- Announcement
- Coverage
- Global
- Primary source
- Datasette Blog ↗
What changed?
Maintainer Simon Willison advised operators of Datasette instances on the public internet to upgrade, particularly when authentication plugins protect private data alongside public tables.
The stable and alpha releases bundle multiple fixes found through external reports and a broader security audit. The published changelog identifies a SQL-injection issue involving databases that combine public and private tables, alongside permission and caching corrections.
What should you keep in mind?
Operators should review the full changelog against their deployment and plugin configuration rather than assuming that authentication alone removes exposure.
Go to the source
Source announcement: . This is an original summary, not independent on-the-ground reporting.
Last updated: . Editorial policy & corrections


