Skip to content

Conversation

@sfc-gh-joshi
Copy link
Contributor

@sfc-gh-joshi sfc-gh-joshi commented Jan 23, 2026

  1. Which Jira issue is this PR addressing? Make sure that there is an accompanying issue to your PR.

    Fixes SNOW-3018722
    Fixes SNOW-3018722: Use latest protobuf version due to CVE-2026-0994 #4056

  2. Fill out the following pre-review checklist:

    • I am adding a new automated test(s) to verify correctness of my new code
      • If this test skips Local Testing mode, I'm requesting review from @snowflakedb/local-testing
    • I am adding new logging messages
    • I am adding a new telemetry message
    • I am adding new credentials
    • I am adding a new dependency
    • If this is a new feature/behavior, I'm adding the Local Testing parity changes.
    • I acknowledge that I have ensured my changes to be thread-safe. Follow the link for more information: Thread-safe Developer Guidelines
    • If adding any arguments to public Snowpark APIs or creating new public Snowpark APIs, I acknowledge that I have ensured my changes include AST support. Follow the link for more information: AST Support Guidelines
  3. Please describe how your code solves the related issue.

Bumps the protobuf dependency in response to a high-severity CVE. There appear to be no major breaking changes on our end, though a newly-raised TypeError actually uncovered a bug in our UDF registration code.

As protobuf 7.34.0rc1 is still a release candidate, we may need to wait for a full 7.34.0 release to properly test.

@sfc-gh-joshi sfc-gh-joshi changed the title SNOW-3018722: Bump protobuf to <= 7.35 SNOW-3018722: Bump protobuf to < 7.35 Jan 23, 2026
@sfc-gh-joshi sfc-gh-joshi force-pushed the joshi-SNOW-3018722-protobuf-bump branch from 947d60a to c751179 Compare January 29, 2026 23:28
@sfc-gh-joshi sfc-gh-joshi changed the title SNOW-3018722: Bump protobuf to < 7.35 NO-SNOW: Fix UDF parameter registration error Jan 29, 2026
@github-actions github-actions bot locked and limited conversation to collaborators Jan 29, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SNOW-3018722: Use latest protobuf version due to CVE-2026-0994

3 participants