dremio / dbt-dremio

dbt (data build tool) adapter for the Dremio
Apache License 2.0
44 stars 21 forks source link

Upgrade sqlparse to 0.4.4 #180

Closed ArgusLi closed 1 year ago

ArgusLi commented 1 year ago

Describe the enhancement requested

Upgrade sqlparse to 0.4.4.

Justification for this enhancement

This release fixes a security vulnerability in the parser where a regular expression vulnerable to ReDOS (Regular Expression Denial of Service) was used. See the security advisory for details: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-rrm6-wvj7-cwh2 The vulnerability was discovered by @erik-krogh from GitHub Security Lab (GHSL). Thanks for reporting!

Source: https://sqlparse.readthedocs.io/en/latest/changes/#release-0-4-4-apr-18-2023