Skip to content

Bump the go-minor-and-patch group across 1 directory with 8 updates - #8

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-minor-and-patch-6a81fec19d
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-minor-and-patch-6a81fec19d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the go-minor-and-patch group with 8 updates in the / directory:

Package From To
github.com/compose-spec/compose-go/v2 2.10.1 2.16.1
github.com/gin-gonic/gin 1.9.1 1.12.0
github.com/go-pkgz/auth 1.25.2 1.27.0
github.com/shirou/gopsutil/v3 3.24.1 3.24.5
golang.org/x/net 0.56.0 0.57.0
golang.org/x/sync 0.21.0 0.22.0
golang.org/x/term 0.44.0 0.45.0
modernc.org/sqlite 1.28.0 1.60.1

Updates github.com/compose-spec/compose-go/v2 from 2.10.1 to 2.16.1

Release notes

Sourced from github.com/compose-spec/compose-go/v2's releases.

v2.16.1

What's Changed

Full Changelog: compose-spec/compose-go@v2.16.0...v2.16.1

v2.16.0

⚠️ Breaking change (Go API)

types.ServiceConfig now embeds types.ContainerSpec and types.WorkloadSpec, shared with the new jobs element and pre_start init containers. Field access is unchanged (svc.Image), but struct literals must now set moved fields through the embedded structs, and code walking ServiceConfig with reflection will see these two embedded structs instead of a flat list of fields:

types.ServiceConfig{Name: "web", ContainerSpec: types.ContainerSpec{Image: "nginx"}}

ServiceConfig.PreStart is now a []types.PreStartHook (was []types.ServiceHook), which embeds a full ContainerSpec; Image and PerReplica are no longer fields of ServiceHook.

The order of keys in the YAML and JSON produced for a service also changes (service-level keys first, then container-level, then workload-level ones). The content is the same, but expected files compared as text need to be regenerated.

What's Changed

New Contributors

Full Changelog: compose-spec/compose-go@v2.15.0...v2.16.0

v2.15.0

What's Changed

... (truncated)

Commits
  • 32d8d5d override: share the by-key compaction and reject null ipam config items
  • 7ed4d72 override: pin the merge of KEY=VALUE entries that are not interpolated
  • be0aa2f override: compact repeated keys and keep empty lists in KEY=VALUE merge
  • 398bcb3 override: merge KEY=VALUE lists by key so the last entry wins
  • 832c7b5 override: accept a null value when merging a list or mapping attribute
  • 6ec8efb lint: fix gocritic, gofumpt and govet issues
  • 98fd653 loader: reuse deepClone instead of duplicating it as cloneYaml
  • e93a134 loader: merge an extension into the attribute it stands for
  • f33989c loader: pin promotion of extensions before extends merges services
  • 732bdd9 loader: apply !reset and !override to the attribute an extension stands for
  • Additional commits viewable in compare view

Updates github.com/gin-gonic/gin from 1.9.1 to 1.12.0

Release notes

Sourced from github.com/gin-gonic/gin's releases.

v1.12.0

Changelog

Features

  • 192ac89eefc1c30f7c97ae48a9ffb1c6f1c8c8bc: feat(binding): add support for encoding.UnmarshalText in uri/query binding (#4203) (@​takanuva15)
  • 53410d2e07054369e0960fbe2eed97e1b9966f12: feat(context): add GetError and GetErrorSlice methods for error retrieval (#4502) (@​raju-mechatronics)
  • acc55e049e33b401e810dbd8c0d6dcb6b3ba2b05: feat(context): add Protocol Buffers support to content negotiation (#4423) (@​1911860538)
  • 38e765119241d990705169bedb5002a29ae0cbd1: feat(context): implemented Delete method (@​Spyder01)
  • 771dcc6476d7bc6abb9ec0235ecefa4d38fe6fb0: feat(gin): add option to use escaped path (#4420) (@​ldesauw)
  • 4dec17afdff48e8018c83618fbbe69fceeb2b41d: feat(logger): color latency (#4146) (@​wsyqn6)
  • d7776de7d444935ea4385999711bd6331a98fecb: feat(render): add bson protocol (#4145) (@​laurentcau)

