damccorm commented on PR #39756: URL: https://github.com/apache/beam/pull/39756#issuecomment-5315821241
> The change is kind of massive - maybe it makes sense to separate a generalized update without the version bump? Or, likely, it'll be nearly identical minus just the cryptography lines so note really smaller. Yeah, I think we can take it as is. We regenerate these dependencies every release (usually right after the cut, so this is timely), and these bumps should be helpful. Really this is just giving us visibility into the cascading stream of dependency updates that happens automatically if you don't explicitly pin every dependency. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
