Skip to content

build(deps): Bump net.snowflake:snowflake-jdbc from 4.3.4 to 4.4.0 - #7690

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/net.snowflake-snowflake-jdbc-4.4.0
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/net.snowflake-snowflake-jdbc-4.4.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps net.snowflake:snowflake-jdbc from 4.3.4 to 4.4.0.

Release notes

Sourced from net.snowflake:snowflake-jdbc's releases.

v4.4.0

Changelog

Sourced from net.snowflake:snowflake-jdbc's changelog.

For all official JDBC Release Notes please refer to https://docs.snowflake.com/en/release-notes/clients-drivers/jdbc

Changelog

  • v4.4.1-SNAPSHOT

  • v4.4.0

    • Hardened external-browser callback handling by checking the Originsnowflakedb/snowflake-jdbc#27
    • OCSP revocation checking is now off by default. Enable it by setting ocspFailOpen (true = fail-open, false = fail-closed). disableOCSPChecks=false and insecureMode=false are the old default values and do not opt in. disableOCSPChecks=true and the deprecated insecureMode=true always turn OCSP off, including when ocspFailOpen is set; the ignored fail-open is logged at warn. The deprecated insecureMode property no longer selects the OCSP mode and no longer throws when it disagrees with disableOCSPChecks; leftover OCSP cache/server settings are logged at warn as ignored while OCSP is off.
    • Removed the SSE-S3 (AES256) header from PUT to unencrypted S3 stages so objects inherit the bucket default encryption instead of overriding it; client-side-encrypted stages are unchanged (SNOW-3701700).
    • Added workloadIdentityHost connection property that overrides the STS host used by AWS Workload Identity Federation, for endpoints the driver cannot derive from the region (such as an interface VPC endpoint). The default STS host is now resolved via the AWS SDK so partitions that do not use amazonaws.com (ISO, European Sovereign Cloud, ...) get the correct hostname. A privately routed host cannot be reached by Snowflake on the default GetCallerIdentity path, so a VPC or PrivateLink STS endpoint also requires workloadIdentityAwsUseOutboundToken=true (SNOW-4017201).
    • Added ci/scripts/generate_sbom.sh, which generates a CycloneDX SBOM (target/bom.json) covering both the driver and FIPS JAR dependency trees; not part of the release artifacts.
    • Removed the unused Conscrypt library (org.conscrypt:conscrypt-openjdk-uber) from the self-contained (fat) and FIPS JARs. It was only transitive weight from google-cloud-storage and is never used by the driver (SNOW-4071987).
    • Fixed the platformDetectionTimeoutMs connection property having no effect: platform detection always ran with the hardcoded 200 ms default, so the documented platformDetectionTimeoutMs=0snowflakedb/snowflake-jdbc#9
    • Added JVM-wide fallbacks for both platform-detection settings, so air-gapped deployments can suppress instance-metadata probes for the whole process instead of per connection: disablePlatformDetection now also reads the net.snowflake.jdbc.disablePlatformDetection system property and the SNOWFLAKE_DISABLE_PLATFORM_DETECTION environment variable (both accepting only a case-insensitive true), and platformDetectionTimeoutMs reads net.snowflake.jdbc.platformDetectionTimeoutMs / SNOWFLAKE_PLATFORM_DETECTION_TIMEOUT_MS; the connection property takes precedence over the system property, which takes precedence over the environment variable. A negative timeout is now treated as 0 instead of still issuing the requests, and a timeout above 5000 ms is clamped to that maximum, since detection holds a process-wide lock and an unbounded value would stall every other connection attempt for its full duration. When detection is disabled the driver reports PLATFORM=["disabled"]snowflakedb/snowflake-jdbc#9
    • Deprecated the MIN_TLS_VERSION and MAX_TLS_VERSION connection properties in favour of the JVM-wide jdk.tls.client.protocolssnowflakedb/snowflake-jdbc#10
    • Fixed the TLS version settings being held in process-global static fields and omitted from the HTTP client cache key, so a connection could silently inherit another connection's enabled TLS protocols; they are now part of HttpClientSettingsKey and scoped per connection. As a consequence they no longer reach HTTP clients built outside a session (Workload Identity platform detection, the sessionless SnowflakeFileTransfer entry point, and result sets rebuilt from a serialized form), which use the driver defaults of TLS 1.2-1.3; use jdk.tls.client.protocolssnowflakedb/snowflake-jdbc#10
    • Fixed invalid MIN_TLS_VERSION/MAX_TLS_VERSION values and an inverted version range surfacing as an unwrapped IllegalArgumentException from socket factory construction instead of a SnowflakeSQLException when the property is set, and fixed TLS version availability being resolved from the protocols the JSSE provider implements rather than the ones it will actually enable, so a version banned through the jdk.tls.disabledAlgorithmssnowflakedb/snowflake-jdbc#10
    • Fixed cipher suite selection using SSLServerSocketFactory's server-side default suites for the driver's client connections, which both discarded the JVM-wide jdk.tls.client.cipherSuites and jdk.tls.disabledAlgorithms settings and bypassed Apache HttpClient's weak-suite filtering. Selection is now left to JSSE unless https.cipherSuites is set, whose value is also trimmed. This covers the Snowflake connection and result-set chunk downloads only; PUT/GET stage transfers go through cloud storage SDKs that supply their own cipher list, where jdk.tls.disabledAlgorithmssnowflakedb/snowflake-jdbc#14
    • Fixed GET from a client-side-encrypted GCS stage on the GCSAccessStrategyAwsSdk strategy (useVirtualUrl) writing ciphertext and reporting success: encryption metadata returned as x-goog-meta-* is now read from the raw response headers instead of the empty S3 metadata map.
    • Fixed the GCS GCSAccessStrategyAwsSdk strategy (useVirtualUrl) leaking a thread pool on every PUT and GET; the per-call executor passed to S3TransferManager is now shut down in a finally on both the upload and download paths, mirroring the earlier S3 fix in snowflakedb/snowflake-jdbc#2602 (SNOW-4098951).
    • Bumped the following dependencies:
      • netty to 4.1.138.Final from 4.1.137.Final.
      • zstd-jni to 1.5.7-16 from 1.5.6-5.
      • BouncyCastle to 1.86 from 1.85.
      • jackson-databind to 2.18.11 from 2.18.10.
  • v4.3.4

    • Added validation of account, port and protocol in the auto-configuration (connections.toml) path, where the connect string's host is synthesized from account, so that none of the interpolated components can alter the resulting URL authority. Each dot-separated label of account may contain only letters, digits, underscores and hyphens (mirroring the Python connector), port must be a number in 1-65535, and protocol must be http or https. Absent or empty values keep their existing "not specified" meaning. As defense in depth, the ACCOUNTsnowflakedb/snowflake-jdbc#2752
    • Reduced sensitive detail in debug and response logging: the chunk result-master key is logged as a presence flag instead of its value, HTTP response header values are no longer logged (only header names), and chunk-download responses are rendered as a status line plus header names instead of HttpResponse.toString(), which would render every header value. SecretDetector additionally masks the X-Amz-Credential and X-Amz-Security-Token URL parameters, qrmksnowflakedb/snowflake-jdbc#2751
    • Restricted WORKLOAD_IDENTITY authentication to recognized Snowflake hosts: the attestation flow now verifies the target host before any ambient cloud credential is fetched and otherwise fails with WORKLOAD_IDENTITY_FLOW_ERROR naming the rejected host. Additional host suffixes can be permitted for local or test setups through the SNOWFLAKE_WIF_ALLOWED_HOST_SUFFIXESsnowflakedb/snowflake-jdbc#2750
    • Improved robustness of OCSP revocation checking: a definitive revocation result is now authoritative regardless of OCSP mode instead of being downgraded to a tolerable failure under the default FAIL_OPEN mode, each OCSP response entry is verified to describe the certificate being validated (issuer name hash, issuer key hash and serial number), and the cache entry is evicted on a definitive failure so it is not retained indefinitely. Recognized Snowflake host suffixes are now an explicit list (snowflakecomputing.com, snowflakecomputing.cn, snowflakecomputing.mil) matched on a label boundary, so a host on any other top-level domain is no longer detected as PrivateLink (SNOW-3649698).
    • Fixed PrivateLinkDetector.isPrivateLink() accepting any hostname that merely contained .privatelink.snowflakecomputing. as a substring, so a host such as evil.privatelink.snowflakecomputing.attacker.com was classified as a PrivateLink Snowflake host; a hostname must now actually end with .snowflakecomputing.<tld>. The OCSP response cache server URL, which is held in a JVM-wide static field, is now rejected when its host is not a Snowflake host (SNOW-3649698).
    • Fixed DecorrelatedJitterBackoff.nextSleepTime throwing IllegalArgumentException: bound must be greater than originsnowflakedb/snowflake-jdbc#2744
    • Fixed DatabaseMetaData.getTablePrivileges() concatenating unescaped table and schema names into SQL string literals, which allowed a quote character to break out of the query (SNOW-3236395).
    • Fixed DECFLOAT ResultSet.getString() using engineering notation (120E+198) instead of normalized scientific notation (1.2e200); values whose unsigned plain form fits in 38 characters stay in plain decimal (SNOW-3229469).
    • Fixed null nested structured-type fields throwing NullPointerException in JsonSqlOutput when binding via SQLOutput reference writers such as writeObject, writeBigDecimal, writeBytes, writeDate, and writeTimestamp (SNOW-1449489).
    • snowflakedb/snowflake-jdbc#2377
    • Fixed SnowflakeBasicDataSourcesnowflakedb/snowflake-jdbc#2621
    • Fixed SFFormatter omitting the associated stack trace when a log record has a thrown exception (SNOW-466174).
    • Fixed Linux credential cache parsing checking the root JSON node type a second time instead of the tokens child, which could fail the cache load when tokens was present but not an object (SNOW-4009235).
    • Fixed DatabaseMetaData.getColumns() discarding trim() on column default values and throwing NullPointerException when SHOW COLUMNS returns a SQL NULL default (SNOW-4009234).
    • Fixed PreparedStatement.setObject(parameterIndex, byte[], Types.BINARY) (and Types.VARBINARY/Types.LONGVARBINARY) binding the array's object reference ([B@..) instead of its hex value, causing a server-side Invalid bind value ... for type (BINARY) error; byte[] is now hex-encoded as setBytessnowflakedb/snowflake-jdbc#2731
    • Fixed slow PUT uploads to client-side-encrypted (internal/temporary) stages on the AWS SDK v2 async upload path — S3, and the GCS GCSAccessStrategyAwsSdk strategy (useVirtualUrl); the default GCP path (GCSDefaultAccessStrategy) is unchanged — where the CipherInputStreamsnowflakedb/snowflake-jdbc#2746
    • Bumped the following dependencies:
      • snowflakedb/snowflake-jdbc#2747
      • snowflakedb/snowflake-jdbc#2735
    • Fixed CertificateDiagnosticCheck completing its TLS probe without SNI for allowlist hosts containing underscores (Snowflake account names): such hosts are rejected by SNIHostName per the RFC 952 Letter-Digit-Hyphen rule, causing the JDK to silently send no server_name extension and the check to report on a default certificate rather than the one a real client would be served. The check now probes the hyphenated host variant that Snowflake also serves. Host normalization is unified across the diagnostic checks and connect-string parsing in a single SnowflakeUtil.normalizeSnowflakeHost helper and is scoped to Snowflake hosts, so third-party allowlist hosts (cloud storage, OCSP responders, Duo, ...) are left unchanged. The allowUnderscoresInHostsnowflakedb/snowflake-jdbc#2729
  • v4.3.3

... (truncated)

Commits
  • 85556ff NO-SNOW: Bump version to 4.4.0
  • d7215d1 SNOW-4109567: add CHANGELOG entry for external-browser callback origin hardening
  • 273ce8e [SNOW-4108953] OCSP disable by default
  • cf321bc SNOW-4109567: Accept external-browser callback Origin only from the Snowflake...
  • 6bc6315 SNOW-3701700 Remove SSE forced by the driver, depend on bucket defaults
  • b1dc356 NO-SNOW: Use a larger Windows runner for the heavy IT shard
  • 898ff16 SNOW-4143382: fix GCS encrypted GET returning ciphertext on the AWS-SDK strategy
  • b8664d2 NO-SNOW: Avoid Maven Central 429s when downloading Maven in CI
  • 5c46896 NO-SNOW: bumped jackson-databind to 2.18.11 from 2.18.10
  • e86d59f SNOW-4017201 Make AWS STS hostname configurable
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [net.snowflake:snowflake-jdbc](https://github.com/snowflakedb/snowflake-jdbc) from 4.3.4 to 4.4.0.
- [Release notes](https://github.com/snowflakedb/snowflake-jdbc/releases)
- [Changelog](https://github.com/snowflakedb/snowflake-jdbc/blob/master/CHANGELOG.md)
- [Commits](snowflakedb/snowflake-jdbc@v4.3.4...v4.4.0)

---
updated-dependencies:
- dependency-name: net.snowflake:snowflake-jdbc
  dependency-version: 4.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants