Skip to content

Update snowflake-connector-python requirement from <4.8,>=3.12.1 to >=3.12.1,<4.9 - #657

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/snowflake-connector-python-gte-3.12.1-and-lt-4.9
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/snowflake-connector-python-gte-3.12.1-and-lt-4.9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on snowflake-connector-python to permit the latest version.

Release notes

Sourced from snowflake-connector-python's releases.

4.8.0

  • OCSP certificate revocation checks are now off unless you opt in. Set ocsp_fail_open=True or ocsp_fail_open=False to enable OCSP. The stored default is None (unset); only an explicit True/False opts in, so forwarding DEFAULT_CONFIGURATION as kwargs does not turn OCSP on. disable_ocsp_checks=True (or insecure_mode=True) always turns OCSP off, including when ocsp_fail_open is also set. disable_ocsp_checks=False and insecure_mode=False are the stored defaults and are not an opt-in. Connection attribute ocsp_fail_open is no longer a report of whether OCSP is fail-open; it is the stored preference (None = unset, True = fail-open, False = fail-closed). Use _ocsp_mode() / disable_ocsp_checks to see whether checks are actually on. ocsp_response_cache_filename and ocsp_root_certs_dict_lock_timeout do not turn OCSP on; if they are set without an OCSP mode parameter they are ignored and a warning is logged. The SF_OCSP_FAIL_OPEN environment variable still only switches fail-open vs fail-closed after OCSP is already on. Login OCSP_MODE telemetry now reports DISABLE_OCSP_CHECKS by default. The process-global FEATURE_OCSP_MODE is updated by each constructed REST client, except that a later default (OCSP off) client does not overwrite a non-default already stored on the process, and a later FAIL_OPEN client does not overwrite FAIL_CLOSED.

  • Fixed external-browser (SSO) authentication to validate the Origin header on the local callback server, rejecting tokens delivered from unexpected origins. A trailing slash in the origin (e.g. https://account.snowflakecomputing.com/) is now accepted on par with the bare origin, matching JDBC and other driver behaviour. Preconnect probe connections (empty recv) no longer count against the retry budget and no longer abort the login flow.

  • Added the SNOWFLAKE_TLS_CIPHERS environment variable to restrict which TLS ciphers the connector offers. It takes a colon-separated list; names beginning with TLS_ are applied as TLS 1.3 cipher suites and the remainder as the cipher list for TLS 1.2 and below, so a single variable covers both. Leaving it unset keeps OpenSSL's defaults unchanged, and an unrecognized cipher name is rejected rather than silently ignored. The restriction covers Snowflake API traffic, cloud-storage (stage) transfers, OCSP/CRL fetches and IdP requests. Requests issued by the AWS and Azure SDKs, and asynchronous connections, are not covered — for TLS 1.3 suites specifically they cannot be, because the Python standard library exposes no API for restricting them.

  • Raised the minimum pyOpenSSL requirement to 25.3.0, the first version providing set_tls13_ciphersuites. This does not narrow the set of installable versions in practice: earlier releases cap cryptography below 46 and so were already uninstallable alongside the connector's own cryptography>=46.0.5 requirement.

  • Added the workload_identity_host connection option that overrides the STS host used by AWS Workload Identity Federation, for endpoints the driver cannot derive from the region (such as an interface VPC endpoint). The default STS host is now resolved via botocore so partitions that do not use amazonaws.com (ISO, European Sovereign Cloud, ...) get the correct hostname. A privately routed host cannot be reached by Snowflake on the default GetCallerIdentity path, so a VPC or PrivateLink STS endpoint also requires workload_identity_aws_use_outbound_token=True (SNOW-4017192).

  • Fixed MD5 computation for Azure clouds (SNOW-4168830).

Commits
  • b4a5554 Bump up version to 4.8.0
  • e147a72 Mirroring sync after upstream SNOW-4082370 fix copybara actor for clo…
  • 2d6b531 SNOW-4108950 OCSP disabled by default
  • 963040f SNOW-4109570: Accept external-browser callback Origin only from the Snowflake...
  • d15f999 SNOW-4017190 Fix meta.yaml pyopenssl version
  • 0603714 Optimise calculation of Azure md5 checksum
  • 1d701fd SNOW-4017192 Make AWS STS hostname configurable
  • bbcf3f5 SNOW-4017190 Add SNOWFLAKE_TLS_CIPHERS support
  • 7eed898 SNOW-4109042: re-download remote chunks that under-fill rowCount
  • 5848911 Bump up version to 4.7.5
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [snowflake-connector-python](https://github.com/snowflakedb/snowflake-connector-python) to permit the latest version.
- [Release notes](https://github.com/snowflakedb/snowflake-connector-python/releases)
- [Commits](snowflakedb/snowflake-connector-python@v3.12.1...v4.8.0)

---
updated-dependencies:
- dependency-name: snowflake-connector-python
  dependency-version: 4.8.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Review — no comment produced this round

The review job finished without producing findings (job log). A maintainer may want to re-run it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants