Google Cloud release notes

The following release notes cover the most recent changes over the last 60 days.For a comprehensive list of product-specific release notes, see theindividual product release note pages.

You can also see and filter all release notes in theGoogle Cloud console or youcan programmatically access release notes inBigQuery.

To get the latest product updates delivered to you, add the URL of this page to yourfeed reader, or add thefeed URL directly.

February 18, 2026

App Engine flexible environment .NET
Feature
Bigtable
Announcement

New best practices are available for securing generative AI agents using ModelContext Protocol (MCP) with Google Cloud databases. This guide covers keysecurity measures like least privilege, native database controls, and secureagent design to help you build safer AI applications. For more information, seeBest practices for securing agent interactions with Model Context Protocol.

Feature

You can migrate a machine learning feature management workload from Vertex AIFeature Store (Legacy) to a Bigtable instance. For more information, seeMigrate from Vertex AI Feature Store (Legacy) toBigtable.

Cloud Run
Feature
Cloud Run functions
Feature
Cloud SQL for MySQL
Deprecated

Control of MCP use with organization policies is deprecated.After March 17, 2026, organization policies that use thegcp.managed.allowedMCPServices constraint won't work,and you can control MCP use with IAM deny policies.For more information about controlling MCP use, seeControl MCP use with IAM.

Change

After March 17, 2026, when you enable the Cloud SQL Admin API(sqladmin.googleapis.com), the Cloud SQL remote MCP server isenabled automatically.

The Cloud SQL remote MCP server is inPreview.

Cloud SQL for PostgreSQL
Deprecated

Control of MCP use with organization policies is deprecated.After March 17, 2026, organization policies that use thegcp.managed.allowedMCPServices constraint won't work,and you can control MCP use with IAM deny policies.For more information about controlling MCP use, seeControl MCP use with IAM.

Change

After March 17, 2026, when you enable the Cloud SQL Admin API(sqladmin.googleapis.com)`, the Cloud SQL remote MCP server isenabled automatically.

The Cloud SQL remote MCP server is inPreview.

Cloud SQL for SQL Server
Deprecated

Control of MCP use with organization policies is deprecated.After March 17, 2026, organization policies that use thegcp.managed.allowedMCPServices constraint won't work,and you can control MCP use with IAM deny policies.For more information about controlling MCP use, seeControl MCP use with IAM.

Change

After March 17, 2026, when you enable the Cloud SQL Admin API(sqladmin.googleapis.com), the Cloud SQL remote MCP server isenabled automatically.

The Cloud SQL remote MCP server is inPreview.

Cloud Service Mesh
Announcement

CNI and managed data plane controller version 1.23.6-asm.28 is rolling out to allrelease channels.

While the managed data plane automatically updates Envoy Proxies by restartingworkloads, you must manually restart any StatefulSets and Jobs.

This patch includes the fix for the following CVEs:

NameCNIMDPCSeverity
CVE-2017-11164YesYesHigh (7.5)
CVE-2022-27943YesYesMedium (5.5)
CVE-2022-41409YesYesHigh (7.5)
CVE-2022-4899YesYesHigh (7.5)
CVE-2023-29383YesYesLow (3.3)
CVE-2023-34969YesYesMedium (6.5)
CVE-2023-50495YesYesMedium (6.5)
CVE-2023-7008YesYesMedium (5.9)
CVE-2024-41996YesYesHigh (7.5)
CVE-2025-8114YesYesMedium (4.7)
CVE-2025-9086YesYesHigh (7.5)
Compute Engine
Feature

Generally available: You can use Hyperdisk Exapools for large-scaleworkloads, such as AI and machine learning, that require between 500 TiB and 5EiB of block storage and more than 100 GiB/s of concurrent performance in asingle zone. With Hyperdisk Exapools, you purchase storage and performance in bulkand share those resources across as many as 500,000 disks in a single project.

To use Hyperdisk Exapools with your projects,contact your account teamto get access.

To learn more about Hyperdisk Exapools, seeHyperdisk Exapools overview.

Google Cloud Armor
Change

Cloud Armorpreconfigured WAF rules support for inspection up to the first 64 kB (either 8 kB, 16 kB, 32 kB, 48 kB, or 64 kB) of therequest body content is Generally Available.

Google Kubernetes Engine
Security

Multiple security vulnerabilities have been identified in the OpenSSL library.The most significant finding is CVE-2025-15467, a critical vulnerability thatmight allow for remote code execution (RCE) or denial of service (DoS) attacksvia network-based vectors.For more information, see theGCP-2026-006 security bulletin.

Google SecOps Marketplace
Feature

NewProofpoint Threat Protection integration

Change

CrowdStrike Falcon: Version 70.0

  • Deprecated the following actions:

    • Add Incident Comment

    • Update Incident

    • Add Comment to Detection

    • Close Detection

    • Update Detection

  • Deprecated the following connectors:

    • CrowdStrike - Detections Connector

    • Crowdstrike - Incidents Connector

Change

Exchange: Version 119.0

  • Updated the handling of S/MIME emails sent on MacOS in the followingconnectors:

    • Exchange - Mail Connector v2 with OAuth Authentication

    • Exchange - Mail Connector v2

Change

Google Chronicle: Version 76.0

  • Restored the previous JSON result structure for empty result sets in thefollowing action:

    • Execute UDM Query
Change

Palo Alto Cortex XDR: Version 23.0

  • Added the ability to provide agents using input parameters in the followingactions:

    • Scan Endpoint

    • Isolate Endpoint

    • Unisolate Endpoint

Change

QRadar: Version 63.0

  • Updated the logic for offense processing in the following connectors:

    • Qradar Correlation Events Connector V2

    • Qradar Offenses Connector

Change

Qualys VM: Version 21.0

  • Integration: Added the ability to configure theX-Requested-With header.
Change

Cofense Triage: Version 17.0

  • Optimized the report processing in the following connector:

    • Cofense Triage - Reports Connector
Network Intelligence Center
Feature

Cloud Network Insightsis available inPreview.

Cloud Network Insights monitors your network and web application performance acrossmulticloud and hybrid networks and provides visualizationtools to help identify and diagnose network issues.

Contact your Technical Account Manager to request access.

SAP on Google Cloud
Announcement

New SAP HANA certifications for OLAP and OLTP workloads

For use with SAP HANA, SAP has certified the following:

  • You can use them3-ultramem-128,m4-hypermem-64,x4-480-6t-metal,x4-480-8t-metal, andx4-960-12t-metal machine types to run OLAPworkloads in scale-out configurations with up to 8 nodes.
  • You can use thex4-480-8t-metal andx4-960-12t-metal machine types to runOLTP workloads in scale-out configurations with up to 4 nodes.

For more information, seeCertified Compute Engine machine types for SAP HANA.

Vertex AI Agent Builder
Announcement

Vertex AI Agent Builder

Vertex AI Agent EngineCode Executionis nowGenerally Available.

February 17, 2026

AlloyDB for PostgreSQL
Feature

AlloyDBperformance snapshot and reports now support read pool instance nodes, providing deeper observability into read operations and replica-specific performance issues.

Announcement

New best practices are available for securing generative AI agents using ModelContext Protocol (MCP) with Google Cloud databases. This guide covers keysecurity measures like least privilege, native database controls, and secureagent design to help you build safer AI applications. For more information, seeBest practices for securing agent interactions with Model Context Protocol.

Feature

You can now make AI function calls in bulk rather than row-by-row, which lets youscale your intelligent workflows faster with new support for array-basedprocessing. For more information, seePerform intelligent SQL queries using AI functions.

This feature is inPreview.

Feature

You can now use theAlloyDB remote MCP server.The AlloyDB remote MCP server lets you interact easily with AlloyDB clustersfrom LLMs, AI applications, and AI-enabled development platforms.

This feature is inPreview.

BigQuery
Feature

You can now runglobal queries, which let youreference data stored in more than one region in a single query. This feature isinPreview.

Deprecated

Control of MCP use with organization policies is deprecated. AfterMarch 17, 2026, organization policies that use thegcp.managed.allowedMCPServices constraint won't work, and you can controlMCP use with IAM deny policies. For more information about controlling MCP use,seeControl MCP use with IAM deny policies.

Change

After March 17, 2026, when you enable BigQuery, the BigQuery MCP server isautomatically enabled.

Bigtable
Feature

You can use theBigtable Admin API MCP serverto enable agents and AI applications to perform a range of data-related tasks.This feature is inPreview.

Buildpacks
Feature

Cloud Runsource deployment supports Ubuntu 24LTS base images inGeneral Availability. This builder is available undergcr.io/buildpacks/builder:google-24. For more information, seeBuilders.

Cloud Run
Feature

Cloud Runsource deployment supports Ubuntu 24LTS base images inGeneral Availability. This builder is available undergcr.io/buildpacks/builder:google-24. For more information, seeBuilders.

Cloud SQL for MySQL
Announcement

New best practices are available for securing generative AI agents usingModel Context Protocol (MCP) with Google Cloud databases. This guide coverskey security measures like least privilege, native database controls, andsecure agent design to help you build safer AI applications.For more information, seeBest practices for securing agent interactions with Model Context Protocol.

Cloud SQL for PostgreSQL
Announcement

New best practices are available for securing generative AI agents usingModel Context Protocol (MCP) with Google Cloud databases. This guide coverskey security measures like least privilege, native database controls, andsecure agent design to help you build safer AI applications.For more information, seeBest practices for securing agent interactions with Model Context Protocol.

Cloud SQL for SQL Server
Announcement

New best practices are available for securing generative AI agents usingModel Context Protocol (MCP) with Google Cloud databases. This guide coverskey security measures like least privilege, native database controls, andsecure agent design to help you build safer AI applications.For more information, seeBest practices for securing agent interactions with Model Context Protocol.

Cloud Trace
Deprecated

Starting February 18, 2026,trace sinks are deprecated.For more information, seeExport trace spans with sinks deprecation.

You can use the Log Analytics page, which provides a SQL queryinterface, to query both your trace and log data. To learn more, see thefollowing documents:

Compute Engine
Change

After March 17, 2026, when you enable Compute Engine,the Compute Engine MCP server is automatically enabled.

Deprecated

Control of MCP use with organization policies is deprecated. After March 17, 2026,organization policies that use thegcp.managed.allowedMCPServices constraintwon't work, and you can control MCP use with IAM deny policies.For more information about controlling MCP use, seeControl MCP use with IAM.

Document AI
Deprecated

Document AI legacy processors will be discontinued onJune 30, 2026. To preemptthe risk of service failure while using legacy processors, we recommend transitioning tomore stable, higher-quality processors.

The affected versions are:

TypeVersion
Identityparserspretrained-us-passport-v1.0-2021-06-14
pretrained-fr-driver-license-v1.0-2021-06-14
Tax andfinanceparserspretrained-1099misc-v1.1-2021-12-10
pretrained-1099nec-v1.0-2021-08-11
pretrained-1099r-v2.0-2022-07-25
pretrained-1099int-v1.1-2021-12-10
pretrained-ssa1099-v1.0-2021-08-09
pretrained-1099g-v1.0-2021-05-27
pretrained-1099g-v1.1-2021-12-10
pretrained-1120-v3.0-2022-04-26
pretrained-w9-v1.0-2020-09-25
pretrained-w9-v1.1-2021-12-10
pretrained-w9-v1.2-2022-01-27
pretrained-w9-v2.0-2022-06-23
Mortage andbankingparserspretrained-mortgage-statement-v1.0-2021-10-17
Procurementpretrained-utility-v1.1-2021-04-09
pretrained-utility-v1.2-2022-12-15
Splittingpretrained-procurement-splitter-v1.1-2021-04-09
pretrained-procurement-splitter-v1.2-2022-08-19
pretrained-lending-document-split-v1.0-2021-12-08
pretrained-lending-document-split-v2.0-2021-12-09
Summarypretrained-foundation-model-v1.0-2023-08-22

To ensure uninterrupted service and benefit from improved extraction quality,we recommend you migrate to the following later versions beforeJune 30, 2026:

To learn more about the migration process, refer toManage processor versions.

If you have any questions or require assistance, contact us atGoogle Cloud support.

Firestore
Announcement

New best practices are available for securing generative AI agents using Model Context Protocol (MCP) with Google Cloud databases. This guide covers key security measures like least privilege, native database controls, and secure agent design to help you build safer AI applications. For more information, seeBest practices for securing agent interactions with Model Context Protocol.

Deprecated

Control of MCP use with organization policies is deprecated. After March 17,2026, organization policies that use thegcp.managed.allowedMCPServicesconstraint won't work, and you can control MCP use with IAM deny policies. Formore information about controlling MCP use, seeControl MCP use with IAM.

Change

After March 17, 2026, when you enable Firestore, the FirestoreMCP server is automatically enabled.

Generative AI on Vertex AI
Deprecated

Image generation preview endpoints deprecation

The following table describes image generation endpoints that are deprecated andtheir replacements. We recommend updating your model endpoints before March 19,2026, to avoid service disruption.

Discontinued endpointsRecommended endpoint migration
gemini-2.0-flash-image-generation-previewgemini-2.5-flash-image
gemini-2.5-flash-image-generation-previewimagen-4.0-generate-001 orgemini-2.5-flash-image
imagen-4.0-generate-preview-05-20imagen-4.0-generate-001 orgemini-2.5-flash-image
imagen-4.0-generate-preview-06-06imagen-4.0-generate-001 orgemini-2.5-flash-image
imagen-4.0-ultra-generate-preview-06-06imagen-4.0-generate-001 orgemini-2.5-flash-image
imagen-4.0-fast-generate-preview-05-20imagen-4.0-generate-001 orgemini-2.5-flash-image
imagen-product-recontext-preview-06-30gemini-2.5-flash-image
imagen-2.0-edit-preview-0627gemini-2.5-flash-image
virtual-try-on-preview-08-04virtual-try-on-001
imagen-4.0-ingredients-previewgemini-2.5-flash-image
Feature

Anthropic's Claude Sonnet 4.6

Claude Sonnet 4.6is available in Model Garden.

Google Cloud Contact Center as a Service
Fixed

The following issues were addressed in this release:

  • Fixed the following issues with the standard (non-advanced reporting)dashboards:

    • TheDashboard> Queue Reports dashboard had broken tableheaders.

    • TheDashboard> Call dashboard was missing metrics labelsin theLOGGED IN AGENT tile.

  • Fixed an issue where calls were mistakenly saved in MP3 format rather thanWAV format in external storage.

  • Fixed an issue that occurred after an agent put an end-user on hold,transferred the call to another agent, and then left the call. When theremaining agent took the end-user off hold, the agent and the end-usercouldn't hear each other.

  • Fixed an issue with NICE WFM export where queue abandoned calls wereinaccurately reported to the WFM system.

  • Fixed an issue where theAssign Human Agents page for queues appearedblank, preventing administrators from viewing or managing agent assignments.

  • Fixed an issue where an email with a message ID longer than 255 charactersfailed to process and blocked the processing of other emails.

  • Fixed an issue where agents in theIn-email status didn't receiveincoming calls or chats.

  • Fixed an issue where CSAT ratings were missing from metadata files and rawdata exports.

  • Fixed an issue where Salesforce integrations incorrectly created duplicatecases for a single outbound call.

  • Fixed an issue where unsupported settings, such asCascade ConditionsandWrap-up settings, mistakenly appeared in the queue menu settings forApple Messages for Business queues.

  • Fixed an issue where attempting to barge into a chat while monitoring itreturned aYou are already in Chat error instead of completing the action.

  • Fixed an agent desktop issue where theNew photo received bannerreappeared after viewing a photo and switching between active chat tabs.

  • Fixed an issue where Direct Access Points failed to route calls correctlyfor SIP URIs with spaces or non-standard formats.

  • Fixed an issue where an agent's personal contact name was mistakenlydisplayed as the caller ID to other agents when they received a call fromthe agent.

  • Fixed an issue where agents appeared asAvailable in theAgent ActivityTimeline report after signing out.

Announcement

Google Cloud CCaaS 4.0

We've released version 4.0 of Google Cloud CCaaS.

The timing of the update to your instance depends on the deployment schedulethat you have chosen. For more information, seeDeploymentschedules.

Feature

Raw data export: new call_participants data type

We've added thecall_participants data type to raw data export. This data typehelps you track the following escalation details for wait-time virtual agents:

  • The amount of time the wait-time virtual agent spent in queue.

  • The number of events sent to the wait-time virtual agent while it was inqueue.

For more information, seeRaw data exportdictionary.

Feature

Salesforce Service Cloud: new secondary lookup object

The Salesforce Service Cloud integration can now use a secondary lookup objectto identify customer records when the primary lookup object returns no results.This helps prevent the creation of duplicate records.

Administrators: When you clickSettings> Developer Settings> CRM> Salesforce> SFDC Cloud Selection> Service Cloud, a newSecondary Lookup Object checkbox appearsin theAccount Lookup section.

For more information, seeConfigure account lookup and fieldmapping.

Google Kubernetes Engine
Deprecated

Control of MCP use with organization policies is deprecated. After March 17,2026, organization policies that use thegcp.managed.allowedMCPServicesconstraint won't work, and you can control MCP use with IAM deny policies. Formore information about controlling MCP use, seeControl MCP use with IAM.

Change

After March 17, 2026, when you enable GKE, the GKEMCP server is automatically enabled.

Google SecOps
Change

After March 17, 2026, when you enable Google SecOps, the Google SecOps MCP server is automatically enabled.

Deprecated

Control of MCP use with organization policies is deprecated. After March 17, 2026, organization policies that use thegcp.managed.allowedMCPServices constraint won't work, and you can control MCP use with IAM deny policies. For more information about controlling MCP use, seeControl MCP use with IAM.

Google SecOps SIEM
Change

After March 17, 2026, when you enable Google SecOps, the Google SecOps MCP server is automatically enabled.

Deprecated

Control of MCP use with organization policies is deprecated. After March 17, 2026, organization policies that use thegcp.managed.allowedMCPServices constraint won't work, and you can control MCP use with IAM deny policies. For more information about controlling MCP use, seeControl MCP use with IAM.

Looker
Feature

Rolling out in preview starting February 17, 2026, LookML developers can unlock their Git branch in cases where their Git branch is locked as a result of another Git operation in progress or a previous Git operation failing. When the Git repository is locked, Looker displays theUnlock Branch option in theGit Actions panel of the Looker IDE. In addition, if a LookML developer tries to commit a change on a locked Git branch, Looker displays a warning in theCommit dialog, along with an option to delete the Git lock. See theUsing version control and deploying documentation page for details.

Note: This item was added on February 18, 2026.

Feature

Rolling out in preview starting February 17, 2026, theSelf-service Explores feature supports updating the data for a self-service Explore. The owner of a self-service Explore can update it with data from the latest version of the file that was used to create the self-service Explore. See theCreating self-service Explores documentation page for more information.

Feature

Rolling out in preview starting February 17, 2026, theSelf-service Explores feature supportsuploading data from Google Sheets. To support uploading data from Google Sheets, your Looker admin mustenable the required APIs in the Google Cloud project that houses your BigQuery database.

Feature

Rolling out in preview starting February 17, 2026, theIn-database merge queries feature is supported formerging results of two queries that are on the same BigQuery connection. Previously, the join for merging results was always performed in Looker memory, which limited each query to 5,000 rows that could be calculated in the join. If your Looker admin has enabled theIn-database merge queries Looker Labs feature, the join between two queries that are on the same BigQuery connection is performed in the BigQuery database itself. Performing the join in the database is more performant and allows for unlimited rows that can be joined.

Feature

TheSystem Activity User Activity dashboard has been updated to improve authentication troubleshooting. New information includes: recent login failures, the authentication method that was used, the error message that was returned, and the time of the attempt.

Feature

Rolling out in preview starting February 17, 2026, thecontent certification feature includes several new updates:

  • TheSettings page in the General section of the Admin panel now includes options that let admins enable or disable content certification, set a custom URL for the certification process, and control whether certification is revoked when content is edited.
  • LookML dashboards can now be certified.
  • Looks and dashboards that are based on uncertified self-service Explores now display the "ungoverned" badge.
  • Searching for content now includes the ability to sort content based on its certification status.
Feature

Now rolling out in preview, dashboard editors can change the size and layout of dashboard tiles with more granularity. To enable this feature, a Looker admin must turn on theGranular Dashboard Sizing Labs feature.

Feature

Now rolling out in preview, dashboard editors canset default options for how the download of a dashboard tile includes query results. They can set the download to include by default all query results or the current result table that is displayed in the visualization, or set a custom number of rows and columns. To enable this feature, a Looker admin must turn on theTile Download Default Options Labs feature.

Feature

Rolling out in preview starting February 17, 2026, theEmbed Conversational Analytics Labs feature is now available. When enabled, the Embed Conversational Analytics Labs feature lets youembed Conversational Analytics conversations and agents in an iframe like other Looker content types.

Spanner
Announcement

New best practices are available for securing generative AI agents usingModel Context Protocol (MCP) with Google Cloud databases. This guide coverskey security measures like least privilege, native database controls, and secureagent design to help you build safer AI applications. For more information, seeBest practices for securing agent interactions with Model Context Protocol.

This feature is inPreview.

Workflows
Change

Workflows is available in the following additionalregion:asia-southeast3 (Bangkok, Thailand).

February 16, 2026

Cloud Composer
Change

Newimagesare available in Cloud Composer 2:

Deprecated

The following Cloud Composer versions and builds have reached theirend of support period:composer-3-airflow-2.9.3-build.15 and composer-2.11.2-*.

Feature

Environment snapshotsare available in environments with Airflow 3 (Preview). This change is nowrolled out to all regions supported by Cloud Composer 3.

Document AI
Feature

Thelayout parser web interface is inPreview.

It supports a document view display for processed PDF files and supportsvisualizing the document's parsed JSON, block layout, andimage or table annotation data in a user-friendly interface. Bounding box supportonly exists for version processorpretrained-layout-parser-v1.0-2024-06-03.

It also supports modifying the input layout config to allowfor configuring the table and image annotation feature directly from the interface.

February 15, 2026

Carbon Footprint
Feature

Methodology update: Starting with January 2026 data, we have updated ourcalculation model to align with the comprehensive AI energy/emissions frameworkdetailed inMeasuring the environmental impact of delivering AI at Google Scale.This update allocates previously unallocated AI inference model emissions to theassociated Google Cloud services, following the SKU-level allocation describedin theCarbon Footprint reporting methodology. This change is part of our ongoing effort to provide more accurate andtransparent emissions data for AI inference.

Impact: Customers will see an increase in reported emissions for servicesthat utilize AI model inference across all SKUs. Such an increase is spreadacross all SKUs within those services, based on the SKU-level allocationmethodology.The primary impact is on Vertex AI. Other impacted services include VideoStitcher API, Notebooks, Cloud Natural Language, Cloud Speech API, CloudDocument AI API, Cloud Dialogflow API, Cloud Machine Learning Engine, CloudText-to-Speech API and Cloud Vision API.

Dataproc
Announcement

NewDataproc on Compute Engine subminor image versions:

  • 2.0.159-debian10, 2.0.159-rocky8, 2.0.159-ubuntu18
  • 2.1.108-debian11, 2.1.108-rocky8, 2.1.108-ubuntu20, 2.1.108-ubuntu20-arm
  • 2.2.76-debian12, 2.2.76-rocky9, 2.2.76-ubuntu22, 2.2.76-ubuntu22-arm
  • 2.3.23-debian12, 2.3.23-ml-ubuntu22, 2.3.23-rocky9, 2.3.23-ubuntu22, 2.3.23-ubuntu22-arm
Google SecOps SIEM
Announcement

Release 6.3.76 is being rolled out to the first phase of regions as listedhere.

This release contains internal and customer bug fixes.

Google SecOps SOAR
Announcement

Release 6.3.76 is being rolled out to the first phase of regions as listedhere.

This release contains internal and customer bug fixes.

Resource Manager
Change

After March 17, 2026, when you enable Resource Manager, the Resource Manager MCP server is automatically enabled.

Deprecated

Control of MCP use with organization policies is deprecated. After March 17, 2026, organization policies that use thegcp.managed.allowedMCPServices constraint won't work, and you can control MCP use with IAM deny policies. For more information about controlling MCP use, seeControl MCP use with IAM.

February 14, 2026

Google SecOps SIEM
Announcement

Release 6.3.75 is now available for all regions.

Google SecOps SOAR
Announcement

Release 6.3.75 is now available for all regions.

February 13, 2026

Apigee UI
Change

Updated the route for Operations Anomalies fromapigee/analytics/operations-anomalies toapigee/aapi-ops/operations-anomalies.

Announcement

On February 13, 2026, we released an updated version of the Apigee UI.

Apigee X
Announcement

On February 13, 2026, we published a security bulletin for Apigee.

Security

A vulnerability was identified in the Apigee platform (CVE-2025-13292) that could have allowed a malicious actor with administrative or developer-level permissions in their own Apigee environment to elevate privileges and access cross-tenant data.

Security bulletin published:GCP-2026-010

Bigtable
Feature

You can use theFlink Bigtable connectorversion 0.3.2 to connect to Bigtable from Apache Flink version 2.1.0.Additionally, this version of the connector lets you specify the number ofmutations to include in each batch sent to Bigtable. This feature isgenerally available (GA).

Dataproc
Announcement
Google Cloud VMware Engine
Announcement

The VMware Engineve2 node type is now available in the followingadditional region:

  • Osaka, Japan, Asia Pacific (asia-northeast2)
Google Distributed Cloud (software only) for VMware
Feature

The following feature was added in 1.34.100-gke.93:

You can deployvsphere-csi-controller in the advanced cluster on the usercluster control plane nodes.

Announcement

Google Distributed Cloud (software only) for VMware 1.34.100-gke.93 is now availablefor download. To upgrade, see Upgrade a cluster. Google Distributed Cloud1.34.100-gke.93 runs on Kubernetes v1.34.1-gke.4700.

If you are using a third-party storage vendor, check the Google Distributed Cloud-readystorage partners document to make sure the storage vendor has already passed thequalification for this release.

After a release, it takes approximately 7 to 14 days for the version to becomeavailable for use with GKE On-Prem API clients: the Google Cloud console, thegcloud CLI, and Terraform.

Google Distributed Cloud (software only) for bare metal
Feature

The following feature was added in 1.34.100-gke.93:

Thespec.taints field in theNodePoolClaim resource is mutable. You canadd or remove taints on existing node pools without recreating theNodePoolClaim. You can use this field to manage GPU nodes.

Announcement

Google Distributed Cloud (software only) for bare metal 1.34.100-gke.93 is now available fordownload. To upgrade, see Upgrade clusters. Google Distributed Cloud for bare metal1.34.100-gke.93 runs on Kubernetes v1.34.1-gke.4700.

After a release, it takes approximately 7 to 14 days for the version to becomeavailable for installations or upgrades with the GKE On-Prem API clients: theGoogle Cloud console, the gcloud CLI, and Terraform.

If you use a third-party storage vendor, check the Google Distributed Cloud-readystorage partners document to make sure the storage vendor has already passed thequalification for this release of Google Distributed Cloud for bare metal.

Google Kubernetes Engine
Feature

You can now determine the status and health of a TPU slice and partition by monitoring these new beta system metrics:

  • kubernetes.io/accelerator/slice/state: Indicates the current status of the slice.
  • kubernetes.io/accelerator/partition/state: Indicates the health of the partition.

For more information, see theGKE system metrics documentation.

Network Intelligence Center
Feature

Flow Analyzersupports latency mode, allowing you to analyze round-trip time in yourtraffic flows.For more information, seeDisplay flows in latency mode.

February 12, 2026

App Engine standard environment Go
Feature

Support for deploying your existing apps in the standard environment to Cloud Run usingthegcloud beta app migrate-to-run command is inPreview. For more information, seeDeploy an App Engine app in the standard environment to Cloud Run.

App Engine standard environment Java
Feature

Support for deploying your existing apps in the standard environment to Cloud Run usingthegcloud beta app migrate-to-run command is inPreview. For more information, seeDeploy an App Engine app in the standard environment to Cloud Run.

App Engine standard environment Node.js
Feature

Support for deploying your existing apps in the standard environment to Cloud Run usingthegcloud beta app migrate-to-run command is inPreview. For more information, seeDeploy an App Engine app in the standard environment to Cloud Run.

App Engine standard environment PHP
Feature

Support for deploying your existing apps in the standard environment to Cloud Run usingthegcloud beta app migrate-to-run command is inPreview. For more information, seeDeploy an App Engine app in the standard environment to Cloud Run.

App Engine standard environment Python
Feature

Support for deploying your existing apps in the standard environment to Cloud Run usingthegcloud beta app migrate-to-run command is inPreview. For more information, seeDeploy an App Engine app in the standard environment to Cloud Run.

App Engine standard environment Ruby
Feature

Support for deploying your existing apps in the standard environment to Cloud Run usingthegcloud beta app migrate-to-run command is inPreview. For more information, seeDeploy an App Engine app in the standard environment to Cloud Run.

BigQuery
Feature

You can now usedataset insightsto understand relationships between tables in a dataset by generatingrelationship graphs and cross-table queries. You can automatically generatedataset summaries, infer relationships across tables, and receive suggestionsfor analytical questions. This feature is inPreview.

Feature

You can now provide descriptions for the fields in your custom output schemawhen you use theAI.GENERATEandAI.GENERATE_TABLEfunctions.This feature isgenerally available(GA).

Feature

TheAI.CLASSIFY functionnow supports classifying your input into multiple categories. This feature is inPreview.

Cloud Build
Change

Cloud Build is now available in theasia-southeast3 region.

For more information, seeCloud Build locations.

Cloud Logging
Feature

You no longer need to configure BigQuery reservation assignmentsto create SQL-based alerting policies or run Log Analytics queries onBigQuery slots. These queries now use on-demand slots by defaultif no BigQuery reservation assignment exists.

For more information, see the following documents:

Compute Engine
Feature

Generally available: You can use instance flexibility to improve resource availability when creating VMs in bulk in a region. With instance flexibility, you specify one or more suitable machine types for your workload. Compute Engine then provisions VMs from the list of machine types based on capacity and quota availability.

For more information, seeAbout instance flexibility for VMs created in bulk andCreate VMs in bulk with instance flexibility.

Developer Connect
Feature

Developer Connect now supportsHTTP connections, for access toarbitrary HTTP endpoints.

Gemini Enterprise
Feature

Gemini Enterprise mobile app: Standard and Plus editions (Private GA)

The Gemini Enterprise mobile app is available in Private GA. The mobile app letsusers interact with organizational data, engage with agents, and execute tasksseamlessly using their mobile device.

To ensure that you have the latest features, security, and best experience, youmay occasionally be required to update your Gemini Enterprise mobile app, orinstall a new version. Some updates may be necessary to continue using the app.

Contact your account manager to access the mobile app.

Google SecOps
Feature

Advanced Joins in Search

Google SecOps now supports expanded capabilities for correlating data acrossmultiple sources. These join operations are also supported in multistage queries.

Joins without amatch section: You can now use join operations to correlateand combine data from multiple sources based on common field values withoutrequiring amatch section (unlike statistical joins). Results are displayed in aJoins table, which you can download as a CSV, or for event-to-event joins,exported to a datatable for further analysis.

For more information, seeImplement joins without a match section.

Outer joins: Search now supports left and right outer joins. Unlike standardinner joins, these operations let you retrieve all records from a primarydata source even if no matching entry exists in the secondary source (unmatchedfields are returned asnull). This action lets you correlate datawithout losing unmatched events.

For more information, seeCorrelate data with outer joins.

Google SecOps SIEM
Feature

Advanced Joins in Search

Google SecOps now supports expanded capabilities for correlating data acrossmultiple sources. These join operations are also supported in multistage queries.

Joins without amatch section: You can now use join operations to correlateand combine data from multiple sources based on common field values withoutrequiring amatch section (unlike statistical joins). Results are displayed in aJoins table, which you can download as a CSV, or for event-to-event joins,exported to a datatable for further analysis.

For more information, seeImplement joins without a match section.

Outer joins: Search now supports left and right outer joins. Unlike standardinner joins, these operations let you retrieve all records from a primarydata source even if no matching entry exists in the secondary source (unmatchedfields are returned asnull). This action lets you correlate datawithout losing unmatched events.

For more information, seeCorrelate data with outer joins.

Feature

Advanced Joins in Search

Google SecOps now supports expanded capabilities for correlating data acrossmultiple sources. These join operations are also supported in multistage queries.

Joins without amatch section: You can now use join operations to correlateand combine data from multiple sources based on common field values withoutrequiring amatch section (unlike statistical joins). Results are displayed in aJoins table, which you can download as a CSV, or for event-to-event joins,exported to a datatable for further analysis.

For more information, seeImplement joins without a match section.

Outer joins: Search now supports left and right outer joins. Unlike standardinner joins, these operations let you retrieve all records from a primarydata source even if no matching entry exists in the secondary source (unmatchedfields are returned asnull). This action lets you correlate datawithout losing unmatched events.

For more information, seeCorrelate data with outer joins.

Looker Studio
Feature

Pro feature: Change the billing account

You can change the Google Cloud billing account that is associated with a Looker Studio Pro subscription without interrupting access to your Pro assets.

Learn how to change the Pro billing account.

Feature

Additional search parameters

When searching for reports or data sources, you can filter search results by the following parameters:

  • Type
  • Owner
  • Location
  • Date Modified
Oracle Database@Google Cloud
Feature

Oracle Database@Google Cloud adds zoneeurope-west2-a-r1 (London, Europe) for the following services:

  • Exadata Database Service on Exascale infrastructure
  • Base Database Service

For a list of supported locations, seeSupported regions and zones.

February 11, 2026

BigQuery
Feature

You can now run pipelines with three distinct execution methods: running alltasks, running selected tasks, and running tasks with selected tags. For moreinformation, seeRun a pipeline.This feature isgenerally available(GA).

Buildpacks
Feature

Support forosonly24 runtime is inGeneral Availability. The OS only runtime lets you deploy Go applications from source, and binaries such as Dart and Go. For more information, seeConfigure the OS only runtime.

Cloud Deploy
Feature

You can nowdeploy containerized workloads to Cloud Run worker pools. This feature is now generallyavailable (GA).

Cloud Key Management Service
Feature

Cloud KMS Autokey for projects is available in Public Preview. Autokey forprojects lets you enable Cloud KMS Autokey for delegated key management. Indelegated key management, keys created by Autokey are created in the sameproject as the resources they protect. This option is suitable for yourorganization if project administrators are in charge of key management for theprojects they manage.

You can still use Cloud KMS Autokey for centralized key management in a folder,where all keys that protect resources in that folder are created in a dedicatedkey project. You can also use centralized key management in a folder, withcertain projects within that folder configured to use delegated key managementand same-project keys instead of creating keys in the dedicated key project.

You can enable Autokey for projects on individual projects or on all projectswithin a folder. For more information, seeEnable Cloud KMS Autokey.

Cloud Run
Feature

Support forosonly24 runtime is inGeneral Availability. The OS only runtime lets you deploy Go applications from source, and binaries such as Dart and Go. For more information, seeConfigure the OS only runtime.

Dataplex
Feature

You can now use metadata change feeds to receive near real-time notificationsabout metadata changes in Dataplex. Dataplex publishes notifications to aPub/Sub topic of your choice, letting you build event-driven workflows,sync metadata to external catalogs, or trigger data quality checks.For more information, seeAbout metadata change feeds.

Google Kubernetes Engine
Change

(2026-R6) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and formanual control plane upgrades and node upgrades for existing clusters. For moreinformation about versioning and upgrades, seeGKE versioning andsupport andAbout GKEcluster upgrades.

Rapid channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Regular channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Stable channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
  • Version1.33.5-gke.2118001 is now the default version for cluster creation in the Stable channel.
  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.32.9-gke.1728000
    • 1.33.5-gke.2100001
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Extended channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

No channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Security

(2026-R6) Security updates

This release includes new GKE versions that use updatedContainer-Optimized OS images. These updated images are cumulative,incorporating security fixes from all Container-Optimized OSversions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updatedContainer-Optimized OS image, see theSecurity release notesfor that image. The following table includes links to the release notes foreach updated Container-Optimized OS image:

GKE versionContainer-Optimized OS versionDetails
1.32.11-gke.1264000cos-117-18613-439-108cos-117-18613-439-108 release notes
1.34.3-gke.1444000cos-125-19216-104-133cos-125-19216-104-133 release notes
1.35.0-gke.2232000cos-125-19216-104-45cos-125-19216-104-45 release notes
1.35.0-gke.2398000cos-125-19216-104-126cos-125-19216-104-126 release notes

Change

(2026-R6) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R6) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R6) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R6) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R6) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
  • Version1.33.5-gke.2118001 is now the default version for cluster creation in the Stable channel.
  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.32.9-gke.1728000
    • 1.33.5-gke.2100001
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
Google SecOps Marketplace
Feature

CiscoUmbrella: Version 15.0

  • The following new actions have been added:

    • Is Domain In Cisco Popularity List

    • List Top Domains

Change

Palo Alto Cortex XDR: Version 22.0

  • Updated the event processing and dynamic list handling of the followingconnector:

    • Palo Alto Cortex XDR Connector
  • Added the ability to ignore certain types of artifacts to the followingconnector:

    • Palo Alto Cortex XDR Connector
Change

Google Threat Intelligence: Version 9.0

  • Added the ability to define the data freshness threshold for available hashesto the following action:

    • Submit File
  • Added the ability to filter using monitor names to the following connector:

    • Google Threat Intelligence - DTM Alerts Connector
  • Integration: Updated the connectivity test method to avoid API quotaconsumption.

Change

Tenable.io: Version 13.0

  • Optimized the asset processing of the following connector:

    • TenableIO - Vulnerabilities Connector
  • Updated the entity processing logic of the following actions:

    • Enrich Entities

    • List Endpoint Vulnerabilities

    • Scan Endpoints

Oracle Database@Google Cloud
Feature

For Exadata Database Service, Oracle Database@Google Cloud supports the following regions and zones:

  • australia-southeast2-a-r2 (Melbourne, Australia)
  • asia-south2-b-r1 (Delhi, India)

For a list of supported locations, seeSupported regions and zones.

