Hello,
I think that the affected/fixed version metadata for GHSA-887w-45rq-vxgf partially regressed in commit 41214dc.
That commit introduced a more-precise fix version of sqlalchemy version 1.3.0b3 (containing sqlalchemy/sqlalchemy@30307c4) -- but it also indicated that version 1.2.18 of sqlalchemy contains the fix, and that is not true.
I found this while reading pull request #7486 that corrects the metadata.
Thanks,
James
Hello,
I think that the affected/fixed version metadata for GHSA-887w-45rq-vxgf partially regressed in commit 41214dc.
That commit introduced a more-precise fix version of
sqlalchemyversion1.3.0b3(containing sqlalchemy/sqlalchemy@30307c4) -- but it also indicated that version1.2.18ofsqlalchemycontains the fix, and that is not true.I found this while reading pull request #7486 that corrects the metadata.
Thanks,
James