diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index 46f1a70..5703258 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -1 +1 @@ -* @sfc-gh-yhailu \ No newline at end of file +* @sfc-gh-yhailu @sfc-gh-skalaga \ No newline at end of file diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index aea652e..6bbf017 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -9,9 +9,9 @@ jobs: release: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Set up JDK 11 - uses: actions/setup-java@v4 + uses: actions/setup-java@v6 with: java-version: '11' distribution: 'temurin' @@ -20,7 +20,9 @@ jobs: export VERSION=$(grep "^releaseVersion=" gradle.properties | awk -F"=" '{ print $2 }') echo "VERSION=$VERSION" >> $GITHUB_ENV - name: Setup Gradle - uses: gradle/gradle-build-action@v2 + uses: gradle/actions/setup-gradle@v6 + with: + cache-provider: basic - name: Build with Gradle run: ./gradlew clean build - name: setup git config @@ -33,7 +35,7 @@ jobs: git tag -a v${{ env.VERSION }} -m "version ${{ env.VERSION }}" git push origin v${{ env.VERSION }} - name: Create GitHub Release - uses: softprops/action-gh-release@v1 + uses: softprops/action-gh-release@v3 with: tag_name: v${{ env.VERSION }} name: Release v${{ env.VERSION }} diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index cc6feb4..674c590 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -9,11 +9,13 @@ jobs: test: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-java@v4 + - uses: actions/checkout@v7 + - uses: actions/setup-java@v6 with: java-version: '11' distribution: 'temurin' - - uses: gradle/actions/setup-gradle@v4 + - uses: gradle/actions/setup-gradle@v6 + with: + cache-provider: basic - name: test with gradle run: ./gradlew test \ No newline at end of file diff --git a/CHANGELOG.md b/CHANGELOG.md index 931fd79..fb5d447 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,14 @@ This project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## [3.3.0] - 2026-09-30 +### Added +- Workload Identity Federation (WIF) JDBC auth: pass `token` and `workloadIdentityProvider` through to Snowflake JDBC +- Upgraded `snowflake-jdbc` from 3.25.1 to 3.28.0 (WIF authenticator support) +### Changed +- Updated GitHub Actions to supported versions: `actions/checkout` v7, `actions/setup-java` v6, `softprops/action-gh-release` v3 +- Replaced deprecated `gradle/gradle-build-action` with `gradle/actions/setup-gradle` v6 + ## [3.2.0] - 2026-02-27 ### Added - Added PLAN command for deployment preview (dry-run without database modifications) diff --git a/README.md b/README.md index 9034832..558883b 100644 --- a/README.md +++ b/README.md @@ -347,6 +347,8 @@ connection: authenticator: # snowflake authenticator(optional) private_key_file: # snowflake p8 file (optional) private_key_pwd: # password for private key file (optional) + token: # OAuth or WIF token (optional) + workloadIdentityProvider: # OIDC, AWS, AZURE, or GCP when authenticator is WORKLOAD_IDENTITY (optional) ``` The `configTables` is used by create script module to add the data of the tables to the script file. The `scriptExclusion` is used to exclude the script files from being processed by this tool. @@ -362,11 +364,13 @@ db=database #your database schema=dl_sync #your dl_sync schema. It will use this schema to store neccessary tables for this tool user=user_name #user name of the database password=password #password for the connection (optional) -authenticator=externalbrowser #authenticator used for the connection (optional) +authenticator=externalbrowser #authenticator used for the connection (optional). Use WORKLOAD_IDENTITY for WIF warehouse=my_warehouse #warehouse to be used by the connection role=my_role #role used by this tool private_key_file=my_private_key_file.p8 # private key file used for the connection (optional) private_key_pwd=my_private_key_password # password for the private key file (optional) +token=oauth_or_wif_token # OAuth / WIF token (optional) +workloadIdentityProvider=OIDC # OIDC, AWS, AZURE, or GCP when authenticator=WORKLOAD_IDENTITY (optional) JAVA_TOOL_OPTIONS ="-Dnet.snowflake.jdbc.enableBouncyCastle=true" # This must be set if using encrypted key-pair authentication ``` diff --git a/build.gradle b/build.gradle index 6d2ca55..0cbad7e 100644 --- a/build.gradle +++ b/build.gradle @@ -16,7 +16,7 @@ repositories { dependencies { implementation 'org.apache.commons:commons-text:1.14.0' - implementation 'net.snowflake:snowflake-jdbc:3.25.1' + implementation 'net.snowflake:snowflake-jdbc:3.28.0' implementation 'ch.qos.logback:logback-core:1.5.25' implementation 'ch.qos.logback:logback-classic:1.5.25' implementation 'org.slf4j:slf4j-api:2.0.4' diff --git a/gradle.properties b/gradle.properties index ff0ecd6..eb6c507 100644 --- a/gradle.properties +++ b/gradle.properties @@ -1 +1 @@ -releaseVersion=3.2.0 \ No newline at end of file +releaseVersion=3.3.0 \ No newline at end of file diff --git a/pom.xml b/pom.xml index c193297..253af79 100644 --- a/pom.xml +++ b/pom.xml @@ -22,7 +22,7 @@ net.snowflake snowflake-jdbc - 3.25.1 + 3.28.0 ch.qos.logback diff --git a/src/main/java/com/snowflake/dlsync/ConfigManager.java b/src/main/java/com/snowflake/dlsync/ConfigManager.java index d6ba243..a550bde 100644 --- a/src/main/java/com/snowflake/dlsync/ConfigManager.java +++ b/src/main/java/com/snowflake/dlsync/ConfigManager.java @@ -18,7 +18,7 @@ @Slf4j public class ConfigManager { private final static String CONFIG_FILE_NAME = "config.yaml"; - private final static String[] JDBC_KEY = {"url", "account", "user", "password", "authenticator", "role", "warehouse", "db", "schema", "private_key_file", "private_key_pwd"}; + private final static String[] JDBC_KEY = {"url", "account", "user", "password", "authenticator", "role", "warehouse", "db", "schema", "private_key_file", "private_key_pwd", "token", "workloadIdentityProvider"}; private final static String SCRIPT_ROOT_KEY = "SCRIPT_ROOT"; private String scriptRoot; private String profile;