Skip to content

build(deps): bump pymysql from 1.2.0 to 1.2.3 - #1798

Open
dependabot[bot] wants to merge 2 commits into
masterfrom
dependabot/pip/pymysql-1.2.3
Open

dependabot[bot] wants to merge 2 commits into
masterfrom
dependabot/pip/pymysql-1.2.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Bumps pymysql from 1.2.0 to 1.2.3.

Release notes

Sourced from pymysql's releases.

v1.2.3

Full Changelog: PyMySQL/PyMySQL@v1.2.2...v1.2.3

v1.2.2

Restored the ability to import pymysql.converters.escape_dict for compatibility with aiomysql. This function does not escape dictionaries and is entirely unnecessary. Unless you use aiomysql, there is no need to upgrade from v1.2.1.

Full Changelog: PyMySQL/PyMySQL@v1.2.1...v1.2.2

v1.2.1

What's Changed

New Contributors

Full Changelog: PyMySQL/PyMySQL@v1.2.0...v1.2.1

Changelog

Sourced from pymysql's changelog.

v1.2.3

Release date: 2026-09-17

Restored the ability to import pymysql.converters.escape_bytes_prefixed for compatibility with aiomysql.

Use pymysql.converters at your own risk. It's internal functions. No backward compatibility are guaranteed.

v1.2.2

Release date: 2026-09-17

Restored the ability to import pymysql.converters.escape_dict for compatibility with aiomysql. This function does not escape dictionaries and is entirely unnecessary. Unless you use aiomysql, there is no need to upgrade from v1.2.1.

v1.2.1 (security fix)

Release date: 2026-09-17

Fixed a SQL injection vulnerability caused by incorrect escaping of bytes parameters when using the big5, gbk, sjis, cp932, or gb18030 character sets. This vulnerability also occurs when strings decoded from bytes using surrogateescape are passed as query parameters.

See also: https://github.com/PyMySQL/PyMySQL/security/advisories/GHSA-x4f8-9hx9-hpp9

  • Queries are now encoded using the strict error handler instead of surrogateescape. Queries that cannot be encoded using the connection encoding can no longer be sent.

  • bytes parameters are now always sent as hexadecimal literals, such as X'636174'. Note that this increases the number of bytes sent.

  • The binary_prefix parameter of connect() is deprecated. The _binary prefix is no longer sent.

These changes address the confirmed SQL injection vulnerabilities related to character encoding. However, we strongly recommend using UTF-8 (utf8mb4). Other character sets are not thoroughly tested, and their limited use means that problems may go unreported. In the 2020s, encodings other than UTF-8 should be considered legacy.

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Sep 21, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) September 21, 2026 02:24
@dependabot
dependabot Bot force-pushed the dependabot/pip/pymysql-1.2.3 branch 4 times, most recently from 1915b3d to 7a05ad9 Compare October 2, 2026 02:30
Bumps [pymysql](https://github.com/PyMySQL/PyMySQL) from 1.2.0 to 1.2.3.
- [Release notes](https://github.com/PyMySQL/PyMySQL/releases)
- [Changelog](https://github.com/PyMySQL/PyMySQL/blob/main/CHANGELOG.md)
- [Commits](PyMySQL/PyMySQL@v1.2.0...v1.2.3)

---
updated-dependencies:
- dependency-name: pymysql
  dependency-version: 1.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/pymysql-1.2.3 branch from 7a05ad9 to 8c3f9cb Compare October 2, 2026 02:37
@codspeed

codspeed Bot commented Oct 2, 2026

Copy link
Copy Markdown

Merging this PR will degrade performance by 10.2%

❌ 1 regressed benchmark
✅ 97 untouched benchmarks

Warning

Please fix the performance issues or acknowledge them on CodSpeed.

Performance Changes

Benchmark BASE HEAD Efficiency
❌ test_get_column_name_from_alias_book[10000] 51.2 ms 57 ms -10.2%

Tip

Investigate this regression by commenting @codspeedbot fix this regression on this PR, or directly use the CodSpeed MCP with your agent.


Comparing dependabot/pip/pymysql-1.2.3 (5ecb0b9) with master (325d6ad)

Open in CodSpeed

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant