Skip to content

Update Microsoft.Data.Sqlite to 10.0.11 - #304

Merged
Michael Jolley (michaeljolley) merged 3 commits into
microsoft:mainfrom
yeelam-gordon:fix/sqlite-native-update
Sep 8, 2026
Merged

Michael Jolley (michaeljolley) merged 3 commits into
microsoft:mainfrom
yeelam-gordon:fix/sqlite-native-update

Conversation

@yeelam-gordon

@yeelam-gordon Gordon Lam (yeelam-gordon) commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Update the existing direct dependency Microsoft.Data.Sqlite from 10.0.10 to 10.0.11. This is the only code change in this PR.

Why this version

Microsoft.Data.Sqlite 10.0.10 selects SQLitePCLRaw 2.1.11, including the old native SQLite package. The 10.0.11 package declares dependencies on SQLitePCLRaw bundle/core 2.1.12, so updating the higher-level dependency brings in the updated native library without an explicit transitive-package override.

Resolved dependency chain:

Microsoft.Data.Sqlite 10.0.11
  -> SQLitePCLRaw.bundle_e_sqlite3 2.1.12
     -> SQLitePCLRaw.lib.e_sqlite3 2.1.12 (native SQLite 3.53.3)

No additional package references, version-assertion tests, database schema changes, or save-behavior changes. The existing PowerToysPublicDependencies NuGet configuration is unchanged.

Validation

  • Restored through the existing feed and confirmed the application dependency graph selects the 2.1.12 native package rather than 2.1.11.
  • Existing Release x64 datastore/persistence tests passed; no new tests were added.
  • Native SQLite 3.53.3 was confirmed from the restored 2.1.12 Windows x64 DLL.
  • CI and official Component Governance scan confirmation remain pending; this PR does not claim dashboard alert closure.

Add an explicit bundle reference so Microsoft.Data.Sqlite resolves the updated native SQLite library. Add a runtime-version regression test.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 29358262-0349-4b94-92cd-209de73b0420
Copilot AI lite review requested due to automatic review settings September 8, 2026 01:17

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change is small and low-risk, and the added test directly validates the native SQLite runtime version requirement.

Pull request overview

This PR updates the SQLite native bundle used by the extension to ensure the runtime loads a SQLite version that meets the security advisory minimum, independent of the broader .NET 10 migration work.

Changes:

  • Add an explicit SQLitePCLRaw.bundle_e_sqlite3 2.1.12 package reference to override the transitive 2.1.11 selection.
  • Add a unit test that opens an in-memory SQLite connection and asserts sqlite_version() is at least 3.50.2.
File summaries
File Description
GitHubExtension/GitHubExtension.csproj Pins SQLitePCLRaw bundle to 2.1.12 to ensure the updated native SQLite is used.
GitHubExtension.Test/DataStoreTests/DataObjectTests.cs Adds a regression test validating the loaded native SQLite version meets the minimum required version.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread GitHubExtension.Test/DataStoreTests/DataObjectTests.cs Outdated
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 29358262-0349-4b94-92cd-209de73b0420
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 29358262-0349-4b94-92cd-209de73b0420
@yeelam-gordon Gordon Lam (yeelam-gordon) changed the title Update SQLite native bundle to 2.1.12 Update Microsoft.Data.Sqlite to 10.0.11 Sep 8, 2026
@michaeljolley
Michael Jolley (michaeljolley) merged commit 16906fe into microsoft:main Sep 8, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants