Skip to content

fix(deps): upgrade sqlparse to 0.6.0 for security fixes - #241

Merged
matrixise merged 1 commit into
masterfrom
security/upgrade-sqlparse
Sep 24, 2026
Merged

matrixise merged 1 commit into
masterfrom
security/upgrade-sqlparse

Conversation

@matrixise

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades sqlparse from 0.5.5 to 0.6.0
  • Resolves 5 open Dependabot alerts (high/medium): quadratic CPU consumption during tuple list reindentation and comment grouping, ReDoS on dollar-quoted SQL literals, unbounded value materialization in TokenList.__init__ before depth/token caps trigger, and SQL string breakout via unescaped backslashes in generated Python/PHP snippets
  • Advisories: GHSA-cfqr-cjx5-5jcm, GHSA-prg7-hcfm-mfcr, GHSA-pwgv-4x5q-6m9f, GHSA-f2ff-p2ww-7p4p, GHSA-3496-9g83-7v6x

Test plan

  • python manage.py test pythonie --settings=pythonie.settings.tests (SQLite, 7/7 passed)
  • ruff check pythonie clean

@matrixise
matrixise force-pushed the security/upgrade-sqlparse branch from 949f3ee to 956bd32 Compare September 24, 2026 06:36
Resolves multiple high/medium severity Dependabot alerts: quadratic CPU
consumption during tuple list reindentation and comment grouping,
ReDoS on dollar-quoted SQL literals, unbounded value materialization
in TokenList.__init__ before depth/token caps trigger, and SQL string
breakout via unescaped backslashes in generated Python/PHP snippets.

GHSA-cfqr-cjx5-5jcm, GHSA-prg7-hcfm-mfcr, GHSA-pwgv-4x5q-6m9f,
GHSA-f2ff-p2ww-7p4p, GHSA-3496-9g83-7v6x

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@matrixise
matrixise force-pushed the security/upgrade-sqlparse branch from 956bd32 to 2a79c79 Compare September 24, 2026 06:36
@matrixise
matrixise merged commit 903de2a into master Sep 24, 2026
0 of 2 checks passed
@matrixise
matrixise deleted the security/upgrade-sqlparse branch September 24, 2026 06:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant