datasette 1.0a38
datasette 1.0a38 patches a SQL injection vulnerability affecting instances that serve a mix of public and private tables from the same database using Datasette's built-in permissions system. Administrators running access-controlled multi-table instances should update immediately. Instances serving only public data, or where all tables share the same access level, are not affected.
Simon Willison