Skip to content

deps: update snowflake-connector-python requirement from <4,>=3.6 to >=3.6,<5 in /scripts - #7

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/scripts/snowflake-connector-python-gte-3.6-and-lt-5
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/scripts/snowflake-connector-python-gte-3.6-and-lt-5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 12, 2026

Copy link
Copy Markdown

Updates the requirements on snowflake-connector-python to permit the latest version.

Release notes

Sourced from snowflake-connector-python's releases.

4.4.0

  • v4.4.0(March 24,2026)
    • Bump the lower boundary of cryptography to 46.0.5 due to CVE-2026-26007.
    • Added support for Python 3.14.
    • Removed pyOpenSSL upper bound dependency constraint to allow installation of pyOpenSSL 26.0.0+, which includes a fix for GHSA-vp96-hxj8-p424.
    • Fixed Azure IMDS Metadata header to use lowercase "true" instead of "True", which caused 400 errors during Azure Workload Identity Federation authentication.
    • Fixed default crl_download_max_size to be 20MB instead of 200MB, as the previous value was set too high and could cause out-of-memory issues.
    • Fixed a bug where Azure GET commands would incorrectly set the file status to UPLOADED instead of preserving the DOWNLOADED status during metadata retrieval.
    • Renamed the environment variable for skipping config file permission warnings from SF_SKIP_WARNING_FOR_READ_PERMISSIONS_ON_CONFIG_FILE to SF_SKIP_TOKEN_FILE_PERMISSIONS_VERIFICATION. The old variable is still supported but emits a deprecation warning.
    • Fixed unsafe_skip_file_permissions_check flag not being respected when reading connections.toml.
    • Fixed JSONDecodeError in result_batch._load() when fetching large result sets
Commits
  • 2b59c8a Upgrade cryptography to match setup cfg (#2824)
  • 1f6635d NO-SNOW: test_cursor_execute_timeout failure on Windows Python 3.9/3.10 (#2822)
  • 98f314e SNOW-3192362: Fix AWS integration regressions without matrix changes (#2819)
  • d743057 SNOW-3244317: Fix pytest session hang caused by pytest-rerunfailures socket s...
  • f3d7434 Bump up version to 4.4.0 (#2806)
  • 218e2f7 NO-SNOW: Require mitmproxy 12+ on Python 3.12+ to fix cryptography (#2801)
  • e4dcba5 Snow-2684150: 3.14 wheels fix docker (#2799)
  • 5d7af3b Fix JSONDecodeError in result_batch._load() when fetching large result sets (...
  • 469f300 NO-SNOW: Refactor _detect_libc to use platform.libc_ver (#2780)
  • 7c4408f Upgrade cryptography from 44.0.1 to 46.0.5 (#2800)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [snowflake-connector-python](https://github.com/snowflakedb/snowflake-connector-python) to permit the latest version.
- [Release notes](https://github.com/snowflakedb/snowflake-connector-python/releases)
- [Commits](snowflakedb/snowflake-connector-python@v3.6.0...v4.4.0)

---
updated-dependencies:
- dependency-name: snowflake-connector-python
  dependency-version: 4.4.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github May 12, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies, python. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants