: document the libc v1.75.7 bump and the Performance section
  • 35c446e update dependencies, make vendor
  • 9ad02ac Merge branch 'udf-context-tests' into 'master'
  • d6d84a9 sqlite: pin the identity and the pooling of the FunctionContext in tests
  • 59ec397 doc.go: add a Performance section with measured driver-vs-C ratios
  • 51cbcbf Merge branch 'udf-call-pool' into 'master'
  • e390a0c sqlite: pool the FunctionContext handed to UDF and aggregate callbacks
  • 38af581 doc.go, README.md: point readers at CHANGELOG.md
  • 37e55e4 CHANGELOG.md: reconstruct the missing entries for v1.38.1 through v1.44.1 and...
  • 2f7234f AUTHORS, CONTRIBUTORS: add Nathan Herring; CHANGELOG.md: credit him by name
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note

Low Risk
Lockfile-only patch dependency bump with no repo code changes; SQLite engine version is unchanged and usage is standard sql.Open with WAL pragmas.

Overview
This PR only updates go.mod and go.sum: modernc.org/sqlite 1.58.0 → 1.59.0 and the required companion pin modernc.org/libc 1.75.6 → 1.75.7. There are no application code changes.

For Radar, the driver backs local SQLite persistence (AI investigation history and optional timeline storage) via database/sql. The upstream 1.59.0 release keeps the same transpiled SQLite 3.53.4; it mainly re-vendors against libc v1.75.7, which on Linux can reduce CPU on query-heavy workloads, and pools FunctionContext for user-defined function callbacks (Radar does not register custom UDFs).

Reviewed by Cursor Bugbot for commit f4230c8. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) from 1.58.0 to 1.59.0.
- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)
- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.58.0...v1.59.0)

---
updated-dependencies:
- dependency-name: modernc.org/sqlite
  dependency-version: 1.59.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 30, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 30, 2026
@nadaverell

Copy link
Copy Markdown
Contributor

Superseded by #1942, which batches this update with the other soaked, reviewed Dependabot bumps from 2026-09-30 (same target version, verified together).

@nadaverell nadaverell closed this Sep 30, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/go_modules/modernc.org/sqlite-1.59.0 branch September 30, 2026 09:25
nadaverell added a commit that referenced this pull request Sep 30, 2026
One tested batch replacing this week's soaked, low-risk Dependabot PRs.
Dependency-only: no application source changes.

**Screening time:** 2026-09-30T08:40:02Z (re-checked 09:12Z, base
`0490dd87` unchanged)
**72h cutoff:** published at or before 2026-09-27T08:40:02Z. Every
resolved version below clears it.

## Included

| PR | Dependency | Old → New | Published (UTC) | Soak | Risk conclusion
|
|---|---|---|---|---|---|
| #1932 | k8s.io/{api, apiextensions-apiserver, apimachinery, apiserver,
cli-runtime, client-go, component-helpers, component-base, streaming} |
v0.37.0 → v0.37.1 | 2026-09-23 20:28–23:27 | ~6.5d | Negligible. Every
staging repo's v0.37.0...v0.37.1 compare is a single "Update
dependencies to v0.37.1 tag" commit touching only go.mod/go.sum.
`streaming` v0.37.1 is the same commit as v0.37.0. |
| #1938 | github.com/jackc/pgx/v5 | v5.10.0 → v5.11.0 | 2026-09-07 23:39
| ~22d | Low. Used only by the Postgres timeline store through `stdlib`.
See notes. |
| #1936 | github.com/klauspost/compress | v1.20.0 → v1.20.1 | 2026-09-25
08:00 | ~5d | Low–moderate. Encoder/decoder performance rewrites plus
correctness fixes; no API or default changes. Radar uses it directly
only for the HTTP gzip encoder. |
| #1934 | modernc.org/sqlite (+ modernc.org/libc) | v1.58.0 → v1.59.0
(libc v1.75.6 → v1.75.7) | sqlite 2026-09-15 07:30; libc 2026-09-01
19:33 | ~15d / ~29d | Low. The transpiled SQLite is unchanged (3.53.4).
libc uses native Go mem*/str* routines. The UDF context-pooling change
doesn't apply because Radar registers no UDFs. |
| #1937 | eslint | 10.10.0 → 10.11.0 | 2026-09-18 20:15 | ~11.5d | Low.
A few rule refinements, no breaking changes. Lint gives 0 errors / 441
warnings, the same as main. |
| #1935 | vite | 8.2.2 → 8.3.1 | 2026-09-24 12:26 | ~6d | Low. Moves
rolldown 1.2.6 → 1.2.11, whose tree-shaking and code-splitting fixes can
change bundle output, so I smoke-tested the built binary in a browser
(below). |
| #1931 | lucide-react | 1.37.0 → 1.48.0 | 2026-09-24 05:53 | ~6d | Low.
No exports were removed between the two tarballs (6137 → 6347). All 226
icon names Radar imports exist in 1.48.0. The k8s-ui peer range
`>=0.400.0` is unchanged. |

