Bump software.amazon.awssdk:cognitoidentityprovider from 2.30.26 to 2.30.35 - #1746
Conversation
Bumps software.amazon.awssdk:cognitoidentityprovider from 2.30.26 to 2.30.35. --- updated-dependencies: - dependency-name: software.amazon.awssdk:cognitoidentityprovider dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
SummaryUpdated the version of the
|
There was a problem hiding this comment.
While this dependency update appears safe as a minor version bump, there are some concerns regarding version alignment across AWS SDK dependencies that should be addressed:
- The project currently has mismatched versions of AWS SDK components:
- AWS SDK BOM: 2.30.26
- cognitoidentity: 2.30.6
- cognitoidentityprovider: proposed update to 2.30.35
To ensure consistent behavior and avoid potential compatibility issues, it's recommended to:
- Update the AWS SDK BOM to 2.30.35 first
- Allow the BOM to manage the versions of individual AWS SDK components
- Remove explicit versions from individual AWS SDK dependencies where possible
This approach will provide better dependency management and reduce the risk of version conflicts.
Powered by Stanza
Available commands
`@stanza-ai review` - Re-review the PR `@stanza-ai ` - Chat with the code review agent| <dependency> | ||
| <groupId>software.amazon.awssdk</groupId> | ||
| <artifactId>cognitoidentityprovider</artifactId> | ||
| <version>2.30.26</version> | ||
| <version>2.30.35</version> | ||
| </dependency> |
There was a problem hiding this comment.
Consider removing the explicit version here and letting it be managed by the AWS SDK BOM. This ensures consistent versions across all AWS SDK components.
|
Superseded by #1747. |
Bumps software.amazon.awssdk:cognitoidentityprovider from 2.30.26 to 2.30.35.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)