This is an automated email from the ASF dual-hosted git repository.

jbonofre pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/arrow-java.git


The following commit(s) were added to refs/heads/main by this push:
     new d9d6112b3 MINOR: Bump com.google.guava:guava-bom from 33.4.8-jre to 
33.5.0-jre (#1083)
d9d6112b3 is described below

commit d9d6112b3e4037d72aa44e978bc72c2f7706c52c
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
AuthorDate: Mon Mar 23 18:46:51 2026 +0100

    MINOR: Bump com.google.guava:guava-bom from 33.4.8-jre to 33.5.0-jre (#1083)
    
    Bumps [com.google.guava:guava-bom](https://github.com/google/guava) from
    33.4.8-jre to 33.5.0-jre.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/google/guava/releases";>com.google.guava:guava-bom's
    releases</a>.</em></p>
    <blockquote>
    <h2>33.5.0</h2>
    <h3>Maven</h3>
    <pre lang="xml"><code>&lt;dependency&gt;
      &lt;groupId&gt;com.google.guava&lt;/groupId&gt;
      &lt;artifactId&gt;guava&lt;/artifactId&gt;
      &lt;version&gt;33.5.0-jre&lt;/version&gt;
      &lt;!-- or, for Android: --&gt;
      &lt;version&gt;33.5.0-android&lt;/version&gt;
    &lt;/dependency&gt;
    </code></pre>
    <h3>Jar files</h3>
    <ul>
    <li><a
    
href="https://repo1.maven.org/maven2/com/google/guava/guava/33.5.0-jre/guava-33.5.0-jre.jar";>33.5.0-jre.jar</a></li>
    <li><a
    
href="https://repo1.maven.org/maven2/com/google/guava/guava/33.5.0-android/guava-33.5.0-android.jar";>33.5.0-android.jar</a></li>
    </ul>
    <p>Guava requires <a
    
href="https://github.com/google/guava/wiki/UseGuavaInYourBuild#what-about-guavas-own-dependencies";>one
    runtime dependency</a>, which you can download here:</p>
    <ul>
    <li><a
    
href="https://repo1.maven.org/maven2/com/google/guava/failureaccess/1.0.3/failureaccess-1.0.3.jar";>failureaccess-1.0.3.jar</a></li>
    </ul>
    <h3>Javadoc</h3>
    <ul>
    <li><a
    href="https://guava.dev/releases/33.5.0-jre/api/docs/";>33.5.0-jre</a></li>
    <li><a
    
href="https://guava.dev/releases/33.5.0-android/api/docs/";>33.5.0-android</a></li>
    </ul>
    <h3>JDiff</h3>
    <ul>
    <li><a
    href="https://guava.dev/releases/33.5.0-jre/api/diffs/";>33.5.0-jre vs.
    33.4.8-jre</a></li>
    <li><a
    href="https://guava.dev/releases/33.5.0-android/api/diffs/";>33.5.0-android
    vs. 33.4.8-android</a></li>
    <li><a
    
href="https://guava.dev/releases/33.5.0-android/api/androiddiffs/";>33.5.0-android
    vs. 33.5.0-jre</a></li>
    </ul>
    <h3>Changelog</h3>
    <ul>
    <li>Restored the <code>Automatic-Module-Name</code> to
    <code>guava-android</code>. (It, unlike, <code>guava-jre</code>, is not
    a proper module.) (7a04a8a955)</li>
    <li>For users of <code>guava-gwt</code>: Google <a
    href="https://redirect.github.com/gwtproject/gwt-site/pull/394";>has
    moved off GWT internally</a>. We plan to continue to release
    <code>guava-gwt</code> for users of GWT and <a
    href="https://github.com/google/j2cl";>J2CL</a>, but the artifact is no
    longer tested for GWT-specific issues, and we have limited resources to
    fix any unexpected issues that might arise. While we do not anticipate
    any specific problems, we can't guarantee how long support will
    continue.</li>
    <li>Increased our Android <code>minSdkVersion</code> to 23
    (Marshmallow). This follows the minimum of Google's foundational Android
    libraries, and we expect it to have no practical impact on users.
    (5c23347cc1)</li>
    <li>Listed the JSpecify annotations as an optional dependency in our
    OSGi metadata. (2dfd572981)</li>
    <li><code>cache</code>: Improved the handling of exceptions from compute
    functions in <code>Cache.asMap()</code>. (We do still <a
    
href="https://guava.dev/releases/snapshot-jre/api/docs/com/google/common/cache/CacheBuilder.html#prefer-caffeine-over-guava-s-caching-api-heading";>recommend</a>
    using <a href="https://github.com/ben-manes/caffeine";>Caffeine</a>
    rather than <code>com.google.common.cache</code>.) (087f2c4a80)</li>
    <li><code>collect</code>: Improved <code>Iterators.mergeSorted()</code>
    to preserve stability for equal elements. (4dc93be9a8)</li>
    <li><code>math</code>: Added <code>saturatedAbs</code> methods to
    <code>IntMath</code> and <code>LongMath</code>. (ed0e518f20)</li>
    <li><code>net</code>: Added <code>image/avif</code> to
    <code>MediaType</code>. (53344caba6)</li>
    <li><code>testing</code>: Made <code>CollectorTester</code> available to
    Android users. (294c251079)</li>
    <li><code>util.concurrent</code>: Added <code>Striped.custom</code>.
    (1586eb271d)</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li>See full diff in <a
    href="https://github.com/google/guava/commits";>compare view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.google.guava:guava-bom&package-manager=maven&previous-version=33.4.8-jre&new-version=33.5.0-jre)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] 
<49699333+dependabot[bot]@users.noreply.github.com>
---
 pom.xml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/pom.xml b/pom.xml
index c0a01c605..200371e26 100644
--- a/pom.xml
+++ b/pom.xml
@@ -97,7 +97,7 @@ under the License.
     <dep.junit.platform.version>1.9.0</dep.junit.platform.version>
     <dep.junit.jupiter.version>5.12.2</dep.junit.jupiter.version>
     <dep.slf4j.version>2.0.17</dep.slf4j.version>
-    <dep.guava-bom.version>33.4.8-jre</dep.guava-bom.version>
+    <dep.guava-bom.version>33.5.0-jre</dep.guava-bom.version>
     <dep.netty-bom.version>4.2.10.Final</dep.netty-bom.version>
     <dep.grpc-bom.version>1.79.0</dep.grpc-bom.version>
     <dep.protobuf-bom.version>4.34.1</dep.protobuf-bom.version>

Reply via email to