-
Notifications
You must be signed in to change notification settings - Fork 2.2k
Closed
Labels
dependency_conflictsPython dependencies that are too narrow or in conflictPython dependencies that are too narrow or in conflictenhancementNew feature or requestNew feature or requesthelp_wantedTrickier changes, with a clear starting point, good for previous/experienced contributorsTrickier changes, with a clear starting point, good for previous/experienced contributors
Milestone
Description
Is this your first time submitting a feature request?
- I have read the expectations for open source contributors
- I have searched the existing issues, and I could not find an existing issue for this feature
- I am requesting a straightforward extension of existing dbt functionality, rather than a Big Idea better suited to a discussion
Describe the feature
sqlparse <0.4.4 contains a moderate security vulnerability: GHSA-rrm6-wvj7-cwh2
dbt-core has started to pin to <0.4.4 in #7394 which makes it difficult for packages using dbt to update to the fixed version.
Would it be possible for dbt to support v0.4.4?
Describe alternatives you've considered
The answer might just be "no". In which case we will have to wait until a new version of sqlparse addresses the issue. It does not seem like there is anything upstream sqlparse tracking work to resolve #7396. So, if the answer is no, then I would hope the appropriate effort upstream can be made so we have a path forward eventually.
Who will this benefit?
All users of dbt-core who want to update to a non-vulnerable sqlparse version.
Are you interested in contributing this feature?
No response
Anything else?
No response
petermorrowdev, dimoschi, nickozilla, cmanou, aksestok and 4 more
Metadata
Metadata
Assignees
Labels
dependency_conflictsPython dependencies that are too narrow or in conflictPython dependencies that are too narrow or in conflictenhancementNew feature or requestNew feature or requesthelp_wantedTrickier changes, with a clear starting point, good for previous/experienced contributorsTrickier changes, with a clear starting point, good for previous/experienced contributors