Skip to content

build(deps): bump software.amazon.kinesis:amazon-kinesis-client from 3.5.2 to 3.5.3 - #20533

Open
dependabot[bot] wants to merge 2 commits into
masterfrom
dependabot/maven/software.amazon.kinesis-amazon-kinesis-client-3.5.3
Open

dependabot[bot] wants to merge 2 commits into
masterfrom
dependabot/maven/software.amazon.kinesis-amazon-kinesis-client-3.5.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps software.amazon.kinesis:amazon-kinesis-client from 3.5.2 to 3.5.3.

Release notes

Sourced from software.amazon.kinesis:amazon-kinesis-client's releases.

Release 3.5.3 of the Amazon Kinesis Client Library for Java

Release 3.5.3 (September 24, 2026)

  • #1811 Table Migration metrics fixes
  • #1812 Fix phase1 worker count to include workers with active metrics but no leases
  • #1813 KCL version migration tool support for rollbacking to v2
  • #1815 Fix lease discovery thread pool leak on shutdown
  • #1816 Pack CloudWatch metrics into far fewer PutMetricData calls
  • #1814 Add fixed-width threshold option for variance-based lease rebalancing
  • #1818 Remove binary file
Changelog

Sourced from software.amazon.kinesis:amazon-kinesis-client's changelog.

Release 3.5.3 (September 24, 2026)

  • #1811 Table Migration metrics fixes
  • #1812 Fix phase1 worker count to include workers with active metrics but no leases
  • #1813 KCL version migration tool support for rollbacking to v2
  • #1815 Fix lease discovery thread pool leak on shutdown
  • #1816 Pack CloudWatch metrics into far fewer PutMetricData calls
  • #1814 Add fixed-width threshold option for variance-based lease rebalancing
  • #1818 Remove binary file
Commits
  • c342236 Prepare for KCL release v3.5.3 (#1819)
  • fe60a5e Remove binary file (#1818)
  • 902fb6e Add fixed-width threshold option for variance-based lease rebalancing (#1814)
  • 6ffda28 Pack CloudWatch metrics into far fewer PutMetricData calls (#1816)
  • d5387dc Fix lease discovery thread pool leak on shutdown (#1815)
  • 4d46a03 KCL version migration tool support rollback to v2 mode (#1813)
  • d87a3d3 Fix phase1 worker count to include workers with active metrics but no leases ...
  • a2d4be5 Table Migration metrics fixes (#1811)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [software.amazon.kinesis:amazon-kinesis-client](https://github.com/awslabs/amazon-kinesis-client) from 3.5.2 to 3.5.3.
- [Release notes](https://github.com/awslabs/amazon-kinesis-client/releases)
- [Changelog](https://github.com/awslabs/amazon-kinesis-client/blob/master/CHANGELOG.md)
- [Commits](awslabs/amazon-kinesis-client@v3.5.2...v3.5.3)

---
updated-dependencies:
- dependency-name: software.amazon.kinesis:amazon-kinesis-client
  dependency-version: 3.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 8, 2026

@FrankChen021 FrankChen021 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is an automated review by Codex GPT-5.6 Luna(Max).

Compatibility analysis

Dependency: software.amazon.kinesis:amazon-kinesis-client, source 3.5.2, target 3.5.3. The complete actually published release path reviewed in ROUND_1 is 3.5.2 -> 3.5.3, with no intervening published release. The carried-forward ROUND_1 verdict is SAFE after the bounded license-registry repair. Published source and bytecode for Druid's AggregatorUtil, KinesisClientRecord, and its builder are identical between releases, preserving the API/ABI and deaggregation runtime behavior. Of 82 retrieval classes compared, only RetrievalConfig differs, in its user-agent version constant. The upstream lease-assignment, migration-tool, metrics, and coordinator-shutdown fixes affect KCL facilities Druid does not use. Druid configuration, KPL serialization/wire decoding, persisted ingestion offsets, client behavior, and extension/plugin SPI remain unchanged. Published module and parent POMs differ only in their release versions, preserving transitive dependency declarations. Apache 2.0 license terms are unchanged; licenses.yaml now records the shipped target version.

Druid impact

Reviewed the complete original one-file PR diff in extensions-core/kinesis-indexing-service/pom.xml and the subsequent one-file repair in licenses.yaml. Relevant consumers are KinesisRecordSupplier, which builds KinesisClientRecord and calls AggregatorUtil.deaggregate, plus KinesisRecordEntity, KinesisInputFormat, and their existing Kinesis tests. Druid does not run KCL's lease coordinator or migration tool. No tracked production or test source changed. The practical impact is the Kinesis client patch upgrade with matching distribution license metadata; Druid's record decoding and ingestion contracts are preserved.

Validation

  • ROUND_1 verified Maven Central's complete published release path, inspected upstream release notes and the source comparison, compared published source/binary artifacts and module/parent POMs, and reviewed Druid call sites and dependency exclusions.
  • Focused Maven dependency resolution for extensions-core/kinesis-indexing-service passed and selected amazon-kinesis-client:3.5.3.
  • The focused registry check passed: the unique Kinesis entry matches the POM coordinate and version 3.5.3, retaining Apache License version 2.0.
  • git diff --check passed; the isolated worktree is clean at the pushed repair commit. No local unit tests or full packaging build were run.
  • Fresh CI for the repaired commit passed every reported check, including packaging, static checks, compilation, unit-test and QTest partitions, coverage, and CodeQL. ROUND_2 reused the recorded compatibility evidence without repeating release research.

CI gate

Exact current head: bb7d3ee8bd17366b21b03201c0c9c9a0b0561243. The PR is OPEN, non-draft, MERGEABLE, and CLEAN. The authoritative statusCheckRollup state is SUCCESS: all 27 CheckRuns are COMPLETED/SUCCESS, and 0 StatusContexts are reported. Pagination is complete (hasNextPage=false); every reported item succeeded. The previous packaging job 113601093093 in run 37862435111 failed because the license registry lacked Kinesis 3.5.3. The new commit's packaging check succeeded after the metadata repair; no failure remains.

Automation actions

The automation changed only licenses.yaml, updating the Kinesis Client registry version from 3.5.2 to 3.5.3, and pushed commit bb7d3ee8bd17366b21b03201c0c9c9a0b0561243 (build: align Kinesis client license metadata). No production or test source changed, and no CI jobs were rerun.

No merge was performed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Area - Dependencies Area - Streaming Ingestion dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant