Skip to content

Bump snowflake-connector-python from 4.7.2 to 4.7.5 in /Controller - #48

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/Controller/snowflake-connector-python-4.7.5
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/Controller/snowflake-connector-python-4.7.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown
Contributor

Bumps snowflake-connector-python from 4.7.2 to 4.7.5.

Release notes

Sourced from snowflake-connector-python's releases.

4.7.5

Fixes

  • Follow-up to the v4.7.4 incomplete-result fix (SNOW-4109042): when a successful query-request has an incomplete inline first chunk, the connector re-fetches the finished query once via GET /queries/{qid}/result before building the result set. JSON treats empty or shorter-than-declared inline rowsets as incomplete; Arrow only treats a missing/empty rowsetBase64 as incomplete so the execute hot path does not decode IPC. If the result GET fails (transport error or success: false), the original payload is kept; if the GET succeeds but is still incomplete, that response is used. In either incomplete case the existing rowcount/total checks still raise OperationalError errno 252013 when the result is drained (no silent EOF). On the sync path, a remote result chunk whose body holds fewer rows than its declared rowCount is re-downloaded once before that check raises, so a truncated-but-valid chunk download can recover without silent data loss. Asynchronous (snowflake.connector.aio) remote-chunk re-download is unchanged. set. Both the sync and async paths are fixed (SNOW-4109042).
  • Fixed a TLS handshake failure that cannot succeed on a retry — a minimum-version mismatch, an untrusted certificate, a hostname mismatch — being reported by connect() as a generic 250001: Could not connect to Snowflake backend after N attempt(s) alongside a firewall-troubleshooting hint. The network layer already identified and named such failures, but the authentication layer retried them until the login timeout expired and then replaced the diagnosis. They now surface as NonRetryableTlsError (a subclass of OperationalError keeping the same errno, so existing handlers are unaffected) naming the underlying cause, and are no longer retried. Transient handshake faults (ECONNRESET, unexpected EOF) remain retryable.

Features

  • Added the SNOWFLAKE_MIN_TLS_VERSION environment variable (1.2, 1.3, TLSv1.2 or TLSv1.3, defaulting to TLS 1.2) to raise the minimum TLS version on every outbound connection a synchronous connector makes: the Snowflake API, stage transfers, OCSP/CRL fetches, platform detection, IdP requests, AWS SDK requests (workload identity STS calls and the platform-detection identity probe) and Azure AD token requests made by azure-identity. An unrecognized value is rejected at connect time.

4.7.4

  • Fixed missing retries on transient HTTP failures when fetching an OAuth access token from the IdP token endpoint (OAUTH_CLIENT_CREDENTIALS and OAUTH_AUTHORIZATION_CODE). Token requests now retry transport errors, HTTP 408/429, and 5xx responses (SNOW-3984430, #3003).
  • Fixed a bug where a TLS handshake terminated by the peer (SSLError containing SysCallError(-1, 'Unexpected EOF')) was classified as non-retryable and surfaced as an OperationalError, unlike ECONNRESET. Such handshake Unexpected EOF errors are now retried, on both the sync and async request paths (SNOW-4058589).
  • Fixed fetchone(), fetchmany(), fetchall() and cursor iteration silently returning an incomplete result set. A downloaded result chunk holding fewer rows than the back-end reported just ended the iteration, which the fetch methods report as a normal end of results, so callers received fewer rows than the query produced with no exception raised. Such a chunk now raises an OperationalError (errno 252013). Errors raised while iterating a result set are no longer reported as end-of-results either: _fetchone() caught every TypeError and returned None, so a failure anywhere in the download/parse chain was indistinguishable from an exhausted result set. Both the sync and async paths are fixed (SNOW-4109042).

4.7.3

  • v4.7.3(Sep 3,2026)
    • Added experimental Python 3.14t (free-threaded CPython) wheel support. Experimental — not intended for production use.
    • Fixed TLS hostname verification rejecting matching certificate SANs when a Snowflake account locator contains an underscore (SNOW-4011646).
    • Fixed connect() being significantly slower on deep call stacks (e.g. Django apps with several middleware/decorator layers) because get_application_path() used inspect.stack(), which reads and parses the source file of every frame on the stack. It now walks frame references directly instead (SNOW-3691001, #2908).
    • Fixed split_statements truncating unquoted URLs containing :// at the //, misreading it as a line comment. The guards added alongside // comment support in 4.7.2 (SNOW-3772985) only recognized file://, so every other scheme (http://, https://, s3://, snow://, azure://) was cut short. Any scheme:// is now recognized, on both the line-comment and block-comment paths (the latter affected globs such as s3://bucket/*.csv) (SNOW-3930192).
    • Fixed the on-disk OCSP response validation cache failing with RuntimeError: UnixFileLock on ... was inherited across fork; construct a new instance when it was written from a forked child process. This could surface on fork-based platforms when fetching results with client_fetch_use_mp=True, where chunk downloads run in worker processes that perform their own certificate revocation checks. The cache's file lock is now re-created when the owning process changes, matching what already happened for the spawn start method.
    • Result batch construction now logs only whether a qrmk is present, for both the sync and async result paths (SNOW-3675590).
    • DEBUG logging in create_batches_from_response() reports chunk-header names with type/length value metadata (SNOW-3675590).
    • The malformed-response ERROR log in create_batches_from_response() reports a structural summary of the response (SNOW-3675590).
    • SQL text is masked before it is written to DEBUG logs: _format_query_for_log() runs the query through SecretDetector, covering the cursor and connection paths on both sync and async. The cancel-query log paths use the same masking (SNOW-3675590).
    • Deferred the SQL-masking cost to log emit-time: query DEBUG lines pass a lazy _format_query_for_log_lazy() wrapper whose __str__ masks only whena handler emits the record (SNOW-3675590).
    • Corrected the invalid-account-identifier error message so it matches the validator, which allows '.' as a label separator.
    • The WORKLOAD_IDENTITY authenticator runs only against recognized Snowflake hosts: the connection host is normalized and suffix-anchored against snowflakecomputing.com, .cn, and .mil before the workload-identity flow proceeds. The SNOWFLAKE_WIF_ALLOWED_HOST_SUFFIXES environment variable additively extends the recognized-host list (SNOW-3675580).
    • Improved the robustness and correctness of OCSP revocation checking (SNOW-3675581).
      • When SF_OCSP_RESPONSE_CACHE_SERVER_URL is set, the connector uses it as the OCSP cache server, including on PrivateLink hosts.
      • A PrivateLink OCSP cache URL is derived only for hosts that consist of hostname characters, include a .privatelink. label, and end at snowflakecomputing.com, .cn, or .mil. Other hosts use the public default cache URL; set SF_OCSP_RESPONSE_CACHE_SERVER_URL to use a different cache server.
    • Extended log secret masking coverage (SNOW-3675583). The connection-token pattern accepts : and % in the token value. Added patterns for OAuth access and refresh tokens in serialized JSON, for one-time passcodes, and for OAuth client identifiers and secrets. The passcode pattern accepts quoted values. The password pattern requires at least six characters in the value, so ordinary prose following the word "password" is not redacted.
    • Request headers are copied before mutation on the async path, and masking is applied to the Authorization header in error logs (SNOW-3675593).
    • Applied secret masking to the snowflake.connector loggers by default, independent of how application logging is configured. The same filter also covers the third-party loggers the connector uses (botocore, boto3, aiohttp, aiobotocore, aioboto3, vendored urllib3). Set SNOWFLAKE_DISABLE_LOG_SECRET_MASKING=true to opt out; it is honored at emit time, including after import (SNOW-3675583).
Commits
  • 7eed898 SNOW-4109042: re-download remote chunks that under-fill rowCount
  • 5848911 Bump up version to 4.7.5
  • 2be12fb SNOW-4017190 Add min TLS version knob to sync path
  • 3787518 SNOW-4109042: re-fetch result when the inline first chunk is incomplete
  • be70390 Bump up version to 4.7.4
  • 7a19e81 SNOW-3984430: retry transient OAuth token-request HTTP failures
  • 1309e17 SNOW-4109042: fail instead of silently returning an incomplete result set
  • 7598b45 SNOW-3882899 Copybara init
  • e1c7771 Fix 4.7.2 changelog after bad merge (#3029)
  • a28c63e SNOW-4058589: retry SSLError "Unexpected EOF" during TLS handshake (#3027)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [snowflake-connector-python](https://github.com/snowflakedb/snowflake-connector-python) from 4.7.2 to 4.7.5.
- [Release notes](https://github.com/snowflakedb/snowflake-connector-python/releases)
- [Commits](snowflakedb/snowflake-connector-python@v4.7.2...v4.7.5)

---
updated-dependencies:
- dependency-name: snowflake-connector-python
  dependency-version: 4.7.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants