Skip to content

build(deps): bump github.com/openclaw/crawlkit from 0.16.4 to 0.16.5 - #260

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/openclaw/crawlkit-0.16.5
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/openclaw/crawlkit-0.16.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 26, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/openclaw/crawlkit from 0.16.4 to 0.16.5.

Release notes

Sourced from github.com/openclaw/crawlkit's releases.

v0.16.5

0.16.5 - 2026-09-22

Highlights: Safer sidecar paths and a faster SQLite runtime.

  • Reject overlapping sidecar roots expressed with mixed relative and absolute paths, and reject nested destination directory symlinks before copying so managed files cannot be written outside the target or pruned through an alias.
  • Preserve literal whitespace in sidecar directory names and reject ambiguous Windows directory aliases so sync cannot overwrite or prune a different, trimmed destination.
  • Update the SQLite driver to v1.59.0 with its required libc v1.75.7 runtime for faster Linux memory operations and fewer callback allocations, retaining the Go 1.27.0 minimum.
Changelog

Sourced from github.com/openclaw/crawlkit's changelog.

0.16.5 - 2026-09-22

Highlights: Safer sidecar paths and a faster SQLite runtime.

  • Reject overlapping sidecar roots expressed with mixed relative and absolute paths, and reject nested destination directory symlinks before copying so managed files cannot be written outside the target or pruned through an alias.
  • Preserve literal whitespace in sidecar directory names and reject ambiguous Windows directory aliases so sync cannot overwrite or prune a different, trimmed destination.
  • Update the SQLite driver to v1.59.0 with its required libc v1.75.7 runtime for faster Linux memory operations and fewer callback allocations, retaining the Go 1.27.0 minimum.
Commits
  • 493f747 chore: prepare crawlkit 0.16.5 (#141)
  • 7f5b176 build(deps): refresh SQLite runtime and security actions (#140)
  • f9914f2 fix(snapshot): preserve literal sidecar directory names (#139)
  • a7c7ca0 fix(snapshot): contain sidecar copies and reject aliased overlaps (#138)
  • 1d5f12f chore: open next unreleased section (#137)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/openclaw/crawlkit](https://github.com/openclaw/crawlkit) from 0.16.4 to 0.16.5.
- [Release notes](https://github.com/openclaw/crawlkit/releases)
- [Changelog](https://github.com/openclaw/crawlkit/blob/main/CHANGELOG.md)
- [Commits](openclaw/crawlkit@v0.16.4...v0.16.5)

---
updated-dependencies:
- dependency-name: github.com/openclaw/crawlkit
  dependency-version: 0.16.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 26, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 26, 2026 12:52
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 26, 2026
@clawsweeper

clawsweeper Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 26, 2026
@clawsweeper

clawsweeper Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Codex review: needs maintainer review before merge. Reviewed September 26, 2026, 8:55 AM ET / 12:55 UTC.

ClawSweeper review

What this changes

The branch updates Discrawl’s direct Crawlkit dependency from 0.16.4 to 0.16.5 and replaces its Go module checksums.

Merge readiness

✅ Ready for maintainer review

Current main and the latest Discrawl release still use Crawlkit 0.16.4, so this focused dependency update remains useful. The reviewed diff shows no concrete defect or unresolved merge risk.

Priority: P3
Reviewed head: 76eac6d03807f960049f9a9ea0b8193ddab61aba

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) The version-only patch is focused and consistent with Discrawl’s dependency pairing, with no concrete defect found.
Proof confidence 🌊 off-meta tidepool Not applicable: This Dependabot PR is exempt from the external-contributor runtime-proof gate. The changed production dependency feeds Discrawl’s archive publish and import paths; the PR supplies no after-update runtime observation, and no stored-data contract change is identified.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: This Dependabot PR is exempt from the external-contributor runtime-proof gate. The changed production dependency feeds Discrawl’s archive publish and import paths; the PR supplies no after-update runtime observation, and no stored-data contract change is identified.
Evidence reviewed 6 items Introduced dependency change: The pinned PR delta changes only the Crawlkit version in go.mod and its two checksum lines in go.sum.
Current main: The reviewed main revision still pins Crawlkit v0.16.4, so the requested bump is not implemented there.
Dependency integration: Discrawl calls Crawlkit snapshot export when publishing an archive; this is an affirmative dependency-contract signal.
Findings None None.
Security None None.

How this fits together

Discrawl uses Crawlkit’s snapshot and mirror packages to publish Discord archives and import shared archives into local SQLite databases. The module version selects the Crawlkit implementation used by those flows.

flowchart LR
  A[Discord archive] --> B[Discrawl publish and update]
  B --> C[Crawlkit snapshot APIs]
  C --> D[Git snapshot]
  D --> E[Subscriber import]
  E --> F[Local SQLite archive]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

None.

Technical review

Best possible solution:

Use Crawlkit 0.16.5 through Discrawl’s existing snapshot integration while retaining the required SQLite and libc version pairing.

Do we have a high-confidence way to reproduce the issue?

Not applicable: this PR updates a dependency rather than reporting a reproducible Discrawl bug.

Is this the best way to solve the issue?

Yes. A direct module-version and checksum update is the narrowest change for adopting this Crawlkit release.

AGENTS.md: not found in the target repository.

Codex review notes: model internal, reasoning medium; reviewed against a7ec0d0e3079.

Labels

Label changes:

  • add P3: This is a narrow patch-version dependency update without an identified urgent Discrawl regression.
  • add rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • add status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: This Dependabot PR is exempt from the external-contributor runtime-proof gate. The changed production dependency feeds Discrawl’s archive publish and import paths; the PR supplies no after-update runtime observation, and no stored-data contract change is identified.

Label justifications:

  • P3: This is a narrow patch-version dependency update without an identified urgent Discrawl regression.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: This Dependabot PR is exempt from the external-contributor runtime-proof gate. The changed production dependency feeds Discrawl’s archive publish and import paths; the PR supplies no after-update runtime observation, and no stored-data contract change is identified.

Evidence

What I checked:

  • Introduced dependency change: The pinned PR delta changes only the Crawlkit version in go.mod and its two checksum lines in go.sum. (go.mod:11, 76eac6d03807)
  • Current main: The reviewed main revision still pins Crawlkit v0.16.4, so the requested bump is not implemented there. (go.mod:11, a7ec0d0e3079)
  • Dependency integration: Discrawl calls Crawlkit snapshot export when publishing an archive; this is an affirmative dependency-contract signal. (internal/share/share.go:97, a7ec0d0e3079)
  • Upgrade pairing: Discrawl’s release guidance requires SQLite v1.59.0 to stay paired with libc v1.75.7; both versions are already present and unchanged by this PR. (docs/RELEASING.md:21, a7ec0d0e3079)
  • Area history: Recent merged dependency work and snapshot integration changes identify routing candidates. The available parent objects did not support an introduction claim for a specific source line. (go.mod:11, 936e3adff1f9)
  • PR release context: The supplied PR body describes Crawlkit 0.16.5 as a sidecar-path hardening and SQLite-runtime release. The latest Discrawl release supplied in repository state is v0.15.5, which predates this PR.

Likely related people:

  • Peter Steinberger: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • Hannes Rudolph: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@vincentkoc

Copy link
Copy Markdown
Member

Superseded by #262, merged at 4792f2b. Main now uses the published Crawlkit v0.16.6 tag, so the v0.16.5-only update is no longer needed.

@vincentkoc vincentkoc closed this Sep 28, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/go_modules/github.com/openclaw/crawlkit-0.16.5 branch September 28, 2026 15:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant