Repository navigation
Bump the go-dependencies group across 2 directories with 2 updates - #696
Conversation
3b6d441 to
b3310c2
Compare
|
@dependabot rebase |
Bumps the go-dependencies group with 1 update in the /packager directory: [golang.org/x/mod](https://github.com/golang/mod). Bumps the go-dependencies group with 1 update in the /riverproui directory: [modernc.org/sqlite](https://gitlab.com/cznic/sqlite). Updates `golang.org/x/mod` from 0.40.0 to 0.41.0 - [Commits](golang/mod@v0.40.0...v0.41.0) Updates `modernc.org/sqlite` from 1.57.0 to 1.60.1 - [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md) - [Commits](https://gitlab.com/cznic/sqlite/compare/v1.57.0...v1.60.1) --- updated-dependencies: - dependency-name: golang.org/x/mod dependency-version: 0.41.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: modernc.org/sqlite dependency-version: 1.59.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
b3310c2 to
1757c95
Compare
There was a problem hiding this comment.
🤖 Codex review: Approved after refreshed dependency security and combined-tree compatibility verification. The maintainer explicitly authorizes bypassing the known Dependabot-only Pro AWS OIDC CI failure after confirming master is green.
Current scope
- PR head:
1757c95001c23a5bb771267da34e3433f492555d. - Actual master base:
82cde9fc39dfca9c5a4cdef4b0e92a653e52fb42. - Validated combined tree:
db8cb877062218565469fd1b49bf9d66803b7ddf. - Compared the complete current contribution against the original reviewed patch. Every dependency/lockfile field, artifact identity and added/removed source line is identical; unchanged deep source/provenance evidence is reused.
Security review
- All 14 old/new public module archives and go.mod files match the PR h1 sums and independent sumdb records. Canonical vanity paths, source tags and proxy origin commits agree. No same-version checksum rewrite, fork/replace, workspace, Go/toolchain directive, new cgo/binary/downloader or lifecycle change. None of the selected targets is retracted; SQLite's required libc is pinned to 1.77.1.
- Reviewed handwritten runtime and sensitive generated-source deltas: WAL panic/fault recovery, optional Linux OFD locking (off by default), driver/cancellation/cache/VFS behavior, libc unsafe/syscall/environment mirrors, allocator retention, and generator changes. SQLite's 513-file vendor stamp independently reproduces, and the upstream SQLite 3.53.4 amalgamation SHA3 matches its official release. No new secret harvesting, listener, process launch or outbound destination found. x/mod changes only its Go minimum and documentation.
- Exact-version OSV queries find no advisories for these module pairs; old x/mod 0.40.0 already contains its known fixes. This is not classified as a newly confirmed security update.
- Rebase preserves all four Go dependency files and exact artifact pairs; reused deep evidence and refreshed compatibility on the current tree.
Compatibility verification
Go checks reused after exact relevant source/module/config tree comparison— passed on the combined tree.frontend checks reused after exact relevant source/module/config tree comparison— passed on the combined tree.- Additional unaffected checks are reused only after comparing their complete relevant source/module/config input trees byte-for-byte; the input fingerprints and original evidence are retained locally.
Master before this merge series (dfedb5e36e3362ec492f64946baf5254044e94a4) passes all required checks, both OSS/Pro image pipelines and CodeQL. Current PR failures outside the known Pro workflow are not bypassed.
Residual risk
Modernc contains large generated unsafe code that was not fully semantically audited or independently regenerated for every target. WAL fault handling, libc ABI changes and allocator retention are meaningful runtime changes despite passing integration/race checks; workload performance and peak memory remain residual. No blocking supply-chain finding identified. Required Pro image CI remains unresolved.
Bumps the go-dependencies group with 1 update in the /packager directory: golang.org/x/mod.
Bumps the go-dependencies group with 1 update in the /riverproui directory: modernc.org/sqlite.
Updates
golang.org/x/modfrom 0.40.0 to 0.41.0Commits
d0a27b2modfile: fix Cleanup and DropTool documentationd12008call: upgrade go directive to at least 1.26.0 [generated]Updates
modernc.org/sqlitefrom 1.57.0 to 1.60.1Changelog
Sourced from modernc.org/sqlite's changelog.
... (truncated)
Commits
b122d04conn: bind statement arguments in linear time7d5a376CHANGELOG.md: slim the v1.60.0 sectiona604165CHANGELOG.md: the SEH emulation, the re-vendor and the removed lib constants;...fb4aac4vendor.json: stamp lib/ from libsqlite3 v1.15.0 and vec/ from libsqlite_vec v...0f7ae7dMerge branch 'master' into seh-emulation2e43324lib: re-vendor from modernc.org/libsqlite3 v1.15.0 (SEH emulation), pin libc ...50380eelib, tests: Go side of the wal.c SEH emulation for Windows in-page faults (#221)4552e53Merge branch 'vendor-stamp' into 'master'3775177Makefile, doc.go, IRP.md: VENDORFLAGS for debug builds; name every refusal86c97d4CHANGELOG.md: link merge request !140