Repository navigation
build(deps): bump google-cloud-kms from 2.24.2 to 3.17.0 - #6252
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [google-cloud-kms](https://github.com/googleapis/google-cloud-python) from 2.24.2 to 3.17.0. - [Release notes](https://github.com/googleapis/google-cloud-python/releases) - [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md) - [Commits](googleapis/google-cloud-python@google-cloud-kms-v2.24.2...google-cloud-kms-v3.17.0) --- updated-dependencies: - dependency-name: google-cloud-kms dependency-version: 3.17.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
🟡 Waiting for changesLast updated: 2026-10-01 01:28 UTC |
rtibblesbot
left a comment
There was a problem hiding this comment.
PR #6252: the resolver downgraded google-cloud-logging 2.7.1 → 2.6.0 and google-cloud-appengine-logging 1.8.0 → 0.2.0, and CI doesn't exercise the error-reporting path that uses them.
Suggestion: google-cloud-error-reporting 1.4.0 (middleware/error_reporting.py) now runs on that older logging stack with protobuf 6. Confirm error reporting works in staging before merge, or bump error-reporting in a separate PR.
Otherwise fine (google-cloud-kms 2.24.2 → 3.17.0, major, production, CI passing):
- Studio uses only
KeyManagementServiceClient(),crypto_key_path()anddecrypt(request=...)incontentcuration/utils/secretmanagement.py; no code change needed. - Peer bumps:
protobuf4.25.8 → 6.33.6,googleapis-common-protos1.57.0 → 1.75.5,grpc-google-iam-v1→ 0.14.5. - No security fixes identified. I did not read the upstream changelog.
@rtibblesbot's comments are generated by an LLM, and should be evaluated accordingly
How was this generated?
Ran a dependency-update review pipeline over the version bump:
- Classified the bump by semver (patch / minor / major) and dependency type (production vs. development)
- Extracted the changelog and release notes across the version range
- Assessed compatibility with this project's usage and whether any code changes are required
- Treated CI as the primary safety net
- Scaled the review depth to the update's risk
- Chose the verdict from semver risk, changelog findings, and CI status
|
Closing for now due to downgrades. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps google-cloud-kms from 2.24.2 to 3.17.0.
Release notes
Sourced from google-cloud-kms's releases.
Changelog
Sourced from google-cloud-kms's changelog.
... (truncated)
Commits
773373echore: release main (#18368)3b3cc6ffix: empty commit to bump v1beta version (#18411)dd24029fix(spanner): release transaction lock if inline begin fails (#18409)a511b55chore: migrate pre-release test into nightly GitHub Action (#18387)91b7ae7feat(google/cloud/backupdr/v1beta): add google-cloud-backupdr (#18399)20bdcc8chore: onboard google-cloud-spanner-dbapi-driver (#18403)136d4b9feat(firestore): add BSONInt32 support (#18388)8df34cefeat(google/cloud/networkservices/v1beta1): add google-cloud-network-services...e9f8e59feat: update API sources and regenerate (#18396)0d7d59cfix: disambiguate google-cloud-bigqueryto_dataframeusage from `pandas-gbq...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)