Skip to content

Bump pymongo from 4.10.1 to 4.18.0 - #516

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/pip/develop/pymongo-4.18.0
Closed

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/pip/develop/pymongo-4.18.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor

Bumps pymongo from 4.10.1 to 4.18.0.

Release notes

Sourced from pymongo's releases.

PyMongo 4.18.0

Community notes: https://www.mongodb.com/community/forums/t/pymongo-4-18-released/343137

PyMongo 4.17.0

Community notes

What's Changed

... (truncated)

Changelog

Sourced from pymongo's changelog.

Changes in Version 4.18.0 (2026/09/03)

PyMongo 4.18 brings a number of changes including:

  • Added srvAllowedHostsSuffix as a URI option and keyword argument to :class:~pymongo.synchronous.mongo_client.MongoClient and :class:~pymongo.asynchronous.mongo_client.AsyncMongoClient. When connecting via mongodb+srv://, this option overrides the default requirement that SRV-returned hosts share the same parent domain as the seed hostname, allowing hosts under a different domain suffix to be accepted. The suffix must not be a public suffix (per the Public Suffix List <https://publicsuffix.org/list/>_). See the :class:~pymongo.synchronous.mongo_client.MongoClient and :class:~pymongo.asynchronous.mongo_client.AsyncMongoClient documentation for security considerations.
  • Dropped support for MongoDB 4.2.
  • Added support for MongoDB 9.0.
  • PyPy support is deprecated and will be removed in a future release.
  • Improved TLS connection performance by reusing TLS sessions across connections to the same server, avoiding a full handshake on each new connection. Session resumption is supported on all Python versions for synchronous clients and on Python 3.11+ for async clients.
  • Improved performance for MongoDB 9.0's Intelligent Workload Management (IWM) by only retrying overload errors when doing so is expected to not worsen server conditions.
  • Added support for exhaust cursors (:attr:~pymongo.cursor.CursorType.EXHAUST) against mongos 7.1+. An older mongos still raises :class:~pymongo.errors.InvalidOperation, now on the first iteration of the cursor rather than from :meth:~pymongo.synchronous.collection.Collection.find, since the requirement is checked against the connection in use. Separately, async cursors combining limit with :attr:~pymongo.cursor.CursorType.EXHAUST now raise at find rather than on first iteration, matching the synchronous API.
  • Redacted potentially sensitive authentication mechanism properties, including AWS session tokens, from the representations of :class:~pymongo.synchronous.mongo_client.MongoClient and :class:~pymongo.asynchronous.mongo_client.AsyncMongoClient.
  • Command monitoring events and command log messages for a single logical operation now share one stable operation_id across all of its retry attempts, so consumers can correlate a retried operation's events. As a result, operation_id is no longer equal to the per-attempt request_id for these operations.
  • Added validation of OP_COMPRESSED decompressed message size against max_message_size to prevent memory exhaustion from maliciously crafted compressed server responses.
  • Improved the performance and memory usage of decoding large documents to :class:~bson.raw_bson.RawBSONDocument. Documents and subdocuments that are 4KB or greater and decoded from an immutable buffer are now exposed as read-only :class:memoryview slices instead of :class:bytes copies. Documents decoded from mutable buffers such as a :class:bytearray are always :class:bytes copies.
  • :func:bson.get_data_and_view now returns a view of a private :class:bytes copy

... (truncated)

Commits
  • 8e7ece4 PYTHON-6072 - Update changelog for 4.18 release (#3038)
  • f4d0ca6 PYTHON-5814 Configurable DNS domain validation for SRV records (#2868)
  • 3ed144a PYTHON-6070 Improve help output for just run-server and just setup-tests (#3035)
  • 003c9cc PYTHON-6020 Move _have_dnspython into uri_parser_shared.py (#3032)
  • a3c768d PYTHON-5983 Validate uncompressed size in OP_COMPRESSED messages (#2976)
  • 1a99d50 PYTHON 5790 Standardize references to test collections in tests (#3026)
  • 364c1ea PYTHON-5884 Explicit Encryption prose test "Case 2" fails on latest server: p...
  • cc5deb2 PYTHON-6017 Consolidate QE enums into shared class (#3024)
  • 6506f48 PYTHON-6007 Fix versionchanged marker for text_opts in ClientEncryption.encry...
  • f9f9b03 PYTHON-6019 Consolidate mongo_client module-level helpers into shared… (#3031)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added the dependency_updates For issues/PRs relating to dependency upgrades label Sep 7, 2026
Bumps [pymongo](https://github.com/mongodb/mongo-python-driver) from 4.10.1 to 4.18.0.
- [Release notes](https://github.com/mongodb/mongo-python-driver/releases)
- [Changelog](https://github.com/mongodb/mongo-python-driver/blob/main/doc/changelog.rst)
- [Commits](mongodb/mongo-python-driver@4.10.1...4.18.0)

---
updated-dependencies:
- dependency-name: pymongo
  dependency-version: 4.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/develop/pymongo-4.18.0 branch from 62141df to e47c431 Compare September 11, 2026 18:24
@dependabot @github

dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #518.

@dependabot dependabot Bot closed this Sep 14, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/develop/pymongo-4.18.0 branch September 14, 2026 18:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependency_updates For issues/PRs relating to dependency upgrades

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants