Repository navigation
build(deps-dev): bump com.google.auth:google-auth-library-credentials from 1.52.0 to 1.53.0 - #20514
Conversation
Bumps com.google.auth:google-auth-library-credentials from 1.52.0 to 1.53.0. --- updated-dependencies: - dependency-name: com.google.auth:google-auth-library-credentials dependency-version: 1.53.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
FrankChen021
left a comment
There was a problem hiding this comment.
This is an automated review by Codex GPT-5.6 Luna(Max).
Compatibility analysis
Dependency: com.google.auth:google-auth-library-credentials; source 1.52.0; target 1.53.0; PR base 131989817271bc836e815db738cc2be33fba3538; exact head c30cd1003a5fd027312a5476c14a7cbb3b70795f.
Published release inventory: Maven Central metadata contains the adjacent path 1.50.0, 1.51.0, 1.52.0, 1.53.0, 1.54.0; there is no published 1.52.x release between the source and target. The actual transition is therefore 1.52.0 -> 1.53.0; 1.52.0 was published 2026-09-04T21:16:00Z and 1.53.0 was published 2026-09-23T22:49:07Z. The published POM, JAR, sources, and Javadoc artifacts for both versions were inspected.
Compatibility evidence for the transition and target: the six Java source files in the credentials artifact are identical; the class inventory is identical; javap -public -s and javap -p -c comparisons have empty diffs; and the manifest keeps Automatic-Module-Name: com.google.auth. The artifact POM changes only its parent version. The parent POM changes only its own version and the unused-for-this-artifact api-common dependency-management property from 2.68.0 to 2.69.0; the credentials artifact continues to declare the same org.jspecify:jspecify dependency. There is no observed API/ABI, runtime, configuration, serialization/wire, persistence, or client behavior change in the published target. Both published POMs declare the BSD New/BSD-3-Clause license.
Druid impact
The complete PR diff changes only embedded-tests/pom.xml, the test-scoped declaration at lines 823-827. No Druid Java source, resource, configuration, serialization, persistence, or extension descriptor is changed. There are no direct Druid imports of com.google.auth; the embedded GCS consumers use StorageOptions/NoCredentials in embedded-tests/src/test/java/org/apache/druid/testing/embedded/gcs/GoogleStorageTestModule.java and configure a fake GCS endpoint in GoogleCloudStorageResource.java.
The production Google extension call sites (GoogleStorageDruidModule, GoogleStorage, GoogleDataSegmentPusher, GoogleDataSegmentPuller, GoogleDataSegmentKiller, GoogleTaskLogs, the Google input sources, and the export-storage provider) consume Google Cloud Storage APIs, not this credential API. The DruidModule service descriptor and Jackson/Guice SPI registrations are unchanged. extensions-contrib/druid-iceberg-extensions has the same Google Cloud Storage transitive path but no direct credential call site.
Maven resolution confirms the scope boundary: embedded-tests selects direct test dependency google-auth-library-credentials:1.53.0 and omits the 1.52.0 copies brought by google-cloud-storage:2.73.0, gapic-google-cloud-storage-v2:2.73.0, and google-cloud-core:2.75.0; extensions-core/google-extensions and extensions-contrib/druid-iceberg-extensions continue to resolve production 1.52.0. The unchanged licenses.yaml google-auth entry is therefore correct for the shipped Google extension, and the test-only bump adds no shipped license or plugin/SPI surface.
Verdict: SAFE.
Validation
git diff --check 131989817271bc836e815db738cc2be33fba3538 c30cd1003a5fd027312a5476c14a7cbb3b70795f passed. Narrow Maven dependency-tree validation completed with BUILD SUCCESS for embedded-tests, extensions-core/google-extensions, and extensions-contrib/druid-iceberg-extensions; the queried graphs matched the resolution described above. Published source/JAR/API comparisons also passed with no semantic differences. No repair commit or additional local full-suite run was needed; the complete current CI gate was re-fetched below.
CI gate
Immediately before this approval, the live PR was re-fetched at exact head c30cd1003a5fd027312a5476c14a7cbb3b70795f against base 131989817271bc836e815db738cc2be33fba3538; it is OPEN, MERGEABLE, and CLEAN, with no prior review entries and no blocking review decision. The paginated GraphQL statusCheckRollup.contexts(first:100, after:$endCursor) returned one page with hasNextPage: false: 27 CheckRuns and 0 StatusContexts. Every CheckRun was individually inspected and is COMPLETED with conclusion SUCCESS (27/27); there are no pending, failing, cancelled, skipped, or external-failure items. The rollup covers CodeQL, PR Commit Checks, Pull Request Labeler, five Static Checks CI items, and sixteen Unit & Integration tests CI items.
Automation actions
This approval is for exact head c30cd1003a5fd027312a5476c14a7cbb3b70795f only. No files were repaired, no CI reruns were needed, no shared automation queue was written, and no merge action was performed.
No merge was performed.
Bumps com.google.auth:google-auth-library-credentials from 1.52.0 to 1.53.0.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)