chore(deps): bump net.snowflake:snowflake-jdbc from 4.1.0 to 4.2.0#901
Open
dependabot[bot] wants to merge 1 commit into
Open
chore(deps): bump net.snowflake:snowflake-jdbc from 4.1.0 to 4.2.0#901dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Contributor
🧪 Java Unit Tests
📦 Artifacts
🛡 TrivyVulnerability in:
|
| Vulnerability | Severity | Package | Installed Version | Fixed Version |
|---|---|---|---|---|
| GHSA-72hv-8253-57qq | MEDIUM | com.fasterxml.jackson.core:jackson-core | 2.21.0 | 2.21.1, 2.18.6 |
| CVE-2025-53864 | MEDIUM | com.nimbusds:nimbus-jose-jwt | 9.40 | 10.0.2, 9.37.4 |
| CVE-2025-48924 | MEDIUM | commons-lang:commons-lang | 2.4 | |
| CVE-2026-42583 | HIGH | io.netty:netty-codec-compression | 4.2.12.Final | 4.2.13.Final |
| CVE-2026-42583 | HIGH | io.netty:netty-codec-compression | 4.2.12.Final | 4.2.13.Final |
| CVE-2026-42583 | HIGH | io.netty:netty-codec-compression | 4.2.9.Final | 4.2.13.Final |
| CVE-2026-42579 | HIGH | io.netty:netty-codec-dns | 4.2.12.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-42579 | HIGH | io.netty:netty-codec-dns | 4.2.12.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-42584 | HIGH | io.netty:netty-codec-http | 4.2.12.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-42584 | HIGH | io.netty:netty-codec-http | 4.2.12.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-42587 | HIGH | io.netty:netty-codec-http | 4.2.12.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-42587 | HIGH | io.netty:netty-codec-http | 4.2.12.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-41417 | MEDIUM | io.netty:netty-codec-http | 4.2.12.Final | 4.1.133.Final, 4.2.13.Final |
| CVE-2026-41417 | MEDIUM | io.netty:netty-codec-http | 4.2.12.Final | 4.1.133.Final, 4.2.13.Final |
| CVE-2026-42580 | MEDIUM | io.netty:netty-codec-http | 4.2.12.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-42580 | MEDIUM | io.netty:netty-codec-http | 4.2.12.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-42581 | MEDIUM | io.netty:netty-codec-http | 4.2.12.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-42581 | MEDIUM | io.netty:netty-codec-http | 4.2.12.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-42585 | MEDIUM | io.netty:netty-codec-http | 4.2.12.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-42585 | MEDIUM | io.netty:netty-codec-http | 4.2.12.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-33870 | HIGH | io.netty:netty-codec-http | 4.2.9.Final | 4.1.132.Final, 4.2.10.Final |
| CVE-2026-42584 | HIGH | io.netty:netty-codec-http | 4.2.9.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-42587 | HIGH | io.netty:netty-codec-http | 4.2.9.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-41417 | MEDIUM | io.netty:netty-codec-http | 4.2.9.Final | 4.1.133.Final, 4.2.13.Final |
| CVE-2026-42580 | MEDIUM | io.netty:netty-codec-http | 4.2.9.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-42581 | MEDIUM | io.netty:netty-codec-http | 4.2.9.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-42585 | MEDIUM | io.netty:netty-codec-http | 4.2.9.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-42587 | HIGH | io.netty:netty-codec-http2 | 4.2.12.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-33871 | HIGH | io.netty:netty-codec-http2 | 4.2.9.Final | 4.1.132.Final, 4.2.11.Final |
| CVE-2026-42587 | HIGH | io.netty:netty-codec-http2 | 4.2.9.Final | 4.2.13.Final, 4.1.133.Final |
| CVE-2026-42578 | LOW | io.netty:netty-handler-proxy | 4.2.12.Final | 4.1.133.Final, 4.2.13.Final |
| CVE-2026-42578 | LOW | io.netty:netty-handler-proxy | 4.2.12.Final | 4.1.133.Final, 4.2.13.Final |
| CVE-2026-42578 | LOW | io.netty:netty-handler-proxy | 4.2.9.Final | 4.1.133.Final, 4.2.13.Final |
| CVE-2026-42577 | HIGH | io.netty:netty-transport-native-epoll | 4.2.12.Final | 4.2.13.Final |
| CVE-2026-42577 | HIGH | io.netty:netty-transport-native-epoll | 4.2.12.Final | 4.2.13.Final |
| CVE-2024-57699 | HIGH | net.minidev:json-smart | 2.5.1 | 2.5.2 |
| CVE-2026-34479 | MEDIUM | org.apache.logging.log4j:log4j-1.2-api | 2.25.3 | 2.25.4 |
| CVE-2026-34477 | MEDIUM | org.apache.logging.log4j:log4j-core | 2.25.3 | 2.25.4 |
| CVE-2026-34478 | MEDIUM | org.apache.logging.log4j:log4j-core | 2.25.3 | 2.25.4 |
| CVE-2026-34480 | MEDIUM | org.apache.logging.log4j:log4j-core | 2.25.3 | 2.25.4 |
| CVE-2026-40490 | MEDIUM | org.asynchttpclient:async-http-client | 3.0.7 | 3.0.9, 2.14.5 |
🔁 Unreleased Commits
✅ No unreleased commits found.
Contributor
Tests report quick summary:success ✅ > tests: 309, success: 256, skipped: 53, failed: 0 unfold for details
|
Member
|
@dependabot rebase |
Bumps [net.snowflake:snowflake-jdbc](https://github.com/snowflakedb/snowflake-jdbc) from 4.1.0 to 4.2.0. - [Release notes](https://github.com/snowflakedb/snowflake-jdbc/releases) - [Changelog](https://github.com/snowflakedb/snowflake-jdbc/blob/master/CHANGELOG.md) - [Commits](snowflakedb/snowflake-jdbc@v4.1.0...v4.2.0) --- updated-dependencies: - dependency-name: net.snowflake:snowflake-jdbc dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
4ae0084 to
f625073
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps net.snowflake:snowflake-jdbc from 4.1.0 to 4.2.0.
Release notes
Sourced from net.snowflake:snowflake-jdbc's releases.
Changelog
Sourced from net.snowflake:snowflake-jdbc's changelog.
... (truncated)
Commits
42fd80cNO-SNOW: Prepare v4.2.0 release (#2618)1f48f61SNOW-3445811 migrate nodes to snowos, remove default tag (#2613)2081ac3SNOW-3350278: Honor SKIP_TOKEN_FILE_PERMISSIONS_VERIFICATION for connections....6bbe33fNO-SNOW: dependency bump: netty 4.1.132.Final -> 4.1.133.Final, grpc-java 1.8...56fa127SNOW-3463039: fix NPE in TelemetryClient operations when session is null for ...cffbc1dSNOW-3313736 ExternalId Support for AWS WIF Impersonation (#2565)076ff68SNOW-3445438: bouncycastle.version 1.82 -> 1.84 (also maven-shade-plugin to 3...1f23b6bNO-SNOW: Add repo-local graphite-pr-workflow skill with mvn format + checksty...70c48feNO-SNOW: Remove ALLOW_LARGE_LOBS_IN_EXTERNAL_SCAN from LobSizeLatestIT (#2605)da2e018SNOW-3428785: add shutdown to executorService in s3 transfers (#2602)