Skip to content

chore(deps): bump the go-modules group with 3 updates - #138

Merged
ralyodio merged 1 commit into
mainfrom
dependabot/go_modules/go-modules-2d0c5ef0d7
Oct 2, 2026
Merged

ralyodio merged 1 commit into
mainfrom
dependabot/go_modules/go-modules-2d0c5ef0d7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-modules group with 3 updates: github.com/livekit/protocol, github.com/pion/webrtc/v4 and modernc.org/sqlite.

Updates github.com/livekit/protocol from 1.52.0 to 1.52.1

Release notes

Sourced from github.com/livekit/protocol's releases.

@​livekit/protocol@​1.52.1

Patch Changes

  • Add configutil.Derive for narrowing an observable config onto a subtree - #1795 (@​paulwe)

  • Add configutil.NewStaticObserver, which builds an Observer over an already-built config with no file to watch, for stubbing observable config in tests. EmitConfigUpdate now also stores the config it emits, so Load reflects an update pushed by hand. - #1795 (@​paulwe)

  • Add configutil.Validator, an optional builder hook run on every config load after InitDefaults. A config that fails validation, or whose InitDefaults returns an error, now fails NewObserver; on reload the failure is logged and the previous config stays in effect. - #1795 (@​paulwe)

  • Add FlexFEC stats to RTPStats - #1818 (@​chenosaurus)

  • logger.Config implements yaml.Marshaler, so marshaling a *Config snapshots it under the same lock Update takes instead of reading fields alongside a concurrent update. - #1813 (@​paulwe)

  • Update psrpc to v0.8.0 - #1808 (@​paulwe)

  • agent_simulation: repeat scenarios within a run for pass@k / pass^k, and decide a scenario's verdict from a Sampling.pass_rate - #1799 (@​u9g)

  • Add lk.sip.inviteTime SIP participant attribute and agents sip_invite_latency reporter - #1815 (@​paulwe)

  • Add utils/leaftest, which asserts that a package imports nothing beyond the standard library and an explicit allow list. leaftest.Assert(t) names the package from the working directory, so a guarded package's test carries no import path to keep in sync. Test-only imports are not counted. - #1795 (@​paulwe)

Changelog

Sourced from github.com/livekit/protocol's changelog.

1.52.1

Patch Changes

  • Add configutil.Derive for narrowing an observable config onto a subtree - #1795 (@​paulwe)

  • Add configutil.NewStaticObserver, which builds an Observer over an already-built config with no file to watch, for stubbing observable config in tests. EmitConfigUpdate now also stores the config it emits, so Load reflects an update pushed by hand. - #1795 (@​paulwe)

  • Add configutil.Validator, an optional builder hook run on every config load after InitDefaults. A config that fails validation, or whose InitDefaults returns an error, now fails NewObserver; on reload the failure is logged and the previous config stays in effect. - #1795 (@​paulwe)

  • egressobs.GetAudioOnly reports v2 StartEgress and replay export requests as audio-only when their Template or Web source sets audio_only. - #1816 (@​milos-lk)

  • Add FlexFEC stats to RTPStats - #1818 (@​chenosaurus)

  • logger.Config implements yaml.Marshaler, so marshaling a *Config snapshots it under the same lock Update takes instead of reading fields alongside a concurrent update. - #1813 (@​paulwe)

  • Update psrpc to v0.8.0 - #1808 (@​paulwe)

  • agent_simulation: repeat scenarios within a run for pass@k / pass^k, and decide a scenario's verdict from a Sampling.pass_rate - #1799 (@​u9g)

  • Add lk.sip.inviteTime SIP participant attribute and agents sip_invite_latency reporter - #1815 (@​paulwe)

  • Add utils/leaftest, which asserts that a package imports nothing beyond the standard library and an explicit allow list. leaftest.Assert(t) names the package from the working directory, so a guarded package's test carries no import path to keep in sync. Test-only imports are not counted. - #1795 (@​paulwe)

Commits
  • 8632616 Version Packages (#1806)
  • f979b9b Add FlexFEC metrics to RTPStats (#1818)
  • 9f0ebd0 egressobs: report audio_only for v2 egress and replay requests (#1816)
  • 0ffd718 sip: add inviteTime attribute and agents sip_invite_latency reporter (#1815)
  • 935e69b agent_simulation: sample scenarios within a run for pass@k / pass^k (#1799)
  • 72d9ef1 Removing twirp error unknown prefix (#1814)
  • efea868 logger: allocation-free component level resolution, yaml.Marshaler on Config ...
  • 570ad99 Update module github.com/prometheus/client_model to v0.6.3 (#1811)
  • 26af364 deps: update psrpc to v0.8.0 (#1808)
  • b4dd53e configutil: add Derive and a Validator hook on the observer (#1795)
  • See full diff in compare view

Updates github.com/pion/webrtc/v4 from 4.2.20 to 4.2.22

Release notes

Sourced from github.com/pion/webrtc/v4's releases.

v4.2.22

Changelog

  • ef0e4301807de30cf4dbf2c11a5ae15829c4ed89 Set TCP mux write buffer to 4 MB
  • 73d256a216e651b94a1d030b38b3bf74f8749279 Handle omitted media direction

v4.2.21

Changelog

  • e604a52ce95e4a8a01d37745924e7b65275372de Avoid re-parsing SDP for every payload type
  • d9d1a1f6e8455bb672e0f0b47b26391d2cb11218 Add browsers interops
  • 603ea7498959514d3ee5c6b64e23b7395932e4ac Update module github.com/pion/transport/v5 to v5.1.1
  • 2270461ff874b2d1413084043d2fe295a9dc9ba1 Update module github.com/pion/transport/v5 to v5.1.0 (#3556)
  • 7fd537723276883a95e40ccd93edcf4b0920e738 Update module github.com/pion/rtcp to v1.2.18 (#3558)
  • 3079642da9bfe281bb58df2e63393382567db136 Update CI configs to v0.12.7
  • 26f7ef74103f34dafe2b317832ea1a3ef9ba689f Added support for Cryptex (RFC 9335)
  • 91bfc6c2039fcafef2a8a2d5f9e48ba4cd99430c Add StartContext to SCTPTransport (#3548)
  • 7f6c2cc42cabe54150d3fcade3bd1a6bb3778f04 Update module github.com/pion/srtp/v3 to v3.1.0 (#3553)
  • c869fd8f2018a7b6049453ab0f76e7c318811d75 Fix DTLS role during renegotiation
  • 8190951af637f42619ab7ae395b3d6546ee4a83e Update module github.com/pion/ice/v4 to v4.4.4 (#3542)
  • 22576b9b984239999f460ad01618955fc0797cf1 Fix duplicate compatible codec payload selection (#3551)
  • 5589f4d22ebaca69a18445174ad16700cf8af63b Update module github.com/pion/transport/v5 to v5.0.1 (#3547)
  • 65a0eef1af6de7f40781258674e5aae0754ad4d2 Fix data race and leaked goroutines in test waits
  • 4f8e4f5c26bd4ee98cf9a644b3279d0714b025d2 Update module github.com/pion/sdp/v3 to v3.0.20 (#3545)
  • 1b03b762d59a63cc8c1b3ccdb72d32c3a1867b71 Update to transport/v5
  • 0684ea37abb80b58ea6a834f1da641424d7a9459 Update module github.com/pion/transport/v4 to v4.1.1 (#3537)
  • 86107df1be4fbba2a15b423fc3219838d3fc1a17 Update module github.com/pion/turn/v5 to v5.1.1 (#3528)
  • 308ca743c4d3d653e2b6b1cfd8c9f106ba027803 Update module github.com/pion/srtp/v3 to v3.0.15 (#3527)
  • d8eb70e6c13410c399fd6f1c964b48305c29c7ba Update module github.com/pion/srtp/v3 to v3.0.14 (#3523)
  • f06c094949c8efc53b9a2fd4c6df1b26b3f9e940 Fix ivfwriter panic on VP8 descriptor-only packet
Commits
  • ef0e430 Set TCP mux write buffer to 4 MB
  • 73d256a Handle omitted media direction
  • e604a52 Avoid re-parsing SDP for every payload type
  • d9d1a1f Add browsers interops
  • 603ea74 Update module github.com/pion/transport/v5 to v5.1.1
  • 2270461 Update module github.com/pion/transport/v5 to v5.1.0 (#3556)
  • 7fd5377 Update module github.com/pion/rtcp to v1.2.18 (#3558)
  • 3079642 Update CI configs to v0.12.7
  • 26f7ef7 Added support for Cryptex (RFC 9335)
  • 91bfc6c Add StartContext to SCTPTransport (#3548)
  • Additional commits viewable in compare view

Updates modernc.org/sqlite from 1.59.0 to 1.60.0

Changelog

Sourced from modernc.org/sqlite's changelog.

Changelog

Entries for v1.38.1 through v1.44.1 and for v1.49.1 were added on 2026-09-05, reconstructed from the git history and the merge requests they cite; they were missing at release time.

  • 2026-09-30 v1.61.0:

  • 2026-09-29 v1.60.1:

    • Binding arguments to a statement is no longer quadratic in the number of its parameters, which made multi-row INSERTs with thousands of ? parameters slow. Resolves [GitHub issue #8](modernc-org/sqlite#8), thanks wencycool!
  • 2026-09-28 v1.60.0:

    • A fault while reading the memory-mapped -shm file of a WAL database no longer crashes the process. The statement fails with a disk I/O error, extended code SQLITE_IOERR_IN_PAGE (8714), and the connection stays usable, as in MSVC builds of SQLite. On by default on every platform and not switchable; lib.SehInject and lib.SehPending inject such a fault for tests. Resolves [GitLab issue #221](https://gitlab.com/cznic/sqlite/-/issues/221), thanks Roman (@​requilence) for the report, and supersedes libsqlite3!4 and [GitHub pull request #7](modernc-org/sqlite#7), thanks hazyhaar for the two rounds, the ccgo finding and the Windows Server runs!
    • Re-vendor lib/ from modernc.org/libsqlite3 v1.15.0 and vec/ from modernc.org/libsqlite_vec v0.6.0; SQLite stays 3.53.4 and sqlite-vec v0.1.9. Go 1.26 is now required, and the pinned modernc.org/libc becomes v1.77.1; as always, downstream go.mod files must pin the same modernc.org/libc version this repository's go.mod does, see [GitLab issue #177](https://gitlab.com/cznic/sqlite/-/issues/177).
    • Nine exported lib constants that never had a meaningful value are gone: INFINITY, MB_CUR_MAX, NAN, RESERVED_BYTE, SHARED_FIRST, SQLITE_CANTOPEN_BKPT, SQLITE_CORRUPT_BKPT, SQLITE_DEFAULT_LOOKASIDE and SQLITE_MISUSE_BKPT. The transpiler now evaluates object-like macros as C expressions, so other constants take their C value (lib.WALINDEX_PGSZ is 32768, not 0) and some appear; the full list is in libsqlite3's CHANGELOG under 2026-09-19.
    • make vendor now writes vendor.json, the modernc.org/libsqlite3 and modernc.org/libsqlite_vec commits and the Go toolchain lib/ and vec/ were vendored with, so git show vX.Y.Z:vendor.json says which revisions a release carries; the test suite fails when they no longer match. Tooling only. See [GitLab merge request #140](https://gitlab.com/cznic/sqlite/-/merge_requests/140).
    • vfs.FS.Close now refuses while a database opened through it is still open, returning an error that wraps the new vfs.ErrInUse and leaving the VFS registered. It used to free the VFS the open connection still called through, so the next query crashed the process or read through freed memory. Close the databases first, then the FS.
    • Fix handle reuse in modernc.org/sqlite/vfs on 32-bit targets: after 2^32 file opens in one process the handle counter wrapped and could overwrite a live entry, such as a file system registered at start-up, and crash. 64-bit targets were not affected.
    • The pluggable page cache now panics when a Cache breaks its contract by returning nil, or a different Page, from Fetch for a page SQLite still holds pinned. It used to free memory SQLite was still using, corrupting the database without an error. Only a Cache implementation with that bug is affected; modernc.org/sqlite/pcache is not.
    • Document three limits of the pluggable page cache on RegisterPageCache and Cache: it cannot be combined with modernc.org/sqlite/vec, PageCache.Create may be called concurrently, and under cache=shared a Cache is called from several goroutines. Documentation only.
    • Document in the package documentation that state set on a pooled connection is inherited by the next caller to borrow it, and that a connection reached through sql.Conn.Raw is not safe for concurrent use. Documentation only.
    • Add StrictPragmas, opt-in and off by default: once enabled, a connection whose _pragma DSN value holds more than one SQL statement fails to open with ErrMultiStatementPragma, before any DSN parameter is applied. A _pragma value runs as SQL text, so anything after a ; runs too. Recommended for any application whose DSN is not a compile-time constant.
    • Document SQLite's own URI query parameters on Driver.Open: mode, cache, immutable, nolock, psow and modeof, which have always worked in a DSN starting with file:, and the trap that a plain file name has its query stripped before SQLite sees it, so /path/to.db?mode=ro opens read-write. Resolves [GitLab issue #257](https://gitlab.com/cznic/sqlite/-/issues/257). Documentation only.
    • Add SECURITY.md, the vulnerability reporting policy: three private channels, what is in scope, that only the latest release is supported, and how a confirmed report is disclosed, including an entry in the Go vulnerability database so govulncheck reports it. IRP.md, linked from it, is the maintainers' incident response plan. Documentation only.
    • Add CONTRIBUTING.md: where to send a merge request, which files are generated and must not be edited by hand, how to build and test across the 20 supported targets, and the AUTHORS/CONTRIBUTORS convention. Documentation only.
    • Ship LICENSE-3RD-PARTY.md, a transitively flattened inventory of every third-party component this module carries with all seventeen license texts in full, and a Software Bill of Materials, sbom.cdx.json (CycloneDX 1.6) and sbom.spdx.json (SPDX 2.3), explained in SBOM.md. Both cover what a module-graph tool cannot see: the transpiled SQLite and sqlite-vec C, and the upstreams modernc.org/libc carries, musl among them. Documentation only.
  • 2026-09-15 v1.59.0:

