fix(deps): update grpc-java monorepo to v1.84.0 - #30
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/grpc-java-monorepo
branch
from
June 10, 2026 19:43
f366458 to
3a59942
Compare
renovate
Bot
force-pushed
the
renovate/grpc-java-monorepo
branch
from
June 23, 2026 21:00
3a59942 to
4258923
Compare
renovate
Bot
force-pushed
the
renovate/grpc-java-monorepo
branch
from
June 24, 2026 02:03
4258923 to
a07a247
Compare
renovate
Bot
force-pushed
the
renovate/grpc-java-monorepo
branch
from
July 9, 2026 22:02
a07a247 to
db7ce51
Compare
renovate
Bot
force-pushed
the
renovate/grpc-java-monorepo
branch
from
July 10, 2026 01:59
db7ce51 to
c7a4e04
Compare
renovate
Bot
force-pushed
the
renovate/grpc-java-monorepo
branch
from
July 22, 2026 16:46
c7a4e04 to
6369baf
Compare
renovate
Bot
force-pushed
the
renovate/grpc-java-monorepo
branch
from
July 22, 2026 22:51
6369baf to
354a888
Compare
renovate
Bot
force-pushed
the
renovate/grpc-java-monorepo
branch
from
July 30, 2026 10:10
354a888 to
faf00a6
Compare
renovate
Bot
force-pushed
the
renovate/grpc-java-monorepo
branch
from
September 1, 2026 18:10
faf00a6 to
b595bf7
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.80.0→1.84.01.80.0→1.84.01.80.0→1.84.0Release Notes
grpc/grpc-java (io.grpc:grpc-stub)
v1.84.0Compare Source
In this release we drop support for Android API level 23 or lower (Marshmallow or earlier), following Google Play Service’s now requiring a minimum of API level 24 (Android 7.0 Nougat).
API Changes
ac02c6f)XdsServerBuilderwithSocketAddresses (#12925) (ac02c6f)6966536)Behavior Changes
96807d8)Ignore all but the first certificate if the x5c JWK parameter contains multiple values.
Skip the JWK entry instead of stopping execution or throwing when x5c is missing or contains an empty list, complying with the requirement that entries without x5c must be ignored.
Bug Fixes
72c6e5f)Fixes a bug whereby an OOB channel shutdown incorrectly shut down the shared transport factory with the main channel, and the main channel was unable to create subchannels anymore and faced an exception in doing so.
shutdownNow()becoming a no-op aftershutdown()(#12982) (3cb7007)d49a589)296c007) Chains multiple childChannelConfigurator() calls instead of overwriting them in ManagedChannelImplBuilder and XdsServerBuilder, ensuring all configurators are preserved and executed when child channels are created.7843bd4) Caches header_data received in RouteLookupResponse and sends it back as stale_header_data in RouteLookupRequest when refreshing stale cache entries, complying with the RLS specification.Improvements
56205f9) Configure max active streams limit directly uponDefaultHttp2Connectioninitialization. BecauseNettyServerHandlerinstantiatesDefaultHttp2Connectiondirectly rather than using Netty'sAbstractHttp2ConnectionHandlerBuilder, it missed Netty's built-in CVE-2026-47244 patch. This left a pre-handshake window where the server's local connection allowed up to Integer.MAX_VALUE active client-initiated streams until a SETTINGS_ACK was received. Enforcing the limit proactively at startup closes this vulnerability window and prevents client-initiated stream floods / resource exhaustion.AsyncServletOutputStreamWriterdetect and handle write when not ready (#12732) (46f3080) In highly concurrent scenarios, cached servlet container ready to write state can become stale. The servlet container may have already transitioned to a 'not ready' state, but the corresponding callback has not yet updated gRPC's internal state. This fix makes the ready state to be evaluated explicitly before attempting to write directly to the servlet output stream.0f859c3) By RFC 9113, section 6.9, receivers must take frames into account for flow control even if they're errored. This change moves the stream error response logic after connection window updates0585d48)bc01994)9fdef96)9ffa1e1)Dependencies
6ccd065). Update the maximum supported edition in the Java gRPC compiler plugin to EDITION_2026 when compiling against Protobuf version 7.35.0 (v35.0) or later.5d0a012)1bc2f5a)Documentation
ee08f53)New Features
073fd5e) Implements attempt-level RPC delay observability across the core delayed transport, built-in load balancers (pick_first, round_robin), RLS, and xDS policies, aligned with gRFC A121. Adds LoadBalancer.PickResult.withNoResult(delayType, delayReason) and delay tracing callbacks on ClientStreamTracer. Records attempt delay duration metrics (grpc.client.attempt.delay.duration) and child tracing spans ("Attempt Delay") via the OpenTelemetry plugin.Thanks to
@Zhengcy05
@carl-mastrangelo
@themechbro
@JasonLunn
@martinbaillie
@eado
@TimurRakhmatullin86
v1.83.1gRPC Java 1.83.1 Release Notes
Improvements
v1.83.0gRPC Java 1.83.0 Release Notes
API Changes
4456721)2b86f8f). This allows users to explicitly provide a NameResolverRegistry during channel creation rather than relying on the global registry, offering better isolation and control over name resolution per-channel.Behavior Changes
3018ce3). v1.82.0 enabled TLS 1.3 for clients; this does the same for servers1e85674) Enables xDS configuration to control which fields get propagated from ORCA backend metric reports to LRS load reports as per gRFC A85c8079ee). This only has an effect when using aggregate clusters3db3235). Previously, modifications to LoadBalancerRegistry could cause failures in the LB treed49c0b1). If using xds heavily with many targets, then MAX_CONCURRENT_STREAMS to the control plane could be exceeded. This then prevents loading resources for new targets, which causes those channels to hang on name resolution. RPCs would see the nondescript "DEADLINE_EXCEEDED: Deadline Context was exceeded after Xs" or "DEADLINE_EXCEEDED: Deadline CallOptions was exceeded after Xs"Improvements
103bd4b)663c505) This updates default service config validation to accept numeric values represented as Number, not only Double. Common JSON parsers may deserialize integer-looking JSON values such as maxAttempts: 4 and backoffMultiplier: 2 as Integer, which previously caused defaultServiceConfig() to fail with IllegalArgumentException. The values are normalized to Double when copied into the validated service config, preserving the existing internal representation expected by the service config parsing code.56d2b25). Previously there was not a hint as to what gRPC was delayed on when the deadline was exceeded.4ec83df). This removes unnecessary log noise89aef90). This introduces the ChildChannelConfigurer API to allow intercepting and customizing the configuration (such as injecting interceptors or modifying credentials) of child channels created dynamically by load balancers.Dependencies
66c6ab1). If you need Netty 4.1 support, please file an issuec886f0a)064272c):Documentation
f94574e)Thanks to
tian__mi__mi@
codingkiddo@
Zhengcy05@
v1.82.4gRPC Java 1.82.4 Release Notes
Improvements
v1.82.3gRPC Java 1.82.3 Release Notes
The fixes that were supposed to go in this release were not included in the patch by mistake. Use 1.82.4 instead.
v1.82.2Compare Source
v1.82.1Compare Source
v1.82.0Compare Source
This release drops support for Bazel 7. It may still run, but we are no longer testing it. We are testing Bazel 8 and 9.
We are anticipating requiring Netty 4.2 in the next release. Please file an issue if you still need Netty 4.1 support.
Behavior Changes
UNIMPLEMENTED, which tears down the stream and EDS data never arrives. This fix makes it skip DiscoveryRequests for resource types we don't actually subscribe to on a given server.Improvements
@ThreadSafeannotation and replace with JavaDoc (#12762). Removes JSR-305 annotations but instead of replacing it with ErrorProne's ThreadSafe, sticks to adding a JavaDoc comment. This is done only in public non-final classes and interfaces. This allows Java applications that have moved away from javax to compile and avoids a bug in Immutables and Lombok (and possibly other annotation processors) from failing when JSR-305 is not present.b38df6c). The main improvement here is not retaining the request Metadata for the life of the RPC. That means RPCs with larger request Metadata would see a larger benefit.f430131)cc0d1a8). This is most noticeable when there are many endpoints returned by EDS, but the LB policy only uses a few of them, like pick_first.324fce7). This reduces the per-RPC overhead of the gRFC A114 support added in v1.81.013b4b97). This preserves more information for failures communicating with the control plane.d92ca44)Bug Fixes
bb153a8).streamClosed()happens beforeserverCallStarted().GRPC_EXPERIMENTAL_ENABLE_NEW_PICK_FIRST=truewhen accepting resolved addresses and in CONNECTING state (#12814). It makes sure that whenever PickFirstLeafLoadBalancer transitions into CONNECTING the current address in the addressIndex has a corresponding subchannel. This prevents an NPE in acceptResolvedAddresses in some situations.ec10992). This should have no visible impact in normal use. It mostly just makes it easier to debug broken implementationsf4125c5)f021bef)New Features
?force-xdsquery parameter in thegoogle-c2presolver (#12760) (86fa860). This disables environment checks and uses xDS unconditionally. Please note that this feature has not yet seen comprehensive testing.Dependencies
ada087b)1dbb1a1(ec0a9c9). This fixed a rules_go incompatibility issue with Bazel 9.1. But it also greatly reduced the overall transitive dependencies, as the C++ grpc repo is no longer a dependency039ad77) add Bazel 9.1.0 to our CI matrix (17be0d3)8802dc3,da98b04)Thanks to
@becomeStar
@bengtsson1-flir
@jnowjack-lucidchart
@Kainsin
@kenkangxgwe
@mfperminov
@paulmurhy123
@schiemon
@therepanic
v1.81.1Compare Source
v1.81.0Compare Source
In this release we drop support for Android API level 22 or lower (Lollipop or earlier), following Google Play Service’s discontinued updates for Lollipop (API levels 21 & 22) and now requires a minimum of API level 23 (Android 6.0 Marshmallow).
API Changes
Behavior Changes
0675f70). DnsNameResolver ignores re-resolution requests on OpenJDK-like platforms if it has been too soon since the last DNS query because InetAddress.getAllByName() has a cache with a fixed entry lifetime, but this logic was disabled for Android which does not have that style of cache. Android’s cache uses the result TTL, which will rarely be less than 30 seconds. This change would probably be most noticeable when 1) changing to a different network (e.g., from wifi to mobile), 2) the server has different addresses for different networks, and 3) the app is not using AndroidChannelBuilder with anandroid.context.Context. For reference, it seems Chrome caches for 1 minutee39c38b). Previously each channel using the xds name resolver would create its own channel to communicate with the control plane. Now they share control plane channels, while still having separate RPCsBug Fixes
ManagedChannelOrphanWrappercould incorrectly log a "not shutdown properly" warning during garbage collection when using directExecutor(). (#12705) (d459338)typeUrl. (#12740) (eac9fe9)backend_service. This ensures xDS load balancing metrics are reported accurately. (#12735)New Features
0e39b29). This CallOption is copied by grpc-opentelemetry to thegrpc.client.call.customlabel as defined by gRFC A108. See also the gRPC OpenTelemetry Metrics guide (update in-progress)AdvancedTlsX509KeyManagerso that developers can now preserve and use key aliases when dynamically reloading TLS certificates. (#12686)Documentation
a3a9ffc) (#12726) (65ae2ef)3ed732f)Dependencies
16e17ab). Google-auth-library: 1.42.1, animal-sniffer: 1.27, assertj-core:3.27.7, error_prone_annotations:2.48.0, proto-google-common-protos:2.64.1, google-cloud-logging:3.23.10, jetty-http2-server:12.1.7, jetty-ee10-servlet:12.1.7, lincheck:3.4, opentelemetry-api:1.60.1, opentelemetry-exporter-prometheus:1.60.1-alpha, opentelemetry-gcp-resources:1.54.0-alpha, opentelemetry-sdk-extension-autoconfigure:1.60.1, opentelemetry-sdk-testing:1.60.1, robolectric:4.16.1, tomcat-embed-core:10.1.52, tomcat-embed-core9: 9.0.115,1528f80)Thanks to
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.