Repository navigation
build(deps): bump aws.sdk.v2.version from 2.55.4 to 2.55.5 - #20531
Conversation
Bumps `aws.sdk.v2.version` from 2.55.4 to 2.55.5. Updates `software.amazon.awssdk:s3` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:s3-transfer-manager` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:sts` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:apache-client` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:auth` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:regions` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:ec2` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:aws-core` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:sdk-core` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:netty-nio-client` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:aws-crt-client` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:bom` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:retries-spi` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:retries` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:kinesis` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:http-client-spi` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:utils` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:rds` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:glue` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:kms` from 2.55.4 to 2.55.5 Updates `software.amazon.awssdk:bundle` from 2.55.4 to 2.55.5 --- updated-dependencies: - dependency-name: software.amazon.awssdk:s3 dependency-version: 2.55.5 dependency-type: direct:development update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:s3-transfer-manager dependency-version: 2.55.5 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:sts dependency-version: 2.55.5 dependency-type: direct:development update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:apache-client dependency-version: 2.55.5 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:auth dependency-version: 2.55.5 dependency-type: direct:development update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:regions dependency-version: 2.55.5 dependency-type: direct:development update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:ec2 dependency-version: 2.55.5 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:aws-core dependency-version: 2.55.5 dependency-type: direct:development update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:sdk-core dependency-version: 2.55.5 dependency-type: direct:development update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:netty-nio-client dependency-version: 2.55.5 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:aws-crt-client dependency-version: 2.55.5 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:bom dependency-version: 2.55.5 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:retries-spi dependency-version: 2.55.5 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:retries dependency-version: 2.55.5 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:kinesis dependency-version: 2.55.5 dependency-type: direct:development update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:http-client-spi dependency-version: 2.55.5 dependency-type: direct:development update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:utils dependency-version: 2.55.5 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:rds dependency-version: 2.55.5 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:glue dependency-version: 2.55.5 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:kms dependency-version: 2.55.5 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: software.amazon.awssdk:bundle dependency-version: 2.55.5 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
FrankChen021
left a comment
There was a problem hiding this comment.
This is an automated review by Codex GPT-5.6 Luna(Max).
Compatibility analysis
AWS SDK for Java v2 advances from 2.55.4 to 2.55.5. The actually published release path reviewed in ROUND_1 was 2.55.4 -> 2.55.5, with no intervening release. The carried-forward ROUND_1 verdict is SAFE. Comparison of 11,065 Java source files across 19 Druid-relevant published artifacts found no added or removed classes and no source changes other than VersionInfo.SDK_VERSION. This preserves the Druid-used API/ABI, credential, retry, HTTP client, service-client and extension/plugin SPI surfaces. The endpoint metadata change adds only EventBridge V2 endpoints; the other release features concern service models outside the inspected Druid consumers. No Druid configuration, serialization/wire or persisted-data contract change was identified. The published parent POM changes only release/history versions, preserving transitive dependency versions and the Apache-2.0 license. The Druid license registry is now aligned to the target version.
Druid impact
Reviewed both changed files: the dependency property in pom.xml and the bounded registry repair in licenses.yaml. Consumers include AWS credential/retry utilities in cloud/aws-common, S3 storage, ingestion, export and transfer-manager operations, KinesisRecordSupplier, EC2 autoscaling, AWSRDSTokenPasswordProvider, and managed Glue/KMS dependencies. No tracked production or test source changed. The practical effect is the SDK patch-version update and accurate distribution license metadata; the inspected Druid behavior remains compatible.
Validation
- ROUND_1 reviewed the complete PR diff, base/head commits, published release inventory, upstream changes, Druid consumers, and published source and parent POM comparisons described above.
- The failed packaging job
113599802310in run37862039643explicitly reported 11 resolved AWS SDK2.55.5artifact coordinates missing from the registry. The focused registry check verified that all 11 coordinates are covered by the target-version Apache-2.0 entry and that its version matches the POM. git diff --checkpassed for the complete diff, and the isolated worktree is clean. A full local license-check execution was unavailable because local Python lacked PyYAML; the new packaging CI check passed, providing distribution-level license validation.- Fresh CI for the repaired commit reports all 27 CheckRuns completed successfully, including packaging, static checks, compilation, tests, coverage and CodeQL. ROUND_2 reused the compatibility evidence without repeating release research.
CI gate
Exact current head: 3f31d7a32ebc9ae243365a706e07fe3df416e165. The PR is OPEN, non-draft, MERGEABLE and CLEAN. The authoritative statusCheckRollup state is SUCCESS: 27 CheckRuns are COMPLETED/SUCCESS and 0 StatusContexts are reported. Every reported item succeeded; pagination is complete (hasNextPage=false). The earlier packaging license failure is resolved by the metadata repair and successful CI for this commit.
Automation actions
The automation changed only licenses.yaml, updating the AWS SDK for Java 2 registry entry from 2.55.4 to 2.55.5, and pushed commit 3f31d7a32ebc9ae243365a706e07fe3df416e165 (build: align AWS SDK 2.55.5 license metadata). No CI jobs were rerun, and no tracked production or test source changed. No merge was performed.
Bumps
aws.sdk.v2.versionfrom 2.55.4 to 2.55.5.Updates
software.amazon.awssdk:s3from 2.55.4 to 2.55.5Updates
software.amazon.awssdk:s3-transfer-managerfrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:stsfrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:apache-clientfrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:authfrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:regionsfrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:ec2from 2.55.4 to 2.55.5Updates
software.amazon.awssdk:aws-corefrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:sdk-corefrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:netty-nio-clientfrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:aws-crt-clientfrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:bomfrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:retries-spifrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:retriesfrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:kinesisfrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:http-client-spifrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:utilsfrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:rdsfrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:gluefrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:kmsfrom 2.55.4 to 2.55.5Updates
software.amazon.awssdk:bundlefrom 2.55.4 to 2.55.5Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)