Bug fixes

  • b917b14ff9d189f16a7492be79d123a47806ee19: fix(binding): empty value error (#2169) (@​guonaihong)
  • c3d1092b3b48addf6f9cd00fe274ec3bd14650eb: fix(binding): improve empty slice/array handling in form binding (#4380) (@​1911860538)
  • 9914178584e42458ff7d23891463a880f58c9d86: fix(context): ClientIP handling for multiple X-Forwarded-For header values (#4472) (@​Nurysso)
  • 2a794cd0b0faa7d829291375b27a3467ea972b0d: fix(debug): version mismatch (#4403) (@​zeek0x)
  • c3d5a28ed6d3849da820195b6774d212bcc038a9: fix(gin): close os.File in RunFd to prevent resource leak (#4422) (@​1911860538)
  • 5fad976b372e381312f8de69f0969f1284d229d3: fix(gin): literal colon routes not working with engine.Handler() (#4415) (@​pawannn)
  • 63dd3e60cab89c27fb66bce1423bd268d52abad1: fix(recover): suppress http.ErrAbortHandler in recover (#4336) (@​MondayCha)
  • 5c00df8afadd06cc5be530dde00fe6d9fa4a2e4a: fix(render): write content length in Data.Render (#4206) (@​dengaleev)
  • 234a6d4c00cb77af9852aca0b8289745d5529b4b: fix(response): refine hijack behavior for response lifecycle (#4373) (@​appleboy)
  • 472d086af2acd924cb4b9d7be0525f7d790f69bc: fix(tree): panic in findCaseInsensitivePathRec with RedirectFixedPath (#4535) (@​veeceey)
  • 8e07d37c63e5536eb25f4af4c91eabeee4011fba: fix: Correct typos, improve documentation clarity, and remove dead code (#4511) (@​mahanadh)

Enhancements

  • ba093d19477b896ac89a7fc3246af23d290b8e26: chore(binding): upgrade bson dependency to mongo-driver v2 (#4549) (@​BobDu)
  • b2b489dbf4826c2c630717a77fd5e42774625410: chore(context): always trust xff headers from unix socket (#3359) (@​WeidiDeng)
  • ecb3f7b5e2f3915bf1db240ed5eee572f8dbea36: chore(deps): upgrade golang.org/x/crypto to v0.45.0 (#4449) (@​appleboy)
  • af6e8b70b8261bb0c99ad094fe552ab92991620a: chore(deps): upgrade quic-go to v0.57.1 (@​appleboy)
  • db309081bc5c137b2aa15701ef53f7f19788da25: chore(logger): allow skipping query string output (#4547) (@​USA-RedDragon)
  • 26c3a628655cad2388380cb8102d6ce7d4875f3b: chore(response): prevent Flush() panic when http.Flusher (#4479) (@​Twacqwq)
  • 5dd833f1f26de0eb30eae47b17e05ced2482dc41: chore: bump minimum Go version to 1.24 and update workflows (#4388) (@​appleboy)

Refactor

  • 39858a0859c914bd26948fa950477e11bd8d3823: refactor(binding): use maps.Copy for cleaner map handling (#4352) (@​russcoss)
  • c0048f645ee945c4db30593afdea10123e2c30a6: refactor(context): omit the return value names (#4395) (@​wanghaolong613)
  • 915e4c90d28ec4cffc6eb146e208ab5a65eac772: refactor(context): replace hardcoded localhost IPs with constants (#4481) (@​pauloappbr)
  • 414de60574449457f3192a7a1d5528940db2836d: refactor(context): using maps.Clone (#4333) (@​cuiweixie)
  • 59e9d4a794f12c4f9a6c7bed441b9644e5f6d99b: refactor(ginS): use sync.OnceValue to simplify engine function (#4314) (@​1911860538)
  • 3ab698dc5110af1977d57226e4995c57dd34c233: refactor(recovery): smart error comparison (#4142) (@​zeek0x)
  • d1a15347b1e45a8ee816193d3578a93bfd73b70f: refactor(utils): move util functions to utils.go (#4467) (@​zeek0x)
  • e3118cc378d263454098924ebbde7e8d1dd2e904: refactor: for loop can be modernized using range over int (#4392) (@​wanghaolong613)
  • 488f8c3ffa579a8d19beb2bae95ff8ef36b3d53f: refactor: replace magic numbers with named constants in bodyAllowedForStatus (#4529) (@​veeceey)
  • 9968c4bf9d5a99edc3eee2c068a4c9160ece8915: refactor: use b.Loop() to simplify the code and improve performance (#4389) (@​reddaisyy)
  • a85ef5ce4d0cda8834c59c855068ed48b51192d1: refactor: use b.Loop() to simplify the code and improve performance (#4432) (@​efcking)

Build process updates

  • 61b67de522a189b568aced4c5c16917c558e3387: ci(bot): increase frequency and group updates for dependencies (#4367) (@​appleboy)
  • fb27ef26c2fdfe25344b4c039d8a53551f9e912c: ci(lint): refactor test assertions and linter configuration (#4436) (@​appleboy)
  • 93ff771e6dbf10e432864b30f3719ac5c84a4d4a: ci(sec): improve type safety and server organization in HTTP middleware (#4437) (@​appleboy)
  • e88fc8927a52b74f55bec0351604a56ac0aa1c51: ci(sec): schedule Trivy security scans to run daily at midnight UTC (#4439) (@​appleboy)
  • 5e5ff3ace496a31b138b0820136a146bfb5de0ef: ci: replace vulnerability scanning workflow with Trivy integration (#4421) (@​appleboy)
  • 00900fb3e1ea9dde33985a0e4f6afec793d5e786: ci: update CI workflows and standardize Trivy config quotes (#4531) (@​appleboy)
  • ae3f524974fc4f55d18c9e7fae4614503c015226: ci: update Go version support to 1.25+ across CI and docs (#4550) (@​appleboy)

... (truncated)

Changelog

Sourced from github.com/gin-gonic/gin's changelog.

Gin v1.12.0

Features

  • feat(render): add bson protocol (#4145)
  • feat(context): add GetError and GetErrorSlice methods for error retrieval (#4502)
  • feat(binding): add support for encoding.UnmarshalText in uri/query binding (#4203)
  • feat(gin): add option to use escaped path (#4420)
  • feat(context): add Protocol Buffers support to content negotiation (#4423)
  • feat(context): implemented Delete method (#38e7651)
  • feat(logger): color latency (#4146)

Enhancements

  • perf(tree): reduce allocations in findCaseInsensitivePath (#4417)
  • perf(recovery): optimize line reading in stack function (#4466)
  • perf(path): replace regex with custom functions in redirectTrailingSlash (#4414)
  • perf(tree): optimize path parsing using strings.Count (#4246)
  • chore(logger): allow skipping query string output (#4547)
  • chore(context): always trust xff headers from unix socket (#3359)
  • chore(response): prevent Flush() panic when the underlying ResponseWriter does not implement http.Flusher (#4479)
  • refactor(recovery): smart error comparison (#4142)
  • refactor(context): replace hardcoded localhost IPs with constants (#4481)
  • refactor(utils): move util functions to utils.go (#4467)
  • refactor(binding): use maps.Copy for cleaner map handling (#4352)
  • refactor(context): using maps.Clone (#4333)
  • refactor(ginS): use sync.OnceValue to simplify engine function (#4314)
  • refactor: replace magic numbers with named constants in bodyAllowedForStatus (#4529)
  • refactor: for loop can be modernized using range over int (#4392)

Bug Fixes

  • fix(tree): panic in findCaseInsensitivePathRec with RedirectFixedPath (#4535)
  • fix(render): write content length in Data.Render (#4206)
  • fix(context): ClientIP handling for multiple X-Forwarded-For header values (#4472)
  • fix(binding): empty value error (#2169)
  • fix(recover): suppress http.ErrAbortHandler in recover (#4336)
  • fix(gin): literal colon routes not working with engine.Handler() (#4415)
  • fix(gin): close os.File in RunFd to prevent resource leak (#4422)
  • fix(response): refine hijack behavior for response lifecycle (#4373)
  • fix(binding): improve empty slice/array handling in form binding (#4380)
  • fix(debug): version mismatch (#4403)
  • fix: correct typos, improve documentation clarity, and remove dead code (#4511)

Build process updates / CI

  • ci: update Go version support to 1.25+ across CI and docs (#4550)
  • chore(binding): upgrade bson dependency to mongo-driver v2 (#4549)

Gin v1.11.0

... (truncated)

Commits
  • 73726dc docs: update documentation to reflect Go version changes (#4552)
  • e292e5c docs: document and finalize Gin v1.12.0 release (#4551)
  • ae3f524 ci: update Go version support to 1.25+ across CI and docs (#4550)
  • 38534e2 chore(deps): bump golang.org/x/net from 0.50.0 to 0.51.0 (#4548)
  • 472d086 fix(tree): panic in findCaseInsensitivePathRec with RedirectFixedPath (#4535)
  • fb25834 test(context): use http.StatusContinue constant instead of magic number 100 (...
  • 6f1d5fe test(render): add comprehensive error handling tests (#4541)
  • 5c00df8 fix(render): write content length in Data.Render (#4206)
  • db30908 chore(logger): allow skipping query string output (#4547)
  • ba093d1 chore(binding): upgrade bson dependency to mongo-driver v2 (#4549)
  • Additional commits viewable in compare view

Updates github.com/go-pkgz/auth from 1.25.2 to 1.27.0

Release notes

Sourced from github.com/go-pkgz/auth's releases.

Version 1.27.0

The Telegram provider no longer hard-codes https://api.telegram.org. NewTelegramAPIWithBaseURL takes the base, and every request goes through it, avatar downloads included. An empty base falls back to the public API.

Moving a token-bearing URL off a constant is what the rest of the change is for: the bot token travels in the request path, and the answers now come from a host the library does not control. The base is validated, error text is scrubbed of the token in raw and encoded forms, a success response has to match Telegram's own username shape, and redirects are refused by default because Go copies the previous URL into Referer.

One behaviour change. A caller that relied on the default redirect policy now gets an error on a redirect. A caller-supplied CheckRedirect remains in force.

Also in this release: the Apple public-key test no longer binds a shared port, and the Telegram tests no longer race or depend on order.

Full detail in #316.

Version 1.26.0

EmailParams gains HELOHost, which sets the hostname the sender announces in the SMTP greeting. Left empty it stays localhost, so existing configurations are unchanged. A relay enforcing reject_non_fqdn_helo_hostname or reject_unknown_helo_hostname refuses the default greeting, and the verification message never leaves.

Verification email delivery is now bound to the request context. TimeOut covered the connection setup only, so a server that accepted the connection and then stalled held the login request for as long as it liked. The send now ends when the request does. Sender implementations that do not offer SendContext keep working through the existing Send.

Also updates dependencies across the root, v2 and example modules, and sets explicit GITHUB_TOKEN permissions in the workflows.

Version 1.25.7

Avatar storage on GridFS destroyed data. Every Put created a new revision under the same filename, so old avatars accumulated, Remove deleted only the newest one and left the avatar readable, and ID could return a stale revision. Cleanup now removes only revisions older than the upload that just completed, so two concurrent uploads for the same user cannot delete each other's file.

Apple public keys are now cached rather than fetched on every login, refreshed when a token names an unknown key so rotation still works, and reused for up to 12 hours if the key service is unreachable. A non-2xx response or an empty key set is rejected instead of being cached as valid.

The post-auth redirect uses 303 instead of 307. Apple's form_post callback arrives as a POST, and a method-preserving redirect replayed it onto the target page, which a static file server answers with 405. This changes the status for the oauth1, oauth2 and verify providers as well.

Two documented parameters now work: session is honoured by the direct and verify providers, and aud is accepted alongside site on the verify confirmation request. Apple no longer forces a persistent cookie when a session-only login was requested. For the direct and verify providers any non-zero sess value now means session-only, where previously only sess=1 did.

The avatar route returns 404 when no avatar store is configured, instead of dereferencing a nil proxy.

Dependencies: go-pkgz/email v0.8.0 and go-pkgz/rest v1.24.0. CI moves to go 1.26 and golangci-lint v2.12.

Version 1.25.6

The GitHub provider can now derive the local user id from the immutable numeric account id instead of the mutable login. This is opt-in and off by default, since enabling it changes the id of every existing GitHub user. Separately, the OAuth1 and OAuth2 callbacks no longer skip the user info HTTP status check, which previously let an error response map every failed login onto one shared user id.

Changes since v1.25.5

  • #301 opt-in github numeric user id, reject non-2xx user info
  • #298 bump golang.org/x/image from 0.39.0 to 0.41.0

Full Changelog: go-pkgz/auth@v1.25.5...v1.25.6

Version 1.25.5

Changes since v1.25.4

  • #293 redact sensitive auth logging
  • #292 package-wide comment sweep
  • #291 fix misleading and stale docstrings around the security fix

Full Changelog: go-pkgz/auth@v1.25.4...v1.25.5

Version 1.25.4

Security: fixes stored XSS in avatar.Proxy by rejecting non-image avatar content before storage and before serving. Also adds CSP/nosniff headers, WebP-safe validation, ETag parsing fixes, and decompression-bomb checks. Credit to @​paskal.

