supply chain / dbt-databricks

dbt Databricks Adapter

registryPyPI
package namedbt-databricks
maintainerDatabricks

dbt-databricks is the Databricks adapter for dbt Core, enabling SQL model compilation and execution on Databricks SQL warehouses and Delta Live Tables. It authenticates via Databricks personal access tokens. It is required for dbt projects that run on the Databricks Lakehouse platform.

api usage

Checking dbt Databricks Adapter

dbt-databricks 1.8.0 is a clean version with no known supply chain compromise. The response returns compromised: false with an empty sources array.

bash
curl "https://api.attestd.io/v1/check?product=dbt-databricks&version=1.8.0" \
  -H "Authorization: Bearer YOUR_API_KEY"
json
{
  "product": "dbt-databricks",
  "version": "1.8.0",
  "supported": true,
  "risk_state": "none",
  "supply_chain": {
    "compromised": false,
    "sources": [],
    "malware_type": null,
    "description": null,
    "advisory_url": null,
    "compromised_at": null,
    "removed_at": null
  },
  "last_updated": "2026-05-01T00:00:00Z"
}
attack surface

Why this package is monitored

Databricks personal access tokens grant access to all workspaces, compute clusters, and Unity Catalog data assets associated with the account. A compromised adapter can forward these tokens to gain full platform access.

Attestd monitors dbt-databricks using the following detection sources:

registry

Manually curated advisories in the Attestd registry, verified by a human analyst. Confidence 1.0.

osv

OSV.dev malicious-package advisories with IDs prefixed MAL-. Confidence 0.95.

pypi_yank

Versions yanked on PyPI with a security-related yanked_reason annotation. Confidence 0.80.

related