Skip to content

[CT-2533] [Feature] Support sqlparse 0.4.4 #7515

@lukehsiao

Description

@lukehsiao

Is this your first time submitting a feature request?

  • I have read the expectations for open source contributors
  • I have searched the existing issues, and I could not find an existing issue for this feature
  • I am requesting a straightforward extension of existing dbt functionality, rather than a Big Idea better suited to a discussion

Describe the feature

sqlparse <0.4.4 contains a moderate security vulnerability: GHSA-rrm6-wvj7-cwh2

dbt-core has started to pin to <0.4.4 in #7394 which makes it difficult for packages using dbt to update to the fixed version.

Would it be possible for dbt to support v0.4.4?

Describe alternatives you've considered

The answer might just be "no". In which case we will have to wait until a new version of sqlparse addresses the issue. It does not seem like there is anything upstream sqlparse tracking work to resolve #7396. So, if the answer is no, then I would hope the appropriate effort upstream can be made so we have a path forward eventually.

Who will this benefit?

All users of dbt-core who want to update to a non-vulnerable sqlparse version.

Are you interested in contributing this feature?

No response

Anything else?

No response

Metadata

Metadata

Assignees

Labels

dependency_conflictsPython dependencies that are too narrow or in conflictenhancementNew feature or requesthelp_wantedTrickier changes, with a clear starting point, good for previous/experienced contributors

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions