Skip to content

build(deps): bump the go-dependencies group in /integrations/bunguard with 2 updates - #95

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/integrations/bunguard/go-dependencies-aaa4959b5d
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/integrations/bunguard/go-dependencies-aaa4959b5d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the go-dependencies group in /integrations/bunguard with 2 updates: github.com/uptrace/bun and github.com/uptrace/bun/dialect/sqlitedialect.

Updates github.com/uptrace/bun from 1.2.18 to 1.3.0

Release notes

Sourced from github.com/uptrace/bun's releases.

v1.3.0

Please refer to CHANGELOG.md for details

Changelog

Sourced from github.com/uptrace/bun's changelog.

1.3.0 (2026-09-30)

Breaking Changes

Compared with v1.2.18, this release contains four categories of breaking changes. Two are tracked in #1363, and two additional behavioral changes were identified during the release audit.

  • Count, Limit, and Offset use int64 (#1348). DeleteQuery.Limit, SelectQuery.Limit, SelectQuery.Offset, SelectQuery.Count, SelectQuery.ScanAndCount, and UpdateQuery.Limit changed from int parameters or return values to int64. Update affected variables and assignments to int64, or add explicit conversions at call sites.
  • pgdriver verifies TLS certificates (#1398, fixed by #1402). pgdriver.WithInsecure(false) now verifies the server certificate and hostname. Configure valid trust roots and a matching server name. Code that intentionally needs unverified TLS must now opt in explicitly with WithTLSConfig(&tls.Config{InsecureSkipVerify: true}); this is not recommended for production.
  • Duplicate migration IDs are rejected (#1357). Migrations.Discover now returns an error when different migration base filenames share an ID instead of silently overwriting one migration. This also rejects a Go migration registered with MustRegister or Register when Discover encounters a differently named SQL migration with the same ID. Rename conflicting migration files so each ID has a single base filename; a matching .up.sql/.down.sql pair remains valid.
  • NUL-containing strings are rejected (#1406). schema.BaseDialect.AppendString now reports a formatting error instead of silently stripping NUL bytes. Reject or sanitize such input before building queries. This affects the PostgreSQL, SQLite, Oracle, and MSSQL base dialect paths; MySQL's override is unchanged.

Security

  • pgdriver: verify server certificate for WithInsecure(false) (#1402) (023fe24)
  • schema: fail closed when a string contains a NUL byte (#1406) (276ac9f)
  • schema: prevent line-comment SQL injection with negative numbers (CVE-2024-44906 class) (#1396) (13f55cd)

Bug Fixes

  • add LineComment function for handling line comment in formatQuery (49b0464)
  • automigrate: include scanonly fields in the BunModelInspector output (0a83ffc)
  • bunotel: honor WithMeterProvider when reporting DB stats metrics (048005b), closes #1270
  • copy execution state in SelectQuery.Clone (9dad9ac)
  • copy whereHasOr field in SelectQuery.Clone() to preserve soft-delete WhereOr state (e7611b7), closes #1321
  • correct error message prefix and error type (89bf06d)
  • db: propagate transaction context into RunInTx callback (#1381) (640437e)
  • detect duplicate migration IDs during Discover (b8f7b77)
  • detect OR separators case-insensitively for whereHasOr (1110700)
  • improve formatQuery in pgdriver for queries with apostrophes in comments (#1349) (93974c9)
  • migrate: do not append blank lines to SQL query (d32af16)
  • migrate: ignore --bun:skip with a blank query (a34fd3a)
  • migrate: surface lost SQL migration finalizer errors (#1389) (1a289f8)
  • mssql: apply the unicode N prefix to JSON literals (5eb86ee)
  • pgdialect: return an error instead of panicking on empty array input (a3c48dd), closes #1431
  • pgdriver: add slice of byte array support to pgdialect (#1391) (0e5e868)
  • pgdriver: send required params during startup (#1374) (e402298)
  • query: remove debug print and simplify union wrapping (4bdf4d8)
  • query: skip UNION wrapping for SQLite (777c8e2)
  • relation: do not duplicate joined models on a shared base model (856d4d9), closes #1386
  • resolve map column types before scanning rows (af3f6dc), closes #1434
  • resolve nested Relation() with circular struct composition (dd2e4c9), closes #1243
  • return an error instead of panicking when scanning JSON into an unaddressable value (c323fa3), closes #1306
  • schema: do not reject pointers stored in an interface (cc2cd23)
  • schema: escape backslash in AppendJSON without consuming the next byte (#1405) (445907b)
  • schema: resolve m2m BasePKs through the base table's FieldMap (#1375) (9f4d368)
  • schema: return an error when scanning NULL into an unaddressable value (29e4e6e)
  • schema: use dialect-specific AppendBool in QueryGen.Append (#1373) (e91aa81)

... (truncated)

Commits
  • 7d78f9c docs: refine v1.3.0 changelog
  • 8de7fb6 fix(schema): reject NUL before opening string literal
  • ea8b47c docs: document v1.3.0 breaking changes
  • e73781c chore: release v1.3.0 (release.sh)
  • 691d97d Merge pull request #1428 from visheshgubrani/feat/uuid-support
  • 74e036c Merge pull request #1432 from chiliec/fix-array-parser-empty-input
  • 854cf90 Merge pull request #1435 from hsdfat/fix/map-scan-column-types-deadlock
  • aff017d refactor(schema): isolate UUID handlers behind build tags
  • af3f6dc fix: resolve map column types before scanning rows
  • e22ddd3 feat(schema): support Go 1.27 stdlib uuid.UUID (#1427)
  • Additional commits viewable in compare view

Updates github.com/uptrace/bun/dialect/sqlitedialect from 1.2.18 to 1.3.0

Release notes

Sourced from github.com/uptrace/bun/dialect/sqlitedialect's releases.

v1.3.0

Please refer to CHANGELOG.md for details

Changelog

Sourced from github.com/uptrace/bun/dialect/sqlitedialect's changelog.

1.3.0 (2026-09-30)

Breaking Changes

Compared with v1.2.18, this release contains four categories of breaking changes. Two are tracked in #1363, and two additional behavioral changes were identified during the release audit.

  • Count, Limit, and Offset use int64 (#1348). DeleteQuery.Limit, SelectQuery.Limit, SelectQuery.Offset, SelectQuery.Count, SelectQuery.ScanAndCount, and UpdateQuery.Limit changed from int parameters or return values to int64. Update affected variables and assignments to int64, or add explicit conversions at call sites.
  • pgdriver verifies TLS certificates (#1398, fixed by #1402). pgdriver.WithInsecure(false) now verifies the server certificate and hostname. Configure valid trust roots and a matching server name. Code that intentionally needs unverified TLS must now opt in explicitly with WithTLSConfig(&tls.Config{InsecureSkipVerify: true}); this is not recommended for production.
  • Duplicate migration IDs are rejected (#1357). Migrations.Discover now returns an error when different migration base filenames share an ID instead of silently overwriting one migration. This also rejects a Go migration registered with MustRegister or Register when Discover encounters a differently named SQL migration with the same ID. Rename conflicting migration files so each ID has a single base filename; a matching .up.sql/.down.sql pair remains valid.
  • NUL-containing strings are rejected (#1406). schema.BaseDialect.AppendString now reports a formatting error instead of silently stripping NUL bytes. Reject or sanitize such input before building queries. This affects the PostgreSQL, SQLite, Oracle, and MSSQL base dialect paths; MySQL's override is unchanged.

Security

  • pgdriver: verify server certificate for WithInsecure(false) (#1402) (023fe24)
  • schema: fail closed when a string contains a NUL byte (#1406) (276ac9f)
  • schema: prevent line-comment SQL injection with negative numbers (CVE-2024-44906 class) (#1396) (13f55cd)

Bug Fixes

  • add LineComment function for handling line comment in formatQuery (49b0464)
  • automigrate: include scanonly fields in the BunModelInspector output (0a83ffc)
  • bunotel: honor WithMeterProvider when reporting DB stats metrics (048005b), closes #1270
  • copy execution state in SelectQuery.Clone (9dad9ac)
  • copy whereHasOr field in SelectQuery.Clone() to preserve soft-delete WhereOr state (e7611b7), closes #1321
  • correct error message prefix and error type (89bf06d)
  • db: propagate transaction context into RunInTx callback (#1381) (640437e)
  • detect duplicate migration IDs during Discover (b8f7b77)
  • detect OR separators case-insensitively for whereHasOr (1110700)
  • improve formatQuery in pgdriver for queries with apostrophes in comments (#1349) (93974c9)
  • migrate: do not append blank lines to SQL query (d32af16)
  • migrate: ignore --bun:skip with a blank query (a34fd3a)
  • migrate: surface lost SQL migration finalizer errors (#1389) (1a289f8)
  • mssql: apply the unicode N prefix to JSON literals (5eb86ee)
  • pgdialect: return an error instead of panicking on empty array input (a3c48dd), closes #1431
  • pgdriver: add slice of byte array support to pgdialect (#1391) (0e5e868)
  • pgdriver: send required params during startup (#1374) (e402298)
  • query: remove debug print and simplify union wrapping (4bdf4d8)
  • query: skip UNION wrapping for SQLite (777c8e2)
  • relation: do not duplicate joined models on a shared base model (856d4d9), closes #1386
  • resolve map column types before scanning rows (af3f6dc), closes #1434
  • resolve nested Relation() with circular struct composition (dd2e4c9), closes #1243
  • return an error instead of panicking when scanning JSON into an unaddressable value (c323fa3), closes #1306
  • schema: do not reject pointers stored in an interface (cc2cd23)
  • schema: escape backslash in AppendJSON without consuming the next byte (#1405) (445907b)
  • schema: resolve m2m BasePKs through the base table's FieldMap (#1375) (9f4d368)
  • schema: return an error when scanning NULL into an unaddressable value (29e4e6e)
  • schema: use dialect-specific AppendBool in QueryGen.Append (#1373) (e91aa81)

... (truncated)

Commits
  • 7d78f9c docs: refine v1.3.0 changelog
  • 8de7fb6 fix(schema): reject NUL before opening string literal
  • ea8b47c docs: document v1.3.0 breaking changes
  • e73781c chore: release v1.3.0 (release.sh)
  • 691d97d Merge pull request #1428 from visheshgubrani/feat/uuid-support
  • 74e036c Merge pull request #1432 from chiliec/fix-array-parser-empty-input
  • 854cf90 Merge pull request #1435 from hsdfat/fix/map-scan-column-types-deadlock
  • aff017d refactor(schema): isolate UUID handlers behind build tags
  • af3f6dc fix: resolve map column types before scanning rows
  • e22ddd3 feat(schema): support Go 1.27 stdlib uuid.UUID (#1427)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-dependencies group in /integrations/bunguard with 2 updates: [github.com/uptrace/bun](https://github.com/uptrace/bun) and [github.com/uptrace/bun/dialect/sqlitedialect](https://github.com/uptrace/bun).


Updates `github.com/uptrace/bun` from 1.2.18 to 1.3.0
- [Release notes](https://github.com/uptrace/bun/releases)
- [Changelog](https://github.com/uptrace/bun/blob/master/CHANGELOG.md)
- [Commits](uptrace/bun@v1.2.18...v1.3.0)

Updates `github.com/uptrace/bun/dialect/sqlitedialect` from 1.2.18 to 1.3.0
- [Release notes](https://github.com/uptrace/bun/releases)
- [Changelog](https://github.com/uptrace/bun/blob/master/CHANGELOG.md)
- [Commits](uptrace/bun@v1.2.18...v1.3.0)

---
updated-dependencies:
- dependency-name: github.com/uptrace/bun
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: github.com/uptrace/bun/dialect/sqlitedialect
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 5, 2026
@codeant-ai

codeant-ai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Skipping PR review because a bot author is detected.

If you want to trigger CodeAnt AI, comment @codeant-ai review to trigger a manual review.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: KARTIKrocks/sqlguard/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: ce8d233e-02b2-4df2-8be1-29158165241a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codeant-ai

codeant-ai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

🏁 CodeAnt Quality Gate Results

Commit: 6272e763
Scan Time: 2026-10-05 10:37:59 UTC

✅ Overall Status: PASSED

Quality Gate Details

Quality Gate Status Details
Secrets ✅ PASSED 0 secrets found
SAST ✅ PASSED No security issues
SCA (Dependencies) ✅ PASSED Rating S: No vulnerabilities

View Full Results

@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 5, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/integrations/bunguard/go-dependencies-aaa4959b5d branch October 5, 2026 10:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants