Python Projects & Skills / The web and automation
Lesson 22 of 28
SQLite databases
SQLite stores data in a single file and comes built into Python. Always use ? placeholders for values, never string formatting, to avoid SQL injection.
Key points
- sqlite3.connect('app.db')
- Use ? placeholders
- commit() saves changes
import sqlite3
db = sqlite3.connect("app.db")
db.execute("CREATE TABLE IF NOT EXISTS users (name TEXT)")
db.execute("INSERT INTO users VALUES (?)", (name,))
db.commit()Quiz · +10 XP
What is the safe way to put user input into a SQL query?
Log in to save progress and earn XP.