Skip to content

chore(deps): bump better-sqlite3 from 12.11.1 to 13.0.3 - #1058

Merged
objectstack-fleet[bot] merged 4 commits into
mainfrom
dependabot/npm_and_yarn/better-sqlite3-13.0.3
Oct 3, 2026
Merged

objectstack-fleet[bot] merged 4 commits into
mainfrom
dependabot/npm_and_yarn/better-sqlite3-13.0.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 10, 2026 •

Copy link
Copy Markdown
Contributor

Bumps better-sqlite3 from 12.11.1 to 13.0.3.

Release notes

Sourced from better-sqlite3's releases.

v13.0.3

What's Changed

Full Changelog: WiseLibs/better-sqlite3@v13.0.2...v13.0.3

v13.0.2

What's Changed

New Contributors

Full Changelog: WiseLibs/better-sqlite3@v13.0.1...v13.0.2

v13.0.1

Full Changelog: WiseLibs/better-sqlite3@v13.0.0...v13.0.1

Fixed a regression in parameter binding where it would be overly strict and reject plain objects from other realms (e.g., in jest tests).

v13.0.0

Version 13.0.0 marks a major milestone, as it's the first version of better-sqlite3 to run on the N-API. This means prebuilt binaries should theoretically work across different versions of Node.js and Electron, and perhaps even other runtimes like Bun. As a result, we've removed the deprecated prebuild-install dependency, and now prebuilt binaries are published directly with the better-sqlite3 code itself. If your platform/architecture doesn't have a prebuilt binary, it should compile during install as before.

What's Changed

New Contributors

Full Changelog: WiseLibs/better-sqlite3@v12.12.0...v13.0.0

v12.12.0

What's Changed

[!WARNING]

BREAKING: Starting with Electron v43, binary assets will require glibc 2.41 or higher on Linux hosts.

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot @github

dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automated. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added dependencies Dependency bumps and lockfile changes skip-changeset PR ships nothing to users (pure CI/docs chore) — changeset gate waived labels Aug 10, 2026
@vercel

vercel Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
hotcrm Ignored Ignored Oct 3, 2026 5:00am UTC

Request Review

@dependabot @github

dependabot Bot commented on behalf of github Aug 20, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

1 similar comment
@dependabot @github

dependabot Bot commented on behalf of github Aug 23, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

@dependabot @github

dependabot Bot commented on behalf of github Aug 27, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

Bumps [better-sqlite3](https://github.com/WiseLibs/better-sqlite3) from 12.11.1 to 13.0.3.
- [Release notes](https://github.com/WiseLibs/better-sqlite3/releases)
- [Commits](WiseLibs/better-sqlite3@v12.11.1...v13.0.3)

---
updated-dependencies:
- dependency-name: better-sqlite3
  dependency-version: 13.0.3
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

os-zhuang commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Review: better-sqlite3 12.11.1 to 13.0.3 — measured, nothing breaks

Measured today (2026-09-07) against this PR's head (7144bf6b) merged locally with origin/main (b760fb08). The merge was local, for measurement only; nothing was pushed to this branch.

1. This bump aligns hotcrm with the platform it pins

Read from the installed packages at hotcrm's pinned @objectstack/* 17.3.0, not from the platform's main:

Installed package (17.3.0) Declares
@objectstack/driver-sql optionalDependencies.better-sqlite3: ^13.0.3, devDependencies.better-sqlite3: ^13.0.3
@objectstack/cli optionalDependencies.better-sqlite3: ^13.0.3
@objectstack/plugin-sharing devDependencies.better-sqlite3: ^13.0.3

So hotcrm's current ^12.11.1 is the misaligned state: every platform package at the pinned version already asks for ^13.0.3. This PR closes that gap rather than opening one. (@objectstack/driver-turso is not installed in this app's tree.)

2. Breaking-change sweep, 13.0.0 through 13.0.3

hotcrm has zero first-party usage of the library — git grep -n "better-sqlite3|new Database(" origin/main -- src scripts test returns exactly one hit, a prose comment in test/undeclared-key-probe.test.ts:235. The only consumer is @objectstack/driver-sql, and it does not import the module either: it configures knex with client: 'better-sqlite3', so knex 3.3.0's dialect is the real API surface.

Change in 13.0.x Applies? Evidence
N-API rewrite; prebuild-install dropped; prebuilt binaries ship inside the package Applies (install path only) — strictly better gypfile: false, no install/postinstall script; the only .node files in the package are prebuilds/*.node; build/Release/ contains no compiled binary. See section 3.
engines narrowed to node: ">=22" (was 20.x || 22.x || ...) Does not apply Repo engines.node: ">=22", .nvmrc = 22, every workflow pins node 22.x, and .npmrc has engine-strict=true — the constraint is already satisfied everywhere.
New db.explain() and preparedStatement.toString() Does not apply (additive) Nothing in hotcrm or in knex's dialect calls them.
SqliteError cross-realm / Error.isError compatibility fix Does not apply No first-party code catches or subclasses SqliteError; driver-sql maps knex errors.
13.0.1: parameter binding was overly strict, rejecting plain objects from other realms Does not apply — fixed upstream before this target This PR lands on 13.0.3, which is past the fix.
13.0.2: stricter validation of db.table() parameters Does not apply Virtual tables are not used by knex's dialect nor by driver-sql.
13.0.2: fixed abort when a worker thread terminates Does not apply (benign fix) No worker threads drive SQLite here.
12.12.0 note: Electron v43 binaries need glibc 2.41+ Does not apply No Electron in this app.

The exact knex call shape was exercised against 13.0.3 and passes: new Database(filename, { nativeBinding: undefined, readonly: false }), defaultSafeIntegers(), prepare(), statement.safeIntegers(), statement.reader, statement.all(bindingsArray), statement.run(bindingsArray), result.lastInsertRowid, result.changes, close(). Note that knex passes nativeBinding: undefined explicitly; 13.x's option validator only rejects a non-null value that is neither string nor object, so undefined passes.

One honest caveat: better-auth@1.7.2 declares an optional peer better-sqlite3: ^12.0.0, which 13.0.3 does not satisfy. It caused no install error (.npmrc has auto-install-peers=false, strict-peer-dependencies unset) and no runtime exposure — grep over node_modules/better-auth/dist finds no reference to better-sqlite3 at all; better-auth reaches SQL through kysely here. Worth knowing, not a blocker.

3. Native build: there is no native build any more

This was the stated main risk of the bump. It is the opposite of a risk on 13.x.

$ rm -rf node_modules && pnpm install
Lockfile is up to date, resolution step is skipped
Packages: +684
Progress: resolved 0, reused 678, downloaded 0, added 684, done
Done in 4.1s using pnpm v10.33.0
EXIT=0  elapsed=5s

No node-gyp phase runs, because 13.0.0 moved to the N-API and publishes prebuilt binaries with the package. pnpm install --frozen-lockfile (the CI shape) is also clean, EXIT=0, and reported Packages: +3 -76 against the 12.x tree — the 76 removed packages are the prebuild-install / bindings chain that 13.x no longer needs.

Corollary worth recording: the better-sqlite3 native ABI mismatch gotcha in AGENTS.md (line 549) and docs/MAINTENANCE.md (line 73) describes a failure mode that the N-API binaries structurally remove — a prebuild is not tied to a Node ABI version. The advice stays harmless, but it stops being the likely diagnosis.

4. Verification

pnpm verify — the repo's own chain, validate && typecheck && lint && lint:i18n-gate && hygiene && hygiene:tokens && build && test:

VERIFY_EXIT=0  elapsed=386s
  ✓ Validation passed (1981ms)
  ✓ i18n lint gate: 0 `i18n/missing-*` issues
  ✓ source hygiene clean
  ✓ source token ratchet clean  (authored total ~136,683 / ceiling ~140,000)
 Test Files  161 passed (161)
      Tests  3416 passed | 1 skipped (3417)

pnpm verify is necessary but not sufficient for this particular bump: the suite runs on the memory and sqlite-wasm drivers, and better-sqlite3 appears nowhere in its 523 KB log. So the app was also booted for real on the merged tree, on a wiped .objectstack/data:

  ✓ Server is ready
  Driver:  SqlDriver(better-sqlite3)  → .objectstack/data/objectstack.db
  Tenancy: single
  Plugins: 38 loaded
  Flows:   27 flow(s) 19 bound to triggers

No NODE_MODULE_VERSION flood, and no step-down to wasm — driver-sql logs native better-sqlite3 unavailable ... will step down to wasm SQLite when the native module fails to load, and that line never appeared. Schema sync and seeding ran through knex on 13.0.3: 99 tables created, WAL journal mode, crm_account 9 / crm_contact 9 / crm_lead 21 / crm_opportunity 23 rows written and read back. GET /api/v1/health 200, GET /_console/ 200, GET /api/v1/mcp/skill 200. The only boot warning was the pre-existing seeder budget notice (inline seed exceeded 8000ms, continues in background) — unrelated to this dependency.

5. What is left, and what the maintainer needs to do

CI on this PR is green — 7 successful checks plus Check Changeset skipped by the skip-changeset label already applied — but that run is from 2026-09-03 against head 7144bf6b, and main has moved on. GitHub reports mergeable_state: dirty: pnpm-lock.yaml conflicts with today's main, which is exactly the conflict the local measurement merge had to resolve.

Deviation worth flagging, and a blocker on acting for you: the plan for this review said to comment the dependabot rebase command. The evidence says recreate is the right one instead. Dependabot has reported "tried to update this pull request, but something went wrong" three times here — 2026-08-20, 2026-08-23, 2026-08-27 — and each notice itself recommends the recreate command. The likely reason a rebase keeps failing is visible in the branch: its tip 7144bf6b is a merge commit (Merge branch 'main' into dependabot/npm_and_yarn/better-sqlite3-13.0.3), which is not the linear shape dependabot's rebase expects. recreate discards and regenerates the branch from current main, which also regenerates the stale lockfile. Nothing human-authored would be lost: the PR touches only package.json and pnpm-lock.yaml, both dependabot-generated.

This seat cannot issue that command. The first version of this comment opened with the command written out in full; on posting, the platform rewrote it, injecting U+00B7 MIDDLE DOT characters into every at-mention of the bot in the body (the first line came back as (middle-dot)@(middle-dot)d(middle-dot)ependabot r(middle-dot)ecreate). Read back over the public API, the mangled text can no longer match what dependabot parses, so the command was inert. That rewrite is a deliberate guard against agents triggering bots, so it has not been worked around through another channel — this comment has instead been edited to remove the dead command. A human has to type it.

Maintainer actions:

  1. Comment the dependabot recreate command yourself — the bot's own name with a leading at-sign, then recreate — so the branch is rebuilt against current main, then wait for the fresh CI run. Nothing in this review requires a rebase of a different shape; recreate is what dependabot's own three failure notices ask for.
  2. Merge it yourself. This repo's AGENTS.md authorises no seat merge action — measured today, carded as AGENTS.md says nothing about how a green PR lands — no seat can tell whether it may enable auto-merge, mark ready, or must leave it to the maintainer #1742 — so no auto-merge has been armed, nothing has been marked ready, and no review has been submitted from here.

Separately, and unrelated to whether this merges: dependabot's very first comment on this PR reports that the label automated named in .github/dependabot.yml does not exist in this repository, so dependabot cannot label its PRs. That is a repo-configuration defect worth its own card.


Generated by Claude Code

claude added 2 commits October 3, 2026 03:34
Brings the better-sqlite3 12.11.1 -> 13.0.3 bump onto main 25cd8d7.
The only conflict was pnpm-lock.yaml: main's side was taken and the
lockfile was regenerated with pnpm install (pnpm 10.33.0); package.json
keeps the single specifier change. The 12.x prebuild-install chain
drops out of the tree.

Claude-Session: https://claude.ai/code/session_01ER8ntXZhYebyQ66aXWdjfT
Co-authored-by: Claude <noreply@anthropic.com>
Refreshes the better-sqlite3 12.11.1 -> 13.0.3 bump onto main 2e3a8b4
(after the tsx bump landed). The only conflict was pnpm-lock.yaml:
main's side was taken and the lockfile was regenerated with pnpm
install (pnpm 10.33.0); package.json keeps the single specifier change.

Claude-Session: https://claude.ai/code/session_01ER8ntXZhYebyQ66aXWdjfT
Co-authored-by: Claude <noreply@anthropic.com>
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Oct 3, 2026
Merged via the queue into main with commit a1c2c9d Oct 3, 2026
9 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/better-sqlite3-13.0.3 branch October 3, 2026 05:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency bumps and lockfile changes skip-changeset PR ships nothing to users (pure CI/docs chore) — changeset gate waived

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants