Bump com.google.firebase:firebase-perf from 21.0.1 to 22.0.5#3715
Bump com.google.firebase:firebase-perf from 21.0.1 to 22.0.5#3715dependabot[bot] wants to merge 2 commits into
Conversation
Bumps [com.google.firebase:firebase-perf](https://github.com/firebase/firebase-android-sdk) from 21.0.1 to 22.0.5. - [Commits](https://github.com/firebase/firebase-android-sdk/commits) --- updated-dependencies: - dependency-name: com.google.firebase:firebase-perf dependency-version: 22.0.5 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
🔍 Dependency Analysis Summary
Overall risk: LOW — despite the major version bump, the breaking changes do not affect this project (minSdk already 23, AGP/Gradle/perf-plugin already meet requirements, and the project never used the deprecated 📋 Detailed Changelog ReviewPackage: Notable releases across the range:
Breaking changes: minSdk 23 (we already require 23 — see Security fixes: CVE-2024-7254 (protobuf) picked up via 21.0.2. Migration notes: None required for this project.
|
Bumps com.google.firebase:firebase-perf from 21.0.1 to 22.0.5.
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)