This release includes 1 security fix for security teams reviewing exposed deployments.
Published 3mo
Data Pipelines & ETL
✓ No known CVEs patched
This release patches 1 known CVE
Topics
data-cleaning
data-engineering
data-matching
data-quality
deduplication
entity-resolution
+14 more
fellegi-sunter
fuzzy-matching
knowledge-graph
llm
master-data-management
mcp-server
polars
pprl
python
record-linkage
rust
splink
typescript
zero-config
Affected surfaces
deps
Summary
AI summaryBump pydantic minimum to >=2.7 resolving CVE-2024-3772 regex DoS.
Full changelog
- Bump pydantic minimum to >=2.7 (resolves CVE-2024-3772 regex DoS)
- Fix server.json repository URL (.git suffix removed)
- Sync PyPI metadata with MCP Marketplace
Security Fixes
- CVE-2024-3772 — regex DoS vulnerability fixed by requiring pydantic >=2.7
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About GoldenMatch
All releases →Related context
Related tools
Earlier breaking changes
- v3.1.0 `GOLDENMATCH_FRAME=polars` now requires the `[polars]` extra; raises error without it.
- vgoldencheck-v3.0.0 `inferred_type` emits neutral dtype vocabulary (str/int/uint/float/date/datetime/bool/other) instead of raw Polars dtypes.
- vgoldencheck-v3.0.0 'inferred_type' now emits a neutral dtype vocabulary instead of raw Polars dtype strings.
- vgoldencheck-v3.0.0 `scan_file`, `scan_dataframe`, and CLI `check` now run without Polars, using Arrow-native pyarrow.Table.
- v3.0.0 Result frames now return pyarrow.Table instead of Polars DataFrame.
Beta — feedback welcome: [email protected]