Repository navigation
build(deps): bump org.asynchttpclient:async-http-client from 3.0.13 to 3.0.14 - #20535
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [org.asynchttpclient:async-http-client](https://github.com/AsyncHttpClient/async-http-client) from 3.0.13 to 3.0.14. - [Release notes](https://github.com/AsyncHttpClient/async-http-client/releases) - [Commits](AsyncHttpClient/async-http-client@async-http-client-project-3.0.13...async-http-client-project-3.0.14) --- updated-dependencies: - dependency-name: org.asynchttpclient:async-http-client dependency-version: 3.0.14 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
FrankChen021
left a comment
There was a problem hiding this comment.
This is an automated review by Codex GPT-5.6 Luna(Max).
Compatibility analysis
The carried-forward ROUND_1 verdict is SAFE for org.asynchttpclient:async-http-client 3.0.13 -> 3.0.14 and the target's cumulative effect on Druid. Maven Central's published inventory contains no intervening release: the complete reviewed path is 3.0.13 -> 3.0.14. ROUND_2 reuses that assessment rather than repeating release research.
Published artifacts, POMs, release notes and relevant source changes were checked against Druid consumers. API/ABI comparison of eleven used public classes found no removed signatures and 23 additions; new configuration-interface methods have defaults, preserving implementations and Druid's emitter extension SPI. Java's baseline remains 11. New event-loop timeout, absolute-deadline and redirect-restriction options default off; timeout race fixes preserve Druid's timer and per-request timeout usage. Druid's emitters send byte-buffer JSON POST bodies with explicit headers and optional gzip, with redirects disabled by default; they do not configure cookie, proxy, realm or WebSocket behavior. The changed security/pooling paths introduce no identified incompatibility for these consumers. Event serialization remains Druid-owned, and this transport dependency does not define segment or persisted metadata formats. The resolved target uses Druid-managed Netty 4.2.18.Final and SLF4J 2.0.20; upstream zstd/Brotli dependencies remain optional. The published Apache-2.0 license is unchanged, and bundled public-suffix data remains covered by Druid's MPL-2.0 entry.
Druid impact
The complete diff changes only the dependency version in root pom.xml. Reviewed consumers include processing's HttpPostEmitter, emitter factories and tests, and server's HttpEmitterModule and parametrized emitter setup. No tracked production or test source changed. The practical impact is the upstream HTTP-client fixes while retaining Druid's existing emitter request construction and configuration.
Validation
- Focused
AsyncHttpClientTest,HttpEmitterTest,HttpPostEmitterTest,ParametrizedUriEmitterTestandEmitterTest: 16 tests passed, zero failures, errors or skips. - Maven dependency-tree resolution for processing: BUILD SUCCESS; managed Netty and SLF4J versions verified.
- Published API comparison: eleven classes, no removed public signatures.
- Exact-head packaging/license CI: SUCCESS. Its printed license inventory retains older version text; that text was not treated as evidence of a failure.
- Complete diff review and
git diff --check: passed; isolated worktree clean at the reviewed head.
CI gate
Fresh live reads confirm head 6454aaee4dd6497a992bb2839dc8d2908ef566ac, OPEN, non-draft, MERGEABLE/CLEAN. The complete exact-head statusCheckRollup is SUCCESS: 27 CheckRuns COMPLETED/SUCCESS and zero StatusContexts, with no additional page. Every reported item succeeded, including coverage.
The original H/D/T/O partition failed before tests on a Maven Central HTTP 403 fetching org.apache:apache:pom:40. The original N/Q partition failed QueryVirtualStorageTest.testQueryTooMuchData's storage-error-message assertion; that cluster uses a latchable emitter and broker service-client queries, not Async HTTP Client emission. Both were classified as unrelated failures and resolved by the reserved failed-workflow rerun. Run 37862778027, attempt 2, completed SUCCESS on the unchanged head; replacement jobs 113661998684 and 113661998460 and dependent coverage succeeded.
Automation actions
The automation changed no files and pushed no commits. It reran failed jobs in workflow run 37862778027 once using gh run rerun --failed; no further rerun was used. This approval uses the persisted ROUND_1 SAFE assessment and the fresh ROUND_2 exact-head CI evidence.
No merge was performed.
Bumps org.asynchttpclient:async-http-client from 3.0.13 to 3.0.14.
Release notes
Sourced from org.asynchttpclient:async-http-client's releases.
Commits
bec30bb[maven-release-plugin] prepare release async-http-client-project-3.0.14b61637fBound how far a compressed WebSocket message may inflate6ec7ee4Keep plaintext responses from setting or overlaying Secure cookiesd3bb4d6Scope pooled connections by authenticated identity, including proxiesfd97636Keep a caller-set Cookie header when the jar contributes7dc5bbcEnforce public suffix rules by A-label, locale, host-only, IPc1a6063Keep a caller's cookie when the store refuses Set-Cookie (#2349)5f970a4Treat Domain=. as a host-only cookie (#2350)faccbabFix/auth retry stale cookies (#2351)0ace000Close with 1009 when a WebSocket message is too big (#2352)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)