datasette (0.65.5+ds-1) unstable; urgency=high * New upstream security releases 0.65.4 and 0.65.5. - Fix a trailing newline in a requested table name bypassing table permissions and exposing private rows (GHSA-h547-rmjf-5m2m). (Closes: #1148576) - Fix case-insensitive table permission checks and require access to intermediate tables used by through filters. - Fix SQL identifier escaping in row queries and pagination, and parameterize full-text search index detection. - Prevent shared caching of private and personalized responses. - Disable SQLite extension loading after configured extensions load. - Fix task IDs for non-blocking writes. * Refresh patches for the updated upstream setup.py and changelog. -- Mahangu Weerasinghe Mon, 21 Sep 2026 09:22:59 +0530 datasette (0.65.3+ds-1) unstable; urgency=medium * New upstream release. * Fix SQL injection in table filters when identifiers contain ]. (GHSA-w3hf-fcg5-p4cc, upstream #2868) * debian/watch: only match 0.x tags so uscan does not select 1.x. * debian/copyright: update years. * debian/control: Standards-Version 4.7.4. Drop redundant Priority. Build-Depend on pybuild-plugin-pyproject. -- Mahangu Weerasinghe Thu, 13 Aug 2026 04:06:00 +0000 datasette (0.65.2+ds-2) unstable; urgency=medium * Skip test_max_csv_mb: timing-dependent, fails on i386 and riscv64 -- Mahangu Weerasinghe Tue, 31 Mar 2026 08:32:20 +0000 datasette (0.65.2+ds-1) unstable; urgency=medium * Initial release. (Closes: #1120835) -- Mahangu Weerasinghe Fri, 05 Dec 2025 08:23:36 +0000