Skip to content

build(deps): bump github.com/openclaw/crawlkit from 0.16.4 to 0.16.5 - #257

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/openclaw/crawlkit-0.16.5
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/openclaw/crawlkit-0.16.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/openclaw/crawlkit from 0.16.4 to 0.16.5.

Release notes

Sourced from github.com/openclaw/crawlkit's releases.

v0.16.5

0.16.5 - 2026-09-22

Highlights: Safer sidecar paths and a faster SQLite runtime.

  • Reject overlapping sidecar roots expressed with mixed relative and absolute paths, and reject nested destination directory symlinks before copying so managed files cannot be written outside the target or pruned through an alias.
  • Preserve literal whitespace in sidecar directory names and reject ambiguous Windows directory aliases so sync cannot overwrite or prune a different, trimmed destination.
  • Update the SQLite driver to v1.59.0 with its required libc v1.75.7 runtime for faster Linux memory operations and fewer callback allocations, retaining the Go 1.27.0 minimum.
Changelog

Sourced from github.com/openclaw/crawlkit's changelog.

0.16.5 - 2026-09-22

Highlights: Safer sidecar paths and a faster SQLite runtime.

  • Reject overlapping sidecar roots expressed with mixed relative and absolute paths, and reject nested destination directory symlinks before copying so managed files cannot be written outside the target or pruned through an alias.
  • Preserve literal whitespace in sidecar directory names and reject ambiguous Windows directory aliases so sync cannot overwrite or prune a different, trimmed destination.
  • Update the SQLite driver to v1.59.0 with its required libc v1.75.7 runtime for faster Linux memory operations and fewer callback allocations, retaining the Go 1.27.0 minimum.
Commits
  • 493f747 chore: prepare crawlkit 0.16.5 (#141)
  • 7f5b176 build(deps): refresh SQLite runtime and security actions (#140)
  • f9914f2 fix(snapshot): preserve literal sidecar directory names (#139)
  • a7c7ca0 fix(snapshot): contain sidecar copies and reject aliased overlaps (#138)
  • 1d5f12f chore: open next unreleased section (#137)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/openclaw/crawlkit](https://github.com/openclaw/crawlkit) from 0.16.4 to 0.16.5.
- [Release notes](https://github.com/openclaw/crawlkit/releases)
- [Changelog](https://github.com/openclaw/crawlkit/blob/main/CHANGELOG.md)
- [Commits](openclaw/crawlkit@v0.16.4...v0.16.5)

---
updated-dependencies:
- dependency-name: github.com/openclaw/crawlkit
  dependency-version: 0.16.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 27, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 27, 2026 20:12
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 27, 2026
@clawsweeper

clawsweeper Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 27, 2026
@clawsweeper

clawsweeper Bot commented Sep 27, 2026

Copy link
Copy Markdown

Codex review: needs maintainer review before merge. Reviewed September 27, 2026, 4:15 PM ET / 20:15 UTC.

ClawSweeper review

What this changes

Updates Slacrawl’s CrawlKit dependency from 0.16.4 to 0.16.5 and replaces its Go module checksums.

Merge readiness

✅ Ready for maintainer review

Current main and the latest release still use CrawlKit 0.16.4, so this update remains useful. The pinned diff and dependency release show no concrete introduced defect.

Priority: P3
Reviewed head: 69c76784dea89dd6b759746ddbfa8b84c448dc81

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) The small, coherent version and checksum update has no identified patch defect; routine dependency validation remains with the normal merge process.
Proof confidence 🌊 off-meta tidepool Not applicable: This bot-authored dependency update has no contributor proof requirement. The inspected evidence identifies Slacrawl’s production CrawlKit store use, but contains no after-update runtime demonstration; no stored-data contract changes in this PR.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: This bot-authored dependency update has no contributor proof requirement. The inspected evidence identifies Slacrawl’s production CrawlKit store use, but contains no after-update runtime demonstration; no stored-data contract changes in this PR.
Evidence reviewed 6 items Introduced dependency change: The pinned PR diff changes only CrawlKit 0.16.4 to 0.16.5 in go.mod and the matching two checksums in go.sum.
Current-main version: The target main revision still pins CrawlKit 0.16.4; the latest Slacrawl changelog also names 0.16.4 for v0.10.1.
Dependency use: Slacrawl opens its database through CrawlKit’s store package, establishing that this dependency is used by production code.
Findings None None.
Security None None.

How this fits together

Slacrawl uses CrawlKit for local database access, Git-backed archive sharing, and command-line features. The Go module version selects the library implementation used by those paths.

flowchart LR
A[Slacrawl commands] --> B[Archive and database operations]
B --> C[CrawlKit library]
D[Go module version] --> C
C --> E[Local database and Git archive]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

None.

Technical review

Best possible solution:

Keep the version bump focused and allow the repository’s normal dependency checks and merge process to validate it.

Do we have a high-confidence way to reproduce the issue?

Not applicable: this PR proposes a dependency update rather than reporting a reproducible bug.

Is this the best way to solve the issue?

Yes: a single version and checksum update is the narrowest path for adopting this CrawlKit release.

AGENTS.md: not found in the target repository.

Codex review notes: model internal, reasoning medium; reviewed against 66a97e2e6346.

Labels

Label changes:

  • add P3: This is a small dependency maintenance update with no demonstrated urgent user-facing failure.
  • add rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • add status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: This bot-authored dependency update has no contributor proof requirement. The inspected evidence identifies Slacrawl’s production CrawlKit store use, but contains no after-update runtime demonstration; no stored-data contract changes in this PR.

Label justifications:

  • P3: This is a small dependency maintenance update with no demonstrated urgent user-facing failure.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: This bot-authored dependency update has no contributor proof requirement. The inspected evidence identifies Slacrawl’s production CrawlKit store use, but contains no after-update runtime demonstration; no stored-data contract changes in this PR.

Evidence

What I checked:

  • Introduced dependency change: The pinned PR diff changes only CrawlKit 0.16.4 to 0.16.5 in go.mod and the matching two checksums in go.sum. (go.mod:12, 69c76784dea8)
  • Current-main version: The target main revision still pins CrawlKit 0.16.4; the latest Slacrawl changelog also names 0.16.4 for v0.10.1. (go.mod:12, 66a97e2e6346)
  • Dependency use: Slacrawl opens its database through CrawlKit’s store package, establishing that this dependency is used by production code. (internal/store/store.go:25, 69c76784dea8)
  • Existing SQLite runtime versions: The main branch already pins SQLite 1.59.0 and libc 1.75.7, the runtime versions named in CrawlKit 0.16.5’s release notes. (go.mod:47, 69c76784dea8)
  • Dependency release scope: The verified v0.16.5 release describes sidecar path hardening and SQLite runtime updates. The version comparison changes CrawlKit’s sidecar implementation and go.mod; no Slacrawl source imports CrawlKit’s snapshot package. (snapshot/sidecar.go:30, 493f7470c5e3)
  • Recent dependency history: Recent go.mod history includes the main-branch CrawlKit 0.16.4 update and earlier dependency maintenance, providing routing context without establishing feature introduction. (go.mod:12, 66a97e2e6346)

Likely related people:

  • steipete: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • Vincent Koc: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@steipete

Copy link
Copy Markdown
Collaborator

Thanks for the dependency update. Superseded by #260, which updates CrawlKit directly to 0.16.6 with passing full checks and independent review. That replacement is ready and awaiting the repository's required code-owner approval.

@steipete steipete closed this Sep 30, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/go_modules/github.com/openclaw/crawlkit-0.16.5 branch September 30, 2026 03:37
steipete added a commit that referenced this pull request Oct 2, 2026
Update CrawlKit from v0.16.4 to v0.16.6 and record it in the changelog. Only CrawlKit changes in go.mod/go.sum; no indirect versions move. Supersedes #257.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

build dependencies Pull requests that update a dependency file go Pull requests that update go code other P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants