-
Notifications
You must be signed in to change notification settings - Fork 18
Bump google-cloud-storage to version 2.58.1 #1026
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Cherry pick to beta success |
1 similar comment
Cherry pick to beta success |
Cherry pick to beta success |
<groupId>com.google.api.grpc</groupId> | ||
<artifactId>proto-google-iam-v1</artifactId> | ||
</exclusion> | ||
<exclusion> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is it okay to remove this exclusion?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes, I did it in a second commit because it failed the test execution. It was looking for a protbuf class in runtime.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
But for some reason that dependency had been excluded... I don't think it's good to add it just like that without being clear about why you need it now and before your change you didn't.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The original library (v1.118.1) was made on August 2021, we are updating it to the latest from october 2025.
When we added it it didn't use anything from protobuf for the functions we use in GX, therefore someone exclude it, samewere in 4 years they made changes there and now they use a class from protobuf to a function we need on GX since it failed on the tests. What? Why? I don't know, it's a transitive reference, tests failed with the message that it couldn't find some protbuf class executing on github. We could try to exclude it again but the test will fail again.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Leave a question
You question has an answer |
Issue:206683
Bump google-cloud-storage from version 1.118.1 to version 2.58.1 (latest)
Fix CVE-2021-22573 from transitive dependency google-oauth-client
Fix CVE-2022-25647 from transitive dependency gson
Add overwrite to transitive dependency grpc-netty-shaded version 1.71.0 to 1.75.0 because of CVE-2025-55163
#GXSEC