Skip to content

Conversation

@shawnwall
Copy link

Please answer these questions before submitting your pull requests. Thanks!

  1. What GitHub issue is this PR addressing? Make sure that there is an accompanying issue to your PR.

    Fixes SNOW-2402222: Dependency constraint on snowflake-connector-python prevents upgrade #615

  2. Fill out the following pre-review checklist:

    • I am adding a new automated test(s) to verify correctness of my new code
    • I am adding new logging messages
    • I am adding new credentials
    • I am adding a new dependency
  3. Please describe how your code solves the related issue.

I am mirroring the change made by dependabot which is failing CI likely due to a missing secrets config. I am hoping to see if this one passes CI.

@shawnwall shawnwall requested a review from a team as a code owner October 23, 2025 15:29
@github-actions
Copy link

github-actions bot commented Oct 23, 2025

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@shawnwall
Copy link
Author

I have read the CLA Document and I hereby sign the CLA

@shawnwall
Copy link
Author

recheck

@shawnwall
Copy link
Author

now that i'm looking at more pending pr's here, it looks like CI is perhaps entirely broken on the repo at the moment

Copy link

@sparkiegeek sparkiegeek left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Change looks good - drive-by comment on the looks-like-a-typo file in snyk/

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks like this file is typo garbage?

Copy link
Author

@shawnwall shawnwall Oct 30, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks like someone was trying to remove something related in #605

@sschrijver-pon
Copy link

We are also eagerly awaiting this change. Our security scans are now flagging PVE-2025-80257 (related to snowflake-connector-python < 4.0.0).
This pull request appears to be the key to allowing an upgrade to the patched connector version.
Could you please provide an update on its status or an estimated timeline for merging?

@shawnwall
Copy link
Author

We are also eagerly awaiting this change. Our security scans are now flagging PVE-2025-80257 (related to snowflake-connector-python < 4.0.0). This pull request appears to be the key to allowing an upgrade to the patched connector version. Could you please provide an update on its status or an estimated timeline for merging?

this library appears fairly unmaintained at the moment, as CI appears to be broken and nothing is getting merged. I'm sure they will get to it in time. I just refactored a codebase to remove it as a dependency as we werent using a ton of the orm features anyway, just the engine.

@hauntsaninja
Copy link

hauntsaninja commented Nov 25, 2025

@sfc-gh-jvasquezrojas thoughts on merging this and making a release?

@ruiyang2015
Copy link

any progress on this?

@sfc-gh-dszmolka
Copy link
Contributor

apologies for the long wait on this, but now the library should be in good hands and PRs like this should get attention much quicker in the future. please see the pinned Issue in this repo

for this particular change, it is already available since 1.8.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SNOW-2402222: Dependency constraint on snowflake-connector-python prevents upgrade

7 participants