### Movement beyond the Dependabot PRs (reviewed, all soaked)
- **k8s alignment:** root `k8s.io/kubectl` and
`k8s.io/csi-translation-lib` (indirect, via `./pkg`) and all of
`pkg/go.mod`'s k8s.io requirements move to v0.37.1 as well. Without
this, #1932 would leave the graph mixing v0.37.0 and v0.37.1.
- kubectl was published 2026-09-24 01:06Z and csi-translation-lib
2026-09-24 00:45Z. Both are go.mod-only tag bumps, like the rest of the
group.
- Module-graph-only entries `k8s.io/{code-generator, kms, metrics}`
v0.37.1 were published 2026-09-23 21:22 / 21:45 / 23:18Z. None of them
appears in go.sum.
- **npm transitives:**
- `rolldown` and all 15 `@rolldown/binding-*` 1.2.6 → 1.2.11 (2026-09-24
13:54–14:30Z)
  - `@oxc-project/types` 0.147.0 → 0.151.0 (2026-09-21)
  - `picomatch` 4.0.5 → 4.0.7 (2026-08-24)
  - Nothing else in `package-lock.json` changed.
- **Newer releases deliberately not picked up:**
  - lucide-react 1.49.0 (2026-09-29) is inside the soak window.
- modernc.org/sqlite v1.60.x (2026-09-28/29) is inside the window, and
it pins libc v1.77.1. libc has an open stack-overflow crash against
v1.77.0 (cznic/libc#60).

## Held / excluded (these PRs stay open)

| PR | Update | Decision | Reason |
|---|---|---|---|
| #1933 | vitest 4.1.11 → 5.0.2 (major) | **Hold** | vitest 5 requires
Node `^22.12 \|\| ^24 \|\| >=26`, but `ci.yml` pins Node 20 for the
Frontend, k8s-ui and Settings jobs. The PR's CI only passed because npm
treats the engine mismatch as a warning (`EBADENGINE`), which Bugbot
also flagged. **Follow-up:** move CI (and CONTRIBUTING's "Node 20+") to
Node 22 first. Note that `web/` runs the hoisted vitest without
declaring it. |
| #1930 | monaco-editor 0.55.1 → 0.57.0 | **Exclude** | Needs source
changes. The deep side-effect imports in
`packages/k8s-ui/src/components/ui/monacoRuntime.ts`
(`esm/vs/editor/contrib/{find,folding,format,gotoError,hover,suggest}/...`)
no longer resolve (TS2882), which fails the Frontend, k8s-ui and
Settings jobs. |
| #1776 | modelcontextprotocol/go-sdk 1.6.1 → 1.8.0 | **Exclude** |
Changes behaviour Radar relies on.
`TestInvestigationHandlerAnnotatesRealToolCallWithoutChangingPublicContract`
fails: "private mount handshake did not mark the scope connected".
Radar's private-mount handling needs adapting first. |
| #1939 | helmfile/helmfile-action v2.2.0 → v2.4.8 | **Exclude** |
Breaks the Helm chart job. Since v2.3.0 the action installs Helm plugins
from `.tgz` release assets
([#648](helmfile/helmfile-action#648)), so
helm-unittest ends up installed twice ("two plugins claim the name
\"unittest\""). It also moved to the node24 runtime (v2.4.0). Needs a
`ci.yml` change to how `helm-plugins` is specified. |

## Radar usage and risk notes
- **pgx 5.11**
([release](https://github.com/jackc/pgx/releases/tag/v5.11.0)):
- It makes connection-string parsing match libpq exactly, which changes
some edge cases: a literal `+` in URI query values, bad percent-encoding
now errors, `#` is data, the last repeated parameter wins, bare IPv6
hosts need brackets, and backslashes in keyword/value strings now
escape.
- That touches user-supplied `RADAR_TIMELINE_POSTGRES_DSN` values with
unusual encoding, which is worth a release-note line.
- The date/time parser rewrite doesn't reach Radar data: timestamps are
stored as int64 nanoseconds.
- The new `Rows.TypeMap` interface method doesn't matter because Radar
implements no custom `pgx.Rows`.
- It also includes security hardening: startup-parameter NUL injection
is rejected, DSN passwords are redacted more thoroughly, and decoders
are hardened against panics.
- The PostgreSQL integration tests skipped locally (no server). CI runs
them with `RADAR_REQUIRE_POSTGRES_TESTS=1` against postgres:17.
- **klauspost/compress 1.20.1**
([release](https://github.com/klauspost/compress/releases/tag/v1.20.1)):
used directly only by `internal/server/compress.go`
(`kgzip.NewWriterLevel`); zstd reaches Radar only transitively (helm,
go-containerregistry, prometheus). In the smoke test, a live
`/api/resources/pods` response came back `Content-Encoding: gzip` and
decoded with system `gunzip` to 269 pods.
- **modernc sqlite/libc**
([CHANGELOG](https://gitlab.com/cznic/sqlite/-/blob/v1.59.0/CHANGELOG.md)):
used by the SQLite timeline store and `ai-runs.db`. libc is exact-pinned
to the version sqlite requires.
- **k8s 0.37.1**
([CHANGELOG-1.37](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.37.md#v1371)):
the library code is identical. The release fixes are in binaries (DRA,
kube-proxy on Windows, kubeadm).
- **vite 8.3 / rolldown**
([8.3.0](https://github.com/vitejs/vite/releases/tag/v8.3.0),
[8.3.1](https://github.com/vitejs/vite/releases/tag/v8.3.1), [rolldown
releases](https://github.com/rolldown/rolldown/releases)):
- Our `manualChunks` does its own `node_modules/` matching, so vite
8.3.0's path-segment change doesn't affect it.
- `@vitejs/plugin-react` 6.1.1 still satisfies its peer range, and
vitest 4.1.11's `vite` peer covers ^8.
- **eslint 10.11**
([release](https://github.com/eslint/eslint/releases/tag/v10.11.0)) and
**lucide-react**
([releases](https://github.com/lucide-icons/lucide/releases)): the
lucide range includes the removal of `trash` (Radar uses `Trash2`) and
glyph redraws for `Trash2` and `Building2`. That's cosmetic; tests that
assert icon class names pass.

## Verification
- **Integrity:** `go mod verify` passes in both root and `pkg`. `go.sum`
/ `pkg/go.sum` were regenerated from main with a clean `go mod tidy`.
Each changes 30 / 14 lines each way, only the modules listed above.
- **Type-check:** `make tsc` passes.
- **Lint:** `cd web && npm run lint` gives 0 errors and 441 warnings
(the same as main).
- **Frontend tests:**
  - `packages/k8s-ui` `npm test`: 209 files, 4030 passed, 1 skipped.
  - `web` `npm run test`: 151 files, 1764 passed.
- **Go tests:**
  - `cd pkg && go test ./...` passes.
- Root `go test ./...` passes except `cmd/desktop`. Its
`TestGetShellEnv` and `TestEnrichEnvPrecedenceAndDiagnostics` hit their
5s login-shell timeout while the full parallel suite was loading the
machine.
- That flake already exists on main and doesn't involve any bumped
module. Re-run on this branch with `go test ./cmd/desktop/ -count=3`,
the tests pass, and they also pass on main.
- **Build:** `make build` passes.
- **Binary smoke test** (built binary against a live GKE cluster):
- All 8 entry assets (index, rolldown-runtime, vendor, ui, monaco
JS/CSS) returned 200.
  - The Pods table rendered with lucide icons.
- The pod drawer's YAML → Edit loaded Monaco along with `monacoRuntime`,
`yamlMonacoRuntime`, the `monacoYaml.worker` and `editor.worker` chunks,
and showed the pod YAML.
- The console showed no errors. The edit was cancelled; nothing was
applied.
- **visual-test:** not run as a full `/visual-test`. The targeted
browser smoke test above covers the rendering-relevant bumps
(vite/rolldown chunking, Monaco loading, lucide icons).

Supersedes #1932, #1938, #1936, #1934, #1937, #1935, #1931

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Patch dependency upgrades with no app code changes; pgx DSN parsing
edge cases are the main operational note for unusual Postgres connection
strings.
> 
> **Overview**
> **Dependency-only batch** — no application source changes. Bumps Go
and npm lockfiles after screening several Dependabot PRs.
> 
> **Go:** Aligns all `k8s.io/*` modules to **v0.37.1** in the root
module, `./pkg`, and checksums (patch tag bumps only). Also bumps **pgx
v5.11.0** (Postgres timeline via `RADAR_TIMELINE_POSTGRES_DSN`),
**klauspost/compress v1.20.1** (HTTP gzip in
`internal/server/compress.go`), and **modernc.org/sqlite v1.59.0** with
**libc v1.75.7** (SQLite timeline / `ai-runs.db`).
> 
> **Frontend:** **vite 8.3.1** (pulls **rolldown 1.2.11** and related
`@rolldown/binding-*` / `@oxc-project/types` transitives in
`package-lock.json`), **eslint 10.11.0**, and **lucide-react 1.48.0** in
`web/` and `packages/k8s-ui`.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
7512c17. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant