Repository navigation
MongoDB (v3): document the 4.4 minimum after the PyMongo 4.18.2 upgrade - #1261
Open
zachharris1 wants to merge 1 commit into
Open
zachharris1 wants to merge 1 commit into
zachharris1 wants to merge 1 commit into
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
✅ Deploy Preview for stitchdocs ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Contributor
📖 Preview deployedS3 path: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of change
Documents the MongoDB server versions the v3 integration supports after singer-io/tap-mongodb#136, which upgrades the tap's
pymongopin from 4.10.1 to 4.18.2 to fix a BSON out-of-bounds read (SAC-32067, Bugcrowd, CWE-125).PyMongo raises its minimum supported MongoDB server version across that range —
MIN_SUPPORTED_WIRE_VERSIONgoes from 6 to 9:The upstream BSON fix exists only in 4.18.0+, so there is no version that fixes the security bug and keeps the 3.6 floor.
What this changes
_database-integrations/mongo/vanilla/v3/mongodb-v3.mdand_database-integrations/mongo/mongo-atlas/v3/mongodb-atlas-v3.md:versions:3.6 through 7.0->4.4 through 7.0driver:PyMongo 4.4.0->PyMongo 4.18.2. This field was already stale — the tap has pinned 4.10.1 since tap-mongodb#121 (documented in the Jan 8, 2025 changelog entry) but the front matter was never updated._changelog-files/2026/2026-10-07-mongodb-v3-pymongo-upgrade-minimum-version.md, typeddeprecationrather thanimprovementbecause this removes support rather than adding anything.The upper bound stays at 7.0. PyMongo 4.18 supports servers up to 9.0, but tap-mongodb's CI only exercises 4.4 / 5.0 / 6.0, so I did not widen a claim this change does not test.
Please do not merge until the tap ships
Two things to fix at merge time:
dateand filename are placeholders set to 2026-10-07. Existing entries are dated to the deployment date (e.g.2026-09-30-github-v2-...was committed on 2026-10-05 with a 2026-09-30 front matter date), so both need updating to the real deploy date.The weekly changelog automation will not duplicate this:
scripts/changelog/changelog.pydedupes on thepull-request:URL, and this entry already carriestap-mongodb/pull/136. It would also have auto-classified the PR asimprovementfrom the word "bump" in the title, which would understate the impact.Open question for reviewers
Dropping support for 3.6 / 4.0 / 4.2 inside an already-released integration version is a breaking change for any customer still on those servers. All three are EOL at MongoDB (Apr 2021 / Apr 2022 / Apr 2023), and the normal Stitch pattern for a support drop is to cut a new integration version rather than narrow an existing one. A census of live connections is still outstanding on the Jira ticket — if it finds affected customers, this may need to become a v4 page instead of an edit to v3.