Update dependency pymysql to v1.2.3 - #296
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/pymysql-1.x
branch
from
May 2, 2026 07:35
3dff472 to
e04089b
Compare
renovate
Bot
force-pushed
the
renovate/pymysql-1.x
branch
from
May 19, 2026 09:08
e04089b to
40e0352
Compare
renovate
Bot
force-pushed
the
renovate/pymysql-1.x
branch
from
September 17, 2026 19:43
40e0352 to
c916145
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==1.1.1→==1.2.3Release Notes
PyMySQL/PyMySQL (pymysql)
v1.2.3Compare Source
Release date: 2026-09-17
Restored the ability to import
pymysql.converters.escape_bytes_prefixedforcompatibility with aiomysql.
Use
pymysql.convertersat your own risk.It's internal functions. No backward compatibility are guaranteed.
v1.2.2Compare Source
Release date: 2026-09-17
Restored the ability to import
pymysql.converters.escape_dictforcompatibility with aiomysql.
This function does not escape dictionaries and is entirely unnecessary.
Unless you use aiomysql, there is no need to upgrade from v1.2.1.
v1.2.1Compare Source
Release date: 2026-09-17
Fixed a SQL injection vulnerability caused by incorrect escaping of
bytesparameters when using the big5, gbk, sjis, cp932, or gb18030 character sets.
This vulnerability also occurs when strings decoded from
bytesusingsurrogateescapeare passed as query parameters.See also: https://github.com/PyMySQL/PyMySQL/security/advisories/GHSA-x4f8-9hx9-hpp9
Queries are now encoded using the
stricterror handler instead ofsurrogateescape.Queries that cannot be encoded using the connection encoding can no longer be sent.
bytesparameters are now always sent as hexadecimal literals, such asX'636174'. Note that this increases the number of bytes sent.The
binary_prefixparameter ofconnect()is deprecated. The_binaryprefix is no longer sent.
These changes address the confirmed SQL injection vulnerabilities related to
character encoding.
However, we strongly recommend using UTF-8 (
utf8mb4).Other character sets are not thoroughly tested, and their limited use means
that problems may go unreported. In the 2020s, encodings other than UTF-8
should be considered legacy.
v1.2.0Compare Source
Release date: 2026-05-19
Breaking changes
Connection.ping()change the default to not reconnect and deprecatereconnectargument.Create a new connection if you want to reconnect. (#1241)
Error classes in Cursor class are removed. (#1240)
connect()argumentsdbandpasswdnow emit DeprecationWarning.Use
databaseandpasswordinstead. (#1240)Reorganize TLS connection behavior.
PyMySQL uses TLS by default when server supports it.
Use
ssl_disabled=Trueto prohibit SSL. (#1213)When
ssl_verify_cert=True,ssl_verify_identity=True, anssl.SSLContextis passed,or when any other SSL option is configured, the connection requires SSL and raises
OperationalError(CR_SSL_CONNECTION_ERROR) if the server doesn't support it. (#1234)Other changes
executemanyINSERT regex. (#1235)decimal.Decimalquery parameters (NaN,sNaN,±Infinity). (#1237)Connection.set_charset(charset)now emitsDeprecationWarning.v1.1.3Compare Source
Release date: 2026-05-01
Security
Fix
Cursor.callproc()didn't escape procedure name. (#1206)There was a possibility of SQL injection when calling a procedure with a string received from an untrusted source as the procedure name.
NOTICE: This change may cause backward compatibility issues. If you specified a procedure name like
"dbname.funcname", the previous version calledCALL dbname.funcname, but from this version, it will callCALL `dbname.funcname`so you cannot specify procedure name with database name anymore.v1.1.2Compare Source
What's Changed
connection._rfileinConnection._force_closeby @cfbolz in #1184New Contributors
Full Changelog: PyMySQL/PyMySQL@v1.1.1...v1.1.2
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.