chore(deps): update upper bound dependencies file#4112
Conversation
Summary of ChangesHello @lqiu96, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request performs a routine update of several key Java dependencies to their latest stable versions. The updates encompass minor and patch releases for libraries such as Google Auth, Error Prone, gRPC, OpenTelemetry, Protobuf, and Apache HttpComponents. This ensures the project benefits from the latest features, bug fixes, performance improvements, and security enhancements provided by these upstream libraries, maintaining compatibility and stability within the ecosystem. Highlights
Changelog
Activity
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here. You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension. Footnotes
|
There was a problem hiding this comment.
Code Review
This pull request, generated by Renovate, updates the versions of several dependencies in the dependencies.txt file, which tracks upper-bound versions for compatibility testing. The changes are all minor or patch updates. My review focuses on the consistency of these version bumps with the rest of the project. I've noted one potential inconsistency where a dependency version that was previously synchronized with the build configuration is now diverging. This might be unintentional and could be worth addressing to ensure the project uses the latest bug fixes from the new version.
| io.grpc:grpc-bom,grpc=1.78.0 | ||
| com.google.auth:google-auth-library-bom,google.auth=1.42.1 | ||
| io.grpc:grpc-bom,grpc=1.79.0 | ||
| com.google.auth:google-auth-library-bom,google.auth=1.43.0 |
There was a problem hiding this comment.
The version of com.google.auth:google-auth-library-bom is being updated to 1.43.0 in this upper-bound tracking file. However, the version used in the build, defined by the google.auth.version property in gapic-generator-java-pom-parent/pom.xml, remains at 1.42.1. While other dependencies in this file are also out of sync with the build, this particular dependency was aligned before this change. This divergence could be unintentional. Please consider updating google.auth.version in gapic-generator-java-pom-parent/pom.xml to 1.43.0 in this or a subsequent PR to maintain consistency and adopt the bug fixes from the new version.
|
|



This PR contains the following updates:
1.42.1->1.43.02.46.0->2.47.04.33.4->4.33.51.78.0->1.79.01.58.0->1.59.05.4->5.4.1Release Notes
googleapis/google-auth-library-java (com.google.auth:google-auth-library-bom)
v1.43.0Compare Source
Features
Bug Fixes
google/error-prone (com.google.errorprone:error_prone_annotations)
v2.47.0: Error Prone 2.47.0Compare Source
New checks:
InterruptedInCatchBlock: Detect accidental calls toThread.interrupted()inside ofcatch(InterruptedException e)blocks.RefactorSwitch: Refactorings to simplify arrow switchesUnnamedVariable: Rename unused variables to_Closed issues: #1811, #4168, #5459, #5460
Full changelog: google/error-prone@v2.46.0...v2.47.0
grpc/grpc-java (io.grpc:grpc-bom)
v1.79.0Compare Source
API Changes
core: Delete the never-used io.grpc.internal.ReadableBuffer.readBytes(ByteBuffer) (#12580) (
738782f). This is deeply internal and not accessible, so shouldn’t impact anything. However, Apache Arrow Java uses reflection to access private fields; GH-939: Remove reflection for gRPC buffers is swapping to gRPC’s public zero-copy APIsopentelemetry: Add target attribute filter for metrics (#12587). Introduce an optional Predicate targetAttributeFilter to control how grpc.target is recorded in OpenTelemetry client metrics. When a filter is provided, targets rejected by the predicate are normalized to "other" to reduce grpc.target metric cardinality, while accepted targets are recorded as-is. If no filter is set, existing behavior is preserved. This change adds a new Builder API on GrpcOpenTelemetry to allow applications to configure the filter.
Behavior Changes
core: Convert AutoConfiguredLB to an actual LB (
4bbf8ee). This is an internal refactoring, but it does improve how errors are handled for broken binaries. Previously, not being able to load pick_first would result in a channel panic. Now it is handled as a regular load balancing errorokhttp: Assert no pending streams before transport READY (#12566) (
ed6d175). No pending streams should exist when the transport transitions to READY. This PR adds an assertion to help verify this invariant.Bug Fixes
228fc8e). Pick-first in grpc-java has behaved this way since it was created, and it was of no consequence. However, now there are some load balancing policies (mainly RLS) that will do a pick() and hope the result to be reasonably accurate for metrics.Improvements
core: Improve DEADLINE_EXCEEDED message for CallCreds delays (
ead532b). Previously the error message contained “buffered_nanos” and “waiting_for_connection” for connection delays. However, we discovered the same strings were also used if waiting on CallCredentials. Now you’ll see details like “connecting_and_lb_delay”, “call_credentials_delay”, and “was_still_waiting”.opentelemetry: Add Android API checking (
a9f73f4). Previously we assumed OpenTelemetry support would not be used on Android. It did happen to be compatible with Android, but since OpenTelemetry does have some Android support, we now have a check that it remains compatiblecore: Catch Errors when calling complex config parsing code (
a535ed7). Error (and any other Throwable) is now caught and handled when parsing configuration (e.g., service config, xds). This will cause such failures to be handled gracefully instead of panicking the channelcore: Implement LoadBalancer.Helper.createOobChannel() with the internals of createResolvingOobChannel() (
3915d02). This API is only expected to be relevant to the gRPC-LB lookaside load balancer, and is not believed to have behavior changes. Out-of-band channel had been implemented with its own stripped-down Channel without load balancing. Reimplementing using the resolving oob channel makes it a full-fledged channel and reduces the burden when integrating new features and allows us to have a ManagedChannelBuilder to use with efforts like gRFC A110: Child Channel Options.xds: Implement the proactive connection logic in RingHashLoadBalancer as outlined in gRFC A61 (#12596). Previously, the Java implementation only initialized child balancers when a ring-chosen endpoint was in TRANSIENT_FAILURE during a picker's pickSubchannel call. This PR adds the missing logic: when a child balancer reports TRANSIENT_FAILURE, the LoadBalancer now proactively initializes the first available IDLE child if no other children are currently connecting or ready.
This ensures a backup subchannel starts warming up immediately outside the RPC flow, reducing failover latency and improving overall resilience. This behavior was previously present but was inadvertently lost after #10610.
f65127c) Experimental RFC 3986 target URI parsing mode (disabled by default)New Features
6b2f758), completing the remaining work in gRFC A96: OTel metrics for SubchannelsDependencies
protobuf: Upgrade Bazel protobuf to 33.1 (#12553) (
b61a8f4) and load java_proto_library from the protobuf repo (c7f3cdb)protobuf: Fix build with Bazel 9 by upgrading bazel_jar_jar and grpc-proto versions (#12569)
Upgrade dependencies (#12588) (
6422092) Netty to 4.1.130, error-prone annotations to 2.45.0, google-auth-library to 1.41.0, tomcat-embed-core9 to 9.0.113, tomcat-embed-core to 10.1.50, opentelemetry to 1.57.0, jetty-ee10-servlet to 12.1.5, jetty-http2-server to 12.1.5, google-cloud-logging to 3.23.9, google-auth to 1.41.0, proto-google-common-protos to 2.63.2.Thanks to
open-telemetry/opentelemetry-java (io.opentelemetry:opentelemetry-bom)
v1.59.0Compare Source
API
(#7973)
(#7809)
Extensions
(#8020)
(#8019)
SDK
(#8003)
(#7991)
Traces
(#7984)
Metrics
(#8000)
(#8017)
Testing
(#7999)
(#8033)
Exporters
opentelemetry-exporter-zipkinis now deprecated with thelast release planned for 1.65.0 (August 2026)
(#7974)
(#7782)
Extensions
(#7970)
(#7877)
Project tooling
(#8023)
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Renovate Bot.