Repository navigation
build(deps-dev): bump com.google.cloud:google-cloud-core from 2.75.0 to 2.76.0 - #20510
FrankChen021 merged 2 commits into
Conversation
Bumps com.google.cloud:google-cloud-core from 2.75.0 to 2.76.0. --- updated-dependencies: - dependency-name: com.google.cloud:google-cloud-core dependency-version: 2.76.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
FrankChen021
left a comment
There was a problem hiding this comment.
This is an automated review by Codex GPT-5.6 Luna(Max).
Compatibility analysis
SAFE. The published Google Cloud Core release inventory for the requested interval is 2.75.0 (source) and 2.76.0 (target), with no intervening 2.75.1 release. The reviewed transition is 2.75.0 -> 2.76.0. Public class inventories are identical across the Core JARs, and public signatures used by Druid remain unchanged for ReadChannel, WriteChannel, and ServiceOptions; the Storage 2.73.0 -> 2.74.0 alignment likewise leaves the Druid-used Storage, StorageOptions, BlobId, and BlobInfo APIs unchanged.
API/ABI: SAFE. Runtime behavior: SAFE for the observed Druid call sites. Configuration, serialization, wire compatibility, and persistence: SAFE; this change adds no configuration keys, serialized forms, protocols, or persisted formats. Client compatibility: SAFE; the Google Storage client is aligned to the Core 2.76.0 dependency set. Transitive dependencies: SAFE after aligning storage 2.74.0, gax 2.86.0, google-auth 1.53.0, api-common 2.69.0, proto-google-iam-v1 1.72.0, and proto-google-common-protos 2.77.0. License metadata: SAFE and updated. Extension/plugin SPI: SAFE; no SPI or module contract changed. No unresolved compatibility concern remains.
Druid impact
The bounded repair changes only dependency metadata in /pom.xml, /extensions-core/google-extensions/pom.xml, /embedded-tests/pom.xml, and /licenses.yaml. Production call sites remain in GoogleStorage.java (ReadChannel, WriteChannel, Blob, BlobId, BlobInfo, Storage), GoogleStorageDruidModule.java (Storage and StorageOptions), and the existing Google storage tests; the embedded test module continues to use NoCredentials and StorageOptions. No Java source, runtime configuration, extension descriptor, plugin SPI, serialization, or persistence file changed.
Validation
Local validation passed: Google extension and embedded-test RequireUpperBoundDeps enforcement; the resolved dependency tree; focused reactor compilation of druid-google-extensions and its prerequisites; git diff --check; and public API/class-inventory comparisons for Google Cloud Core 2.75.0/2.76.0 and Storage 2.73.0/2.74.0. The resolved tree contains Core 2.76.0, Storage 2.74.0, gax 2.86.0, google-auth 1.53.0, api-common 2.69.0, proto-google-iam-v1 1.72.0, and proto-google-common-protos 2.77.0.
CI gate
Fresh CI for exact head 554ce54 is terminal with 27/27 CheckRuns SUCCESS and zero StatusContexts. Static checks, strict compilation, packaging-check-jdk25, OpenRewrite, unit/integration tests, coverage, Docker tests, web checks, CodeQL, title validation, and triage are all successful. The four failures on the prior head were deterministic RequireUpperBoundDeps conflicts caused by Core 2.76.0 requesting newer gax, api-common, auth, and IAM artifacts than Storage 2.73.0; they are resolved by this alignment.
Automation actions
Pushed the bounded repair as commit 554ce54 to the existing PR branch. No CI reruns were needed; the new head received a fresh run. The PR remains open, mergeable, and unmerged.
No merge was performed.
Bumps com.google.cloud:google-cloud-core from 2.75.0 to 2.76.0.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)