Skip to content

meta: audit minimum supported Node.js and database versions #2

Description

@wikirik-agent

Summary

Sequelize v7 still declares support for several Node.js and database versions that are past upstream end-of-life, and the "oldest"/"latest" Docker images we test against have drifted from both the declared minimums and from what upstream still maintains. Since v7 is still in alpha, this is the cheapest moment to raise the floors.

This issue audits every supported target: what we declare today, what upstream still supports, what the minimum should be, and which Docker image corresponds to it. All dates verified 2026-09-12; sources are linked at the bottom.

Current state

Declared Node.js floor (engines.node):

Package Declared
@sequelize/core ^20.9.0 || ^22.11.0 || >=24.0.0
@sequelize/utils ^20.9.0 || ^22.11.0 || >=24.0.0
@sequelize/cli ^20.19.0 || ^22.13.0 || >=24.0.0

CI matrix: Node [20, 22, 24].

Declared database floors (minimumDatabaseVersion) and the images we test:

Dialect minimumDatabaseVersion oldest image latest image
postgres 11.0.0 postgis/postgis:11-2.5 postgis/postgis:17-3.5
mysql 8.0.20 mysql:8.0.20 mysql:8.4.8
mariadb 10.4.30 mariadb:10.4.30 mariadb:11.6.2
sqlite3 3.8.0 n/a (bundled) n/a (bundled)
mssql 14.0.1000 (2017) mcr.microsoft.com/mssql/server:2017-latest (CI job disabled) …:2025-latest
db2 1.0.0 (placeholder) icr.io/db2_community/db2:11.5.5.1 …:12.1.4.0
ibmi 7.3.0 none (not CI-tested) none
snowflake 5.7.0 none none
oracle 18.0.0 gvenzl/oracle-xe:18-slim gvenzl/oracle-free:23.26.1-slim

Proposed minimums

Target Today Upstream status Proposed floor oldest image latest image
Node.js 20.9 20 EOL 2026-04-30 22.13.0 – –
PostgreSQL 11 11/12/13 EOL; 14 EOL 2026-11-12 15 postgis/postgis:15-3.5 postgis/postgis:18-3.6
MySQL 8.0.20 8.0 → Sustaining Support 2026-04-21 8.4.0 mysql:8.4.11 mysql:9.7.2
MariaDB 10.4.30 10.4 EOL 2024-06-18 10.11.0 (or 11.4) mariadb:10.11.19 mariadb:12.3.3
SQLite 3.8.0 n/a 3.35.0 – –
SQL Server 2017 2017 extended EOL 2027-10-12 2019 (15.0.2000) …/mssql/server:2019-latest …:2025-latest
Db2 LUW 1.0.0 11.5 EOS 2027-04-30 11.5.9 icr.io/db2_community/db2:11.5.9.0 …:12.1.5.0
Db2 for IBM i 7.3 7.3 SP support ended 2023-09-30 7.5 none available none available
Snowflake 5.7.0 SaaS, no versions n/a – –
Oracle 18c 18c premier ended 2021-06-30 19c (see open question) gvenzl/oracle-xe:21-slim gvenzl/oracle-free:23.26.3-slim

Details

Node.js — drop 20, floor at 22.13.0

Node 20 (Iron) reached end-of-life on 2026-04-30 (last release 20.20.2, 2026-03-24). Node 22 (Jod) is in maintenance until 2027-04-30, Node 24 (Krypton) is Active LTS until 2026-10-20 with EOL 2028-04-30, and Node 26 became Current on 2026-05-05 and enters Active LTS in October 2026.

Proposal: ^22.13.0 || >=24.0.0 across all packages (currently @sequelize/cli already sits at 22.13, the rest at 22.11 — worth aligning on one floor). CI matrix becomes [22, 24, 26].

Driver floors that already constrain us, and which make 20 hard to keep:

Driver Latest engines.node
tedious 20.0.0 >=22
snowflake-sdk 3.3.0 >=20
sqlite3 6.0.1 >=20.17.0
odbc 2.5.0 >=20.0.0
mariadb 3.5.4 >= 20.0.0
mysql2 3.24.4 >= 8.0 (stale metadata)
pg 8.23.0 >= 16.0.0
oracledb 7.0.1 >=14.17

Note tedious@20 requires Node ≥ 22, so upgrading the mssql driver is blocked until Node 20 is dropped.

PostgreSQL — 11 → 15

PostgreSQL 11 went EOL 2023-11-09, 12 on 2024-11-21, 13 on 2025-11-13. PostgreSQL 14 goes EOL 2026-11-12 — two months from now — so 14 is not worth picking as a new floor. 15 is supported until 2027-11-11.

A floor of ≥ 13 also lets us delete the version branch in packages/postgres/src/query-generator-typescript.internal.ts:278, which falls back to uuid_generate_v4() (requires the uuid-ossp extension) on Postgres < 13 instead of the built-in gen_random_uuid().

latest should also move from Postgres 17 to 18 (released 2025-09-25); postgis/postgis:18-3.6 is published.

MySQL — 8.0.20 → 8.4.0

MySQL 8.0 moved to Oracle Lifetime Sustaining Support on 2026-04-21; Oracle's EOL notice explicitly tells users to move to 8.4 LTS or 9.7 LTS. 8.4 LTS has Premier Support until 2029-04-30 and Extended until 2032-04-30. 9.7 LTS shipped 2026-04-21 with Premier Support to 2034.

Proposal: floor 8.4.0, oldest → mysql:8.4.11, latest → mysql:9.7.2.

Bonus: this retires the mysql:8.0.x CI job, whose server-side crash in the include/limit tests has been a recurring source of flakes.

MariaDB — 10.4.30 → 10.11 (or 11.4)

MariaDB 10.4 went EOL 2024-06-18 and 10.5 on 2025-06-24. 10.6 LTS went EOL on 2026-07-06, so it is not a candidate either. The remaining community-supported LTS lines are 10.11 (EOL 2028-02-16), 11.4 (EOL 2029-05-29), 11.8 (EOL 2028-06-04) and 12.3 (EOL 2029-06-12).

Also worth noting: our latest is pinned to mariadb:11.6.2, a rolling release that is already out of support. latest should track an LTS — mariadb:12.3.3.

Open question: 10.11 is the conservative choice (still supported for ~18 months); 11.4 buys nearly 3 years and lets us drop more compatibility branches. Preference?

SQLite — 3.8.0 is both unreachable and wrong

minimumDatabaseVersion: '3.8.0' dates to SQLite 3.8.0 (2013-08-26). Two problems:

  1. The sqlite3 driver bundles its own SQLite — sqlite3@6.0.1 ships SQLite 3.52.0 (verified locally via select sqlite_version()), so the declared floor only ever applies to custom/system-SQLite builds.
  2. It is factually wrong regardless: packages/sqlite3/src/dialect.ts:48 declares returnValues: 'returning', and RETURNING requires SQLite 3.35.0 (2021-03-12).

Proposal: raise to 3.35.0 at minimum.

Separate concern worth tracking: TryGhost/node-sqlite3 was marked unmaintained in v6.0.0 and the repository was archived on 2026-07-01. The README states "This repository is currently unmaintained. We will not update any of its issues or pull requests." We should decide on a path: node:sqlite (flag-free since Node 22.13/23.4, stability 1.2 "release candidate" as of Node 24), better-sqlite3, or @libsql/client. If we land on node:sqlite, that is another argument for a Node 22.13 floor.

SQL Server — 2017 → 2019, and re-enable the oldest job

SQL Server 2017 mainstream support ended 2022-10-11; extended support runs to 2027-10-12. More practically, the test-mssql-oldest CI job has been commented out in .github/workflows/ci.yml since sequelize#17772 because the 2017 image does not run on ubuntu-22.04 or later, so we currently have zero coverage of our declared minimum.

SQL Server 2019 left mainstream support 2025-02-28 but has extended support until 2030-01-08, and mcr.microsoft.com/mssql/server:2019-latest runs fine on current runners. Moving the floor to 15.0.2000 restores a working oldest job and removes the release job's TODO.

Db2 LUW — replace the 1.0.0 placeholder

minimumDatabaseVersion: '1.0.0' in packages/db2/src/dialect.ts:96 is a placeholder that disables version checking entirely. Db2 11.5 has end of support on 2027-04-30; 12.1 (released 2024-11-14) is current.

The db2_community/db2 registry publishes exactly these tags: 11.5.5.1, 11.5.8.0, 11.5.9.0, 12.1.0.0–12.1.5.0, latest. We pin oldest to 11.5.5.1, which is two mod packs behind the oldest useful 11.5 image.

Proposal: declare 11.5.9.0, move oldest → 11.5.9.0 and latest → 12.1.5.0.

Db2 for IBM i — 7.3 → 7.5

IBM i 7.3 left Service Pack Support on 2023-09-30 (Extended Life Cycle Support to 2028-09-30). IBM i 7.4 leaves Service Pack Support on 2026-09-30 — in two weeks. 7.5 (2022-05-10) and 7.6 (2025-04-18) remain fully supported.

Proposal: floor 7.5. Note there is no IBM i container image, so this dialect has no CI coverage at any version; the floor is a documentation/enforcement decision only.

Snowflake — 5.7.0 is a leftover

packages/snowflake/src/dialect.ts:173 declares minimumDatabaseVersion: '5.7.0', which is a MySQL version inherited from whichever dialect this was forked from. Snowflake is a managed service with no customer-selectable engine version, so no version gate is meaningful here. Proposal: document it as not applicable (and/or set it to 0.0.0 with a comment).

Documentation drift found along the way

  • CONTRIBUTING.md:161-165 is stale: it advertises MariaDB 11.3, MySQL 8.3, Postgres 15 and Db2 11.5.9 as latest, while the compose files actually use 11.6.2, 8.4.8, 17 and 12.1.4.0. It also omits the oracle start scripts entirely.
  • https://sequelize.org/releases/ states v7 requires Node >= 18 and supports MSSQL 2017–2022, contradicting package.json (^20.9.0 || ^22.11.0 || >=24.0.0) and the 2025 image we test. CONTRIBUTING.md:185 points contributors at that page as the source of truth for minimum versions, so it needs to be updated as part of any change here.

Open questions

  1. MariaDB: 10.11 (conservative) or 11.4 (longer runway)?
  2. PostgreSQL: 15, or go to 14 for one more release cycle despite its November 2026 EOL?
  3. Oracle: 19c is the Long-Term Release (Premier to 2029-12-31, Extended to 2032-12-31), but there is no free 19c container — Oracle XE went 18c → 21c, so the only publicly pullable images are gvenzl/oracle-xe:21-slim (21c, Premier ends 2027-07-31) and gvenzl/oracle-free (23ai/26ai). Do we declare 19c and test on 21c, accepting that the declared floor is untested, or declare 21c so the floor matches what CI runs?
  4. Should the floors move now (v7 alpha) in one breaking change, or be staged?

Sources

Node.js

PostgreSQL

MySQL

MariaDB

SQLite

SQL Server

Db2 / IBM i

Oracle

Container image tags were enumerated from the Docker Hub / MCR / ICR registry APIs on 2026-09-12.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions