dbt-labs / dbt-semantic-interfaces

The shared semantic layer definitions that dbt-core and MetricFlow use.
Apache License 2.0
66 stars 13 forks source link

Update Jinja2 to >= 3.1.3 to address CVE-2024-22195 #264

Closed tlento closed 7 months ago

tlento commented 7 months ago

We received a dependabot alert notifying us of this vulnerability.

Dependabot thought this had been fixed in a different PR, but that was a false positive. This PR makes the relevant update on top of an underlying commit to move us off of the ~= dependency syntax.

github-actions[bot] commented 7 months ago

Thank you for your pull request! We could not find a changelog entry for this change. For details on how to document a change, see the contributing guide.