Skip to content

Bump the go-minor-and-patch group across 1 directory with 8 updates - #8

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-minor-and-patch-6a81fec19d
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-minor-and-patch-6a81fec19d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the go-minor-and-patch group with 8 updates in the / directory:

Package From To
github.com/compose-spec/compose-go/v2 2.10.1 2.15.0
github.com/gin-gonic/gin 1.9.1 1.12.0
github.com/go-pkgz/auth 1.25.2 1.27.0
github.com/shirou/gopsutil/v3 3.24.1 3.24.5
golang.org/x/net 0.56.0 0.57.0
golang.org/x/sync 0.21.0 0.22.0
golang.org/x/term 0.44.0 0.45.0
modernc.org/sqlite 1.28.0 1.59.0

Updates github.com/compose-spec/compose-go/v2 from 2.10.1 to 2.15.0

Release notes

Sourced from github.com/compose-spec/compose-go/v2's releases.

v2.15.0

What's Changed

New Contributors

Full Changelog: compose-spec/compose-go@v2.14.0...v2.15.0

v2.14.0

What's Changed

Full Changelog: compose-spec/compose-go@v2.13.0...v2.14.0

v2.13.0

What's Changed

Full Changelog: compose-spec/compose-go@v2.12.1...v2.13.0

... (truncated)

Commits
  • 4ddbf11 cli: validate COMPOSE_FILE entries point to actual compose files
  • 500d50c fix: merge attributes of repeated variable occurrences in ExtractVariables
  • 57f6c16 tests: run named table cases as subtests
  • 261851b loader/tests: completeness test keeps the conformance matrix exhaustive
  • 3843a20 loader/tests: link every attribute file to the spec section it locks
  • 728b3f2 loader/tests: loadsAs expresses expectations as canonical YAML
  • f8211c4 docs: TESTING.md codifies the testing contract
  • 95dbfdf test: cover short/long ulimit syntax combinations in override merge
  • 5a10b5a fix: ignore default .env probe on permission denied
  • f0442ff fix(types): reject unrecognized pull_policy values instead of defaulting
  • Additional commits viewable in compare view

Updates github.com/gin-gonic/gin from 1.9.1 to 1.12.0

Release notes

Sourced from github.com/gin-gonic/gin's releases.

v1.12.0

Changelog

Features

  • 192ac89eefc1c30f7c97ae48a9ffb1c6f1c8c8bc: feat(binding): add support for encoding.UnmarshalText in uri/query binding (#4203) (@​takanuva15)
  • 53410d2e07054369e0960fbe2eed97e1b9966f12: feat(context): add GetError and GetErrorSlice methods for error retrieval (#4502) (@​raju-mechatronics)
  • acc55e049e33b401e810dbd8c0d6dcb6b3ba2b05: feat(context): add Protocol Buffers support to content negotiation (#4423) (@​1911860538)
  • 38e765119241d990705169bedb5002a29ae0cbd1: feat(context): implemented Delete method (@​Spyder01)
  • 771dcc6476d7bc6abb9ec0235ecefa4d38fe6fb0: feat(gin): add option to use escaped path (#4420) (@​ldesauw)
  • 4dec17afdff48e8018c83618fbbe69fceeb2b41d: feat(logger): color latency (#4146) (@​wsyqn6)
  • d7776de7d444935ea4385999711bd6331a98fecb: feat(render): add bson protocol (#4145) (@​laurentcau)

Bug fixes

  • b917b14ff9d189f16a7492be79d123a47806ee19: fix(binding): empty value error (#2169) (@​guonaihong)
  • c3d1092b3b48addf6f9cd00fe274ec3bd14650eb: fix(binding): improve empty slice/array handling in form binding (#4380) (@​1911860538)
  • 9914178584e42458ff7d23891463a880f58c9d86: fix(context): ClientIP handling for multiple X-Forwarded-For header values (#4472) (@​Nurysso)
  • 2a794cd0b0faa7d829291375b27a3467ea972b0d: fix(debug): version mismatch (#4403) (@​zeek0x)
  • c3d5a28ed6d3849da820195b6774d212bcc038a9: fix(gin): close os.File in RunFd to prevent resource leak (#4422) (@​1911860538)
  • 5fad976b372e381312f8de69f0969f1284d229d3: fix(gin): literal colon routes not working with engine.Handler() (#4415) (@​pawannn)
  • 63dd3e60cab89c27fb66bce1423bd268d52abad1: fix(recover): suppress http.ErrAbortHandler in recover (#4336) (@​MondayCha)
  • 5c00df8afadd06cc5be530dde00fe6d9fa4a2e4a: fix(render): write content length in Data.Render (#4206) (@​dengaleev)
  • 234a6d4c00cb77af9852aca0b8289745d5529b4b: fix(response): refine hijack behavior for response lifecycle (#4373) (@​appleboy)
  • 472d086af2acd924cb4b9d7be0525f7d790f69bc: fix(tree): panic in findCaseInsensitivePathRec with RedirectFixedPath (#4535) (@​veeceey)
  • 8e07d37c63e5536eb25f4af4c91eabeee4011fba: fix: Correct typos, improve documentation clarity, and remove dead code (#4511) (@​mahanadh)

Enhancements

  • ba093d19477b896ac89a7fc3246af23d290b8e26: chore(binding): upgrade bson dependency to mongo-driver v2 (#4549) (@​BobDu)
  • b2b489dbf4826c2c630717a77fd5e42774625410: chore(context): always trust xff headers from unix socket (#3359) (@​WeidiDeng)
  • ecb3f7b5e2f3915bf1db240ed5eee572f8dbea36: chore(deps): upgrade golang.org/x/crypto to v0.45.0 (#4449) (@​appleboy)
  • af6e8b70b8261bb0c99ad094fe552ab92991620a: chore(deps): upgrade quic-go to v0.57.1 (@​appleboy)
  • db309081bc5c137b2aa15701ef53f7f19788da25: chore(logger): allow skipping query string output (#4547) (@​USA-RedDragon)
  • 26c3a628655cad2388380cb8102d6ce7d4875f3b: chore(response): prevent Flush() panic when http.Flusher (#4479) (@​Twacqwq)
  • 5dd833f1f26de0eb30eae47b17e05ced2482dc41: chore: bump minimum Go version to 1.24 and update workflows (#4388) (@​appleboy)

Refactor

  • 39858a0859c914bd26948fa950477e11bd8d3823: refactor(binding): use maps.Copy for cleaner map handling (#4352) (@​russcoss)
  • c0048f645ee945c4db30593afdea10123e2c30a6: refactor(context): omit the return value names (#4395) (@​wanghaolong613)
  • 915e4c90d28ec4cffc6eb146e208ab5a65eac772: refactor(context): replace hardcoded localhost IPs with constants (#4481) (@​pauloappbr)
  • 414de60574449457f3192a7a1d5528940db2836d: refactor(context): using maps.Clone (#4333) (@​cuiweixie)
  • 59e9d4a794f12c4f9a6c7bed441b9644e5f6d99b: refactor(ginS): use sync.OnceValue to simplify engine function (#4314) (@​1911860538)
  • 3ab698dc5110af1977d57226e4995c57dd34c233: refactor(recovery): smart error comparison (#4142) (@​zeek0x)
  • d1a15347b1e45a8ee816193d3578a93bfd73b70f: refactor(utils): move util functions to utils.go (#4467) (@​zeek0x)
  • e3118cc378d263454098924ebbde7e8d1dd2e904: refactor: for loop can be modernized using range over int (#4392) (@​wanghaolong613)
  • 488f8c3ffa579a8d19beb2bae95ff8ef36b3d53f: refactor: replace magic numbers with named constants in bodyAllowedForStatus (#4529) (@​veeceey)
  • 9968c4bf9d5a99edc3eee2c068a4c9160ece8915: refactor: use b.Loop() to simplify the code and improve performance (#4389) (@​reddaisyy)
  • a85ef5ce4d0cda8834c59c855068ed48b51192d1: refactor: use b.Loop() to simplify the code and improve performance (#4432) (@​efcking)

Build process updates

  • 61b67de522a189b568aced4c5c16917c558e3387: ci(bot): increase frequency and group updates for dependencies (#4367) (@​appleboy)
  • fb27ef26c2fdfe25344b4c039d8a53551f9e912c: ci(lint): refactor test assertions and linter configuration (#4436) (@​appleboy)
  • 93ff771e6dbf10e432864b30f3719ac5c84a4d4a: ci(sec): improve type safety and server organization in HTTP middleware (#4437) (@​appleboy)
  • e88fc8927a52b74f55bec0351604a56ac0aa1c51: ci(sec): schedule Trivy security scans to run daily at midnight UTC (#4439) (@​appleboy)
  • 5e5ff3ace496a31b138b0820136a146bfb5de0ef: ci: replace vulnerability scanning workflow with Trivy integration (#4421) (@​appleboy)
  • 00900fb3e1ea9dde33985a0e4f6afec793d5e786: ci: update CI workflows and standardize Trivy config quotes (#4531) (@​appleboy)
  • ae3f524974fc4f55d18c9e7fae4614503c015226: ci: update Go version support to 1.25+ across CI and docs (#4550) (@​appleboy)

... (truncated)

Changelog

Sourced from github.com/gin-gonic/gin's changelog.

Gin v1.12.0

Features

  • feat(render): add bson protocol (#4145)
  • feat(context): add GetError and GetErrorSlice methods for error retrieval (#4502)
  • feat(binding): add support for encoding.UnmarshalText in uri/query binding (#4203)
  • feat(gin): add option to use escaped path (#4420)
  • feat(context): add Protocol Buffers support to content negotiation (#4423)
  • feat(context): implemented Delete method (#38e7651)
  • feat(logger): color latency (#4146)

Enhancements

  • perf(tree): reduce allocations in findCaseInsensitivePath (#4417)
  • perf(recovery): optimize line reading in stack function (#4466)
  • perf(path): replace regex with custom functions in redirectTrailingSlash (#4414)
  • perf(tree): optimize path parsing using strings.Count (#4246)
  • chore(logger): allow skipping query string output (#4547)
  • chore(context): always trust xff headers from unix socket (#3359)
  • chore(response): prevent Flush() panic when the underlying ResponseWriter does not implement http.Flusher (#4479)
  • refactor(recovery): smart error comparison (#4142)
  • refactor(context): replace hardcoded localhost IPs with constants (#4481)
  • refactor(utils): move util functions to utils.go (#4467)
  • refactor(binding): use maps.Copy for cleaner map handling (#4352)
  • refactor(context): using maps.Clone (#4333)
  • refactor(ginS): use sync.OnceValue to simplify engine function (#4314)
  • refactor: replace magic numbers with named constants in bodyAllowedForStatus (#4529)
  • refactor: for loop can be modernized using range over int (#4392)

Bug Fixes

  • fix(tree): panic in findCaseInsensitivePathRec with RedirectFixedPath (#4535)
  • fix(render): write content length in Data.Render (#4206)
  • fix(context): ClientIP handling for multiple X-Forwarded-For header values (#4472)
  • fix(binding): empty value error (#2169)
  • fix(recover): suppress http.ErrAbortHandler in recover (#4336)
  • fix(gin): literal colon routes not working with engine.Handler() (#4415)
  • fix(gin): close os.File in RunFd to prevent resource leak (#4422)
  • fix(response): refine hijack behavior for response lifecycle (#4373)
  • fix(binding): improve empty slice/array handling in form binding (#4380)
  • fix(debug): version mismatch (#4403)
  • fix: correct typos, improve documentation clarity, and remove dead code (#4511)

Build process updates / CI

  • ci: update Go version support to 1.25+ across CI and docs (#4550)
  • chore(binding): upgrade bson dependency to mongo-driver v2 (#4549)

Gin v1.11.0

... (truncated)

Commits
  • 73726dc docs: update documentation to reflect Go version changes (#4552)
  • e292e5c docs: document and finalize Gin v1.12.0 release (#4551)
  • ae3f524 ci: update Go version support to 1.25+ across CI and docs (#4550)
  • 38534e2 chore(deps): bump golang.org/x/net from 0.50.0 to 0.51.0 (#4548)
  • 472d086 fix(tree): panic in findCaseInsensitivePathRec with RedirectFixedPath (#4535)
  • fb25834 test(context): use http.StatusContinue constant instead of magic number 100 (...
  • 6f1d5fe test(render): add comprehensive error handling tests (#4541)
  • 5c00df8 fix(render): write content length in Data.Render (#4206)
  • db30908 chore(logger): allow skipping query string output (#4547)
  • ba093d1 chore(binding): upgrade bson dependency to mongo-driver v2 (#4549)
  • Additional commits viewable in compare view

Updates github.com/go-pkgz/auth from 1.25.2 to 1.27.0

Release notes

Sourced from github.com/go-pkgz/auth's releases.

Version 1.27.0

The Telegram provider no longer hard-codes https://api.telegram.org. NewTelegramAPIWithBaseURL takes the base, and every request goes through it, avatar downloads included. An empty base falls back to the public API.

Moving a token-bearing URL off a constant is what the rest of the change is for: the bot token travels in the request path, and the answers now come from a host the library does not control. The base is validated, error text is scrubbed of the token in raw and encoded forms, a success response has to match Telegram's own username shape, and redirects are refused by default because Go copies the previous URL into Referer.

One behaviour change. A caller that relied on the default redirect policy now gets an error on a redirect. A caller-supplied CheckRedirect remains in force.

Also in this release: the Apple public-key test no longer binds a shared port, and the Telegram tests no longer race or depend on order.

Full detail in #316.

Version 1.26.0

EmailParams gains HELOHost, which sets the hostname the sender announces in the SMTP greeting. Left empty it stays localhost, so existing configurations are unchanged. A relay enforcing reject_non_fqdn_helo_hostname or reject_unknown_helo_hostname refuses the default greeting, and the verification message never leaves.

Verification email delivery is now bound to the request context. TimeOut covered the connection setup only, so a server that accepted the connection and then stalled held the login request for as long as it liked. The send now ends when the request does. Sender implementations that do not offer SendContext keep working through the existing Send.

Also updates dependencies across the root, v2 and example modules, and sets explicit GITHUB_TOKEN permissions in the workflows.

Version 1.25.7

Avatar storage on GridFS destroyed data. Every Put created a new revision under the same filename, so old avatars accumulated, Remove deleted only the newest one and left the avatar readable, and ID could return a stale revision. Cleanup now removes only revisions older than the upload that just completed, so two concurrent uploads for the same user cannot delete each other's file.

Apple public keys are now cached rather than fetched on every login, refreshed when a token names an unknown key so rotation still works, and reused for up to 12 hours if the key service is unreachable. A non-2xx response or an empty key set is rejected instead of being cached as valid.

The post-auth redirect uses 303 instead of 307. Apple's form_post callback arrives as a POST, and a method-preserving redirect replayed it onto the target page, which a static file server answers with 405. This changes the status for the oauth1, oauth2 and verify providers as well.

Two documented parameters now work: session is honoured by the direct and verify providers, and aud is accepted alongside site on the verify confirmation request. Apple no longer forces a persistent cookie when a session-only login was requested. For the direct and verify providers any non-zero sess value now means session-only, where previously only sess=1 did.

The avatar route returns 404 when no avatar store is configured, instead of dereferencing a nil proxy.

Dependencies: go-pkgz/email v0.8.0 and go-pkgz/rest v1.24.0. CI moves to go 1.26 and golangci-lint v2.12.

Version 1.25.6

The GitHub provider can now derive the local user id from the immutable numeric account id instead of the mutable login. This is opt-in and off by default, since enabling it changes the id of every existing GitHub user. Separately, the OAuth1 and OAuth2 callbacks no longer skip the user info HTTP status check, which previously let an error response map every failed login onto one shared user id.

Changes since v1.25.5

  • #301 opt-in github numeric user id, reject non-2xx user info
  • #298 bump golang.org/x/image from 0.39.0 to 0.41.0

Full Changelog: go-pkgz/auth@v1.25.5...v1.25.6

Version 1.25.5

Changes since v1.25.4

  • #293 redact sensitive auth logging
  • #292 package-wide comment sweep
  • #291 fix misleading and stale docstrings around the security fix

Full Changelog: go-pkgz/auth@v1.25.4...v1.25.5

Version 1.25.4

Security: fixes stored XSS in avatar.Proxy by rejecting non-image avatar content before storage and before serving. Also adds CSP/nosniff headers, WebP-safe validation, ETag parsing fixes, and decompression-bomb checks. Credit to @​paskal.

... (truncated)

Commits
  • 5f6d12c fix: remove the data race and the order dependence in the telegram tests
  • d9c7fd3 Make the Telegram API base URL configurable, and close what that opens (#316)
  • 5653bd4 fix: stop TestApplePublicKey_Fetch flaking on a shared port
  • 28916b2 add revmux review profile for the repo
  • a1079c6 Cover the cookie attributes from Opts, and assert the avatar path instead of ...
  • a5f6c25 Allow setting the SMTP HELO/EHLO hostname on the email sender (#313)
  • 594a1de Bump dependencies in root, v2 and example modules (#312)
  • 23c3979 Bound verification email delivery to the request context (#310)
  • e439012 chore: ignore the _example build artifact
  • 40d4c2e chore: tidy the example module after the dependency bump
  • Additional commits viewable in compare view

Updates github.com/shirou/gopsutil/v3 from 3.24.1 to 3.24.5

Release notes

Sourced from github.com/shirou/gopsutil/v3's releases.

v3.24.5

What's Changed

cpu

process

Other Changes

New Contributors

Full Changelog: shirou/gopsutil@v3.24.4...v3.24.5

v3.24.4

What's Changed

net

New Contributors

Full Changelog: shirou/gopsutil@v3.24.3...v3.24.4

v3.24.3

What's Changed

disk

host

load

process

New Contributors

... (truncated)

Commits
  • 4336530 Merge pull request #1649 from shirou/feat/add_process_cwd_openbsd
  • cb52f7a Merge pull request #1651 from Dylan-M/aix_support
  • 125da53 Update the README charts with the AIX information
  • ff4ae36 Remove extraneous development note comments
  • df9c9bf Update min version in the readme to match new required min version.
  • 1d7b4a3 Revert accidental change of go version in go.mod (wasn't supposed to commit).
  • 9bf502f Fix logic errors, syntax errors, and typos
  • b133d60 Ignore host_aix_ppc64 for now
  • b4d95a4 Raise minimum go version to 1.18 (required by changes) and run go mod tidy
  • 0917790 Remove inappropriate package addition
  • Additional commits viewable in compare view

Updates golang.org/x/net from 0.56.0 to 0.57.0

Commits
  • b8f09f6 go.mod: update golang.org/x dependencies
  • f05f21b idna: reject all-ASCII xn-- labels on all Go versions
  • 0f748cf internal/http3: clean up stream I/O methods usages in tests
  • 0bb961e internal/http3: add net/http.ResponseController support
  • 0ca694d webdav: document Dir's lack of defense against filesystem modification
  • bd5f1dc http2: initialize Transport on NewClientConn
  • 488ff63 bpf: add security considerations to package docs
  • 93d1f25 xsrftoken: avoid token collisions
  • 5a3baee internal/http3: prevent panic in QPACK decoder due to overflow
  • See full diff in compare view

Updates golang.org/x/sync from 0.21.0 to 0.22.0

Commits

Updates golang.org/x/term from 0.44.0 to 0.45.0

Commits

Updates modernc.org/sqlite from 1.28.0 to 1.59.0

Changelog

Sourced from modernc.org/sqlite's changelog.

Changelog

Entries for v1.38.1 through v1.44.1 and for v1.49.1 were added on 2026-09-05, reconstructed from the git history and the merge requests they cite; they were missing at release time.

  • 2026-09-15 v1.59.1:

    • make vendor now writes vendor.json: the modernc.org/libsqlite3 and modernc.org/libsqlite_vec commits and the Go toolchain lib/ and vec/ were vendored with, so git show vX.Y.Z:vendor.json says which revisions a release carries. It refuses a dirty sibling checkout, siblings on different modernc.org/libc versions, or a libsqlite_vec built against another libsqlite3. The suite fails when lib/, vec/ or the libc in go.mod no longer match the stamp, so a libc bump goes in the same push as make vendor. Tooling only; the vendored code is unchanged. See [GitLab merge request #140](https://gitlab.com/cznic/sqlite/-/merge_requests/140).
    • vfs.FS.Close now refuses while a database opened through it is still open, returning an error that wraps the new vfs.ErrInUse and leaving the VFS registered. It used to free the VFS the open connection still called through, so the next query crashed the process or read through freed memory. Close the databases first, then the FS.
    • Fix handle reuse in modernc.org/sqlite/vfs on 32-bit targets: after 2^32 file opens in one process the handle counter wrapped and could overwrite a live entry, such as a file system registered at start-up, and crash. 64-bit targets were not affected.
    • The pluggable page cache now panics when a Cache breaks its contract by returning nil, or a different Page, from Fetch for a page SQLite still holds pinned. It used to free memory SQLite was still using, corrupting the database without an error. Only a Cache implementation with that bug is affected; modernc.org/sqlite/pcache is not.
    • Document three limits of the pluggable page cache: a program importing modernc.org/sqlite/vec cannot call RegisterPageCache (it fails with SQLITE_MISUSE), PageCache.Create may be called concurrently, and under cache=shared a Cache is called from several goroutines, serialized by SQLite, so it wants a mutex of its own to run clean under -race. Documentation only.
    • Document two properties of connections in the package documentation: state set on a pooled connection -- PRAGMAs set with Exec, ATTACHed databases, temporary tables, anything registered through sql.Conn.Raw -- is inherited by the next caller to borrow it, and a driver connection reached through Raw is not safe for concurrent use even though every connection is opened SQLITE_OPEN_FULLMUTEX. Documentation only.
    • Add StrictPragmas, opt-in and off by default: once enabled, a connection whose _pragma DSN value holds more than one SQL statement fails to open with ErrMultiStatementPragma, before any DSN parameter is applied. A _pragma value runs as SQL text, so _pragma=foreign_keys(1);ATTACH 'x.db' AS x also attaches, and creates, x.db; the Driver.Open documentation said "a PRAGMA statement" and now says what actually happens. Enabling it is recommended for any application whose DSN is not a compile-time constant.
    • Document SQLite's own URI query parameters on Driver.Open: mode, cache, immutable, nolock, psow and modeof. Every connection is opened with SQLITE_OPEN_URI, so in a DSN starting with file: these have always worked; only the driver's own keys were listed. The docstring also spells out the trap that a plain file name has its query stripped before SQLite sees it, so /path/to.db?mode=ro opens read-write. Documentation only.
    • Resolves [GitLab issue #257](https://gitlab.com/cznic/sqlite/-/issues/257).
    • Add IRP.md, an incident response plan: who runs a response when there are two maintainers in different time zones, how a report is scoped across the three layers this module is built from, the fix path for each, and what to do when a released version is itself the problem -- a published Go module version cannot be recalled, so retract plus a new release is the remedy. Linked from SECURITY.md. Documentation only.
    • Add CONTRIBUTING.md: where to send a merge request, which files are generated and must not be edited by hand, how to build and test across the 20 supported targets, and the AUTHORS/CONTRIBUTORS convention. Contribution guidance previously existed only in GOVERNANCE.md and HACKING.md, neither of which a first-time contributor is likely to open. Documentation only.
    • Add SECURITY.md: report a vulnerability through GitHub private vulnerability reporting, a confidential GitLab issue, or the project's Service Desk address, never a public issue. It states what is in scope -- including transpilation faults, where the generated Go does not faithfully implement the C it came from -- that only the latest release is supported, and that a confirmed report is disclosed through a GitHub advisory, an entry in the Go vulnerability database so govulncheck reports it, and a release note. Documentation only.
    • Ship a Software Bill of Materials: sbom.cdx.json (CycloneDX 1.6) and sbom.spdx.json (SPDX 2.3), both validated against the published schemas, with SBOM.md explaining what they cover. They name what an SBOM built from the module graph cannot see -- the transpiled SQLite 3.53.4 and sqlite-vec C, and the upstreams modernc.org/libc vendors, musl among them -- and mark every component as linked into your binary, test-only, or compiled into nothing. Documentation only.
    • Ship LICENSE-3RD-PARTY.md, a transitively flattened inventory of every third-party component this module carries: the whole Go module graph, the transpiled SQLite and sqlite-vec C that no go.mod names, and the upstreams modernc.org/libc carries in turn, musl among them. It reproduces all seventeen distinct license texts in full and separates what is linked into your binary from what only appears in the module graph. The LICENSE name prefix is what makes go mod vendor carry it into downstream vendor/ trees. Documentation only.
  • 2026-09-15 v1.59.0:

    • Bump the pinned modernc.org/libc to v1.75.7 and re-vendor lib/ and vec/. The transpiled SQLite is unchanged, still 3.53.4. On the Linux targets the new libc replaces transpiled musl memcpy, memmove, memset, memcmp and strlen with native Go, cutting CPU time on query-heavy workloads by up to a third; see the new Performance section below. As always, downstream go.mod files must pin the same modernc.org/libc version this repository's go.mod does; see [GitLab issue #177](https://gitlab.com/cznic/sqlite/-/issues/177).
    • Hand user-defined function and aggregate callbacks a pooled *FunctionContext instead of allocating a fresh one per call, removing the last driver-side allocation per invocation. Like the argument slice, it is valid only for the duration of the callback and must not be retained past its return. Updates [GitLab issue #226](https://gitlab.com/cznic/sqlite/-/issues/226). See [GitLab merge request #137](https://gitlab.com/cznic/sqlite/-/merge_requests/137).
    • Add regression tests pinning the identity and the pooling of that context. See [GitLab merge request #138](https://gitlab.com/cznic/sqlite/-/merge_requests/138), thanks Ian Chechin!
    • Add a Performance section to the package documentation: measured CPU-time ratios of this driver against the same SQLite compiled from C, where the gap comes from, and the two consequences for applications — index the columns that ORDER BY, GROUP BY and WHERE use, and bound the database/sql pool with SetMaxOpenConns.
  • 2026-09-01 v1.58.0:

    • Upgrade to SQLite 3.53.4. It carries upstream's own fix for the journal-rollback data-corruption bug, so the local super-journal patch v1.56.0 introduced is dropped; recovery behavior is unchanged. Also bumps the pinned modernc.org/libc to v1.75.6; as always, downstream modules must pin the same version this one does, see [GitLab issue #177](https://gitlab.com/cznic/sqlite/-/issues/177).
    • Add opt-in support for Linux Open File Description (OFD) locks on database files, off by default; without opting in, locking behavior is byte-for-byte that of previous releases. A POSIX record lock is owned by the (process, inode) pair, so any Close of any descriptor of the database file anywhere in the process silently strips SQLite's locks; OFD locks survive that. Enable it process-wide with MODERNC_SQLITE_OFD_LOCK=1 in the environment, or with the new OFDLocking(true) before the first connection is opened; OFDLockingEnabled reports the mode in effect, and the new ErrOFDLockingTooLate and ErrOFDLockingUnavailable report a switch attempted too late and a platform or filesystem without the feature. Why it is process-wide rather than a DSN parameter, what WAL's -shm coordination still uses, and the /proc/locks measurements behind the design are in [GitLab issue #255](https://gitlab.com/cznic/sqlite/-/issues/255).
    • Resolves [GitLab issue #255](https://gitlab.com/cznic/sqlite/-/issues/255). See [GitLab merge request #136](https://gitlab.com/cznic/sqlite/-/merge_requests/136), thanks Nathan Herring (@​technosloth), and thanks Gani Georgiev (@​ganigeorgiev) for pressing the opt-in default!
  • 2026-08-19 v1.57.0:

    • Add an opt-in _defensive DSN query parameter turning on SQLite's defensive mode for the connection. On such a connection PRAGMA writable_schema=ON, PRAGMA journal_mode=OFF and PRAGMA schema_version=N become silent no-ops, and writes to a virtual table's shadow tables and to sqlite_dbpage fail. It is a hardening measure, not a sandbox for hostile database files, for which it is only one of the steps SQLite recommends, and it is a property of the connection, not of the file. Absent, or _defensive=0, nothing changes.
    • Reject _defensive=1 together with _journal_mode=OFF (or _journal=OFF) instead of opening a connection in which neither was honoured: SQLite turns that PRAGMA into a no-op that still reports success. Only DSNs using the new parameter can be affected. See [GitHub pull request #6](modernc-org/sqlite#6), thanks wsman!
    • Ship the sqlite-vec license notice this module has been missing since vec/ arrived in v1.47.0. sqlite-vec is Copyright (c) 2024 Alex Garcia, dual-licensed Apache-2.0 OR MIT and used here under MIT; the text now ships as LICENSE-SQLITE_VEC, and make vendor fails rather than quietly dropping it.
    • The SQLite notice is renamed from SQLITE-LICENSE to LICENSE-SQLITE; update any direct links to it. Its contents are unchanged. The rename is what makes go mod vendor carry both notices into downstream vendor/ trees: it selects license files by name prefix, so a name merely ending in LICENSE was never propagated.
    • Let a caller-constructed Driver register its own functions, collations and virtual table modules, through new RegisterFunction, RegisterScalarFunction, RegisterDeterministicScalarFunction, RegisterCollationUtf8 and RegisterModule methods plus Must* variants, and let vtab.RegisterModule honour its db argument. Behavior change: vtab.RegisterModule(db, ...) where db was opened on a caller-constructed Driver used to discard db and land on the registered sqlite driver, reaching every connection in the process; it now lands on that Driver alone, so a sql.Open("sqlite") connection that used to resolve such a module gets no such module. Everything else is additive, and the isolating change discussed in [GitLab issue #254](https://gitlab.com/cznic/sqlite/-/issues/254) is deliberately not made here. See [GitLab merge request #135](https://gitlab.com/cznic/sqlite/-/merge_requests/135), thanks Ian Chechin!
    • Promote freebsd/386, freebsd/arm and netbsd/amd64 from experimental to fully supported. The package documentation's platform table had carried seventeen entries while this module shipped, cross-built and tested twenty; all three have been in the builder matrix since v1.53.0 and pass the full suite on this release's commit. Documentation only — lib/ is byte-for-byte what v1.56.0 shipped.
  • 2026-08-03 v1.56.0:

    • Re-vendor the transpiled sources, picking up modernc.org/libsqlite3's patch for an upstream data-corruption bug in SQLite 3.53.3's journal rollbackDescription has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 20, 2026
@SamsonNegedu
SamsonNegedu force-pushed the main branch 2 times, most recently from a7b01b2 to 1cfd282 Compare September 20, 2026 01:33
@dependabot dependabot Bot changed the title Bump the go-minor-and-patch group with 8 updates Bump the go-minor-and-patch group across 1 directory with 8 updates Sep 20, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/go-minor-and-patch-6a81fec19d branch from 64ee0a2 to ec9b38e Compare September 20, 2026 01:36
@SamsonNegedu
SamsonNegedu force-pushed the main branch 4 times, most recently from 0d81a28 to 83db0c2 Compare September 20, 2026 10:02
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/go-minor-and-patch-6a81fec19d branch from ec9b38e to 4bab4d3 Compare September 20, 2026 14:43
Bumps the go-minor-and-patch group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/compose-spec/compose-go/v2](https://github.com/compose-spec/compose-go) | `2.10.1` | `2.15.0` |
| [github.com/gin-gonic/gin](https://github.com/gin-gonic/gin) | `1.9.1` | `1.12.0` |
| [github.com/go-pkgz/auth](https://github.com/go-pkgz/auth) | `1.25.2` | `1.27.0` |
| [github.com/shirou/gopsutil/v3](https://github.com/shirou/gopsutil) | `3.24.1` | `3.24.5` |
| [golang.org/x/net](https://github.com/golang/net) | `0.56.0` | `0.57.0` |
| [golang.org/x/sync](https://github.com/golang/sync) | `0.21.0` | `0.22.0` |
| [golang.org/x/term](https://github.com/golang/term) | `0.44.0` | `0.45.0` |
| [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) | `1.28.0` | `1.59.0` |



Updates `github.com/compose-spec/compose-go/v2` from 2.10.1 to 2.15.0
- [Release notes](https://github.com/compose-spec/compose-go/releases)
- [Commits](compose-spec/compose-go@v2.10.1...v2.15.0)

Updates `github.com/gin-gonic/gin` from 1.9.1 to 1.12.0
- [Release notes](https://github.com/gin-gonic/gin/releases)
- [Changelog](https://github.com/gin-gonic/gin/blob/master/CHANGELOG.md)
- [Commits](gin-gonic/gin@v1.9.1...v1.12.0)

Updates `github.com/go-pkgz/auth` from 1.25.2 to 1.27.0
- [Release notes](https://github.com/go-pkgz/auth/releases)
- [Commits](go-pkgz/auth@v1.25.2...v1.27.0)

Updates `github.com/shirou/gopsutil/v3` from 3.24.1 to 3.24.5
- [Release notes](https://github.com/shirou/gopsutil/releases)
- [Commits](shirou/gopsutil@v3.24.1...v3.24.5)

Updates `golang.org/x/net` from 0.56.0 to 0.57.0
- [Commits](golang/net@v0.56.0...v0.57.0)

Updates `golang.org/x/sync` from 0.21.0 to 0.22.0
- [Commits](golang/sync@v0.21.0...v0.22.0)

Updates `golang.org/x/term` from 0.44.0 to 0.45.0
- [Commits](golang/term@v0.44.0...v0.45.0)

Updates `modernc.org/sqlite` from 1.28.0 to 1.59.0
- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)
- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.28.0...v1.59.0)

---
updated-dependencies:
- dependency-name: github.com/compose-spec/compose-go/v2
  dependency-version: 2.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: github.com/gin-gonic/gin
  dependency-version: 1.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: github.com/go-pkgz/auth
  dependency-version: 1.27.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: github.com/shirou/gopsutil/v3
  dependency-version: 3.24.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/net
  dependency-version: 0.57.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/sync
  dependency-version: 0.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/term
  dependency-version: 0.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: modernc.org/sqlite
  dependency-version: 1.59.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/go-minor-and-patch-6a81fec19d branch from 4bab4d3 to afb9d9e Compare September 27, 2026 14:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants