-
Notifications
You must be signed in to change notification settings - Fork 0
Release Python v0.8.0: read-only exports and packaged Dolt support #19
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
49da0f9
72b2019
6a6af2b
6431067
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -49,7 +49,7 @@ equivalence of supported values, order, and dictionary metadata. | |
|
|
||
| The `openstatspec capabilities` command and the | ||
| `openstatspec.capability_matrix()` function are the machine-readable declaration | ||
| of this boundary. It records the pinned source commit and installed engine version, and the adapter stores the same identity in every import and export operation record. The matrix deliberately distinguishes a supported feature from a feature that the underlying engine cannot observe or write faithfully. | ||
| of this boundary. It records the pinned source commit and installed engine version, and the adapter stores the same identity in import operation records. Export is database-read-only: no operation, fidelity, recovery, or Dolt-history records are written, even on failure. Loss diagnostics are returned to the caller. Dolt export identifies the server and validates the catalog and data without requiring write-conformance declarations; write entry points retain that requirement. The matrix deliberately distinguishes a supported feature from a feature that the underlying engine cannot observe or write faithfully. | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win Clarify the Dolt version scope.
🤖 Prompt for AI Agents |
||
|
|
||
| | SPSS semantic | Pinned pyspssio status | Behaviour | | ||
| | --- | --- | --- | | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🛡️ Analyzed with Security Review | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: OpenStatSpec/python
Length of output: 26389
🏁 Script executed:
Repository: OpenStatSpec/python
Length of output: 4126
Security Misconfiguration (CWE-269): Improper Privilege Management
Reachability: External · Exploitability: Trivial
Reduce the privileges of the exposed Dolt account.
This workflow runs on
pull_request, and the test uses the account to create and drop databases and users, grantSELECT, create tables, insert data, and commit Dolt changes.ALL PRIVILEGES ON *.*is broader than required. Reduce the account privileges or split bootstrap and database-scoped test credentials. KeepWITH GRANT OPTIONonly for the account that executes the test'sGRANT SELECTstatement.🧰 Tools
🪛 zizmor (1.29.0)
[warning] 1-237: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
[warning] 145-237: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
🤖 Prompt for AI Agents