Repository navigation
build(deps-dev): bump org.apache.commons:commons-lang3 from 3.20.0 to 3.21.0 - #20548
FrankChen021 merged 1 commit into
Conversation
Bumps org.apache.commons:commons-lang3 from 3.20.0 to 3.21.0. --- updated-dependencies: - dependency-name: org.apache.commons:commons-lang3 dependency-version: 3.21.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
FrankChen021
left a comment
There was a problem hiding this comment.
This is an automated review by Codex GPT-5.6 Luna(Max).
Compatibility analysis
Dependency: org.apache.commons:commons-lang3, source 3.20.0, target 3.21.0. Published release path reviewed: 3.20.0 (2025-11-12) -> 3.21.0 (2026-09-25); Maven Central metadata lists no published release between these versions. ROUND_1 verdict: SAFE. Commons Lang 3.21.0 remains a Java 8+ feature and maintenance release. The published class inventory has no removals, and public signatures of every Commons Lang class used by Druid remain present; the observed API changes are additive. The runtime changes documented for NumberUtils, StringUtils, ArrayUtils, and related utilities were checked against Druid call sites: ParserUtils is the only production NumberUtils.isCreatable consumer, and its subsequent Guava Longs.tryParse / Doubles.tryParse fallback preserves unrecognized numeric forms as strings. The target POM has no compile or runtime dependencies; its listed dependencies are test-scoped, so there is no transitive runtime dependency shift. Druid uses Commons Lang internally for string/config parsing, arrays, mutable holders, regex, booleans, exceptions, OS detection, and diagnostic rendering; no Druid wire, persistence, public client, or extension/plugin SPI contract exposes Commons Lang types. The release explicitly retains serialization compatibility with 3.20.0 for its Range classes, and Druid has no Commons Lang Range or SerializationUtils consumers. Both published artifacts remain Apache License 2.0, with no license-family or notice change. API/ABI, runtime, configuration, serialization/wire, persistence, clients, transitive dependencies, licenses, and extension/plugin SPI evidence is SAFE.
Druid impact
The complete PR diff changes only pom.xml dependency management, changing the Commons Lang3 version from 3.20.0 to 3.21.0; no tracked production or test source changed. The version is consumed by 17 module POMs and 69 Java files (45 production and 24 test files), including processing parser/array consumers, server metadata/query consumers, indexing-service holders and exception handling, SQL query rendering, and Azure, S3, Kubernetes, HDFS, Redis, Protobuf, and security extensions. The practical effect is selecting Commons Lang3 3.21.0 for those existing utility calls; no Druid configuration schema, persistence format, client protocol, or plugin SPI changes.
Validation
- Inspected the complete 1-file PR diff and reserved worktree;
git diff --checkpassed, with onepom.xmlline added and one removed. - Compared the published 3.20.0 and 3.21.0 jars: no class removals and no public-signature removals in the Druid-referenced classes; target-only additions were additive APIs.
- Reviewed published Maven metadata and both version POMs: only 3.20.0 and 3.21.0 are published in the path, and Commons Lang has no compile/runtime dependencies.
- Ran source/target
NumberUtils.isCreatableprobes for representative edge inputs and inspected the Druid fallback path inParserUtils; no incompatible Druid consumer behavior was identified. The target utility API probe also verified the Druid-usedStringUtils,ArrayUtils,ObjectUtils, andBooleanUtilsmethods. - Exact-head packaging logs resolved and packaged
commons-lang3-3.21.0.jar; thecheck-licensesexecution completed successfully, and the static-checks workflow's RAT/license validation also completed successfully.
CI gate
Exact current head dacce927e23dc706370dba5067ec2296c6592993 is OPEN, non-draft, and MERGEABLE with mergeStateStatus=CLEAN. The complete GraphQL statusCheckRollup is SUCCESS with 27 CheckRuns completed with SUCCESS, 0 StatusContexts (0 successful StatusContexts), and no additional rollup page. Every reported CI item succeeded; there were no failed, cancelled, skipped, neutral, unknown, pending, or in-progress items, so no rerun or failure resolution was required.
Automation actions
No PR files were changed by the automation, no commit was pushed, and no jobs were rerun. This approval is for the exact current head above. No merge was performed.
Bumps org.apache.commons:commons-lang3 from 3.20.0 to 3.21.0.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)