Skip to content

Metadata regression: GHSA-887w-45rq-vxgf is not fixed in sqlalchemy v1.2.x #7500

@jayaddison

Description

@jayaddison

Hello,

I think that the affected/fixed version metadata for GHSA-887w-45rq-vxgf partially regressed in commit 41214dc.

That commit introduced a more-precise fix version of sqlalchemy version 1.3.0b3 (containing sqlalchemy/sqlalchemy@30307c4) -- but it also indicated that version 1.2.18 of sqlalchemy contains the fix, and that is not true.

I found this while reading pull request #7486 that corrects the metadata.

Thanks,
James

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions