deps(nuget): Bump SQLitePCLRaw.bundle_e_sqlite3 from 2.1.12 to 3.0.4 - #1528
deps(nuget): Bump SQLitePCLRaw.bundle_e_sqlite3 from 2.1.12 to 3.0.4#1528dependabot[bot] wants to merge 2 commits into
Conversation
--- updated-dependencies: - dependency-name: SQLitePCLRaw.bundle_e_sqlite3 dependency-version: 3.0.4 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
Fresh adversarial review — current head FindingsNo confirmed code or dependency-family defect. This is a major transition, but its NuGet dependency chain is coherent for net8: bundle 3.0.4 requires config 3.0.4 and SourceGear.sqlite3 >=3.53.3; config requires provider 3.0.4; provider requires core 3.0.4. That preserves the matched bundle/config/provider/core/native family required by the prior SQLite security remediation. The green API/integration and native-version checks additionally exercise the SQLite runtime. DCO is green. I read all existing PR-conversation comments, reviews, and review threads: all were empty. Residual merge gates
Recommendation: merge-ready only after those two current-base/governance gates are satisfied; keep the native SQLite runtime test in the refreshed evidence. |
Updated SQLitePCLRaw.bundle_e_sqlite3 from 2.1.12 to 3.0.4.
Release notes
Sourced from SQLitePCLRaw.bundle_e_sqlite3's releases.
3.0.4
Update SQLitePCLRaw.bundle_e_sqlite3 to reference SourceGear.sqlite3 version 3.53.3.
3.0.3
Fixes for some fairly obscure memory corruption bugs, thanks for PR #663 and related
3.0.2
Update SourceGear.lib dependency to 3.50.4.2
3.0.1
SQLitePCLRaw.lib.e_sqlite3toSourceGear.sqlite33.0.0
v3 release notes
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)