Skip to content

[improve][build] Upgrade gRPC to 1.83.1 and Protobuf to 4.35.1 - #26356

Merged
nodece merged 1 commit into
apache:masterfrom
lhotari:lh-improve-grpc-protobuf
Aug 18, 2026
Merged

nodece merged 1 commit into
apache:masterfrom
lhotari:lh-improve-grpc-protobuf

Conversation

@lhotari

@lhotari lhotari commented Aug 17, 2026

Copy link
Copy Markdown
Member

Motivation

gRPC is four minor releases behind and Protobuf has a patch release available.

Kept as its own PR rather than folded into the other dependency updates: gRPC spans the functions
runtime, Oxia and the shaded client jars, and minor gRPC releases move their Netty, Guava and
perfmark expectations, so it deserves an independently bisectable change.

Modifications

gradle/libs.versions.toml:

library from to
grpc 1.79.0 1.83.1
protobuf 4.35.0 4.35.1

Plus the corresponding jar names in the server distribution LICENSE.bin.txt.

gRPC 1.83.1 also lifts com.google.api.grpc:proto-google-common-protos from 2.63.2 to 2.64.1. That
artifact is not pinned in the version catalog, so its LICENSE entry is updated to match what actually
ships — this was caught by checkBinaryLicense rather than by inspection.

Protobuf stays at 4.35.1; 4.36.0 is only available as a release candidate.

Verifying this change

  • Make sure that the change passes the CI checks.

This change is a trivial rework / code cleanup without any test coverage.

Verified locally with ./gradlew sanityCheck and ./gradlew checkBinaryLicense.

Does this pull request potentially affect one of the following parts:

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

- grpc      1.79.0 -> 1.83.1
- protobuf  4.35.0 -> 4.35.1

gRPC 1.83.1 also pulls proto-google-common-protos from 2.63.2 to 2.64.1; that artifact is
not pinned in the version catalog, so the LICENSE entry is updated to match what actually
ships.

Kept separate from the other dependency updates because gRPC spans the functions runtime,
Oxia and the shaded client jars, and minor gRPC releases move their Netty, Guava and
perfmark expectations.

Assisted-by: Claude Code (Opus 5)
@lhotari lhotari added the area/dependency Pull requests that update a dependency file label Aug 17, 2026
@lhotari lhotari added this to the 5.0.0-M2 milestone Aug 17, 2026
@nodece
nodece merged commit 9a9f462 into apache:master Aug 18, 2026
60 of 65 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dependency Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants