Skip to content

v3.17.0

Choose a tag to compare

@sfc-gh-olorek sfc-gh-olorek released this 11 May 15:34
· 434 commits to main since this release

Deprecations

New additions

  • snow app now supports both Snowflake Native Apps (application / application package entities) and Snowflake Apps Deploy (snowflake-app entities). The entity type in snowflake.yml determines which flow is used, so shared subcommands like bundle, deploy, validate, open, events, and teardown automatically pick the correct behavior. The experimental hidden snow __app command group and the ENABLE_SNOWFLAKE_APPS feature flag have been removed.
  • Added snow app setup command for initializing a snowflake.yml for a Snowflake Apps Deploy project.
  • Added snow connection generate-workload-identity-token command to generate a workload identity token for the current environment. Supports AWS, GCP, Azure, and OIDC providers via --workload-identity-provider flag or connection configuration.
  • Added snow custom-image validate command to validate custom Docker images against configured rules (entrypoint, environment variables, Python packages, dependency health). Supports an optional --scan-vulnerabilities flag to run Grype vulnerability scanning.
  • Added snow dcm purge command to drop all the objects managed by the specified DCM Project
  • DCM manifest targets now validate account_identifier and project_owner fields.
    CLI validates these against the current session and prints a warning on mismatch:
    • account_identifier is checked for all manifest-based commands
    • project_owner is checked for snow dcm create
  • Added a --secondary-roles option (plus matching SNOWFLAKE_SECONDARY_ROLES env var and secondary_roles config key) to snow connection add and the global connection overrides. The value is forwarded to snowflake-connector-python and accepts ALL or NONE, so sessions can be pinned to the primary role without running an extra USE SECONDARY ROLES statement.
  • Added --force flag to snow spcs service drop to allow dropping services that contain block storage volumes.

Fixes and improvements

  • Significantly improved DCM files upload performance
  • Fixed snow streamlit deploy failing with a collision error when pages/*.py glob in additional_source_files overlaps with the automatically-included pages/ directory. Overlapping glob patterns are now deduplicated during v1-to-v2 definition conversion.
  • Updated snowflake-connector-python to version 4.4.0. Connector python 4.x series introduced stricter permission checks. In future versions of Snowflake CLI strict configuration file permissions will become mandatory. To test if your files have correct permissions set SNOWFLAKE_CLI_FEATURES_ENFORCE_STRICT_CONFIG_PERMISSIONS=1 before running CLI commands.
  • Fixed error message when PRIVATE_KEY_PASSPHRASE environment variable is set to an empty string.
  • Fixed SELECT * output being corrupted when joined tables share column names. Duplicate column names are now disambiguated by appending a numeric suffix (e.g. NAME, NAME_2).
  • Fixed snow connection generate-jwt and snow connection generate-workload-identity-token failing with Connection None is not configured when used with --temporary-connection.
  • The internal connection cache now remembers failed connect attempts and re-raises the original exception on subsequent accesses within the same process, instead of re-dialing Snowflake every time a command accesses the shared connection. This fixes, among other cases, the customer-visible duplicate LOGIN_HISTORY events (and OVERFLOW_FAILURE_EVENTS_ELIDED) previously emitted when a snow invocation was rejected by an authentication policy.
  • Fixed session/master token connections created from environment variables or named connection config not enabling token keep-alive settings. This could cause follow-up commands to fail with 251007: Session and master tokens invalid.