Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 8 additions & 8 deletions dependencies.txt
Original file line number Diff line number Diff line change
Expand Up @@ -14,9 +14,9 @@ com.google.auth:google-auth-library-bom,google.auth=1.43.0
com.google.http-client:google-http-client,google.http-client=2.1.0
com.google.code.gson:gson,gson=2.13.2
com.google.guava:guava,guava=33.5.0-jre
com.google.protobuf:protobuf-java,protobuf=4.33.5
io.opentelemetry:opentelemetry-bom,opentelemetry=1.59.0
com.google.errorprone:error_prone_annotations,errorprone=2.47.0
com.google.protobuf:protobuf-java,protobuf=4.34.0
io.opentelemetry:opentelemetry-bom,opentelemetry=1.60.1
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The update to io.opentelemetry:opentelemetry-bom from 1.59.0 to 1.60.1 includes a "BREAKING bug fix" in version 1.60.0 related to case sensitivity in GlobUtil and IncludePatternMatching. This could potentially alter behavior in parts of the codebase that rely on the previous case-insensitivity. Please confirm that the impact of this breaking change has been assessed and mitigated if necessary, aligning with the repository's dependency management principles (Repository Style Guide, line 137).

References
  1. Try not to bump any external dependency version unless there is a known CVE (security or vulnerability issue) or a critical bug fix.

com.google.errorprone:error_prone_annotations,errorprone=2.48.0
com.google.j2objc:j2objc-annotations,j2objc-annotations=3.1
org.threeten:threetenbp,threetenbp=1.7.2
org.slf4j:slf4j-api,slf4j=2.0.17
Expand All @@ -25,27 +25,27 @@ org.slf4j:slf4j-api,slf4j=2.0.17
# These dependencies are declared: https://github.com/googleapis/sdk-platform-java/blob/main/java-shared-dependencies/first-party-dependencies/pom.xml
com.google.cloud:grpc-gcp,grpc-gcp=1.9.1
com.google.oauth-client:google-oauth-client,google.oauth-client=1.39.0
com.google.api-client:google-api-client,google.api-client=2.8.1
com.google.api-client:google-api-client,google.api-client=2.9.0

# 3P Shared-Deps
# These dependencies are declared: https://github.com/googleapis/sdk-platform-java/blob/main/java-shared-dependencies/third-party-dependencies/pom.xml
org.threeten:threeten-extra,threeten-extra=1.8.0
io.opencensus:opencensus-api,opencensus=0.31.1
com.google.code.findbugs:jsr305,findbugs=3.0.2
com.fasterxml.jackson:jackson-bom,jackson=2.21.0
com.fasterxml.jackson:jackson-bom,jackson=2.21.1
commons-codec:commons-codec,codec=1.21.0
org.apache.httpcomponents:httpclient,httpcomponents.httpclient=4.5.14
org.apache.httpcomponents:httpcore,httpcomponents.httpcore=4.4.16
org.apache.httpcomponents.client5:httpclient5,apache-httpclient-5=5.6
org.apache.httpcomponents.core5:httpcore5,apache-httpcore-5=5.4.1
org.apache.httpcomponents.core5:httpcore5,apache-httpcore-5=5.4.2
org.json:json,json=20251224
io.perfmark:perfmark-api,perfmark-api=0.27.0
# Note: This is the google opentelemetry exporter and not the general opentelemetry project
com.google.cloud.opentelemetry:exporter-metrics,google.cloud.opentelemetry=0.36.0
com.google.flogger:flogger,flogger=0.9
org.apache.arrow:arrow-memory-core,arrow=18.3.0
dev.cel:cel,dev.cel=0.11.1
dev.cel:cel,dev.cel=0.12.0
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The update to dev.cel:cel from 0.11.1 to 0.12.0 includes explicit "Breaking Changes" as detailed in its release notes. According to the repository's dependency management guidelines, external dependency versions should ideally not be bumped unless there is a known CVE or a critical bug fix (Repository Style Guide, line 137). Please confirm that these breaking changes have been thoroughly evaluated and addressed, or that they do not impact our current usage.

References
  1. Try not to bump any external dependency version unless there is a known CVE (security or vulnerability issue) or a critical bug fix.

com.google.crypto.tink:tink,com.google.crypto.tink=1.20.0
# The follow opentelemetry dependencies have a different version from the opentelemetry-bom
io.opentelemetry.semconv:opentelemetry-semconv,opentelemetry-semconv=1.39.0
io.opentelemetry.semconv:opentelemetry-semconv,opentelemetry-semconv=1.40.0
io.opentelemetry.contrib:opentelemetry-gcp-resources,io.opentelemetry.contrib.opentelemetry-gcp-resources=1.52.0-alpha
Loading