chore(deps): bump the go-minor-patch group across 1 directory with 6 updates - #549
Merged
Merged
Conversation
…updates Bumps the go-minor-patch group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github.com/getkin/kin-openapi](https://github.com/getkin/kin-openapi) | `0.146.0` | `0.149.0` | | [github.com/mattn/go-sqlite3](https://github.com/mattn/go-sqlite3) | `1.14.49` | `1.14.52` | | [github.com/stretchr/testify](https://github.com/stretchr/testify) | `1.11.1` | `1.12.1` | | [golang.org/x/image](https://github.com/golang/image) | `0.44.0` | `0.46.0` | | [golang.org/x/sync](https://github.com/golang/sync) | `0.22.0` | `0.23.0` | | [golang.org/x/term](https://github.com/golang/term) | `0.45.0` | `0.46.0` | Updates `github.com/getkin/kin-openapi` from 0.146.0 to 0.149.0 - [Release notes](https://github.com/getkin/kin-openapi/releases) - [Commits](getkin/kin-openapi@v0.146.0...v0.149.0) Updates `github.com/mattn/go-sqlite3` from 1.14.49 to 1.14.52 - [Release notes](https://github.com/mattn/go-sqlite3/releases) - [Commits](mattn/go-sqlite3@v1.14.49...v1.14.52) Updates `github.com/stretchr/testify` from 1.11.1 to 1.12.1 - [Release notes](https://github.com/stretchr/testify/releases) - [Commits](stretchr/testify@v1.11.1...v1.12.1) Updates `golang.org/x/image` from 0.44.0 to 0.46.0 - [Commits](golang/image@v0.44.0...v0.46.0) Updates `golang.org/x/sync` from 0.22.0 to 0.23.0 - [Commits](golang/sync@v0.22.0...v0.23.0) Updates `golang.org/x/term` from 0.45.0 to 0.46.0 - [Commits](golang/term@v0.45.0...v0.46.0) --- updated-dependencies: - dependency-name: github.com/getkin/kin-openapi dependency-version: 0.149.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: github.com/mattn/go-sqlite3 dependency-version: 1.14.52 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-minor-patch - dependency-name: github.com/stretchr/testify dependency-version: 1.12.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: golang.org/x/image dependency-version: 0.46.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: golang.org/x/sync dependency-version: 0.23.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch - dependency-name: golang.org/x/term dependency-version: 0.46.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/go_modules/go-minor-patch-c42c810266
branch
from
October 2, 2026 15:43
cfb4277 to
ea12d02
Compare
fank
self-requested a review
October 2, 2026 21:53
Member
|
Ratatoskr reviewed this pull request. Approved on Finished 2026-10-02 21:57 UTC. |
fank
approved these changes
Oct 2, 2026
fank
left a comment
Member
There was a problem hiding this comment.
Approve, with 0 blocking findings: all six bumps are drop-in for how this repo uses them. CI passed, the generated OpenAPI spec doesn't change, and the riskiest upstream change, the go-sqlite3 statement cache, is opt-in and not enabled here.
Review details
Why approve: I'd be comfortable as the sole reviewer. I found nothing that needs fixing, and I checked each upstream behaviour change that could matter against how this repo actually calls the library.
What I checked
- go-sqlite3 1.14.49 → 1.14.52
- The new statement-cache code in 1.14.51/1.14.52 (schema-change flush, eager first step) only runs when the DSN sets
_stmt_cache_size. In v1.14.52'ssqlite3.gothe cache stays disabled unlessstmtCacheSize > 0. - This repo opens the DB with
sql.Open("sqlite3", pathDB)(internal/server/operation.go:82).pathDBis a plain path, defaultdata.db(internal/server/setting.go:99), and nothing sets_stmt_cache_size. So the new cache code never runs here. - The bundled SQLite amalgamation is unchanged:
SQLITE_VERSION "3.53.4"in both versions. - The remaining changes are the query-cancellation rework (no more per-row goroutines) and the
sync.Maphandle map. Both are covered by the existing DB tests ininternal/server: there are 26 non-test*Contextcall sites.
- The new statement-cache code in 1.14.51/1.14.52 (schema-change flush, eager first step) only runs when the DSN sets
- kin-openapi 0.146 → 0.149, used through fuego
- The repo builds and vets cleanly.
- On a throwaway copy, I generated the full OpenAPI document via
NewHandler+OutputOpenAPISpec()under both 0.146.0 and 0.149.0. The two JSON outputs are identical (43,909 bytes each), andspec.Validate()passes. So the boolean-schema,prefixItemsand format-validator changes have no visible effect on/swagger/openapi.json.
- testify 1.11.1 → 1.12.1: the YAML library swap and the
*AssertionFuncaliasing don't affect this repo. The repo doesn't usemock,suiteor the*AssertionFunctypes. Dropping go-difflib and go-spew from the indirect requires is consistent with testify vendoring them. - golang.org/x/image, x/sync and x/term: the repo only imports
x/image/draw,x/sync/errgroupandx/term. None of the listed changes touches those paths in a way that matters here. The semaphore negative-capacity panic is inx/sync/semaphore, which isn't used. These modules now need Go ≥ 1.26.0, andgo.modalready saysgo 1.26.5. - Module hygiene:
go mod verifyreports "all modules verified", andgo mod tidy -diffis empty, so go.mod and go.sum are tidy and consistent.
Commands run (head ea12d02, local Go 1.26.5)
go mod verify: passed.go mod tidy -diff: no diff.go build ./...: passed.go vet ./...: passed.go test ./...: only partly run locally. This machine has no C compiler, sogo-sqlite3builds as its cgo stub and theinternal/serverDB tests can't run here.internal/storagepassed.- The Go workflow run for this head (37029024419) used
CGO_ENABLED=1and resolvedgo-sqlite3 v1.14.52. Every package passed there, includinginternal/server,internal/conversionandinternal/maptool.
Limitations
- I didn't build the Docker image locally, because I had no Docker daemon access.
- There were no earlier review threads on this PR to follow up on.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the go-minor-patch group with 6 updates in the / directory:
0.146.00.149.01.14.491.14.521.11.11.12.10.44.00.46.00.22.00.23.00.45.00.46.0Updates
github.com/getkin/kin-openapifrom 0.146.0 to 0.149.0Release notes
Sourced from github.com/getkin/kin-openapi's releases.
Commits
1a812b4openapi3: accept boolean schemas (#1258)9814d1fMerge commit from fork9245cefMerge commit from fork4487f19Merge commit from fork53c2ab1openapi3: validate prefixItems positionally (#1259)ba23e9ddocs: add inspect.software health badge (#1253)94fcebfopenapi3: compare multipleOf on exact rationals, not fixed-precision decimals...e9e5e11openapi3: add FormatOfStringForUUIDOfRFC9562 for UUID v6-v8 (#1251)df7e8f4openapi3: do not forget to carry schema format validators over to OAS3.1 (#1250)eda80e2Merge commit from forkUpdates
github.com/mattn/go-sqlite3from 1.14.49 to 1.14.52Release notes
Sourced from github.com/mattn/go-sqlite3's releases.
Commits
b0be46fMerge pull request #1454 from mattn/fix-stmt-cache-probe-costc8212b8Replace schema probe with eager first step for cached statementsd7f5da7Merge pull request #1452 from mattn/fix-stmt-cache-schema-change6428cadMerge pull request #1444 from bradengroom/codex/efficient-query-cancellationbe93f7aMerge pull request #1453 from mattn/fix-handle-map-quadratic5b285a1Merge branch 'master' into codex/efficient-query-cancellation2294cd9Replace copy-on-write handle map with sync.Map5341ceeGate cache on runtime version and skip probing in transactionsc7ed68dFlush statement cache when the schema changes6507893Merge pull request #1367 from kberov/typosUpdates
github.com/stretchr/testifyfrom 1.11.1 to 1.12.1Release notes
Sourced from github.com/stretchr/testify's releases.
... (truncated)
Commits
959dbdaMerge pull request #1935 from harryzcy/yaml-update9bb7176Update go.yaml.in/yaml/v3 to v3.0.5001eb79Merge pull request #1905 from Kentzo/patch-1ad40f38Merge pull request #1906 from stretchr/dependabot/github_actions/actions/chec...3bae017build(deps): bump actions/checkout from 6.0.2 to 6.0.3f8c01f3mock: Mock.Return does not exist anymore12f8b56Merge pull request #1563 from stretchr/make-AssertionFunc-types-aliasesa11649eassert: make *AssertionFunc type just aliasesdc20f41Merge pull request #1890 from stretchr/dolmen/codegen-modernize098f8d7_codegen: use strings.BuilderUpdates
golang.org/x/imagefrom 0.44.0 to 0.46.0Commits
b06f1dego.mod: update golang.org/x dependencies09b0b4fall: upgrade go directive to at least 1.26.0 [generated]3ebddc7go.mod: update golang.org/x dependencies981eaa0vp8l: avoid allocating many unused Huffman tree groups315273avector: using golang.org/x/sys/cpu for feature detectionUpdates
golang.org/x/syncfrom 0.22.0 to 0.23.0Commits
f75267dsemaphore: panic on negative capacity3ffd83call: upgrade go directive to at least 1.26.0 [generated]Updates
golang.org/x/termfrom 0.45.0 to 0.46.0Commits
6226200go.mod: update golang.org/x dependencies7c2fb74term: process bytes returned with a read error3963fceall: upgrade go directive to at least 1.26.0 [generated]