Skip to content

build(deps-dev): bump com.google.cloud:google-cloud-storage from 2.73.0 to 2.74.0 - #20511

Merged
FrankChen021 merged 2 commits into
masterfrom
dependabot/maven/com.google.cloud-google-cloud-storage-2.74.0
Oct 8, 2026
Merged

FrankChen021 merged 2 commits into
masterfrom
dependabot/maven/com.google.cloud-google-cloud-storage-2.74.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps com.google.cloud:google-cloud-storage from 2.73.0 to 2.74.0.

Changelog

Sourced from com.google.cloud:google-cloud-storage's changelog.

2.74.0 (2025-07-30)

  • No change
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [com.google.cloud:google-cloud-storage](https://github.com/googleapis/google-cloud-java) from 2.73.0 to 2.74.0.
- [Release notes](https://github.com/googleapis/google-cloud-java/releases)
- [Changelog](https://github.com/googleapis/google-cloud-java/blob/main/java-document-ai/CHANGELOG.md)
- [Commits](https://github.com/googleapis/google-cloud-java/commits)

---
updated-dependencies:
- dependency-name: com.google.cloud:google-cloud-storage
  dependency-version: 2.74.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 7, 2026

@FrankChen021 FrankChen021 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is an automated review by Codex GPT-5.6 Luna(Max).

Compatibility analysis

  • Verdict: SAFE for Apache Druid.
  • Release inventory: the canonical Maven Central metadata contains exactly 2.73.0 and 2.74.0 in the requested range; there is no published intermediate 2.73.x release to review. The reviewed transition is com.google.cloud:google-cloud-storage:2.73.0 -> 2.74.0.
  • Target POM review found no dependency-coordinate additions or removals. Its aligned transitive version transitions are: Google Cloud core/core-http/core-grpc 2.75.0 -> 2.76.0; GAX/gax-httpjson/gax-grpc 2.85.0 -> 2.86.0; Google Auth credentials/oauth2-http 1.52.0 -> 1.53.0; api-common 2.68.0 -> 2.69.0; proto-google-iam-v1 1.71.0 -> 1.72.0; proto-google-common-protos 2.76.0 -> 2.77.0; and the storage generated proto/grpc/gapic artifacts 2.73.0 -> 2.74.0.
  • API/ABI: SAFE. The published storage 2.73.0 and 2.74.0 jars each contain 876 class files, with identical class-file contents; the jar differences are metadata/manifests and POM properties only.
  • Runtime: SAFE. The Druid Google extension compiles and its focused test suite passes with the target graph.
  • Configuration: SAFE. No Druid configuration key, default, module binding, or deployment setting changes.
  • Serialization/wire: SAFE. No Druid serialized format or wire implementation changes; generated Google Storage protocol artifacts remain aligned to the target release.
  • Persistence: SAFE. No segment, task-log, metadata, or storage layout behavior changes.
  • Clients: SAFE. Existing Storage, ReadChannel, WriteChannel, Blob, BlobId, BlobInfo, Page, and StorageOptions call sites remain source-compatible and passed compilation/tests.
  • Transitives: CONCERN on the unaligned initial PR state, resolved to SAFE by the bounded direct pins required by Google Storage 2.74.0. The final graph satisfies RequireUpperBoundDeps.
  • Licenses: SAFE. The target POM remains Apache-2.0, and the existing Druid license registry is aligned to all changed published coordinates/versions; no new license family was introduced.
  • Extension/plugin SPI: SAFE. No SPI, service-provider, module descriptor, or extension loading change.

Druid impact

  • The original PR diff changes only the root Google Storage property and the embedded-tests Google Storage test dependency. The bounded follow-up changes the Google extension direct pins for gax and google-cloud-core, the embedded-tests pins for google-cloud-core and Google Auth credentials, and corresponding entries in licenses.yaml.
  • Affected production dependency/call-site scope is extensions-core/google-extensions, including GoogleStorage, GoogleStorageDruidModule, GoogleDataSegmentKiller, GoogleUtils, GCS input-source/pusher/puller/task-log/segment-range-reader/output-connector code, and the embedded GCS resources. The Iceberg extension consumes the same storage property as a compile-only dependency. No Java source file changed.
  • Reviewed base 131989817271bc836e815db738cc2be33fba3538, original head e95ad2dbfd73c213204be62a165753d176257149, and final head 51a8cf1347622dd54624d92cc7d8d21d10fce408.

Validation

  • Focused and reactor-wide Maven Enforcer runs passed, including RequireUpperBoundDeps for the Google extension and embedded-tests scopes.
  • Focused Google extension compile/install passed; focused Google extension tests passed: 117 tests, 0 failures, 0 errors, 0 skipped.
  • Final dependency trees resolve Storage 2.74.0, Cloud core 2.76.0, GAX 2.86.0, Auth 1.53.0, api-common 2.69.0, IAM proto 1.72.0, common protos 2.77.0, and Storage generated artifacts 2.74.0.
  • git diff --check passed before commit. The bounded fix was committed as 51a8cf1347622dd54624d92cc7d8d21d10fce408 and pushed to the PR branch.

CI gate

  • I inspected every initial failed job log: packaging-check-jdk25, static-checks-maven, strict-compilation, and openrewrite. All four had the same deterministic RequireUpperBoundDeps failure: the PR’s direct google-cloud-core:2.75.0 and gax:2.85.0 pins conflicted with Storage 2.74.0’s transitive 2.76.0 and 2.86.0 requirements. No blind reruns were used.
  • After the fix, the exact final head has 27 completed CheckRuns and all 27 conclude SUCCESS; the commit StatusContexts endpoint has zero contexts. The PR snapshot is OPEN, non-draft, MERGEABLE, and CLEAN.

Automation actions

  • Applied the bounded dependency/license alignment, validated it locally, committed and pushed the exact head above, waited for fresh CI, re-fetched the exact-head gate, and submitted this approval for that exact commit. No reruns were necessary.

No merge was performed.

@FrankChen021
FrankChen021 merged commit e9cc7e8 into master Oct 8, 2026
27 checks passed
@dependabot
dependabot Bot deleted the dependabot/maven/com.google.cloud-google-cloud-storage-2.74.0 branch October 8, 2026 11:41
@github-actions github-actions Bot added this to the 39.0.0 milestone Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Area - Dependencies dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant