Skip to content

Conversation

@aosingh
Copy link
Member

@aosingh aosingh commented Jul 19, 2023

dbt-core v1.5.3 upgrades sqlparse to v0.4.4 which fixes CVE GHSA-rrm6-wvj7-cwh2

NIST rates this much higher https://nvd.nist.gov/vuln/detail/CVE-2023-30608

@oracle-contributor-agreement oracle-contributor-agreement bot added the OCA Verified All contributors have signed the Oracle Contributor Agreement. label Jul 19, 2023
@aosingh aosingh merged commit 99e3516 into main Jul 19, 2023
@aosingh aosingh deleted the upgrade/dbt-core branch July 24, 2023 15:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

OCA Verified All contributors have signed the Oracle Contributor Agreement.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants