GHSA-p72q-h37j-3hq7: dbt uses a SQLparse version with a high vulnerability
Using a version of sqlparse
that has a security vulnerability and no way to update in current version of dbt core. Snyk recommends using sqlparse==0.5
but this causes a conflict with dbt. Snyk states the issues is a recursion error: SNYK-PYTHON-SQLPARSE-6615674
.
References
Detect and mitigate GHSA-p72q-h37j-3hq7 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →