Repository navigation
v0.12.3
·
30 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Maintenance patch. No runtime or user-facing change; the core install stays dependency-free.
Security
-
Updated two transitive development dependencies carrying open advisories, clearing all six Dependabot alerts (4 high, 2 moderate):
sqlparse0.5.5 → 0.6.0 — GHSA-prg7-hcfm-mfcr (ReDoS via dollar-quoted SQL literals), GHSA-pwgv-4x5q-6m9f, GHSA-f2ff-p2ww-7p4p, GHSA-3496-9g83-7v6xpymdown-extensions10.21.3 → 11.0.1 — GHSA-gm37-52c6-37mw, GHSA-9xwg-3r6f-jcx2
No previous release was affected.
erdifydeclares no runtime dependencies, and both packages are reached only through the development and documentation groups (sqlparseviadjango,pymdown-extensionsviamkdocs-material). This hardens the development and CI toolchain only.
Changed
- Dependabot now holds freshly published versions back for 7 days (
cooldown.default-days: 7on everyupdatesentry) before proposing a version update, giving the ecosystem and security researchers time to catch a compromised or broken release. Security updates are unaffected —cooldownapplies to version updates only. - Bumped CI actions to their latest majors:
astral-sh/setup-uv9.0.0 → 10.0.1,actions/configure-pages5.0.0 → 6.0.0,actions/upload-pages-artifact4.0.0 → 5.0.0, andactions/deploy-pages4.0.5 → 5.0.0. Repository infrastructure only.
Full Changelog: v0.12.2...v0.12.3