aayant-mend / four-goats-of-the-apocalypse

A large repo used for SCA scanning. Contains NodeGoat, WebGoat, WebGoat.NET, and PyGoat.
https://i2-prod.dailystar.co.uk/incoming/article19639978.ece/ALTERNATES/s615b/0_34409
1 stars 6 forks source link

Update dependency sqlparse to v0.4.2 - autoclosed #26

Closed mend-for-github-com[bot] closed 1 year ago

mend-for-github-com[bot] commented 1 year ago

This PR contains the following updates:

Package Update Change
sqlparse (changelog) minor ==0.3.1 -> ==0.4.2

By merging this PR, the issue #5 will be automatically resolved and closed:

Severity CVSS Score CVE
High High 7.5 WS-2021-0369

Release Notes

andialbrecht/sqlparse ### [`v0.4.2`](https://togithub.com/andialbrecht/sqlparse/blob/HEAD/CHANGELOG#Release-042-Sep-10-2021) [Compare Source](https://togithub.com/andialbrecht/sqlparse/compare/0.4.1...0.4.2) Notable Changes - IMPORTANT: This release fixes a security vulnerability in the strip comments filter. In this filter a regular expression that was vulnerable to ReDOS (Regular Expression Denial of Service) was used. See the security advisory for details: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-p5w8-wqhj-9hhf The vulnerability was discovered by [@​erik-krogh](https://togithub.com/erik-krogh) and [@​yoff](https://togithub.com/yoff) from GitHub Security Lab (GHSL). Thanks for reporting! Enhancements - Add ELSIF as keyword (issue584). - Add CONFLICT and ON_ERROR_STOP keywords (pr595, by j-martin). Bug Fixes - Fix parsing of backticks (issue588). - Fix parsing of scientific number (issue399). ### [`v0.4.1`](https://togithub.com/andialbrecht/sqlparse/blob/HEAD/CHANGELOG#Release-041-Oct-08-2020) [Compare Source](https://togithub.com/andialbrecht/sqlparse/compare/0.4.0...0.4.1) Bug Fixes - Just removed a debug print statement, sorry... ### [`v0.4.0`](https://togithub.com/andialbrecht/sqlparse/blob/HEAD/CHANGELOG#Release-040-Oct-07-2020) [Compare Source](https://togithub.com/andialbrecht/sqlparse/compare/0.3.1...0.4.0) Notable Changes - Remove support for end-of-life Python 2.7 and 3.4. Python 3.5+ is now required. - Remaining strings that only consist of whitespaces are not treated as statements anymore. Code that ignored the last element from sqlparse.split() should be updated accordingly since that function now doesn't return an empty string as the last element in some cases (issue496). Enhancements - Add WINDOW keyword (pr579 by ali-tny). - Add RLIKE keyword (pr582 by wjones1). Bug Fixes - Improved parsing of IN(...) statements (issue566, pr567 by hurcy). - Preserve line breaks when removing comments (issue484). - Fix parsing error when using square bracket notation (issue583). - Fix splitting when using DECLARE ... HANDLER (issue581). - Fix splitting of statements using CASE ... WHEN (issue580). - Improve formatting of type casts in parentheses. - Stabilize formatting of invalid SQL statements.