... (truncated)

Commits
  • 5f6d12c fix: remove the data race and the order dependence in the telegram tests
  • d9c7fd3 Make the Telegram API base URL configurable, and close what that opens (#316)
  • 5653bd4 fix: stop TestApplePublicKey_Fetch flaking on a shared port
  • 28916b2 add revmux review profile for the repo
  • a1079c6 Cover the cookie attributes from Opts, and assert the avatar path instead of ...
  • a5f6c25 Allow setting the SMTP HELO/EHLO hostname on the email sender (#313)
  • 594a1de Bump dependencies in root, v2 and example modules (#312)
  • 23c3979 Bound verification email delivery to the request context (#310)
  • e439012 chore: ignore the _example build artifact
  • 40d4c2e chore: tidy the example module after the dependency bump
  • Additional commits viewable in compare view

Updates github.com/shirou/gopsutil/v3 from 3.24.1 to 3.24.5

Release notes

Sourced from github.com/shirou/gopsutil/v3's releases.

v3.24.5

What's Changed

cpu

process

Other Changes

New Contributors

Full Changelog: shirou/gopsutil@v3.24.4...v3.24.5

v3.24.4

What's Changed

net

New Contributors

Full Changelog: shirou/gopsutil@v3.24.3...v3.24.4

v3.24.3

What's Changed

disk

host

load

process

New Contributors

... (truncated)

Commits
  • 4336530 Merge pull request #1649 from shirou/feat/add_process_cwd_openbsd
  • cb52f7a Merge pull request #1651 from Dylan-M/aix_support
  • 125da53 Update the README charts with the AIX information
  • ff4ae36 Remove extraneous development note comments
  • df9c9bf Update min version in the readme to match new required min version.
  • 1d7b4a3 Revert accidental change of go version in go.mod (wasn't supposed to commit).
  • 9bf502f Fix logic errors, syntax errors, and typos
  • b133d60 Ignore host_aix_ppc64 for now
  • b4d95a4 Raise minimum go version to 1.18 (required by changes) and run go mod tidy
  • 0917790 Remove inappropriate package addition
  • Additional commits viewable in compare view

Updates golang.org/x/net from 0.56.0 to 0.57.0

Commits
  • b8f09f6 go.mod: update golang.org/x dependencies
  • f05f21b idna: reject all-ASCII xn-- labels on all Go versions
  • 0f748cf internal/http3: clean up stream I/O methods usages in tests
  • 0bb961e internal/http3: add net/http.ResponseController support
  • 0ca694d webdav: document Dir's lack of defense against filesystem modification
  • bd5f1dc http2: initialize Transport on NewClientConn
  • 488ff63 bpf: add security considerations to package docs
  • 93d1f25 xsrftoken: avoid token collisions
  • 5a3baee internal/http3: prevent panic in QPACK decoder due to overflow
  • See full diff in compare view

Updates golang.org/x/sync from 0.21.0 to 0.22.0

Commits

Updates golang.org/x/term from 0.44.0 to 0.45.0

Commits

Updates modernc.org/sqlite from 1.28.0 to 1.60.1

Changelog

Sourced from modernc.org/sqlite's changelog.

Changelog

Entries for v1.38.1 through v1.44.1 and for v1.49.1 were added on 2026-09-05, reconstructed from the git history and the merge requests they cite; they were missing at release time.

  • 2026-09-30 v1.61.0:

  • 2026-09-29 v1.60.1:

    • Binding arguments to a statement is no longer quadratic in the number of its parameters, which made multi-row INSERTs with thousands of ? parameters slow. Resolves [GitHub issue #8](modernc-org/sqlite#8), thanks wencycool!
  • 2026-09-28 v1.60.0:

    • A fault while reading the memory-mapped -shm file of a WAL database no longer crashes the process. The statement fails with a disk I/O error, extended code SQLITE_IOERR_IN_PAGE (8714), and the connection stays usable, as in MSVC builds of SQLite. On by default on every platform and not switchable; lib.SehInject and lib.SehPending inject such a fault for tests. Resolves [GitLab issue #221](https://gitlab.com/cznic/sqlite/-/issues/221), thanks Roman (@​requilence) for the report, and supersedes libsqlite3!4 and [GitHub pull request #7](modernc-org/sqlite#7), thanks hazyhaar for the two rounds, the ccgo finding and the Windows Server runs!
    • Re-vendor lib/ from modernc.org/libsqlite3 v1.15.0 and vec/ from modernc.org/libsqlite_vec v0.6.0; SQLite stays 3.53.4 and sqlite-vec v0.1.9. Go 1.26 is now required, and the pinned modernc.org/libc becomes v1.77.1; as always, downstream go.mod files must pin the same modernc.org/libc version this repository's go.mod does, see [GitLab issue #177](https://gitlab.com/cznic/sqlite/-/issues/177).
    • Nine exported lib constants that never had a meaningful value are gone: INFINITY, MB_CUR_MAX, NAN, RESERVED_BYTE, SHARED_FIRST, SQLITE_CANTOPEN_BKPT, SQLITE_CORRUPT_BKPT, SQLITE_DEFAULT_LOOKASIDE and SQLITE_MISUSE_BKPT. The transpiler now evaluates object-like macros as C expressions, so other constants take their C value (lib.WALINDEX_PGSZ is 32768, not 0) and some appear; the full list is in libsqlite3's CHANGELOG under 2026-09-19.
    • make vendor now writes vendor.json, the modernc.org/libsqlite3 and modernc.org/libsqlite_vec commits and the Go toolchain lib/ and vec/ were vendored with, so git show vX.Y.Z:vendor.json says which revisions a release carries; the test suite fails when they no longer match. Tooling only. See [GitLab merge request #140](https://gitlab.com/cznic/sqlite/-/merge_requests/140).
    • vfs.FS.Close now refuses while a database opened through it is still open, returning an error that wraps the new vfs.ErrInUse and leaving the VFS registered. It used to free the VFS the open connection still called through, so the next query crashed the process or read through freed memory. Close the databases first, then the FS.
    • Fix handle reuse in modernc.org/sqlite/vfs on 32-bit targets: after 2^32 file opens in one process the handle counter wrapped and could overwrite a live entry, such as a file system registered at start-up, and crash. 64-bit targets were not affected.
    • The pluggable page cache now panics when a Cache breaks its contract by returning nil, or a different Page, from Fetch for a page SQLite still holds pinned. It used to free memory SQLite was still using, corrupting the database without an error. Only a Cache implementation with that bug is affected; modernc.org/sqlite/pcache is not.
    • Document three limits of the pluggable page cache on RegisterPageCache and Cache: it cannot be combined with modernc.org/sqlite/vec, PageCache.Create may be called concurrently, and under cache=shared a Cache is called from several goroutines. Documentation only.
    • Document in the package documentation that state set on a pooled connection is inherited by the next caller to borrow it, and that a connection reached through sql.Conn.Raw is not safe for concurrent use. Documentation only.
    • Add StrictPragmas, opt-in and off by default: once enabled, a connection whose _pragma DSN value holds more than one SQL statement fails to open with ErrMultiStatementPragma, before any DSN parameter is applied. A _pragma value runs as SQL text, so anything after a ; runs too. Recommended for any application whose DSN is not a compile-time constant.
    • Document SQLite's own URI query parameters on Driver.Open: mode, cache, immutable, nolock, psow and modeof, which have always worked in a DSN starting with file:, and the trap that a plain file name has its query stripped before SQLite sees it, so /path/to.db?mode=ro opens read-write. Resolves [GitLab issue #257](https://gitlab.com/cznic/sqlite/-/issues/257). Documentation only.
    • Add SECURITY.md, the vulnerability reporting policy: three private channels, what is in scope, that only the latest release is supported, and how a confirmed report is disclosed, including an entry in the Go vulnerability database so govulncheck reports it. IRP.md, linked from it, is the maintainers' incident response plan. Documentation only.
    • Add CONTRIBUTING.md: where to send a merge request, which files are generated and must not be edited by hand, how to build and test across the 20 supported targets, and the AUTHORS/CONTRIBUTORS convention. Documentation only.
    • Ship LICENSE-3RD-PARTY.md, a transitively flattened inventory of every third-party component this module carries with all seventeen license texts in full, and a Software Bill of Materials, sbom.cdx.json (CycloneDX 1.6) and sbom.spdx.json (SPDX 2.3), explained in SBOM.md. Both cover what a module-graph tool cannot see: the transpiled SQLite and sqlite-vec C, and the upstreams modernc.org/libc carries, musl among them. Documentation only.
  • 2026-09-15 v1.59.0:

