vault icon indicating copy to clipboard operation
vault copied to clipboard

Bump github.com/snowflakedb/gosnowflake from 1.13.0 to 1.13.3

Open dependabot[bot] opened this issue 8 months ago • 5 comments

Bumps github.com/snowflakedb/gosnowflake from 1.13.0 to 1.13.3.

Release notes

Sourced from github.com/snowflakedb/gosnowflake's releases.

Release

Release

Release

Commits
  • 3d3e3b0 PATCH: Bumped up GoLang connector PATCH version from 1.13.2 to 1.13.3 (#1383)
  • ba94a48 SNOW-1155452 Fix race condition on perm checking for easy logging (#1382)
  • 14db80d SNOW-18254476 Readd PrPr for PAT and OAuth (#1381)
  • 96413d8 SNOW-1825500: Add OAuth Authorization Code, Client Credentials & Refresh Toke...
  • bee8f03 SNOW-2042000 Treat all non-Windows systems the same (#1372)
  • 750a0f3 SNOW-2034185: Remove reencryption when retry PUT upload (#1364)
  • c195281 SNOW-2026797 Adding PAT tests (#1374)
  • ae006c1 SNOW-2040000 change default tag to bptp-stable (#1366)
  • fb3995b SNOW-1825476 Remove PAT with password instead of token (#1357)
  • 912819c NO-SNOW Hide logger enabled flag behind mutex (#1358)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.

dependabot[bot] avatar Apr 29 '25 02:04 dependabot[bot]

Build Results: Build failed for these jobs: test:failure. Please refer to this workflow to learn more: https://github.com/hashicorp/vault/actions/runs/15197539905

github-actions[bot] avatar Apr 29 '25 02:04 github-actions[bot]

CI Results: All Go tests succeeded! :white_check_mark:

github-actions[bot] avatar Apr 29 '25 02:04 github-actions[bot]

Hello, Is there a possibility to have this ( upgrade of snowflake to 1.13.3) merged ? CVE-2025-46327 - is a HIGH according to NIST https://nvd.nist.gov/vuln/detail/CVE-2025-46327

arw357 avatar May 19 '25 09:05 arw357

@dependabot rebase

dduzgun-security avatar May 22 '25 21:05 dduzgun-security

@dependabot rebase

mcollao-hc avatar May 22 '25 21:05 mcollao-hc

Completed via https://github.com/hashicorp/vault/pull/31299

VioletHynes avatar Jul 17 '25 15:07 VioletHynes

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

dependabot[bot] avatar Jul 17 '25 15:07 dependabot[bot]