nodejs / nodejs/node

SQLite in core: maintenance trade-offs compared with other language ecosystems

Ouverte
#65,974 1 commentaire 3 réactions 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

question
Langage dominant
JavaScript
Étoiles
122k
Forks
37.3k
Merge moyen
4 j 2 h
PR mergées (30 j)
283

Description

I've been reading #49663 and #53264 to understand how SQLite ended up in Node core. I understand that it was first accepted for localStorage, and that exposing node:sqlite followed from that.

Looking at other ecosystems, there seem to be a few different approaches:

  • Python includes the sqlite3 wrapper in its standard library, though how the SQLite engine is supplied depends on the distribution.
  • Java provides JDBC, while SQLite support comes through a separate driver.
  • .NET provides an official Microsoft.Data.Sqlite package, installed separately through NuGet.
  • Go provides database/sql and leaves the actual drivers to external packages.
  • Bun and Deno both provide built-in SQLite APIs.

The .NET approach seems particularly interesting here: users get an officially maintained integration, but its updates can be delivered separately from the runtime.

Given that Node already needs SQLite for localStorage, how much additional maintenance and security exposure comes from offering the broader public API? Was an official, separately distributed binding considered, and what made keeping it in core preferable?

I'm also curious how this works in practice when SQLite publishes a security fix. Where can users find out whether it affects Node's build and exposed functionality, and whether a Node update is needed?

A short explanation of these trade-offs in the docs would be useful. The original issues explain the path to inclusion, but I still have trouble understanding the long-term maintenance implications. Happy to be pointed to an existing discussion if I've missed it.

Guide de contribution

Ouvrir le guide de contribution

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Piste de recherche

Commencez par lire les issues #49663 et #53264, puis examinez la documentation actuelle de node:sqlite. Ajoutez une explication concise des compromis de maintenance, de la raison pour laquelle SQLite reste dans le core et de la manière dont les utilisateurs peuvent déterminer si les correctifs de sécurité de SQLite nécessitent une mise à jour de Node.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
nodejs, sqlite
Domaine
documentation
Type d'issue
Documentation
Difficulté
3/5
Temps estimé
1-2 jours
Activité
Active
Clarté
Plutôt claire
Accessibilité débutants
55/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.