Repository navigation
build(deps): bump com.google.api:gax from 2.85.0 to 2.86.0 - #20516
Conversation
Bumps com.google.api:gax from 2.85.0 to 2.86.0. --- updated-dependencies: - dependency-name: com.google.api:gax dependency-version: 2.86.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
FrankChen021
left a comment
There was a problem hiding this comment.
This is an automated review by Codex GPT-5.6 Luna(Max).
Compatibility analysis
Dependency: com.google.api:gax, source 2.85.0, target 2.86.0. The complete actually published release path reviewed in ROUND_1 is 2.85.0 -> 2.86.0; there is no intervening published release. ROUND_1 verdict: SAFE. The target and the bounded aligned Google Cloud dependency transitions preserve the Druid-used GAX/Page and Google Storage API and ABI surface. Runtime behavior is unchanged. No Druid configuration, serialization or wire contract, persisted-data format, or client contract changes were identified. Transitive dependencies are SAFE after aligning Google Cloud Storage, Core, API Common, Auth, IAM, and related proto pins; license metadata is SAFE after the bounded licenses.yaml alignment. No Druid extension, plugin, or server SPI contract changes.
Druid impact
Affected files are pom.xml, extensions-core/google-extensions/pom.xml, embedded-tests/pom.xml, and licenses.yaml. Relevant consumers are the Google Storage Page and related APIs in extensions-core/google-extensions, GoogleStorage and GoogleStorageDruidModule, embedded GCS consumers, and the existing Google extension dependency graphs. No tracked production or test source changed. The practical effect is a bounded build-time Google dependency alignment for GAX 2.86.0 and its license metadata; Druid runtime, query, ingestion, storage, client, serialization, and extension behavior are unchanged.
Validation
- Reviewed the complete PR diff, source and target versions, base and current head commits, the complete published release path, Druid consumers, and the persisted ROUND_1 compatibility evidence.
- Dependency-tree and RequireUpperBoundDeps validation passed; the six-module reactor compilation passed; and
GoogleStorageTestpassed 14/14. git diff --checkpassed. Local embedded-tests validation was blocked by unrelated missing or stale Druid artifacts; this did not affect the dependency or focused validation.- Fresh exact-head CI completed successfully, including dependency/build checks, CodeQL, all unit and QTest partitions, coverage, and the timeline check.
CI gate
Exact current head: 3cbd2f358b56e448a1e3f7148612827e5af62e50. The PR is OPEN, non-draft, MERGEABLE, and CLEAN. The authoritative statusCheckRollup is SUCCESS with 27 CheckRuns completed successfully and 0 StatusContexts reported. Every reported item succeeded, including the checks that were previously in progress or CodeQL NEUTRAL; coverage and actions-timeline also completed SUCCESS. No failed check remains.
Automation actions
The automation changed pom.xml, extensions-core/google-extensions/pom.xml, embedded-tests/pom.xml, and licenses.yaml, and pushed commit 3cbd2f358b56e448a1e3f7148612827e5af62e50. No CI jobs were rerun; the fresh CI run completed normally. No tracked production or test source changed. No merge was performed.
Bumps com.google.api:gax from 2.85.0 to 2.86.0.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)