The SQLite3 Multiple Ciphers amalgamation, byte for byte as released, for -sys crates to compile with their own options. It compiles nothing and sets no defines, so every consumer keeps its own flags while one Cargo.lock gives them all the same source.
let dir = sqlite3mc_src::source_dir();
assert!(dir.join(sqlite3mc_src::SOURCE_FILE).is_file());
assert!(dir.join(sqlite3mc_src::HEADER_FILE).is_file());The version encodes the release, so 205.1.x is SQLite3MC 2.5.1. A 205.1 requirement also accepts later 2.5 patch releases, never 2.6. Those may wrap a newer SQLite, named by SQLITE_VERSION, so a -sys crate with committed bindings regenerates them.
SQLite3MC is MIT licensed. The amalgamation also carries public-domain code (SQLite among it), a password-hashing file under CC0-1.0, a block under the Unlicense, and Argon2 under CC0-1.0 or Apache-2.0.
A daily workflow in the repository opens a pull request for each new SQLite3MC release, taking the archive's checksum only from the release's Sigstore-signed SHA256SUMS. CI re-runs upgrade.sh, which checks that signature again before trusting the pinned checksum, to prove the vendored bytes match the pinned release. It also compiles the packaged sources natively and through sqlite-wasm-rs, and checks that each build opens the other's files in every cipher, under Node and in headless Chrome and Firefox, on OPFS too.
CI also runs SQLite3MC's own tests, a rekey of every cipher and SQLite's TCL suite through the shipped amalgamation, once plainly and once under the address and undefined-behaviour sanitizers, with every expected failure named and explained.