    • Bump the pinned modernc.org/libc to v1.75.7 and re-vendor lib/ and vec/. The transpiled SQLite is unchanged, still 3.53.4. On the Linux targets the new libc replaces transpiled musl memcpy, memmove, memset, memcmp and strlen with native Go, cutting CPU time on query-heavy workloads by up to a third; see the new Performance section below. As always, downstream go.mod files must pin the same modernc.org/libc version this repository's go.mod does; see [GitLab issue #177](https://gitlab.com/cznic/sqlite/-/issues/177).
    • Hand user-defined function and aggregate callbacks a pooled *FunctionContext instead of allocating a fresh one per call, removing the last driver-side allocation per invocation. Like the argument slice, it is valid only for the duration of the callback and must not be retained past its return. Updates [GitLab issue #226](https://gitlab.com/cznic/sqlite/-/issues/226). See [GitLab merge request #137](https://gitlab.com/cznic/sqlite/-/merge_requests/137).
    • Add regression tests pinning the identity and the pooling of that context. See [GitLab merge request #138](https://gitlab.com/cznic/sqlite/-/merge_requests/138), thanks Ian Chechin!
    • Add a Performance section to the package documentation: measured CPU-time ratios of this driver against the same SQLite compiled from C, where the gap comes from, and the two consequences for applications — index the columns that ORDER BY, GROUP BY and WHERE use, and bound the database/sql pool with SetMaxOpenConns.
  • 2026-09-01 v1.58.0:

    • Upgrade to SQLite 3.53.4. It carries upstream's own fix for the journal-rollback data-corruption bug, so the local super-journal patch v1.56.0 introduced is dropped; recovery behavior is unchanged. Also bumps the pinned modernc.org/libc to v1.75.6; as always, downstream modules must pin the same version this one does, see [GitLab issue #177](https://gitlab.com/cznic/sqlite/-/issues/177).
    • Add opt-in support for Linux Open File Description (OFD) locks on database files, off by default; without opting in, locking behavior is byte-for-byte that of previous releases. A POSIX record lock is owned by the (process, inode) pair, so any Close of any descriptor of the database file anywhere in the process silently strips SQLite's locks; OFD locks survive that. Enable it process-wide with MODERNC_SQLITE_OFD_LOCK=1 in the environment, or with the new OFDLocking(true) before the first connection is opened; OFDLockingEnabled reports the mode in effect, and the new ErrOFDLockingTooLate and ErrOFDLockingUnavailable report a switch attempted too late and a platform or filesystem without the feature. Why it is process-wide rather than a DSN parameter, what WAL's -shm coordination still uses, and the /proc/locks measurements behind the design are in [GitLab issue #255](https://gitlab.com/cznic/sqlite/-/issues/255).
    • Resolves [GitLab issue #255](https://gitlab.com/cznic/sqlite/-/issues/255). See [GitLab merge request #136](https://gitlab.com/cznic/sqlite/-/merge_requests/136), thanks Nathan Herring (@​technosloth), and thanks Gani Georgiev (@​ganigeorgiev) for pressing the opt-in default!
  • 2026-08-19 v1.57.0:

    • Add an opt-in _defensive DSN query parameter turning on SQLite's defensive mode for the connection. On such a connection PRAGMA writable_schema=ON, PRAGMA journal_mode=OFF and PRAGMA schema_version=N become silent no-ops, and writes to a virtual table's shadow tables and to sqlite_dbpage fail. It is a hardening measure, not a sandbox for hostile database files, for which it is only one of the steps SQLite recommends, and it is a property of the connection, not of the file. Absent, or _defensive=0, nothing changes.
    • Reject _defensive=1 together with _journal_mode=OFF (or _journal=OFF) instead of opening a connection in which neither was honoured: SQLite turns that PRAGMA into a no-op that still reports success. Only DSNs using the new parameter can be affected. See [GitHub pull request #6](modernc-org/sqlite#6), thanks wsman!
    • Ship the sqlite-vec license notice this module has been missing since vec/ arrived in v1.47.0. sqlite-vec is Copyright (c) 2024 Alex Garcia, dual-licensed Apache-2.0 OR MIT and used here under MIT; the text now ships as LICENSE-SQLITE_VEC, and make vendor fails rather than quietly dropping it.
    • The SQLite notice is renamed from SQLITE-LICENSE to LICENSE-SQLITE; update any direct links to it. Its contents are unchanged. The rename is what makes go mod vendor carry both notices into downstream vendor/ trees: it selects license files by name prefix, so a name merely ending in LICENSE was never propagated.
    • Let a caller-constructed Driver register its own functions, collations and virtual table modules, through new RegisterFunction, RegisterScalarFunction, RegisterDeterministicScalarFunction, RegisterCollationUtf8 and RegisterModule methods plus Must* variants, and let vtab.RegisterModule honour its db argument. Behavior change: vtab.RegisterModule(db, ...) where db was opened on a caller-constructed Driver used to discard db and land on the registered sqlite driver, reaching every connection in the process; it now lands on that Driver alone, so a sql.Open("sqlite") connection that used to resolve such a module gets no such module. Everything else is additive, and the isolating change discussed in [GitLab issue #254](https://gitlab.com/cznic/sqlite/-/issues/254) is deliberately not made here. See [GitLab merge request #135](https://gitlab.com/cznic/sqlite/-/merge_requests/135), thanks Ian Chechin!
    • Promote freebsd/386, freebsd/arm and netbsd/amd64 from experimental to fully supported. The package documentation's platform table had carried seventeen entries while this module shipped, cross-built and tested twenty; all three have been in the builder matrix since v1.53.0 and pass the full suite on this release's commit. Documentation only — lib/ is byte-for-byte what v1.56.0 shipped.
  • 2026-08-03 v1.56.0:

    • Re-vendor the transpiled sources, picking up modernc.org/libsqlite3's patch for an upstream data-corruption bug in SQLite 3.53.3's journal rollback. A crash during the commit of a multi-database (ATTACH) transaction can leave a hot journal whose zeroed super-journal name still validates, so pager_playback() deletes it without playing it back and leaves the database corrupted. Not a transpilation artifact: a plain gcc build of stock 3.53.3 fails on the same bytes. The SQLite version is unchanged at 3.53.3, every supported target carries the patch, and it will be dropped once upstream ships its own fix.
    • Two targets change beyond that patch. linux/s390x now allocates C bit-fields MSB-first as the big-endian ABI requires, from modernc.org/cc/v4 v4.29.1. linux/riscv64 was regenerated on a host running GCC 11.4.0 rather than 13.3.0, which drops some unreferenced compiler-predefined macro constants and changes what PRAGMA compile_options reports; no SQLite code generation differs. Every other target is byte-identical to v1.55.0 apart from the patch above.
    • Bump the pinned modernc.org/libc to v1.74.4 and the remaining dependencies to their current releases. v1.74.2 and v1.74.3 are retracted upstream over a freeaddrinfo lock leak that deadlocks name resolution, and v1.74.4 is the fix. As always, downstream modules must pin the same modernc.org/libc version this one does, see [GitLab issue #177](https://gitlab.com/cznic/sqlite/-/issues/177).
    • Add NewConnector, returning a database/sql/driver.Connector for use with sql.OpenDB. It opens the same connections sql.Open("sqlite", dsn) does, from the same registered driver, so every function, collation, connection hook and virtual table module registered through this package applies to them. It exists for callers that need to interpose on the physical connections database/sql opens — tracing, metrics, connection-scoped setup — for which the alternative was sql.Register, which is process-global, panics on a repeated name and cannot be undone. A runnable sample is in examples/connector. Resolves [GitLab issue #253](https://gitlab.com/cznic/sqlite/-/issues/253), thanks Alessandro Segala (@​ItalyPaleAle)!

... (truncated)

Commits
  • 7d5a376 CHANGELOG.md: slim the v1.60.0 section
  • a604165 CHANGELOG.md: the SEH emulation, the re-vendor and the removed lib constants;...
  • fb4aac4 vendor.json: stamp lib/ from libsqlite3 v1.15.0 and vec/ from libsqlite_vec v...
  • 0f7ae7d Merge branch 'master' into seh-emulation
  • 2e43324 lib: re-vendor from modernc.org/libsqlite3 v1.15.0 (SEH emulation), pin libc ...
  • 50380ee lib, tests: Go side of the wal.c SEH emulation for Windows in-page faults (#221)
  • 4552e53 Merge branch 'vendor-stamp' into 'master'
  • 3775177 Makefile, doc.go, IRP.md: VENDORFLAGS for debug builds; name every refusal
  • 86c97d4 CHANGELOG.md: link merge request !140
  • 9095339 vendor_libs, Makefile: record where lib/ and vec/ came from in vendor.json
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-modules group with 3 updates: [github.com/livekit/protocol](https://github.com/livekit/protocol), [github.com/pion/webrtc/v4](https://github.com/pion/webrtc) and [modernc.org/sqlite](https://gitlab.com/cznic/sqlite).


Updates `github.com/livekit/protocol` from 1.52.0 to 1.52.1
- [Release notes](https://github.com/livekit/protocol/releases)
- [Changelog](https://github.com/livekit/protocol/blob/main/CHANGELOG.md)
- [Commits](livekit/protocol@v1.52.0...v1.52.1)

Updates `github.com/pion/webrtc/v4` from 4.2.20 to 4.2.22
- [Release notes](https://github.com/pion/webrtc/releases)
- [Commits](pion/webrtc@v4.2.20...v4.2.22)

Updates `modernc.org/sqlite` from 1.59.0 to 1.60.0
- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)
- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.59.0...v1.60.0)

---
updated-dependencies:
- dependency-name: github.com/livekit/protocol
  dependency-version: 1.52.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-modules
- dependency-name: github.com/pion/webrtc/v4
  dependency-version: 4.2.22
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-modules
- dependency-name: modernc.org/sqlite
  dependency-version: 1.60.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 1, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedmodernc.org/​sqlite@​v1.59.0 ⏵ v1.60.077 +110010010070 -10
Updatedgithub.com/​pion/​webrtc/​v4@​v4.2.20 ⏵ v4.2.2273 +1100100100100
Updatedgithub.com/​livekit/​protocol@​v1.52.0 ⏵ v1.52.174 +1100100100100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Priority Alert  (click "▶" to expand/collapse) Action
Medium priority
License policy violation: golang modernc.org/sqlite under LZMA-SDK-9.22

License: LZMA-SDK-9.22 - The applicable license policy does not permit this license (5) (LICENSE-SQLITE)

From: go.mod → golang/modernc.org/sqlite@v1.60.0

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore golang/modernc.org/sqlite@v1.60.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn

View full report

@ralyodio
ralyodio merged commit 34e5075 into main Oct 2, 2026
6 checks passed
@dependabot
dependabot Bot deleted the dependabot/go_modules/go-modules-2d0c5ef0d7 branch October 2, 2026 19:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant