Repository navigation
build(deps): bump software.amazon.kinesis:amazon-kinesis-client from 3.5.2 to 3.5.3 - #20533
dependabot[bot] wants to merge 2 commits into
Conversation
Bumps [software.amazon.kinesis:amazon-kinesis-client](https://github.com/awslabs/amazon-kinesis-client) from 3.5.2 to 3.5.3. - [Release notes](https://github.com/awslabs/amazon-kinesis-client/releases) - [Changelog](https://github.com/awslabs/amazon-kinesis-client/blob/master/CHANGELOG.md) - [Commits](awslabs/amazon-kinesis-client@v3.5.2...v3.5.3) --- updated-dependencies: - dependency-name: software.amazon.kinesis:amazon-kinesis-client dependency-version: 3.5.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
FrankChen021
left a comment
There was a problem hiding this comment.
This is an automated review by Codex GPT-5.6 Luna(Max).
Compatibility analysis
Dependency: software.amazon.kinesis:amazon-kinesis-client, source 3.5.2, target 3.5.3. The complete actually published release path reviewed in ROUND_1 is 3.5.2 -> 3.5.3, with no intervening published release. The carried-forward ROUND_1 verdict is SAFE after the bounded license-registry repair. Published source and bytecode for Druid's AggregatorUtil, KinesisClientRecord, and its builder are identical between releases, preserving the API/ABI and deaggregation runtime behavior. Of 82 retrieval classes compared, only RetrievalConfig differs, in its user-agent version constant. The upstream lease-assignment, migration-tool, metrics, and coordinator-shutdown fixes affect KCL facilities Druid does not use. Druid configuration, KPL serialization/wire decoding, persisted ingestion offsets, client behavior, and extension/plugin SPI remain unchanged. Published module and parent POMs differ only in their release versions, preserving transitive dependency declarations. Apache 2.0 license terms are unchanged; licenses.yaml now records the shipped target version.
Druid impact
Reviewed the complete original one-file PR diff in extensions-core/kinesis-indexing-service/pom.xml and the subsequent one-file repair in licenses.yaml. Relevant consumers are KinesisRecordSupplier, which builds KinesisClientRecord and calls AggregatorUtil.deaggregate, plus KinesisRecordEntity, KinesisInputFormat, and their existing Kinesis tests. Druid does not run KCL's lease coordinator or migration tool. No tracked production or test source changed. The practical impact is the Kinesis client patch upgrade with matching distribution license metadata; Druid's record decoding and ingestion contracts are preserved.
Validation
- ROUND_1 verified Maven Central's complete published release path, inspected upstream release notes and the source comparison, compared published source/binary artifacts and module/parent POMs, and reviewed Druid call sites and dependency exclusions.
- Focused Maven dependency resolution for
extensions-core/kinesis-indexing-servicepassed and selectedamazon-kinesis-client:3.5.3. - The focused registry check passed: the unique Kinesis entry matches the POM coordinate and version
3.5.3, retainingApache License version 2.0. git diff --checkpassed; the isolated worktree is clean at the pushed repair commit. No local unit tests or full packaging build were run.- Fresh CI for the repaired commit passed every reported check, including packaging, static checks, compilation, unit-test and QTest partitions, coverage, and CodeQL. ROUND_2 reused the recorded compatibility evidence without repeating release research.
CI gate
Exact current head: bb7d3ee8bd17366b21b03201c0c9c9a0b0561243. The PR is OPEN, non-draft, MERGEABLE, and CLEAN. The authoritative statusCheckRollup state is SUCCESS: all 27 CheckRuns are COMPLETED/SUCCESS, and 0 StatusContexts are reported. Pagination is complete (hasNextPage=false); every reported item succeeded. The previous packaging job 113601093093 in run 37862435111 failed because the license registry lacked Kinesis 3.5.3. The new commit's packaging check succeeded after the metadata repair; no failure remains.
Automation actions
The automation changed only licenses.yaml, updating the Kinesis Client registry version from 3.5.2 to 3.5.3, and pushed commit bb7d3ee8bd17366b21b03201c0c9c9a0b0561243 (build: align Kinesis client license metadata). No production or test source changed, and no CI jobs were rerun.
No merge was performed.
Bumps software.amazon.kinesis:amazon-kinesis-client from 3.5.2 to 3.5.3.
Release notes
Sourced from software.amazon.kinesis:amazon-kinesis-client's releases.
Changelog
Sourced from software.amazon.kinesis:amazon-kinesis-client's changelog.
Commits
c342236Prepare for KCL release v3.5.3 (#1819)fe60a5eRemove binary file (#1818)902fb6eAdd fixed-width threshold option for variance-based lease rebalancing (#1814)6ffda28Pack CloudWatch metrics into far fewer PutMetricData calls (#1816)d5387dcFix lease discovery thread pool leak on shutdown (#1815)4d46a03KCL version migration tool support rollback to v2 mode (#1813)d87a3d3Fix phase1 worker count to include workers with active metrics but no leases ...a2d4be5Table Migration metrics fixes (#1811)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)