HomeAI NewsDatasette ships security patches for 1.0a39 and 0.65.4 releases

Datasette ships security patches for 1.0a39 and 0.65.4 releases

Simon Willison patched two branches after Sevban Dönmez reported bugs, using frontier models to audit the code.

Datasette published two security patch releases, 1.0a39 for the current alpha series and 0.65.4 for the stable 0.65.x line. The fixes target instances exposed on the public web, especially those that serve both public and private tables.

Simon Willison wrote that Sevban Dönmez reported the issues, then he and Alex Garcia ran an extensive audit using Claude Fable 5.1, GPT-5.6, and GPT-6 Astra. They spent nearly a week reviewing fixes and pairing on tests and patches in a shared private repository.

Anyone running Datasette on the public internet should upgrade immediately, because the bugs hide in subtle authorization paths. The split workflow, where one person writes failing tests and the other implements the fix, gives operators a template for auditing their own code with agent help.

Willison says security audits by frontier models will become part of all Datasette development going forward. Teams that maintain similar projects may want to test whether multiple models catch issues that a single reviewer misses.

What matters

  • Datasette 1.0a39 and 0.65.4 fix security flaws in instances that mix public and private tables.
  • Operators running public Datasette instances should apply both patches to close the reported holes.
  • Willison plans to fold audits by frontier models into all future Datasette development work.

Why it matters

Willison plans to fold audits by frontier models into all future Datasette development work.

This GenAI News article was prepared in original wording using reporting and materials published by Simon Willison’s Weblog. Source reference: https://simonwillison.net/2026/Sep/11/datasette-security/.

Drafted by the GenAI News review pipeline.

latest articles

explore more