cd /news/ai-tools/datasette-1-0a39-and-0-65-4-security… · home topics ai-tools article
[ARTICLE · art-126483] src=simonwillison.net ↗ pub= topic=ai-tools verified=true sentiment=· neutral

Datasette 1.0a39 and 0.65.4 security releases

Datasette released versions 1.0a39 and 0.65.4 to patch security flaws found in an audit run with Claude Fable 5.1, GPT-5.6, and GPT-6 Astra, according to the project's release notes. The audit was prompted by issues reported by Sevban Dönmez, and Datasette creator Simon Willison said he and Alex Garcia spent almost a week reviewing and fixing the bugs, with one person writing automated tests and the other implementing each fix. Willison said security audits by frontier models will be incorporated into all future Datasette development work, and urged anyone running a public Datasette instance that mixes public and private tables to apply the fixes.

read1 min views1 publishedSep 11, 2026

Datasette 1.0a39 and 0.65.4 security releases These are security fixes which you should apply if you are running a Datasette instance on the public web - in particular if that instance mixes both public and private tables.

Following issues reported by Sevban Dönmez, Alex Garcia and I ran an extensive audit of Datasette using Claude Fable 5.1, GPT-5.6, and GPT-6 Astra. We then spent almost a week collaborating on and reviewing the fixes.

They helped find some very subtle bugs. We'll be incorporating security audits by frontier models into all of our development work going forward.

Alex came up with a way of splitting the work which I found extremely productive:

Alex Garcia and I worked together running and then responding to the audit, working in a shared private repository. For most of the issues we split the work: one of us would create the automated tests highlighting the issue, then the other would implement the fix. This ensured that two separate humans had eyes on each of the issues, in addition to our coding agents running different models.

Tags: releases, security, ai, datasette, generative-ai, llms, agentic-engineering, ai-security-research

── more in #ai-tools 4 stories · sorted by recency
── more on @datasette 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/datasette-1-0a39-and…] indexed:0 read:1min 2026-09-11 ·