Bump sqlparse from 0.4.3 to 0.4.4
Created by: dependabot[bot]
Bumps sqlparse from 0.4.3 to 0.4.4.
Changelog
Sourced from sqlparse's changelog.
Release 0.4.4 (Apr 18, 2023)
Notable Changes
- IMPORTANT: This release fixes a security vulnerability in the parser where a regular expression vulnerable to ReDOS (Regular Expression Denial of Service) was used. See the security advisory for details: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-rrm6-wvj7-cwh2 The vulnerability was discovered by
@erik-krogh
from GitHub Security Lab (GHSL). Thanks for reporting!Bug Fixes
- Revert a change from 0.4.0 that changed IN to be a comparison (issue694). The primary expectation is that IN is treated as a keyword and not as a comparison operator. That also follows the definition of reserved keywords for the major SQL syntax definitions.
- Fix regular expressions for string parsing.
Other
- sqlparse now uses pyproject.toml instead of setup.cfg (issue685).
Commits
-
647d145
Update Changelog. -
58dae6f
Bump version. -
d9d69f4
Removed test file -
64bb91f
Testing branch -
c457abd
Remove unnecessary parts in regex for bad escaping. -
b949fdf
CI: Use codecov action. -
fc76056
Cleanup regex for detecting keywords (fixes #709). -
7fdb2da
Merge pull request #633 from shikanime/master -
dd9d5b9
Fix get_type with comments between WITH keyword -
907fb49
change singleton behavior - Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.