Skip to content

build(deps): bump org.asynchttpclient:async-http-client from 3.0.13 to 3.0.14 - #20535

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/org.asynchttpclient-async-http-client-3.0.14
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/org.asynchttpclient-async-http-client-3.0.14

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps org.asynchttpclient:async-http-client from 3.0.13 to 3.0.14.

Release notes

Sourced from org.asynchttpclient:async-http-client's releases.

AHC v3.0.14 Release

What's Changed

Security Advisory

GHSA-v2j5-22fr-j62r GHSA-qjr7-w8pj-pmv9 GHSA-x8v2-478q-2hvg GHSA-p2jm-6hj6-9rjg GHSA-2jwh-9rmr-j4xf

New Contributors

Full Changelog: AsyncHttpClient/async-http-client@async-http-client-project-3.0.13...async-http-client-project-3.0.14

Commits
  • bec30bb [maven-release-plugin] prepare release async-http-client-project-3.0.14
  • b61637f Bound how far a compressed WebSocket message may inflate
  • 6ec7ee4 Keep plaintext responses from setting or overlaying Secure cookies
  • d3bb4d6 Scope pooled connections by authenticated identity, including proxies
  • fd97636 Keep a caller-set Cookie header when the jar contributes
  • 7dc5bbc Enforce public suffix rules by A-label, locale, host-only, IP
  • c1a6063 Keep a caller's cookie when the store refuses Set-Cookie (#2349)
  • 5f970a4 Treat Domain=. as a host-only cookie (#2350)
  • faccbab Fix/auth retry stale cookies (#2351)
  • 0ace000 Close with 1009 when a WebSocket message is too big (#2352)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.asynchttpclient:async-http-client](https://github.com/AsyncHttpClient/async-http-client) from 3.0.13 to 3.0.14.
- [Release notes](https://github.com/AsyncHttpClient/async-http-client/releases)
- [Commits](AsyncHttpClient/async-http-client@async-http-client-project-3.0.13...async-http-client-project-3.0.14)

---
updated-dependencies:
- dependency-name: org.asynchttpclient:async-http-client
  dependency-version: 3.0.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 9, 2026

@FrankChen021 FrankChen021 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is an automated review by Codex GPT-5.6 Luna(Max).

Compatibility analysis

The carried-forward ROUND_1 verdict is SAFE for org.asynchttpclient:async-http-client 3.0.13 -> 3.0.14 and the target's cumulative effect on Druid. Maven Central's published inventory contains no intervening release: the complete reviewed path is 3.0.13 -> 3.0.14. ROUND_2 reuses that assessment rather than repeating release research.

Published artifacts, POMs, release notes and relevant source changes were checked against Druid consumers. API/ABI comparison of eleven used public classes found no removed signatures and 23 additions; new configuration-interface methods have defaults, preserving implementations and Druid's emitter extension SPI. Java's baseline remains 11. New event-loop timeout, absolute-deadline and redirect-restriction options default off; timeout race fixes preserve Druid's timer and per-request timeout usage. Druid's emitters send byte-buffer JSON POST bodies with explicit headers and optional gzip, with redirects disabled by default; they do not configure cookie, proxy, realm or WebSocket behavior. The changed security/pooling paths introduce no identified incompatibility for these consumers. Event serialization remains Druid-owned, and this transport dependency does not define segment or persisted metadata formats. The resolved target uses Druid-managed Netty 4.2.18.Final and SLF4J 2.0.20; upstream zstd/Brotli dependencies remain optional. The published Apache-2.0 license is unchanged, and bundled public-suffix data remains covered by Druid's MPL-2.0 entry.

Druid impact

The complete diff changes only the dependency version in root pom.xml. Reviewed consumers include processing's HttpPostEmitter, emitter factories and tests, and server's HttpEmitterModule and parametrized emitter setup. No tracked production or test source changed. The practical impact is the upstream HTTP-client fixes while retaining Druid's existing emitter request construction and configuration.

Validation

  • Focused AsyncHttpClientTest, HttpEmitterTest, HttpPostEmitterTest, ParametrizedUriEmitterTest and EmitterTest: 16 tests passed, zero failures, errors or skips.
  • Maven dependency-tree resolution for processing: BUILD SUCCESS; managed Netty and SLF4J versions verified.
  • Published API comparison: eleven classes, no removed public signatures.
  • Exact-head packaging/license CI: SUCCESS. Its printed license inventory retains older version text; that text was not treated as evidence of a failure.
  • Complete diff review and git diff --check: passed; isolated worktree clean at the reviewed head.

CI gate

Fresh live reads confirm head 6454aaee4dd6497a992bb2839dc8d2908ef566ac, OPEN, non-draft, MERGEABLE/CLEAN. The complete exact-head statusCheckRollup is SUCCESS: 27 CheckRuns COMPLETED/SUCCESS and zero StatusContexts, with no additional page. Every reported item succeeded, including coverage.

The original H/D/T/O partition failed before tests on a Maven Central HTTP 403 fetching org.apache:apache:pom:40. The original N/Q partition failed QueryVirtualStorageTest.testQueryTooMuchData's storage-error-message assertion; that cluster uses a latchable emitter and broker service-client queries, not Async HTTP Client emission. Both were classified as unrelated failures and resolved by the reserved failed-workflow rerun. Run 37862778027, attempt 2, completed SUCCESS on the unchanged head; replacement jobs 113661998684 and 113661998460 and dependent coverage succeeded.

Automation actions

The automation changed no files and pushed no commits. It reran failed jobs in workflow run 37862778027 once using gh run rerun --failed; no further rerun was used. This approval uses the persisted ROUND_1 SAFE assessment and the fresh ROUND_2 exact-head CI evidence.

No merge was performed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Area - Dependencies dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant