Skip to content

MongoDB (v3): document the 4.4 minimum after the PyMongo 4.18.2 upgrade - #1261

Open
zachharris1 wants to merge 1 commit into
masterfrom
zachharris1/SAC-32067-mongodb-v3-supported-versions
Open

zachharris1 wants to merge 1 commit into
masterfrom
zachharris1/SAC-32067-mongodb-v3-supported-versions

Conversation

@zachharris1

Copy link
Copy Markdown

Description of change

Documents the MongoDB server versions the v3 integration supports after singer-io/tap-mongodb#136, which upgrades the tap's pymongo pin from 4.10.1 to 4.18.2 to fix a BSON out-of-bounds read (SAC-32067, Bugcrowd, CWE-125).

PyMongo raises its minimum supported MongoDB server version across that range — MIN_SUPPORTED_WIRE_VERSION goes from 6 to 9:

pymongo min MongoDB
4.10.1 (what v3 ships today) 3.6
4.11 - 4.13 4.0
4.14 - 4.17 4.2
4.18.x 4.4

The upstream BSON fix exists only in 4.18.0+, so there is no version that fixes the security bug and keeps the 3.6 floor.

What this changes

  • _database-integrations/mongo/vanilla/v3/mongodb-v3.md and _database-integrations/mongo/mongo-atlas/v3/mongodb-atlas-v3.md:
    • versions: 3.6 through 7.0 -> 4.4 through 7.0
    • driver: PyMongo 4.4.0 -> PyMongo 4.18.2. This field was already stale — the tap has pinned 4.10.1 since tap-mongodb#121 (documented in the Jan 8, 2025 changelog entry) but the front matter was never updated.
  • New changelog entry _changelog-files/2026/2026-10-07-mongodb-v3-pymongo-upgrade-minimum-version.md, typed deprecation rather than improvement because this removes support rather than adding anything.

The upper bound stays at 7.0. PyMongo 4.18 supports servers up to 9.0, but tap-mongodb's CI only exercises 4.4 / 5.0 / 6.0, so I did not widen a claim this change does not test.

Please do not merge until the tap ships

Two things to fix at merge time:

  1. This must land only after tap-mongodb 3.3.2 is deployed. Until then the v3 integration still runs pymongo 4.10.1 and still supports 3.6, so merging early makes the docs wrong in the other direction.
  2. The changelog date and filename are placeholders set to 2026-10-07. Existing entries are dated to the deployment date (e.g. 2026-09-30-github-v2-... was committed on 2026-10-05 with a 2026-09-30 front matter date), so both need updating to the real deploy date.

The weekly changelog automation will not duplicate this: scripts/changelog/changelog.py dedupes on the pull-request: URL, and this entry already carries tap-mongodb/pull/136. It would also have auto-classified the PR as improvement from the word "bump" in the title, which would understate the impact.

Open question for reviewers

Dropping support for 3.6 / 4.0 / 4.2 inside an already-released integration version is a breaking change for any customer still on those servers. All three are EOL at MongoDB (Apr 2021 / Apr 2022 / Apr 2023), and the normal Stitch pattern for a support drop is to cut a new integration version rather than narrow an existing one. A census of live connections is still outstanding on the Jira ticket — if it finds affected customers, this may need to become a v4 page instead of an edit to v3.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@netlify

netlify Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for stitchdocs ready!

Name Link
🔨 Latest commit 16b7283
🔍 Latest deploy log https://app.netlify.com/projects/stitchdocs/deploys/6ac682b19770d60008926023
😎 Deploy Preview https://deploy-preview-1261--stitchdocs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

📖 Preview deployed

S3 path: s3://qlikhelp-stitch-preview/pr-1261/

https://stitch-preview.qlik.click/pr-1261/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant