Skip to content

Fix 40 known vulnerabilities: upgrade dbt-core, dbt-duckdb, sqlfluff - #1

Closed
lscholten wants to merge 1 commit into
mainfrom
fix/dependency-vulnerabilities
Closed

lscholten wants to merge 1 commit into
mainfrom
fix/dependency-vulnerabilities

Conversation

@lscholten

@lscholten lscholten commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • uv audit flagged 40 known CVEs, all in transitive deps: click, msgpack, protobuf, pygments, pytest, requests, sqlfluff, sqlparse, urllib3.
  • The fixed versions of most of these require Python >=3.10, and protobuf's fix is blocked by dbt-core 1.7's own protobuf<5 pin. Raising the Python floor and upgrading dbt-core/dbt-duckdb off 1.7 and sqlfluff off 2.x unblocks all of them.
  • Changes: requires-python >=3.8 → >=3.10, dbt-core >=1.7.9,<1.8.0 → >=1.12.0,<1.13.0, dbt-duckdb >=1.7.3,<1.8.0 → >=1.11.0,<1.12.0, sqlfluff >=2.3.5,<3 → >=4.2.0,<5.
  • pytest disappeared from the lockfile — old sqlfluff 2.3.5 pulled it in unconditionally; 4.x moved it behind an optional testutils extra. No impact: this repo has no pytest test suite (tests/ only has __init__.py).

Test plan

  • uv audit — 0 findings (was 40)
  • dbt debug — OK
  • dbt build — 28/28 pass (3 seeds, 6 models, 19 data tests)

🤖 Generated with Claude Code

…qlfluff

uv audit flagged 40 known CVEs in transitive deps (click, msgpack, protobuf,
pygments, pytest, requests, sqlfluff, sqlparse, urllib3). The fixed versions
either require Python >=3.10 or are blocked by dbt-core 1.7's own pins
(e.g. protobuf<5). Raising the Python floor and upgrading dbt-core/dbt-duckdb
off 1.7 and sqlfluff off 2.x unblocks all of them.

- requires-python: >=3.8 -> >=3.10
- dbt-core: >=1.7.9,<1.8.0 -> >=1.12.0,<1.13.0
- dbt-duckdb: >=1.7.3,<1.8.0 -> >=1.11.0,<1.12.0
- sqlfluff: >=2.3.5,<3 -> >=4.2.0,<5

Verified with `uv audit` (0 findings, was 40) and `dbt build` (28/28 pass).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@lscholten lscholten closed this Sep 9, 2026
@lscholten lscholten reopened this Sep 9, 2026
@lscholten lscholten closed this Sep 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant