Repository navigation
build(deps-dev): bump com.google.cloud:google-cloud-storage from 2.73.0 to 2.74.0 - #20511
Merged
FrankChen021 merged 2 commits intoOct 8, 2026
Conversation
Bumps [com.google.cloud:google-cloud-storage](https://github.com/googleapis/google-cloud-java) from 2.73.0 to 2.74.0. - [Release notes](https://github.com/googleapis/google-cloud-java/releases) - [Changelog](https://github.com/googleapis/google-cloud-java/blob/main/java-document-ai/CHANGELOG.md) - [Commits](https://github.com/googleapis/google-cloud-java/commits) --- updated-dependencies: - dependency-name: com.google.cloud:google-cloud-storage dependency-version: 2.74.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
FrankChen021
approved these changes
Oct 8, 2026
FrankChen021
left a comment
Member
There was a problem hiding this comment.
This is an automated review by Codex GPT-5.6 Luna(Max).
Compatibility analysis
- Verdict: SAFE for Apache Druid.
- Release inventory: the canonical Maven Central metadata contains exactly
2.73.0and2.74.0in the requested range; there is no published intermediate2.73.xrelease to review. The reviewed transition iscom.google.cloud:google-cloud-storage:2.73.0 -> 2.74.0. - Target POM review found no dependency-coordinate additions or removals. Its aligned transitive version transitions are: Google Cloud core/core-http/core-grpc
2.75.0 -> 2.76.0; GAX/gax-httpjson/gax-grpc2.85.0 -> 2.86.0; Google Auth credentials/oauth2-http1.52.0 -> 1.53.0; api-common2.68.0 -> 2.69.0; proto-google-iam-v11.71.0 -> 1.72.0; proto-google-common-protos2.76.0 -> 2.77.0; and the storage generated proto/grpc/gapic artifacts2.73.0 -> 2.74.0. - API/ABI: SAFE. The published storage 2.73.0 and 2.74.0 jars each contain 876 class files, with identical class-file contents; the jar differences are metadata/manifests and POM properties only.
- Runtime: SAFE. The Druid Google extension compiles and its focused test suite passes with the target graph.
- Configuration: SAFE. No Druid configuration key, default, module binding, or deployment setting changes.
- Serialization/wire: SAFE. No Druid serialized format or wire implementation changes; generated Google Storage protocol artifacts remain aligned to the target release.
- Persistence: SAFE. No segment, task-log, metadata, or storage layout behavior changes.
- Clients: SAFE. Existing
Storage,ReadChannel,WriteChannel,Blob,BlobId,BlobInfo,Page, andStorageOptionscall sites remain source-compatible and passed compilation/tests. - Transitives: CONCERN on the unaligned initial PR state, resolved to SAFE by the bounded direct pins required by Google Storage 2.74.0. The final graph satisfies RequireUpperBoundDeps.
- Licenses: SAFE. The target POM remains Apache-2.0, and the existing Druid license registry is aligned to all changed published coordinates/versions; no new license family was introduced.
- Extension/plugin SPI: SAFE. No SPI, service-provider, module descriptor, or extension loading change.
Druid impact
- The original PR diff changes only the root Google Storage property and the embedded-tests Google Storage test dependency. The bounded follow-up changes the Google extension direct pins for
gaxandgoogle-cloud-core, the embedded-tests pins forgoogle-cloud-coreand Google Auth credentials, and corresponding entries inlicenses.yaml. - Affected production dependency/call-site scope is
extensions-core/google-extensions, includingGoogleStorage,GoogleStorageDruidModule,GoogleDataSegmentKiller,GoogleUtils, GCS input-source/pusher/puller/task-log/segment-range-reader/output-connector code, and the embedded GCS resources. The Iceberg extension consumes the same storage property as a compile-only dependency. No Java source file changed. - Reviewed base
131989817271bc836e815db738cc2be33fba3538, original heade95ad2dbfd73c213204be62a165753d176257149, and final head51a8cf1347622dd54624d92cc7d8d21d10fce408.
Validation
- Focused and reactor-wide Maven Enforcer runs passed, including RequireUpperBoundDeps for the Google extension and embedded-tests scopes.
- Focused Google extension compile/install passed; focused Google extension tests passed: 117 tests, 0 failures, 0 errors, 0 skipped.
- Final dependency trees resolve Storage 2.74.0, Cloud core 2.76.0, GAX 2.86.0, Auth 1.53.0, api-common 2.69.0, IAM proto 1.72.0, common protos 2.77.0, and Storage generated artifacts 2.74.0.
git diff --checkpassed before commit. The bounded fix was committed as51a8cf1347622dd54624d92cc7d8d21d10fce408and pushed to the PR branch.
CI gate
- I inspected every initial failed job log:
packaging-check-jdk25,static-checks-maven,strict-compilation, andopenrewrite. All four had the same deterministic RequireUpperBoundDeps failure: the PR’s directgoogle-cloud-core:2.75.0andgax:2.85.0pins conflicted with Storage 2.74.0’s transitive2.76.0and2.86.0requirements. No blind reruns were used. - After the fix, the exact final head has 27 completed CheckRuns and all 27 conclude
SUCCESS; the commit StatusContexts endpoint has zero contexts. The PR snapshot is OPEN, non-draft, MERGEABLE, and CLEAN.
Automation actions
- Applied the bounded dependency/license alignment, validated it locally, committed and pushed the exact head above, waited for fresh CI, re-fetched the exact-head gate, and submitted this approval for that exact commit. No reruns were necessary.
No merge was performed.
dependabot
Bot
deleted the
dependabot/maven/com.google.cloud-google-cloud-storage-2.74.0
branch
October 8, 2026 11:41
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps com.google.cloud:google-cloud-storage from 2.73.0 to 2.74.0.
Changelog
Sourced from com.google.cloud:google-cloud-storage's changelog.
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)