Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 10, 2025

Bumps io.grpc:grpc-bom from 1.70.0 to 1.71.0.

Release notes

Sourced from io.grpc:grpc-bom's releases.

V1.71.0

API Changes

  • xds: Enable Xds Client Fallback by default. This allows having a backup xDS server as described in gRFC A71-xds-fallback.md (#11817) (176f3eed1)
  • protobuf: Experimental API marshallerWithRecursionLimit in ProtoUtils is now stabilized (#11884) (90b1c4fe9)

Bug Fixes

  • xds: Cluster weights should be uint32 (199a7ea3e). They were previously processed as int32, although the sum of weights was checked to be positive. So this would have caused a very large weight to never be selected and to reduce the chances of immediately-following clusters to be selected. There have been no reports of control planes using such large weights
  • xds: Fix an unlikely infinite loop triggered by route update (199a7ea3e). Triggering required the old cluster to no longer be used, an RPC processing when the update arrived, and for a RPC to not match any route in the new config. There have been no reports of this actually happening
  • core: Release data frame if it is received before the headers (dc316f7fd)

Improvements

  • Replace jsr305's CheckReturnValue with Error Prone's (#11811) (7b5d0692c)
  • core: optimize number of buffer allocations for message sizes larger than 1 MB (#11879) (5a7f35053)
  • core: Update the retry backoff range from [0, 1] to [0.8, 1.2] as per the A6 redefinition (#11858) (44e92e2c2)
  • core: include last pick status in status message when wait-for-ready RPC’s deadline expires (#11851) (7585b1607). This makes it much easier to debug connectivity issues when using wait-for-ready RPCs
  • xds: Include max concurrent request limit in the error status for concurrent connections limit exceeded (#11845) (0f5503ebb)
  • netty, servlet: Remove 4096 min write buffer size because MessageFramer.flush() is being called between every message, so messages are never combined and the larger allocation just wastes memory. (4a10a3816, 7153ff852)
  • core: When ClientStreamObserver closes the response observer log the error message if this operation fails (#11880) (302342cfc)
  • bom: use gradle java-platform to build pom instead of custom xml generation (#11875) (3142928fa)
  • xds: Reuse filter interceptors on client-side across RPCs (c506190b0, b3db8c248). This was an internal refactor that should have no user-visible change
  • alts: Enhance AltsContextUtil to allow getting the AltsContext on client-side (b1bc0a9d2)
  • xds: Envoy proto sync to 2024-11-11 (#11816) (b44ebce45)

Documentation

  • examples: Update HelloWorldServer to use Executor (#11850) (16edf7ac4)
  • examples: Add README for all examples lacking it (#11676) (9e8629914)

Dependencies

  • Version upgrades (#11874) (fc8571a0e)
  • Upgrade netty-tcnative to 2.0.70 (122b68371)

Thanks to

@​benjamin @​panchenko @​harshagoo94 @​NaveenPrasannaV

Commits
  • 865c443 Bump version to 1.71.0
  • ac9d0d2 Update README etc to reference 1.71.0
  • 16edf7a Examples: Updated HelloWorldServer to use Executor (#11850)
  • 16d2672 s2a: Don't allow S2AStub to be set
  • 9e54e8e servlet: Provide Gradle a filter version number
  • c1d7035 okhttp:Use a locally specified value instead of Segment.SIZE in okhttp (#11899)
  • 57af63a kokoro: Increase gradle mem in android-interop
  • a5347b2 s2a: inject Optional<AccessTokenManager> in tests
  • 41dd0c6 xds:Cleanup to reduce test flakiness (#11895)
  • 5a7f350 optimize number of buffer allocations (#11879)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Mar 10, 2025
@jbonofre
Copy link
Member

@dependabot rebase

@github-actions github-actions bot added this to the 18.3.0 milestone Mar 10, 2025
@jbonofre
Copy link
Member

I'm adding a commit on this PR to keep the LICENSE and NOTICE up to date.

Bumps [io.grpc:grpc-bom](https://github.com/grpc/grpc-java) from 1.70.0 to 1.71.0.
- [Release notes](https://github.com/grpc/grpc-java/releases)
- [Commits](grpc/grpc-java@v1.70.0...v1.71.0)

---
updated-dependencies:
- dependency-name: io.grpc:grpc-bom
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/maven/io.grpc-grpc-bom-1.71.0 branch from e1303d3 to 4852495 Compare March 10, 2025 10:34
@dependabot dependabot bot requested a review from jbonofre as a code owner March 10, 2025 10:34
@jbonofre jbonofre merged commit adfbef4 into main Mar 10, 2025
27 checks passed
@jbonofre jbonofre deleted the dependabot/maven/io.grpc-grpc-bom-1.71.0 branch March 10, 2025 13:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant