nodejs / nodejs/node

SQLite in core: maintenance trade-offs compared with other language ecosystems

Aperta
#65,974 1 commento 3 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

question
Lingua principale
JavaScript
Stelle
122k
Fork
37.3k
Merge medio
4g 2h
PR unite (30g)
283

Descrizione

I've been reading #49663 and #53264 to understand how SQLite ended up in Node core. I understand that it was first accepted for localStorage, and that exposing node:sqlite followed from that.

Looking at other ecosystems, there seem to be a few different approaches:

  • Python includes the sqlite3 wrapper in its standard library, though how the SQLite engine is supplied depends on the distribution.
  • Java provides JDBC, while SQLite support comes through a separate driver.
  • .NET provides an official Microsoft.Data.Sqlite package, installed separately through NuGet.
  • Go provides database/sql and leaves the actual drivers to external packages.
  • Bun and Deno both provide built-in SQLite APIs.

The .NET approach seems particularly interesting here: users get an officially maintained integration, but its updates can be delivered separately from the runtime.

Given that Node already needs SQLite for localStorage, how much additional maintenance and security exposure comes from offering the broader public API? Was an official, separately distributed binding considered, and what made keeping it in core preferable?

I'm also curious how this works in practice when SQLite publishes a security fix. Where can users find out whether it affects Node's build and exposed functionality, and whether a Node update is needed?

A short explanation of these trade-offs in the docs would be useful. The original issues explain the path to inclusion, but I still have trouble understanding the long-term maintenance implications. Happy to be pointed to an existing discussion if I've missed it.

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Direzione di ricerca

Inizia leggendo le issue #49663 e #53264, quindi esamina la documentazione attuale di node:sqlite. Aggiungi una spiegazione concisa dei compromessi di manutenzione, del motivo per cui SQLite rimane nel core e di come gli utenti possano determinare se le correzioni di sicurezza di SQLite richiedono un aggiornamento di Node.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
nodejs, sqlite
Ambito
documentation
Tipo di issue
Documentazione
Difficoltà
3/5
Tempo stimato
1-2 giorni
Stato di attività
Attiva
Chiarezza
Abbastanza chiara
Idoneità per principianti
55/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.