datasette (0.65.5+ds-1) unstable; urgency=high

  * New upstream security releases 0.65.4 and 0.65.5.
    - Fix a trailing newline in a requested table name bypassing table
      permissions and exposing private rows (GHSA-h547-rmjf-5m2m).
      (Closes: #1148576)
    - Fix case-insensitive table permission checks and require access to
      intermediate tables used by through filters.
    - Fix SQL identifier escaping in row queries and pagination, and
      parameterize full-text search index detection.
    - Prevent shared caching of private and personalized responses.
    - Disable SQLite extension loading after configured extensions load.
    - Fix task IDs for non-blocking writes.
  * Refresh patches for the updated upstream setup.py and changelog.

 -- Mahangu Weerasinghe <mahangu@gmail.com>  Mon, 21 Sep 2026 09:22:59 +0530

datasette (0.65.3+ds-1) unstable; urgency=medium

  * New upstream release.
  * Fix SQL injection in table filters when identifiers contain ].
    (GHSA-w3hf-fcg5-p4cc, upstream #2868)
  * debian/watch: only match 0.x tags so uscan does not select 1.x.
  * debian/copyright: update years.
  * debian/control: Standards-Version 4.7.4. Drop redundant Priority.
    Build-Depend on pybuild-plugin-pyproject.

 -- Mahangu Weerasinghe <mahangu@gmail.com>  Thu, 13 Aug 2026 04:06:00 +0000

datasette (0.65.2+ds-2) unstable; urgency=medium

  * Skip test_max_csv_mb: timing-dependent, fails on i386 and riscv64

 -- Mahangu Weerasinghe <mahangu@gmail.com>  Tue, 31 Mar 2026 08:32:20 +0000

datasette (0.65.2+ds-1) unstable; urgency=medium

  * Initial release. (Closes: #1120835)

 -- Mahangu Weerasinghe <mahangu@gmail.com>  Fri, 05 Dec 2025 08:23:36 +0000