    • Bump the pinned modernc.org/libc to v1.75.7 and re-vendor lib/ and vec/. The transpiled SQLite is unchanged, still 3.53.4. On the Linux targets the new libc replaces transpiled musl memcpy, memmove, memset, memcmp and strlen with native Go, cutting CPU time on query-heavy workloads by up to a third; see the new Performance section below. As always, downstream go.mod files must pin the same modernc.org/libc version this repository's go.mod does; see [GitLab issue #177](https://gitlab.com/cznic/sqlite/-/issues/177).
    • Hand user-defined function and aggregate callbacks a pooled *FunctionContext instead of allocating a fresh one per call, removing the last driver-side allocation per invocation. Like the argument slice, it is valid only for the duration of the callback and must not be retained past its return. Updates [GitLab issue #226](https://gitlab.com/cznic/sqlite/-/issues/226). See [GitLab merge request #137](https://gitlab.com/cznic/sqlite/-/merge_requests/137).
    • Add regression tests pinning the identity and the pooling of that context. See [GitLab merge request #138](https://gitlab.com/cznic/sqlite/-/merge_requests/138), thanks Ian Chechin!
    • Add a Performance section to the package documentation: measured CPU-time ratios of this driver against the same SQLite compiled from C, where the gap comes from, and the two consequences for applications — index the columns that ORDER BY, GROUP BY and WHERE use, and bound the database/sql pool with SetMaxOpenConns.
  • 2026-09-01 v1.58.0:

    • Upgrade to SQLite 3.53.4. It carries upstream's own fix for the journal-rollback data-corruption bug, so the local super-journal patch v1.56.0 introduced is dropped; recovery behavior is unchanged. Also bumps the pinned modernc.org/libc to v1.75.6; as always, downstream modules must pin the same version this one does, see [GitLab issue #177](https://gitlab.com/cznic/sqlite/-/issues/177).
    • Add opt-in support for Linux Open File Description (OFD) locks on database files, off by default; without opting in, locking behavior is byte-for-byte that of previous releases. A POSIX record lock is owned by the (process, inode) pair, so any Close of any descriptor of the database file anywhere in the process silently strips SQLite's locks; OFD locks survive that. Enable it process-wide with MODERNC_SQLITE_OFD_LOCK=1 in the environment, or with the new OFDLocking(true) before the first connection is opened; OFDLockingEnabled reports the mode in effect, and the new ErrOFDLockingTooLate and ErrOFDLockingUnavailable report a switch attempted too late and a platform or filesystem without the feature. Why it is process-wide rather than a DSN parameter, what WAL's -shm coordination still uses, and the /proc/locks measurements behind the design are in [GitLab issue #255](https://gitlab.com/cznic/sqlite/-/issues/255).
    • Resolves [GitLab issue #255](https://gitlab.com/cznic/sqlite/-/issues/255). See [GitLab merge request #136](https://gitlab.com/cznic/sqlite/-/merge_requests/136), thanks Nathan Herring (@​technosloth), and thanks Gani Georgiev (@​ganigeorgiev) for pressing the opt-in default!
  • 2026-08-19 v1.57.0:

    • Add an opt-in _defensive DSN query parameter turning on SQLite's defensive mode for the connection. On such a connection PRAGMA writable_schema=ON, PRAGMA journal_mode=OFF and PRAGMA schema_version=N become silent no-ops, and writes to a virtual table's shadow tables and to sqlite_dbpage fail. It is a hardening measure, not a sandbox for hostile database files, for which it is only one of the steps SQLite recommends, and it is a property of the connection, not of the file. Absent, or _defensive=0, nothing changes.
    • Reject _defensive=1 together with _journal_mode=OFF (or _journal=OFF) instead of opening a connection in which neither was honoured: SQLite turns that PRAGMA into a no-op that still reports success. Only DSNs using the new parameter can be affected. See [GitHub pull request #6](modernc-org/sqlite#6), thanks wsman!
    • Ship the sqlite-vec license notice this module has been missing since vec/ arrived in v1.47.0. sqlite-vec is Copyright (c) 2024 Alex Garcia, dual-licensed Apache-2.0 OR MIT and used here under MIT; the text now ships as LICENSE-SQLITE_VEC, and make vendor fails rather than quietly dropping it.
    • The SQLite notice is renamed from SQLITE-LICENSE to LICENSE-SQLITE; update any direct links to it. Its contents are unchanged. The rename is what makes go mod vendor carry both notices into downstream vendor/ trees: it selects license files by name prefix, so a name merely ending in LICENSE was never propagated.
    • Let a caller-constructed Driver register its own functions, collations and virtual table modules, through new RegisterFunction, RegisterScalarFunction, RegisterDeterministicScalarFunction, RegisterCollationUtf8 and RegisterModule methods plus Must* variants, and let vtab.RegisterModule honour its db argument. Behavior change: vtab.RegisterModule(db, ...) where db was opened on a caller-constructed Driver used to discard db and land on the registered sqlite driver, reaching every connection in the process; it now lands on that Driver alone, so a sql.Open("sqlite") connection that used to resolve such a module gets no such module. Everything else is additive, and the isolating change discussed in [GitLab issue #254](https://gitlab.com/cznic/sqlite/-/issues/254) is deliberately not made here. See [GitLab merge request #135](https://gitlab.com/cznic/sqlite/-/merge_requests/135), thanks Ian Chechin!
    • Promote freebsd/386, freebsd/arm and netbsd/amd64 from experimental to fully supported. The package documentation's platform table had carried seventeen entries while this module shipped, cross-built and tested twenty; all three have been in the builder matrix since v1.53.0 and pass the full suite on this release's commit. Documentation only — lib/Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 20, 2026
@SamsonNegedu
SamsonNegedu force-pushed the main branch 2 times, most recently from a7b01b2 to 1cfd282 Compare September 20, 2026 01:33
@dependabot dependabot Bot changed the title Bump the go-minor-and-patch group with 8 updates Bump the go-minor-and-patch group across 1 directory with 8 updates Sep 20, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/go-minor-and-patch-6a81fec19d branch from 64ee0a2 to ec9b38e Compare September 20, 2026 01:36
@SamsonNegedu
SamsonNegedu force-pushed the main branch 4 times, most recently from 0d81a28 to 83db0c2 Compare September 20, 2026 10:02
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/go-minor-and-patch-6a81fec19d branch from ec9b38e to 4bab4d3 Compare September 20, 2026 14:43
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/go-minor-and-patch-6a81fec19d branch from 4bab4d3 to afb9d9e Compare September 27, 2026 14:43
Bumps the go-minor-and-patch group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/compose-spec/compose-go/v2](https://github.com/compose-spec/compose-go) | `2.10.1` | `2.16.1` |
| [github.com/gin-gonic/gin](https://github.com/gin-gonic/gin) | `1.9.1` | `1.12.0` |
| [github.com/go-pkgz/auth](https://github.com/go-pkgz/auth) | `1.25.2` | `1.27.0` |
| [github.com/shirou/gopsutil/v3](https://github.com/shirou/gopsutil) | `3.24.1` | `3.24.5` |
| [golang.org/x/net](https://github.com/golang/net) | `0.56.0` | `0.57.0` |
| [golang.org/x/sync](https://github.com/golang/sync) | `0.21.0` | `0.22.0` |
| [golang.org/x/term](https://github.com/golang/term) | `0.44.0` | `0.45.0` |
| [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) | `1.28.0` | `1.60.1` |



Updates `github.com/compose-spec/compose-go/v2` from 2.10.1 to 2.16.1
- [Release notes](https://github.com/compose-spec/compose-go/releases)
- [Commits](compose-spec/compose-go@v2.10.1...v2.16.1)

Updates `github.com/gin-gonic/gin` from 1.9.1 to 1.12.0
- [Release notes](https://github.com/gin-gonic/gin/releases)
- [Changelog](https://github.com/gin-gonic/gin/blob/master/CHANGELOG.md)
- [Commits](gin-gonic/gin@v1.9.1...v1.12.0)

Updates `github.com/go-pkgz/auth` from 1.25.2 to 1.27.0
- [Release notes](https://github.com/go-pkgz/auth/releases)
- [Commits](go-pkgz/auth@v1.25.2...v1.27.0)

Updates `github.com/shirou/gopsutil/v3` from 3.24.1 to 3.24.5
- [Release notes](https://github.com/shirou/gopsutil/releases)
- [Commits](shirou/gopsutil@v3.24.1...v3.24.5)

Updates `golang.org/x/net` from 0.56.0 to 0.57.0
- [Commits](golang/net@v0.56.0...v0.57.0)

Updates `golang.org/x/sync` from 0.21.0 to 0.22.0
- [Commits](golang/sync@v0.21.0...v0.22.0)

Updates `golang.org/x/term` from 0.44.0 to 0.45.0
- [Commits](golang/term@v0.44.0...v0.45.0)

Updates `modernc.org/sqlite` from 1.28.0 to 1.60.1
- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)
- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.28.0...v1.60.1)

---
updated-dependencies:
- dependency-name: github.com/compose-spec/compose-go/v2
  dependency-version: 2.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: github.com/gin-gonic/gin
  dependency-version: 1.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: github.com/go-pkgz/auth
  dependency-version: 1.27.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: github.com/shirou/gopsutil/v3
  dependency-version: 3.24.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/net
  dependency-version: 0.57.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/sync
  dependency-version: 0.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/term
  dependency-version: 0.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: modernc.org/sqlite
  dependency-version: 1.59.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/go-minor-and-patch-6a81fec19d branch from afb9d9e to 4fda4e6 Compare October 4, 2026 14:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants