Skip to content

Bump snowflake-connector-python from 4.7.3 to 4.8.0 in /Admin UI - #59

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/Admin-UI/snowflake-connector-python-4.8.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/Admin-UI/snowflake-connector-python-4.8.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps snowflake-connector-python from 4.7.3 to 4.8.0.

Release notes

Sourced from snowflake-connector-python's releases.

4.8.0

  • OCSP certificate revocation checks are now off unless you opt in. Set ocsp_fail_open=True or ocsp_fail_open=False to enable OCSP. The stored default is None (unset); only an explicit True/False opts in, so forwarding DEFAULT_CONFIGURATION as kwargs does not turn OCSP on. disable_ocsp_checks=True (or insecure_mode=True) always turns OCSP off, including when ocsp_fail_open is also set. disable_ocsp_checks=False and insecure_mode=False are the stored defaults and are not an opt-in. Connection attribute ocsp_fail_open is no longer a report of whether OCSP is fail-open; it is the stored preference (None = unset, True = fail-open, False = fail-closed). Use _ocsp_mode() / disable_ocsp_checks to see whether checks are actually on. ocsp_response_cache_filename and ocsp_root_certs_dict_lock_timeout do not turn OCSP on; if they are set without an OCSP mode parameter they are ignored and a warning is logged. The SF_OCSP_FAIL_OPEN environment variable still only switches fail-open vs fail-closed after OCSP is already on. Login OCSP_MODE telemetry now reports DISABLE_OCSP_CHECKS by default. The process-global FEATURE_OCSP_MODE is updated by each constructed REST client, except that a later default (OCSP off) client does not overwrite a non-default already stored on the process, and a later FAIL_OPEN client does not overwrite FAIL_CLOSED.

  • Fixed external-browser (SSO) authentication to validate the Origin header on the local callback server, rejecting tokens delivered from unexpected origins. A trailing slash in the origin (e.g. https://account.snowflakecomputing.com/) is now accepted on par with the bare origin, matching JDBC and other driver behaviour. Preconnect probe connections (empty recv) no longer count against the retry budget and no longer abort the login flow.

  • Added the SNOWFLAKE_TLS_CIPHERS environment variable to restrict which TLS ciphers the connector offers. It takes a colon-separated list; names beginning with TLS_ are applied as TLS 1.3 cipher suites and the remainder as the cipher list for TLS 1.2 and below, so a single variable covers both. Leaving it unset keeps OpenSSL's defaults unchanged, and an unrecognized cipher name is rejected rather than silently ignored. The restriction covers Snowflake API traffic, cloud-storage (stage) transfers, OCSP/CRL fetches and IdP requests. Requests issued by the AWS and Azure SDKs, and asynchronous connections, are not covered — for TLS 1.3 suites specifically they cannot be, because the Python standard library exposes no API for restricting them.

  • Raised the minimum pyOpenSSL requirement to 25.3.0, the first version providing set_tls13_ciphersuites. This does not narrow the set of installable versions in practice: earlier releases cap cryptography below 46 and so were already uninstallable alongside the connector's own cryptography>=46.0.5 requirement.

  • Added the workload_identity_host connection option that overrides the STS host used by AWS Workload Identity Federation, for endpoints the driver cannot derive from the region (such as an interface VPC endpoint). The default STS host is now resolved via botocore so partitions that do not use amazonaws.com (ISO, European Sovereign Cloud, ...) get the correct hostname. A privately routed host cannot be reached by Snowflake on the default GetCallerIdentity path, so a VPC or PrivateLink STS endpoint also requires workload_identity_aws_use_outbound_token=True (SNOW-4017192).

  • Fixed MD5 computation for Azure clouds (SNOW-4168830).

4.7.5

Fixes

  • Follow-up to the v4.7.4 incomplete-result fix (SNOW-4109042): when a successful query-request has an incomplete inline first chunk, the connector re-fetches the finished query once via GET /queries/{qid}/result before building the result set. JSON treats empty or shorter-than-declared inline rowsets as incomplete; Arrow only treats a missing/empty rowsetBase64 as incomplete so the execute hot path does not decode IPC. If the result GET fails (transport error or success: false), the original payload is kept; if the GET succeeds but is still incomplete, that response is used. In either incomplete case the existing rowcount/total checks still raise OperationalError errno 252013 when the result is drained (no silent EOF). On the sync path, a remote result chunk whose body holds fewer rows than its declared rowCount is re-downloaded once before that check raises, so a truncated-but-valid chunk download can recover without silent data loss. Asynchronous (snowflake.connector.aio) remote-chunk re-download is unchanged. set. Both the sync and async paths are fixed (SNOW-4109042).
  • Fixed a TLS handshake failure that cannot succeed on a retry — a minimum-version mismatch, an untrusted certificate, a hostname mismatch — being reported by connect() as a generic 250001: Could not connect to Snowflake backend after N attempt(s) alongside a firewall-troubleshooting hint. The network layer already identified and named such failures, but the authentication layer retried them until the login timeout expired and then replaced the diagnosis. They now surface as NonRetryableTlsError (a subclass of OperationalError keeping the same errno, so existing handlers are unaffected) naming the underlying cause, and are no longer retried. Transient handshake faults (ECONNRESET, unexpected EOF) remain retryable.

Features

  • Added the SNOWFLAKE_MIN_TLS_VERSION environment variable (1.2, 1.3, TLSv1.2 or TLSv1.3, defaulting to TLS 1.2) to raise the minimum TLS version on every outbound connection a synchronous connector makes: the Snowflake API, stage transfers, OCSP/CRL fetches, platform detection, IdP requests, AWS SDK requests (workload identity STS calls and the platform-detection identity probe) and Azure AD token requests made by azure-identity. An unrecognized value is rejected at connect time.

4.7.4

  • Fixed missing retries on transient HTTP failures when fetching an OAuth access token from the IdP token endpoint (OAUTH_CLIENT_CREDENTIALS and OAUTH_AUTHORIZATION_CODE). Token requests now retry transport errors, HTTP 408/429, and 5xx responses (SNOW-3984430, #3003).
  • Fixed a bug where a TLS handshake terminated by the peer (SSLError containing SysCallError(-1, 'Unexpected EOF')) was classified as non-retryable and surfaced as an OperationalError, unlike ECONNRESET. Such handshake Unexpected EOF errors are now retried, on both the sync and async request paths (SNOW-4058589).
  • Fixed fetchone(), fetchmany(), fetchall() and cursor iteration silently returning an incomplete result set. A downloaded result chunk holding fewer rows than the back-end reported just ended the iteration, which the fetch methods report as a normal end of results, so callers received fewer rows than the query produced with no exception raised. Such a chunk now raises an OperationalError (errno 252013). Errors raised while iterating a result set are no longer reported as end-of-results either: _fetchone() caught every TypeError and returned None, so a failure anywhere in the download/parse chain was indistinguishable from an exhausted result set. Both the sync and async paths are fixed (SNOW-4109042).
Commits
  • b4a5554 Bump up version to 4.8.0
  • e147a72 Mirroring sync after upstream SNOW-4082370 fix copybara actor for clo…
  • 2d6b531 SNOW-4108950 OCSP disabled by default
  • 963040f SNOW-4109570: Accept external-browser callback Origin only from the Snowflake...
  • d15f999 SNOW-4017190 Fix meta.yaml pyopenssl version
  • 0603714 Optimise calculation of Azure md5 checksum
  • 1d701fd SNOW-4017192 Make AWS STS hostname configurable
  • bbcf3f5 SNOW-4017190 Add SNOWFLAKE_TLS_CIPHERS support
  • 7eed898 SNOW-4109042: re-download remote chunks that under-fill rowCount
  • 5848911 Bump up version to 4.7.5
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [snowflake-connector-python](https://github.com/snowflakedb/snowflake-connector-python) from 4.7.3 to 4.8.0.
- [Release notes](https://github.com/snowflakedb/snowflake-connector-python/releases)
- [Commits](snowflakedb/snowflake-connector-python@v4.7.3...v4.8.0)

---
updated-dependencies:
- dependency-name: snowflake-connector-python
  dependency-version: 4.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants