Open
Conversation
Micro-Learning Topic: SQL injection (Detected by phrase)Matched on "sqli"This is probably one of the two most exploited vulnerabilities in web applications and has led to a number of high profile company breaches. It occurs when an application fails to sanitize or validate input before using it to dynamically construct a statement. An attacker that exploits this vulnerability will be able to gain access to the underlying database and view or modify data without permission. Try a challenge in Secure Code WarriorHelpful references
|
e936ad4 to
dcce6c5
Compare
🔐 Secure Code Review (AI)No eligible code changes. Models can make mistakes. Verify before merging. |
ee55f8f to
9e9d362
Compare
9e9d362 to
fef115c
Compare
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



This PR contains the following updates:
==1.1.1->==3.0.2Release Notes
pallets/markupsafe (MarkupSafe)
v3.0.2Compare Source
Released 2024-10-18
__str__returns astrsubclass. :issue:472475v3.0.1Compare Source
Released 2024-10-08
466467v3.0.0Compare Source
Released 2024-10-07
461pyproject.tomlinstead ofsetup.cfg.:pr:
348distutilsimports tosetuptools. :pr:399400Markupmethods to matchstrsignatures. Usepositional-only arguments. :pr:
400strmethods onMarkupno longer escape their argument:strip,lstrip,rstrip,removeprefix,removesuffix,partition, andrpartition;replaceonly escapes itsnewargument. These methods are conceptually linked to search methods such as
in,find, andindex, which already do not escape their argument.:issue:
401__version__attribute is deprecated. Use feature detection, orimportlib.metadata.version("markupsafe"), instead. :pr:402434437v2.1.5Compare Source
Released 2024-02-02
striptagsnot collapsing spaces. :issue:417v2.1.4Compare Source
Released 2024-01-19
striptags, avoiding a performanceissue. :pr:
413v2.1.3Compare Source
Released 2023-06-02
format_map,casefold,removeprefix, andremovesuffixmethods. :issue:
370strmethods onMarkup. :issue:358Selffor annotating return types. :pr:379v2.1.2Compare Source
Released 2023-01-17
striptagsnot stripping tags containing newlines.:issue:
310v2.1.1Compare Source
Released 2022-03-14
striptags. :pr:293v2.1.0Compare Source
Released 2022-02-17
262soft_unicode, which was previously deprecated. Usesoft_strinstead. :pr:261interpolation. :issue:
225277v2.0.1Compare Source
Released 2021-05-18
imports in user projects. :pr:
215215v2.0.0Compare Source
Released 2021-05-11
Markup.unescapeuses :func:html.unescapeto support HTML5character references. :pr:
117149Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.