Repository navigation
deps(go): bump modernc.org/sqlite from 1.58.0 to 1.59.0 - #1934
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) from 1.58.0 to 1.59.0. - [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md) - [Commits](https://gitlab.com/cznic/sqlite/compare/v1.58.0...v1.59.0) --- updated-dependencies: - dependency-name: modernc.org/sqlite dependency-version: 1.59.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
|
Superseded by #1942, which batches this update with the other soaked, reviewed Dependabot bumps from 2026-09-30 (same target version, verified together). |
Contributor
Author
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
dependabot
Bot
deleted the
dependabot/go_modules/modernc.org/sqlite-1.59.0
branch
September 30, 2026 09:25
nadaverell
added a commit
that referenced
this pull request
Sep 30, 2026
One tested batch replacing this week's soaked, low-risk Dependabot PRs. Dependency-only: no application source changes. **Screening time:** 2026-09-30T08:40:02Z (re-checked 09:12Z, base `0490dd87` unchanged) **72h cutoff:** published at or before 2026-09-27T08:40:02Z. Every resolved version below clears it. ## Included | PR | Dependency | Old → New | Published (UTC) | Soak | Risk conclusion | |---|---|---|---|---|---| | #1932 | k8s.io/{api, apiextensions-apiserver, apimachinery, apiserver, cli-runtime, client-go, component-helpers, component-base, streaming} | v0.37.0 → v0.37.1 | 2026-09-23 20:28–23:27 | ~6.5d | Negligible. Every staging repo's v0.37.0...v0.37.1 compare is a single "Update dependencies to v0.37.1 tag" commit touching only go.mod/go.sum. `streaming` v0.37.1 is the same commit as v0.37.0. | | #1938 | github.com/jackc/pgx/v5 | v5.10.0 → v5.11.0 | 2026-09-07 23:39 | ~22d | Low. Used only by the Postgres timeline store through `stdlib`. See notes. | | #1936 | github.com/klauspost/compress | v1.20.0 → v1.20.1 | 2026-09-25 08:00 | ~5d | Low–moderate. Encoder/decoder performance rewrites plus correctness fixes; no API or default changes. Radar uses it directly only for the HTTP gzip encoder. | | #1934 | modernc.org/sqlite (+ modernc.org/libc) | v1.58.0 → v1.59.0 (libc v1.75.6 → v1.75.7) | sqlite 2026-09-15 07:30; libc 2026-09-01 19:33 | ~15d / ~29d | Low. The transpiled SQLite is unchanged (3.53.4). libc uses native Go mem*/str* routines. The UDF context-pooling change doesn't apply because Radar registers no UDFs. | | #1937 | eslint | 10.10.0 → 10.11.0 | 2026-09-18 20:15 | ~11.5d | Low. A few rule refinements, no breaking changes. Lint gives 0 errors / 441 warnings, the same as main. | | #1935 | vite | 8.2.2 → 8.3.1 | 2026-09-24 12:26 | ~6d | Low. Moves rolldown 1.2.6 → 1.2.11, whose tree-shaking and code-splitting fixes can change bundle output, so I smoke-tested the built binary in a browser (below). | | #1931 | lucide-react | 1.37.0 → 1.48.0 | 2026-09-24 05:53 | ~6d | Low. No exports were removed between the two tarballs (6137 → 6347). All 226 icon names Radar imports exist in 1.48.0. The k8s-ui peer range `>=0.400.0` is unchanged. | ### Movement beyond the Dependabot PRs (reviewed, all soaked) - **k8s alignment:** root `k8s.io/kubectl` and `k8s.io/csi-translation-lib` (indirect, via `./pkg`) and all of `pkg/go.mod`'s k8s.io requirements move to v0.37.1 as well. Without this, #1932 would leave the graph mixing v0.37.0 and v0.37.1. - kubectl was published 2026-09-24 01:06Z and csi-translation-lib 2026-09-24 00:45Z. Both are go.mod-only tag bumps, like the rest of the group. - Module-graph-only entries `k8s.io/{code-generator, kms, metrics}` v0.37.1 were published 2026-09-23 21:22 / 21:45 / 23:18Z. None of them appears in go.sum. - **npm transitives:** - `rolldown` and all 15 `@rolldown/binding-*` 1.2.6 → 1.2.11 (2026-09-24 13:54–14:30Z) - `@oxc-project/types` 0.147.0 → 0.151.0 (2026-09-21) - `picomatch` 4.0.5 → 4.0.7 (2026-08-24) - Nothing else in `package-lock.json` changed. - **Newer releases deliberately not picked up:** - lucide-react 1.49.0 (2026-09-29) is inside the soak window. - modernc.org/sqlite v1.60.x (2026-09-28/29) is inside the window, and it pins libc v1.77.1. libc has an open stack-overflow crash against v1.77.0 (cznic/libc#60). ## Held / excluded (these PRs stay open) | PR | Update | Decision | Reason | |---|---|---|---| | #1933 | vitest 4.1.11 → 5.0.2 (major) | **Hold** | vitest 5 requires Node `^22.12 \|\| ^24 \|\| >=26`, but `ci.yml` pins Node 20 for the Frontend, k8s-ui and Settings jobs. The PR's CI only passed because npm treats the engine mismatch as a warning (`EBADENGINE`), which Bugbot also flagged. **Follow-up:** move CI (and CONTRIBUTING's "Node 20+") to Node 22 first. Note that `web/` runs the hoisted vitest without declaring it. | | #1930 | monaco-editor 0.55.1 → 0.57.0 | **Exclude** | Needs source changes. The deep side-effect imports in `packages/k8s-ui/src/components/ui/monacoRuntime.ts` (`esm/vs/editor/contrib/{find,folding,format,gotoError,hover,suggest}/...`) no longer resolve (TS2882), which fails the Frontend, k8s-ui and Settings jobs. | | #1776 | modelcontextprotocol/go-sdk 1.6.1 → 1.8.0 | **Exclude** | Changes behaviour Radar relies on. `TestInvestigationHandlerAnnotatesRealToolCallWithoutChangingPublicContract` fails: "private mount handshake did not mark the scope connected". Radar's private-mount handling needs adapting first. | | #1939 | helmfile/helmfile-action v2.2.0 → v2.4.8 | **Exclude** | Breaks the Helm chart job. Since v2.3.0 the action installs Helm plugins from `.tgz` release assets ([#648](helmfile/helmfile-action#648)), so helm-unittest ends up installed twice ("two plugins claim the name \"unittest\""). It also moved to the node24 runtime (v2.4.0). Needs a `ci.yml` change to how `helm-plugins` is specified. | ## Radar usage and risk notes - **pgx 5.11** ([release](https://github.com/jackc/pgx/releases/tag/v5.11.0)): - It makes connection-string parsing match libpq exactly, which changes some edge cases: a literal `+` in URI query values, bad percent-encoding now errors, `#` is data, the last repeated parameter wins, bare IPv6 hosts need brackets, and backslashes in keyword/value strings now escape. - That touches user-supplied `RADAR_TIMELINE_POSTGRES_DSN` values with unusual encoding, which is worth a release-note line. - The date/time parser rewrite doesn't reach Radar data: timestamps are stored as int64 nanoseconds. - The new `Rows.TypeMap` interface method doesn't matter because Radar implements no custom `pgx.Rows`. - It also includes security hardening: startup-parameter NUL injection is rejected, DSN passwords are redacted more thoroughly, and decoders are hardened against panics. - The PostgreSQL integration tests skipped locally (no server). CI runs them with `RADAR_REQUIRE_POSTGRES_TESTS=1` against postgres:17. - **klauspost/compress 1.20.1** ([release](https://github.com/klauspost/compress/releases/tag/v1.20.1)): used directly only by `internal/server/compress.go` (`kgzip.NewWriterLevel`); zstd reaches Radar only transitively (helm, go-containerregistry, prometheus). In the smoke test, a live `/api/resources/pods` response came back `Content-Encoding: gzip` and decoded with system `gunzip` to 269 pods. - **modernc sqlite/libc** ([CHANGELOG](https://gitlab.com/cznic/sqlite/-/blob/v1.59.0/CHANGELOG.md)): used by the SQLite timeline store and `ai-runs.db`. libc is exact-pinned to the version sqlite requires. - **k8s 0.37.1** ([CHANGELOG-1.37](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.37.md#v1371)): the library code is identical. The release fixes are in binaries (DRA, kube-proxy on Windows, kubeadm). - **vite 8.3 / rolldown** ([8.3.0](https://github.com/vitejs/vite/releases/tag/v8.3.0), [8.3.1](https://github.com/vitejs/vite/releases/tag/v8.3.1), [rolldown releases](https://github.com/rolldown/rolldown/releases)): - Our `manualChunks` does its own `node_modules/` matching, so vite 8.3.0's path-segment change doesn't affect it. - `@vitejs/plugin-react` 6.1.1 still satisfies its peer range, and vitest 4.1.11's `vite` peer covers ^8. - **eslint 10.11** ([release](https://github.com/eslint/eslint/releases/tag/v10.11.0)) and **lucide-react** ([releases](https://github.com/lucide-icons/lucide/releases)): the lucide range includes the removal of `trash` (Radar uses `Trash2`) and glyph redraws for `Trash2` and `Building2`. That's cosmetic; tests that assert icon class names pass. ## Verification - **Integrity:** `go mod verify` passes in both root and `pkg`. `go.sum` / `pkg/go.sum` were regenerated from main with a clean `go mod tidy`. Each changes 30 / 14 lines each way, only the modules listed above. - **Type-check:** `make tsc` passes. - **Lint:** `cd web && npm run lint` gives 0 errors and 441 warnings (the same as main). - **Frontend tests:** - `packages/k8s-ui` `npm test`: 209 files, 4030 passed, 1 skipped. - `web` `npm run test`: 151 files, 1764 passed. - **Go tests:** - `cd pkg && go test ./...` passes. - Root `go test ./...` passes except `cmd/desktop`. Its `TestGetShellEnv` and `TestEnrichEnvPrecedenceAndDiagnostics` hit their 5s login-shell timeout while the full parallel suite was loading the machine. - That flake already exists on main and doesn't involve any bumped module. Re-run on this branch with `go test ./cmd/desktop/ -count=3`, the tests pass, and they also pass on main. - **Build:** `make build` passes. - **Binary smoke test** (built binary against a live GKE cluster): - All 8 entry assets (index, rolldown-runtime, vendor, ui, monaco JS/CSS) returned 200. - The Pods table rendered with lucide icons. - The pod drawer's YAML → Edit loaded Monaco along with `monacoRuntime`, `yamlMonacoRuntime`, the `monacoYaml.worker` and `editor.worker` chunks, and showed the pod YAML. - The console showed no errors. The edit was cancelled; nothing was applied. - **visual-test:** not run as a full `/visual-test`. The targeted browser smoke test above covers the rendering-relevant bumps (vite/rolldown chunking, Monaco loading, lucide icons). Supersedes #1932, #1938, #1936, #1934, #1937, #1935, #1931 <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Low Risk** > Patch dependency upgrades with no app code changes; pgx DSN parsing edge cases are the main operational note for unusual Postgres connection strings. > > **Overview** > **Dependency-only batch** — no application source changes. Bumps Go and npm lockfiles after screening several Dependabot PRs. > > **Go:** Aligns all `k8s.io/*` modules to **v0.37.1** in the root module, `./pkg`, and checksums (patch tag bumps only). Also bumps **pgx v5.11.0** (Postgres timeline via `RADAR_TIMELINE_POSTGRES_DSN`), **klauspost/compress v1.20.1** (HTTP gzip in `internal/server/compress.go`), and **modernc.org/sqlite v1.59.0** with **libc v1.75.7** (SQLite timeline / `ai-runs.db`). > > **Frontend:** **vite 8.3.1** (pulls **rolldown 1.2.11** and related `@rolldown/binding-*` / `@oxc-project/types` transitives in `package-lock.json`), **eslint 10.11.0**, and **lucide-react 1.48.0** in `web/` and `packages/k8s-ui`. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 7512c17. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps modernc.org/sqlite from 1.58.0 to 1.59.0.
Changelog
Sourced from modernc.org/sqlite's changelog.
... (truncated)
Commits
c96a4e6CHANGELOG.md: document the libc v1.75.7 bump and the Performance section35c446eupdate dependencies, make vendor9ad02acMerge branch 'udf-context-tests' into 'master'd6d84a9sqlite: pin the identity and the pooling of the FunctionContext in tests59ec397doc.go: add a Performance section with measured driver-vs-C ratios51cbcbfMerge branch 'udf-call-pool' into 'master'e390a0csqlite: pool the FunctionContext handed to UDF and aggregate callbacks38af581doc.go, README.md: point readers at CHANGELOG.md37e55e4CHANGELOG.md: reconstruct the missing entries for v1.38.1 through v1.44.1 and...2f7234fAUTHORS, CONTRIBUTORS: add Nathan Herring; CHANGELOG.md: credit him by nameDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Note
Low Risk
Lockfile-only patch dependency bump with no repo code changes; SQLite engine version is unchanged and usage is standard sql.Open with WAL pragmas.
Overview
This PR only updates
go.modandgo.sum:modernc.org/sqlite1.58.0 → 1.59.0 and the required companion pinmodernc.org/libc1.75.6 → 1.75.7. There are no application code changes.For Radar, the driver backs local SQLite persistence (AI investigation history and optional timeline storage) via
database/sql. The upstream 1.59.0 release keeps the same transpiled SQLite 3.53.4; it mainly re-vendors against libc v1.75.7, which on Linux can reduce CPU on query-heavy workloads, and poolsFunctionContextfor user-defined function callbacks (Radar does not register custom UDFs).Reviewed by Cursor Bugbot for commit f4230c8. Bugbot is set up for automated code reviews on this repo. Configure here.