damccorm commented on PR #39756:
URL: https://github.com/apache/beam/pull/39756#issuecomment-5315821241

   > The change is kind of massive - maybe it makes sense to separate a 
generalized update without the version bump? Or, likely, it'll be nearly 
identical minus just the cryptography lines so note really smaller.
   
   Yeah, I think we can take it as is. We regenerate these dependencies every 
release (usually right after the cut, so this is timely), and these bumps 
should be helpful. Really this is just giving us visibility into the cascading 
stream of dependency updates that happens automatically if you don't explicitly 
pin every dependency.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to