chore(deps): bump modernc.org/sqlite from 1.59.0 to 1.60.0 - #228
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) from 1.59.0 to 1.60.0. - [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md) - [Commits](https://gitlab.com/cznic/sqlite/compare/v1.59.0...v1.60.0) --- updated-dependencies: - dependency-name: modernc.org/sqlite dependency-version: 1.60.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
Codex review: needs maintainer review before merge. Reviewed October 2, 2026, 11:03 AM ET / 15:03 UTC (Revision 2). ClawSweeper reviewWhat this changesUpdates Gitcrawl’s SQLite database driver to 1.60.0, its required libc runtime to 1.77.1, and the associated module checksums. Merge readiness✅ Ready for maintainer review The update remains useful: current main and v0.15.0 still use SQLite 1.59.0. The dependency versions and existing toolchain are compatible, and no actionable patch defect was found. Priority: P3 Review scores
Verification
How this fits togetherGitcrawl stores GitHub issues, pull requests, and derived search data in SQLite. The driver supports local database queries and portable archive backups. flowchart LR
A[GitHub archive data] --> B[Gitcrawl storage]
B --> C[SQLite driver]
C --> D[Local database]
D --> E[Search and status]
D --> F[Portable archive backup]
Before mergeNone. Agent review detailsSecurityNone. Review metricsNone. Technical reviewBest possible solution: Keep the SQLite and libc update together while preserving the existing database format, settings, and archive behavior. Do we have a high-confidence way to reproduce the issue? Not applicable: this PR updates dependencies rather than reporting a reproducible Gitcrawl defect; no runtime reproduction was attempted. Is this the best way to solve the issue? Yes: updating the driver and its exact required libc together is the focused maintenance path, and the existing Go toolchain satisfies the new minimum. AGENTS.md: not found in the target repository. Codex review notes: model internal, reasoning medium; reviewed against e8448c176044. LabelsLabel changes: No label changes. Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (1 earlier review cycle)
|
Bumps modernc.org/sqlite from 1.59.0 to 1.60.0.
Changelog
Sourced from modernc.org/sqlite's changelog.
... (truncated)
Commits
7d5a376CHANGELOG.md: slim the v1.60.0 sectiona604165CHANGELOG.md: the SEH emulation, the re-vendor and the removed lib constants;...fb4aac4vendor.json: stamp lib/ from libsqlite3 v1.15.0 and vec/ from libsqlite_vec v...0f7ae7dMerge branch 'master' into seh-emulation2e43324lib: re-vendor from modernc.org/libsqlite3 v1.15.0 (SEH emulation), pin libc ...50380eelib, tests: Go side of the wal.c SEH emulation for Windows in-page faults (#221)4552e53Merge branch 'vendor-stamp' into 'master'3775177Makefile, doc.go, IRP.md: VENDORFLAGS for debug builds; name every refusal86c97d4CHANGELOG.md: link merge request !1409095339vendor_libs, Makefile: record where lib/ and vec/ came from in vendor.jsonDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)