|
1 | 1 | { |
2 | 2 | "vcs_url": "https://github.com/dbt-labs/dbt-core", |
3 | 3 | "vulnerabilities": { |
| 4 | + "CVE-2026-54284": { |
| 5 | + "d7675026bb1cd8595102ec5df4f886c4168fb3b3": "chore(deps): allow sqlparse 0.6.0 to pick up parser DoS fixes (#15989) (#16013)\n\nBackport of defa080fb5f65f574d9b2a589eba55893d4bf958 to 1.12.latest.\n\nsqlparse 0.6.0 is the fixed release for CVE-2026-54284, CVE-2026-59893,\nCVE-2026-59894 and CVE-2026-71491 (parser denial-of-service). Widen the\nceiling from <0.6.0 to <0.7.0 so those fixes can be installed.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>", |
| 6 | + "7c83cc111cf5d3a066a7b27cef7569de9051c5f6": "chore(deps): allow sqlparse 0.6.0 to pick up parser DoS fixes (#15989) (#16014)\n\nBackport of defa080fb5f65f574d9b2a589eba55893d4bf958 to 1.13.latest.\n\nsqlparse 0.6.0 is the fixed release for CVE-2026-54284, CVE-2026-59893,\nCVE-2026-59894 and CVE-2026-71491 (parser denial-of-service). Widen the\nceiling from <0.6.0 to <0.7.0 so those fixes can be installed.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>", |
| 7 | + "a5784247873fb3eecf84f858e5101f4640661fa2": "chore(deps): allow sqlparse 0.6.0 to pick up parser DoS fixes (#15989) (#16012)\n\nBackport of defa080fb5f65f574d9b2a589eba55893d4bf958 to 1.11.latest.\n\nsqlparse 0.6.0 is the fixed release for CVE-2026-54284, CVE-2026-59893,\nCVE-2026-59894 and CVE-2026-71491 (parser denial-of-service). Widen the\nceiling from <0.6.0 to <0.7.0 so those fixes can be installed.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>", |
| 8 | + "defa080fb5f65f574d9b2a589eba55893d4bf958": "chore(deps): allow sqlparse 0.6.0 to pick up parser DoS fixes (#15989)\n\n* chore(deps): require sqlparse>=0.6.0,<0.7.0 to pick up parser DoS fixes\n\nsqlparse 0.6.0 is the fixed release for CVE-2026-54284, CVE-2026-59893,\nCVE-2026-59894 and CVE-2026-71491 (parser denial-of-service). No 0.5.x\nrelease carries those fixes, so raise the floor from 0.5.5 to 0.6.0 and\nwiden the ceiling from <0.6.0 to <0.7.0.\n\nCo-Authored-By: Ashish Shukla <ashish.shukla@dbtlabs.com>\n\n* Update Dependencies-20260819-114500.yaml\n\n* Update sqlparse dependency version range\n\nUpdated sqlparse dependency version range to address security vulnerabilities.\n\n* Update pyproject.toml\n\n---------\n\nCo-authored-by: Ashish Shukla <ashish.shukla@dbtlabs.com>" |
| 9 | + }, |
| 10 | + "CVE-2026-59893": { |
| 11 | + "d7675026bb1cd8595102ec5df4f886c4168fb3b3": "chore(deps): allow sqlparse 0.6.0 to pick up parser DoS fixes (#15989) (#16013)\n\nBackport of defa080fb5f65f574d9b2a589eba55893d4bf958 to 1.12.latest.\n\nsqlparse 0.6.0 is the fixed release for CVE-2026-54284, CVE-2026-59893,\nCVE-2026-59894 and CVE-2026-71491 (parser denial-of-service). Widen the\nceiling from <0.6.0 to <0.7.0 so those fixes can be installed.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>", |
| 12 | + "7c83cc111cf5d3a066a7b27cef7569de9051c5f6": "chore(deps): allow sqlparse 0.6.0 to pick up parser DoS fixes (#15989) (#16014)\n\nBackport of defa080fb5f65f574d9b2a589eba55893d4bf958 to 1.13.latest.\n\nsqlparse 0.6.0 is the fixed release for CVE-2026-54284, CVE-2026-59893,\nCVE-2026-59894 and CVE-2026-71491 (parser denial-of-service). Widen the\nceiling from <0.6.0 to <0.7.0 so those fixes can be installed.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>", |
| 13 | + "a5784247873fb3eecf84f858e5101f4640661fa2": "chore(deps): allow sqlparse 0.6.0 to pick up parser DoS fixes (#15989) (#16012)\n\nBackport of defa080fb5f65f574d9b2a589eba55893d4bf958 to 1.11.latest.\n\nsqlparse 0.6.0 is the fixed release for CVE-2026-54284, CVE-2026-59893,\nCVE-2026-59894 and CVE-2026-71491 (parser denial-of-service). Widen the\nceiling from <0.6.0 to <0.7.0 so those fixes can be installed.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>", |
| 14 | + "defa080fb5f65f574d9b2a589eba55893d4bf958": "chore(deps): allow sqlparse 0.6.0 to pick up parser DoS fixes (#15989)\n\n* chore(deps): require sqlparse>=0.6.0,<0.7.0 to pick up parser DoS fixes\n\nsqlparse 0.6.0 is the fixed release for CVE-2026-54284, CVE-2026-59893,\nCVE-2026-59894 and CVE-2026-71491 (parser denial-of-service). No 0.5.x\nrelease carries those fixes, so raise the floor from 0.5.5 to 0.6.0 and\nwiden the ceiling from <0.6.0 to <0.7.0.\n\nCo-Authored-By: Ashish Shukla <ashish.shukla@dbtlabs.com>\n\n* Update Dependencies-20260819-114500.yaml\n\n* Update sqlparse dependency version range\n\nUpdated sqlparse dependency version range to address security vulnerabilities.\n\n* Update pyproject.toml\n\n---------\n\nCo-authored-by: Ashish Shukla <ashish.shukla@dbtlabs.com>" |
| 15 | + }, |
| 16 | + "CVE-2026-59894": { |
| 17 | + "d7675026bb1cd8595102ec5df4f886c4168fb3b3": "chore(deps): allow sqlparse 0.6.0 to pick up parser DoS fixes (#15989) (#16013)\n\nBackport of defa080fb5f65f574d9b2a589eba55893d4bf958 to 1.12.latest.\n\nsqlparse 0.6.0 is the fixed release for CVE-2026-54284, CVE-2026-59893,\nCVE-2026-59894 and CVE-2026-71491 (parser denial-of-service). Widen the\nceiling from <0.6.0 to <0.7.0 so those fixes can be installed.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>", |
| 18 | + "7c83cc111cf5d3a066a7b27cef7569de9051c5f6": "chore(deps): allow sqlparse 0.6.0 to pick up parser DoS fixes (#15989) (#16014)\n\nBackport of defa080fb5f65f574d9b2a589eba55893d4bf958 to 1.13.latest.\n\nsqlparse 0.6.0 is the fixed release for CVE-2026-54284, CVE-2026-59893,\nCVE-2026-59894 and CVE-2026-71491 (parser denial-of-service). Widen the\nceiling from <0.6.0 to <0.7.0 so those fixes can be installed.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>", |
| 19 | + "a5784247873fb3eecf84f858e5101f4640661fa2": "chore(deps): allow sqlparse 0.6.0 to pick up parser DoS fixes (#15989) (#16012)\n\nBackport of defa080fb5f65f574d9b2a589eba55893d4bf958 to 1.11.latest.\n\nsqlparse 0.6.0 is the fixed release for CVE-2026-54284, CVE-2026-59893,\nCVE-2026-59894 and CVE-2026-71491 (parser denial-of-service). Widen the\nceiling from <0.6.0 to <0.7.0 so those fixes can be installed.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>", |
| 20 | + "defa080fb5f65f574d9b2a589eba55893d4bf958": "chore(deps): allow sqlparse 0.6.0 to pick up parser DoS fixes (#15989)\n\n* chore(deps): require sqlparse>=0.6.0,<0.7.0 to pick up parser DoS fixes\n\nsqlparse 0.6.0 is the fixed release for CVE-2026-54284, CVE-2026-59893,\nCVE-2026-59894 and CVE-2026-71491 (parser denial-of-service). No 0.5.x\nrelease carries those fixes, so raise the floor from 0.5.5 to 0.6.0 and\nwiden the ceiling from <0.6.0 to <0.7.0.\n\nCo-Authored-By: Ashish Shukla <ashish.shukla@dbtlabs.com>\n\n* Update Dependencies-20260819-114500.yaml\n\n* Update sqlparse dependency version range\n\nUpdated sqlparse dependency version range to address security vulnerabilities.\n\n* Update pyproject.toml\n\n---------\n\nCo-authored-by: Ashish Shukla <ashish.shukla@dbtlabs.com>" |
| 21 | + }, |
| 22 | + "CVE-2026-71491": { |
| 23 | + "d7675026bb1cd8595102ec5df4f886c4168fb3b3": "chore(deps): allow sqlparse 0.6.0 to pick up parser DoS fixes (#15989) (#16013)\n\nBackport of defa080fb5f65f574d9b2a589eba55893d4bf958 to 1.12.latest.\n\nsqlparse 0.6.0 is the fixed release for CVE-2026-54284, CVE-2026-59893,\nCVE-2026-59894 and CVE-2026-71491 (parser denial-of-service). Widen the\nceiling from <0.6.0 to <0.7.0 so those fixes can be installed.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>", |
| 24 | + "7c83cc111cf5d3a066a7b27cef7569de9051c5f6": "chore(deps): allow sqlparse 0.6.0 to pick up parser DoS fixes (#15989) (#16014)\n\nBackport of defa080fb5f65f574d9b2a589eba55893d4bf958 to 1.13.latest.\n\nsqlparse 0.6.0 is the fixed release for CVE-2026-54284, CVE-2026-59893,\nCVE-2026-59894 and CVE-2026-71491 (parser denial-of-service). Widen the\nceiling from <0.6.0 to <0.7.0 so those fixes can be installed.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>", |
| 25 | + "a5784247873fb3eecf84f858e5101f4640661fa2": "chore(deps): allow sqlparse 0.6.0 to pick up parser DoS fixes (#15989) (#16012)\n\nBackport of defa080fb5f65f574d9b2a589eba55893d4bf958 to 1.11.latest.\n\nsqlparse 0.6.0 is the fixed release for CVE-2026-54284, CVE-2026-59893,\nCVE-2026-59894 and CVE-2026-71491 (parser denial-of-service). Widen the\nceiling from <0.6.0 to <0.7.0 so those fixes can be installed.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>", |
| 26 | + "defa080fb5f65f574d9b2a589eba55893d4bf958": "chore(deps): allow sqlparse 0.6.0 to pick up parser DoS fixes (#15989)\n\n* chore(deps): require sqlparse>=0.6.0,<0.7.0 to pick up parser DoS fixes\n\nsqlparse 0.6.0 is the fixed release for CVE-2026-54284, CVE-2026-59893,\nCVE-2026-59894 and CVE-2026-71491 (parser denial-of-service). No 0.5.x\nrelease carries those fixes, so raise the floor from 0.5.5 to 0.6.0 and\nwiden the ceiling from <0.6.0 to <0.7.0.\n\nCo-Authored-By: Ashish Shukla <ashish.shukla@dbtlabs.com>\n\n* Update Dependencies-20260819-114500.yaml\n\n* Update sqlparse dependency version range\n\nUpdated sqlparse dependency version range to address security vulnerabilities.\n\n* Update pyproject.toml\n\n---------\n\nCo-authored-by: Ashish Shukla <ashish.shukla@dbtlabs.com>" |
| 27 | + }, |
4 | 28 | "CVE-2024-22195": { |
5 | 29 | "b2270fa38ad76d096029c59cbf9d43f22ba001a8": "[Backport 1.5.latest] Upgrade Jinja2 dependency version specification to address CVE-2024-22195 (#9670)\n\n* Upgrade Jinja2 dependency version specification to address CVE-2024-22195 (#9638)\r\n\r\nCVE-2024-22195 identified an issue in Jinja2 versions <= 3.1.2. As such\r\nwe've gone and changed our dependency requirement specification to be\r\n3.1.3 or greater (but less than 4).\r\n\r\nNote: Preivously we were using the `~=` version specifier. However due\r\nto some issues with the `~=` we've moved to using `>=` in combination\r\nwith `<`. This gives us the same range that `~=` gave us, but avoids\r\na pip resolution issue when multiple packages in an environment use `~=`\r\nfor the same dependency.", |
6 | 30 | "0a6d0c158e5a1956bd48e53793ca3b28faee2b34": "Upgrade Jinja2 dependency version specification to address CVE-2024-22195 (#9638) (#9655)\n\nCVE-2024-22195 identified an issue in Jinja2 versions <= 3.1.2. As such\r\nwe've gone and changed our dependency requirement specification to be\r\n3.1.3 or greater (but less than 4).\r\n\r\nNote: Preivously we were using the `~=` version specifier. However due\r\nto some issues with the `~=` we've moved to using `>=` in combination\r\nwith `<`. This gives us the same range that `~=` gave us, but avoids\r\na pip resolution issue when multiple packages in an environment use `~=`\r\nfor the same dependency.\r\n\r\n(cherry picked from commit 7ea46708327260c85460d8034ef6ab84fe3d1b78)\r\n\r\nCo-authored-by: Quigley Malcolm <QMalcolm@users.noreply.github.com>", |
|
0 commit comments