Repository navigation
Bump sqlite3 from 2.9.5 to 2.9.6 in /ruby/driver/riverqueue-activerecord - #1488
Merged
bgentry merged 1 commit intoOct 9, 2026
Conversation
Contributor
|
@dependabot rebase |
Bumps [sqlite3](https://github.com/sparklemotion/sqlite3-ruby) from 2.9.5 to 2.9.6. - [Release notes](https://github.com/sparklemotion/sqlite3-ruby/releases) - [Changelog](https://github.com/sparklemotion/sqlite3-ruby/blob/main/CHANGELOG.md) - [Commits](sparklemotion/sqlite3-ruby@v2.9.5...v2.9.6) --- updated-dependencies: - dependency-name: sqlite3 dependency-version: 2.9.6 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/bundler/ruby/driver/riverqueue-activerecord/sqlite3-2.9.6
branch
from
October 9, 2026 23:46
ef1e73c to
d814cb8
Compare
bgentry
approved these changes
Oct 9, 2026
bgentry
left a comment
Contributor
There was a problem hiding this comment.
🤖 Codex review: Approved after dependency security and compatibility review.
Upgrade
sqlite3:2.9.5→2.9.6, the Active Record adapter's development/test dependency, for botharm64-darwinandx86_64-linux-gnu.- Reviewed current head:
d814cb8cfb5a0ed968f046af813491cfea1a1533; base:2e37dd3b756b856e971f32c3811c8cf8476236f8.
Security review
- Confirmed fix for GHSA-mwm8-39rw-8826: GC can free TEXT/BLOB values used by multi-argument aggregates in versions through 2.9.5. Inspected the actual C fix rooting argument storage with ALLOCV_N/ALLOCV_END, callback/compaction lifetime fixes, and all published source changes.
- Downloaded all six old/new source and platform gem artifacts. Whole-gem SHA256 matches RubyGems and upstream release checksums; internal archive hashes match. All 198 packaged files with corresponding upstream-tag files match byte-for-byte. Authors, source, license, dependency graph, extension hooks, and runtime loader remain consistent with upstream. Bundled SQLite stays at 3.53.2 with an unchanged source archive.
- Statically inspected all eight rebuilt native binary pairs (two platforms, four Ruby ABIs). Library dependencies are unchanged; import changes correspond to the reviewed GC/buffer/hash/string fixes, with no suspicious new network/credential/process strings. The build environment allowlist is unchanged. No unexpected trust expansion or blocking supply-chain issue found. Exact-version advisory query for 2.9.6 returns no remaining advisories.
- Current arm64 artifact SHA256 is
849b5d7f795e60fe25076d62c72dd722beb45b3850b516ad978d60ee848ec15b; Linux GNU is613188ce02f614126ddbc38c5e217ccffd6306d0dcd9adca9764547aa890a634. The local cache matches the reviewed arm64 identity. - Reused exact version/platform/checksum source and pairwise evidence from initially reviewed head
ef1e73c7481a5ef53811378c0ae80794035ae423. Re-read the rebased PR and inspected the security delta: the only added base change is the already-reviewed JSON 2.19.3 → 2.19.9 security fix from #1489. The current PR still changes only the same two SQLite version entries; no new artifacts, graph churn, integrity rewrites, or other source changes appear. Parallel per-PR review is consolidated here; the coordinator performs all validation and GitHub writes.
Compatibility verification
- Reinstalled all four bundles frozen at the current head's exact gem versions in isolation. Ruby 3.3.12/macOS arm64 requires a temporary
arm64-darwin-25→arm64-darwin-27platform-label adjustment only; no dependency entries change. Temporary labels are restored afterward and the tracked tree is clean. - SQLite aggregate regression: 200 two-argument, 2 KB text rows under GC.stress — passed with loaded SQLite3 2.9.6. JSON streaming-buffer/parser/generator regression — passed with loaded JSON 2.19.9 on this combined tree.
- Refreshed
make test/rubywith required Postgres 18.6 and SQLite coverage — passed: 2,357 examples, zero failures, one expected Ruby-4-only Ractor example pending locally. - Refreshed
make lint/ruby typecheck/ruby verify/ruby-migrations build/ruby— passed, including four gem builds and 32 migrations. - Reused successful
make test,make lint,make tidy,make verify/migrations verify/rust-migrations verify/sqlc check/modzip, andCHECK=true make update-mod-goevidence: a complete tree comparison against validated JSON headfc101deff53f5501f5e7270d8df19ad527d81c30shows no changes outside this Active Record lockfile. All Go, generator, SQL, module, CI, and other relevant inputs are identical. - Current-head GitHub CI is green, including Ruby 3.2–4.0/Postgres 14–18, SQLite, Rails, Go race tests, and Linux/Windows CLI. Bot CodeQL is neutral; no CodeQL analysis result is claimed.
Residual risk
- Gems are unsigned. Precompiled binary behavior was screened statically; equivalence to reviewed source was not established through a reproducible rebuild. Local runtime checks cover arm64/Ruby 3.3; GitHub CI supplies the Linux and broader Ruby matrix. No blocking findings identified.
bgentry
deleted the
dependabot/bundler/ruby/driver/riverqueue-activerecord/sqlite3-2.9.6
branch
October 9, 2026 23:50
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps sqlite3 from 2.9.5 to 2.9.6.
Release notes
Sourced from sqlite3's releases.
Changelog
Sourced from sqlite3's changelog.
Commits
a52dc0dversion bump to v2.9.6cc5ac0cRoot the aggregate argument array so GC cannot free live values (GHSA-mwm8-39...abcb0f6Reject database filenames and VFS names containing NUL (#732)1d86b7aRaise when open_v2 or open16 is called on an open database (#729)7230171Stop a raise inside a UDF block from deadlocking other threads (#731)2677f9aPass TEXT values containing embedded NULs to UDFs intact (#730)3de8f6edoc: update CHANGELOG.mdac6bd2fRelease aggregate instances when sqlite finishes with them (#722)32460e9Stop sqlite calling into moved Ruby objects (#723)f600993build(deps-dev): update rubocop-minitest requirement (#727)