VPC Service Controls
Feature

Preview stage supportfor the following integration:

February 10, 2026

Anthos Attached Clusters
Announcement

You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:

Anthos clusters on AWS
Announcement

You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:

Anthos clusters on Azure
Announcement

You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:

Issue

The following versions are not recommended:

  • 1.33.4-gke.900
  • 1.32.8-gke.600
  • 1.32.4-gke.200

If you use any of the preceding versions, we strongly recommend that you upgrade to version 1.34 or the latest available patch versions.

Apigee XCloud Asset Inventory
Feature

The following resource types are publicly available through theExportAssets,ListAssets,BatchGetAssetsHistory,QueryAssets,Feed,SearchAllResources,andSearchAllIamPoliciesAPIs.

  • Apigee
    • apigee.googleapis.com/ApiProxy
    • apigee.googleapis.com/ApiProxyRevision
    • apigee.googleapis.com/Environment
Cloud Composer
Fixed

(Available without upgrading) Fixed an issue where Airflow workloads used thePerformance Persistent Disk type (pd-ssd) instead of the Standard PersistentDisk type (pd-standard).

Fixed

(Available without upgrading in Cloud Composer 3) Fixed load snapshotoperations that were failing with invalid configuration error for the recentlycreated snapshots.

Cloud SQL for MySQL
Feature

Model endpoint managementfor Cloud SQL for MySQL and theintegration of Cloud SQL for MySQL with Vertex AI are now generally available(GA).

By integrating your Cloud SQL for MySQL instance with Vertex AI, you caninvoke online predictions and generate vector embeddings from models hostedin Vertex AI directly from your Cloud SQL instance.

With model endpoint management, you can build generative AI applications byintegrating your databases with models from third-party providers like OpenAIusing your own API keys. Model endpoint management lets you register andmanage model endpoints for your MySQL instance, making your interactionswith a wider range of ML models seamless.

Compute Engine
Feature

Preview: You can use consistency groups of instant snapshots to back up agroup of disks at the same point in time, ensuring data consistency acrossmultiple disks. Consistency groups of instant snapshots offer the followingbenefits:

  • Simultaneous backups: create instant snapshots for all disks in a consistencygroup with a single operation.
  • Bulk restoration: restore multiple disks at once from a consistency group ofinstant snapshots.

To learn more, seeAbout instant snapshots.

Confidential VM
Security

A vulnerability affecting Intel TDX firmware was discovered and isbeing addressed. For more information, see theGCP-2026-008 security bulletin.

Container Optimized OS
Fixed

Upgraded sys-libs/libcap to v2.77.

Security

Updated dev-libs/libxml2 to version 2.14.6. This resolves CVE-2025-6021.

Fixed

Upgraded app-admin/google-guest-configs to v20251014.00.

Change

cos-113-18244-582-2

KernelDockerContainerdGPU Drivers
COS-6.1.161v24.0.9v1.7.27See List
Announcement
Fixed

Upgraded net-libs/libtirpc to v1.3.7.

Fixed

Upgraded app-containers/docker-credential-helpers to v0.9.4.

Change

cos-125-19216-104-149

KernelDockerContainerdGPU Drivers
COS-6.12.55v27.5.1v2.1.5See List
Feature

Added support for NVIDIA driver v535.288.01, v570.211.01 and v580.126.09.

Feature

Enabled TC Traffic Police as a module.

Security

Fixed CVE-2026-23023 in the Linux kernel.

Security

Fixed CVE-2025-71183 in the Linux kernel.

Fixed

Fixed TCPX performance issues.

Security

Fixed CVE-2026-23038 in the Linux kernel.

Feature

Added support for NVIDIA driver v535.288.01, v570.211.01 and v580.126.09.

Security

Fixed CVE-2024-57982 in the Linux kernel.

Security

Fixed CVE-2024-49968 in the Linux kernel.

Change

cos-121-18867-294-116

KernelDockerContainerdGPU Drivers
COS-6.6.113v27.5.1v2.0.7See List
Firestore
Feature

You can now use theFirestore remote MCP server.The Firestore remote MCP server lets you interact with documents storedin a Firestore database from your AI application.

This feature is inPreview.

Generative AI on Vertex AI
Feature

GLM 5 is available as an experimental launch in Model Garden. This modelis targeting complex systems engineering and long-horizon agentic tasks.GLM 5 is available as a managed API in Model Garden. To learn more, seeGLM 5.

Memorystore for Valkey
Feature

You can now use the Google Cloud console tomanage backups.This feature isGenerally Available.

Spanner
Feature

You can use theSpanner remote MCP server tointeract with Spanner instances and databases from agentic AIapplications such as Gemini CLI, agentmode in Gemini Code Assist, or Claude.ai.

This feature is inPreview.

Virtual Private Cloud
Feature

You can use constraints in custom organization policies to provide more granularand customizable control over specific fields for internal ranges. For moreinformation, seeManage VPC resources by using custom organizationpolicies.

February 09, 2026

AlloyDB for PostgreSQL
Fixed

We are announcing the release of support for the AlloyDB language connectors andAuth Proxy withAuto IAM Authenticationand managed connection pooling. This feature and the fix for the issue frombelow is available starting with maintenance version 20260107.02_05. Clusterswith a maintenance window that may not have received this release can useself-service maintenanceto perform a maintenance update.

BigQuery
Feature

You can now customize the scope of data documentation scans for BigQuery tablesto generate specific insights. You can choose to generate only SQL queries,only table and column descriptions, or all insights.

You can also create one-time data scans that execute immediately upon creation,removing the need for a separaterun command. These scans support aTime to Live (TTL) setting to automatically delete the scan resource aftercompletion.

For more information, seeGenerate insights for a BigQuery table.

Cloud Asset Inventory
Feature

The following resource types are publicly available through theExportAssets,ListAssets,BatchGetAssetsHistory,QueryAssets,Feed,SearchAllResources,andSearchAllIamPoliciesAPIs.

  • Cloud Run
    • run.googleapis.com/WorkerPool
  • Dataform
    • dataform.googleapis.com/TeamFolder
    • dataform.googleapis.com/Folder
  • Discovery Engine
    • discoveryengine.googleapis.com/Assistant
Cloud Data Fusion
Feature

Cloud Data Fusion version 6.11.1.1 isgenerally available (GA).This release includes the following feature:

  • InstanceV3 monitored-resource: Introduceddatafusion.googleapis.com/InstanceV3 as the default monitored resource forinstance-level metrics and system service logs. This resource excludes theorg_id andnamespace labels found inInstanceV2. Emission ofInstanceV2 metrics and logs is disabled by default for new and upgradedinstances but can be re-enabled using the REST API.

    For more information, seeMetrics overview andView pipeline logs.

Fixed

Fixed in Cloud Data Fusion 6.11.1.1:

  • Fixed retries in message publishing when the messaging service istemporarily unavailable(CDAP-21043).
  • Fixed a security vulnerability where user-provided code in preview runnerscould access sensitive data from other preview runs(CDAP-21211).
  • Fixed an issue where internal task workers running user code could hangindefinitely. The system now forces completed tasks to exit and uses ahealth check to restart unresponsive workers(CDAP-21213).
  • Fixed an issue where the list apps API endpoint failed to return all deployedpipelines when used with pagination(CDAP-21220).
Cloud Logging
Feature

You can use theCloud Logging API MCP serverto let agents and AI applications interact with your log entries.This feature is inPreview.

Cloud SQL for MySQL
Feature

You can now use theCloud SQL remote MCP server.The Cloud SQL remote MCP server lets you interact easily with Cloud SQLinstances from LLMs, AI applications, and AI-enabled development platforms.

This feature is inPreview.

Cloud SQL for PostgreSQL
Feature

You can now use theCloud SQL remote MCP server.The Cloud SQL remote MCP server lets you interact easily with Cloud SQLinstances from LLMs, AI applications, and AI-enabled development platforms.

This feature is inPreview.

Cloud SQL for SQL Server
Feature

You can now use theCloud SQL remote MCP server.The Cloud SQL remote MCP server lets you interact easily with Cloud SQLinstances from LLMs, AI applications, and AI-enabled development platforms.

This feature is inPreview.

Cloud Service Mesh
Announcement

The following images are now rolling out for managed Cloud Service Mesh:

  • 1.21.6-asm.10 is rolling out to the rapid release channel.
  • 1.20.8-asm.63 is rolling out to the regular release channel.
  • 1.19.10-asm.57 is rolling out to the stable release channel.

These patch releases contain the fixes for the following managed Cloud Service Mesh CVEs:

CVEProxyControl PlaneCNIDistrolessSeverity
CVE-2025-61729YesYes-YesHigh (7.5)
CVE-2025-61727YesYes-YesMedium (6.5)
CVE-2024-41996YesYes-YesHigh (7.5)
CVE-2025-9086YesYes-YesHigh (7.5)
CVE-2021-46848YesYes-YesCritical (9.1)
CVE-2025-13151YesYes-YesHigh (7.5)
CVE-2025-68973YesYes-YesHigh (7.8)
Compute Engine
Feature

You can autoscale a managed instance group (MIG) thathas instance flexibility configured. Autoscaling lets the MIG create ordelete virtual machine instances based on an increase or decrease in load. Formore information, seeAbout instance flexibility.

Document AIGemini Enterprise
Feature

Gemini Enterprise: Data connector for Notion (Public preview)

You can connect Notion data stores to Gemini Enterprise. For more information,seeConnect Notion.

Support for Notion data sources is in Public preview.

Google SecOps
Announcement

Enhanced rule observability: New metadata, visual indicators, and dashboards

Google Security Operations has introduced updates to how detection and alert data is processed and visualized. These changes help Google SecOps teams distinguish between primary rule runs andrule replays, which provides clarity on detection delays and the impact of late-arriving enrichment data.

  • Key improvements

    • Enhanced metadata: Detection and alert objects now include specific metadata that identifies whether they were produced during a primary rule run, or as part of arule replay or retrohunt.
    • Improved troubleshooting: This data lets Google SecOps teams definitively answer critical operational questions, such as the cause of perceived detection delays or the specific impact of late-arriving enrichment data on active rules.
    • Rule replay insights: Learn more about the distinction between primary runs and replays to manage the re-enrichment of Unified Data Model (UDM) events. For detailed definitions and technical workflows, seeUnderstand rule replay andUnderstand rule detection delays.
    • New detection dashboard: To support these backend metadata changes, a newDetection Health dashboard is now available. This interface provides a visual representation of rule performance and replay status, letting teams monitor detection health more effectively.
    • Custom reporting: There are new fields available in theDetections schema, letting you build custom dashboards.
  • New metadata and third-party integration: Detections and alerts now emit specific metadata to help customers track timing and latency. This data is available for integration with third-party systems using the following fields:

    • detectionTimingDetails: An enum identifying the run type:
    • DETECTION_TIMING_DETAILS_REPROCESSING
    • DETECTION_TIMING_DETAILS_RETROHUNT
    • DETECTION_TIMING_DETAILS_UNSPECIFIED
    • latencyMetrics: Includes timestamps foroldestIngestionTime,newestIngestionTime,oldestEventTime, andnewestEventTime.
  • Enhanced platform and visual indicators:

    • Alerts and rule details: A new visual indicator in theDetection Type column provides granular details on hover.
    • Filter facets: TheAlerts lister page now includesdetection timing details as a filterable facet.
    • SOAR integration: In theCase Overview, theComposite Detections table now carries through the same iconography for a consistent investigation experience.
Google SecOps SIEM
Announcement

Enhanced rule observability: New metadata, visual indicators, and dashboards

Google Security Operations has introduced updates to how detection and alert data is processed and visualized. These changes help Google SecOps teams distinguish between primary rule runs andrule replays, which provides clarity on detection delays and the impact of late-arriving enrichment data.

  • Key improvements

    • Enhanced metadata: Detection and alert objects now include specific metadata that identifies whether they were produced during a primary rule run, or as part of arule replay or retrohunt.
    • Improved troubleshooting: This data lets Google SecOps teams definitively answer critical operational questions, such as the cause of perceived detection delays or the specific impact of late-arriving enrichment data on active rules.
    • Rule replay insights: Learn more about the distinction between primary runs and replays to manage the re-enrichment of Unified Data Model (UDM) events. For detailed definitions and technical workflows, seeUnderstand rule replays andUnderstand rule detection delays.
    • New detection dashboard: To support these backend metadata changes, a newDetection Health dashboard is now available. This interface provides a visual representation of rule performance and replay status, letting teams monitor detection health more effectively.
    • Custom reporting: There are new fields available in theDetections schema, letting you build custom dashboards.
  • New metadata and third-party integration: Detections and alerts now emit specific metadata to help customers track timing and latency. This data is available for integration with third-party systems using the following fields:

    • detectionTimingDetails: An enum identifying the run type:
    • DETECTION_TIMING_DETAILS_REPROCESSING
    • DETECTION_TIMING_DETAILS_RETROHUNT
    • DETECTION_TIMING_DETAILS_UNSPECIFIED
    • latencyMetrics: Includes timestamps foroldestIngestionTime,newestIngestionTime,oldestEventTime, andnewestEventTime.
  • Enhanced platform and visual indicators:

    • Alerts and rule details: A new visual indicator in theDetection Type column provides granular details on hover.
    • Filter facets: TheAlerts lister page now includesdetection timing details as a filterable facet.
    • SOAR integration: In theCase Overview, theComposite Detections table now carries through the same iconography for a consistent investigation experience.
Announcement

Enhanced rule observability: New metadata, visual indicators, and dashboards

Google Security Operations has introduced updates to how detection and alert data is processed and visualized. These changes help Google SecOps teams distinguish between primary rule runs andrule replays, which provides clarity on detection delays and the impact of late-arriving enrichment data.

  • Key improvements

    • Enhanced metadata: Detection and alert objects now include specific metadata that identifies whether they were produced during a primary rule run, or as part of arule replay or retrohunt.
    • Improved troubleshooting: This data lets Google SecOps teams definitively answer critical operational questions, such as the cause of perceived detection delays or the specific impact of late-arriving enrichment data on active rules.
    • Rule replay insights: Learn more about the distinction between primary runs and replays to manage the re-enrichment of Unified Data Model (UDM) events. For detailed definitions and technical workflows, seeUnderstand rule replay andUnderstand rule detection delays.
    • New detection dashboard: To support these backend metadata changes, a newDetection Health dashboard is now available. This interface provides a visual representation of rule performance and replay status, letting teams monitor detection health more effectively.
    • Custom reporting: There are new fields available in theDetections schema, letting you build custom dashboards.
  • New metadata and third-party integration: Detections and alerts now emit specific metadata to help customers track timing and latency. This data is available for integration with third-party systems using the following fields:

    • detectionTimingDetails: An enum identifying the run type:
    • DETECTION_TIMING_DETAILS_REPROCESSING
    • DETECTION_TIMING_DETAILS_RETROHUNT
    • DETECTION_TIMING_DETAILS_UNSPECIFIED
    • latencyMetrics: Includes timestamps foroldestIngestionTime,newestIngestionTime,oldestEventTime, andnewestEventTime.
  • Enhanced platform and visual indicators:

    • Alerts and rule details: A new visual indicator in theDetection Type column provides granular details on hover.
    • Filter facets: TheAlerts lister page now includesdetection timing details as a filterable facet.
    • SOAR integration: In theCase Overview, theComposite Detections table now carries through the same iconography for a consistent investigation experience.
Looker
Feature

The Looker Action Hub has been updated to support newer API versions for Google Ads (from v19 to v22) and Facebook Custom Audiences (from v22 to v24).

Breaking

When you useElite System Activity, all System Activity fields of thelongtext type that have a size greater than 2 MB will be truncated. If a table has only one column with alongtext type, that column will be set to a maximum of 1.9 MB in size. If a table has multiple columns of thelongtext type, the total maximum size across all such columns is 2 MB, and this limit is distributed uniformly among those columns. For example, if a table hasxlongtext columns, each column will have a maximum length of 2 MB divided byx.

Fixed

An issue has been fixed where some drill links could fail to work when cookieless embed was enabled. This feature now performs as expected.

Feature

When you useElite System Activity, themerge_query table now refreshes every 10 minutes.

Feature

When you aredelivering content to an SFTP server, additional key exchange algorithms and host key algorithms are now supported.

Fixed

An issue has been fixed where the pagination option was not being displayed in the LookML Dashboards folder for some users.This feature now performs as expected.

Fixed

An issue has been fixed where custom dimensions that were based on numeric fields could be converted to strings, which caused incorrect sorting. This feature now performs as expected.

Fixed

An issue has been fixed where choosing a non-default color collection and then choosing a custom color in a conditional formatting rule could cause the rule to revert to the default color collection. This feature now performs as expected.

Announcement

Looker 26.2 is expected to include the following changes, features, and fixes:

  • Expected Looker (original) deployment start:Monday, February 9, 2026
  • Expected Looker (original) final deployment and download available:Monday, February 16, 2026
  • Expected Looker (Google Cloud core) deployment start:Monday, February 9, 2026
  • Expected Looker (Google Cloud core) final deployment:Friday, February 27, 2026
Fixed

An issue has been fixed where a modification to the color palette for the "Along a scale..." conditional formatting feature could fail to be saved. This feature now performs as expected.

Feature

Now available in preview, Looker has full support for connections withAlloyDB for PostgreSQL. When youcreate a connection in Looker, you can now select "Google Cloud AlloyDB for PostgreSQL" from the Dialect drop-down menu. This update does not affect existing AlloyDB connections that were created using the PostgreSQL 9.5+ option in the Dialect menu.

Fixed

An issue has been fixed where non-admin users could not favoriteLookML dashboards. This feature now performs as expected.

Feature

The user attribute pairing user interface forSAML,LDAP, andOpenID Connect authentication has been updated. A new "Manage Pairings" side panel provides a robust interface for adding, removing, and viewing attribute pairings. This new interface also includes filtering and pagination and allows for a single claim to be associated with multiple Looker user attributes.

Fixed

An issue has been fixed where Looker could return a 500 error if a user with one or more single quotes in their name attempted to commit LookML. This feature now performs as expected.

Fixed

An issue has been fixed where switching a visualization type from Table to Single Value could carry over unwanted conditional formatting. This feature now performs as expected.

Fixed

An issue has been fixed where conditional formatting no longer appeared on certain dashboard tiles. This feature now performs as expected.

Fixed

An issue has been fixed where changing the collection in a conditional formatting rule could reset styles for the rule. This feature now performs as expected.

Fixed

An issue has been fixed where the filter bar would automatically expand on dashboard load when the filter location was set to "Right". This feature now performs as expected.

Fixed

An issue has been fixed where switching filter types fromMatches (Advanced) to another filter type could populate that filter with an incorrect filter configuration. This feature now performs as expected.

Fixed

An issue has been fixed where adding a new field to a conditionally formatted result set could fail to apply the conditional formatting to the new field. This feature now performs as expected.

Fixed

An issue has been fixed where dashboard tiles with titles that included the % symbol could not be downloaded in the Safari 26.0 browser. This feature now performs as expected.

Feature

Looker admins can nowgrant essential Google Cloud services, such asConversational Analytics, access to a Looker instance, even when an IP allowlist is active.

Feature

Looker admins can now enforce apassword expiration policy, enhancing security for users who authenticate with an email and a password. This new feature lets admins set a password expiration window between 30 and 365 days. Fourteen days before password expiration, a banner will notify the user, and, once their password has expired, the user must reset it at the next login.

Feature

TheCustomer Engineer Advanced Editor default role now includes thegemini_in_looker,chat_with_agent,chat_with_explore, andsave_agents permissions, which grant access to Gemini features and Conversational Analytics functionality.

Resource Manager
Feature

Organization Policy Service custom constraints are available for someNetwork Connectivity resources. For more information, seeManage VPC resources by using custom organization policies.

Spanner
Feature

You can right-click a node in a Spanner Graph queryvisualization to access options like expanding or collapsing adjacent nodes,highlighting or hiding nodes, and viewing only a node's neighbors.

For more information, seeWork with visualizations.

Virtual Private Cloud
Feature

You can bring your own IPv6 global unicast addresses (GUAs)to assign to asubnet's internal IPv6 address range.Although GUAs are typically public addresses, in this configuration they areused privately and function in the same way as Google Cloud-provisioned ULAs.

For more information, seeBring your own IP addresses.

February 08, 2026

Google SecOps SIEM
Announcement

Release 6.3.75 is being rolled out to the first phase of regions as listedhere.

This release contains internal and customer bug fixes.

Google SecOps SOAR
Announcement

Release 6.3.75 is being rolled out to the first phase of regions as listedhere.

This release contains internal and customer bug fixes.

February 07, 2026

Google SecOps SIEM
Announcement

Release 6.3.74 is now available for all regions.

Google SecOps SOAR
Announcement

Release 6.3.74 is now available for all regions.

February 06, 2026

Apigee XApigee hybrid
Announcement

hybrid 1.16.0-hotfix.1

On February 6, 2026 we released Apigee hybrid 1.16.0-hotfix.1.

Important: If your installation is already on Apigee hybrid v1.16.0, use the following procedure to apply this hotfix. For new installations, seeThe big picture and then apply the hotfix to the new installation with the following instructions.

Apply this hotfix with the following steps:

Note: This hotfix installs theapigee-mart-server container images. All other container images are unchanged from Hybrid v1.16.0.
  1. In your overrides file, update theimage.url andimage.tag properties ofao andmart to version1.16.0-hotfix.1:
    ao:  image:    url: "gcr.io/apigee-release/hybrid/apigee-operators"    tag: "1.16.0-hotfix.1"mart:  image:    url: "gcr.io/apigee-release/hybrid/apigee-mart-server"    tag: "1.16.0-hotfix.1"
  2. Install the hotfix release for Apigee operators, beginning with a dry run:
    helm upgrade operator apigee-operator/ \  --install \  --namespaceAPIGEE_NAMESPACE \  --atomic \  -f overrides.yaml \  --dry-run=server
  3. If the dry run is successful, install the hotfix release for Apigee operators:
    helm upgrade operator apigee-operator/ \  --install \  --namespaceAPIGEE_NAMESPACE \  --atomic \  -f overrides.yaml
  4. Install the hotfix release for your organization, beginning with a dry run:
    helm upgrade $ORG_NAME apigee-org/ \  --install \  --namespaceAPIGEE_NAMESPACE \  --atomic \  -f overrides.yaml \  --dry-run=server
  5. If the dry run is successful, install the hotfix release for your organization:
    helm upgrade $ORG_NAME apigee-org/ \  --install \  --namespaceAPIGEE_NAMESPACE \  --atomic \  -f overrides.yaml
  6. Verify the organization chart by checking the state:
    kubectl -nAPIGEE_NAMESPACE get apigeeorg
  7. Install the hotfix release for your environment, beginning with a dry run:
    helm upgradeENV_RELEASE_NAME apigee-env/ \  --install \  --namespaceAPIGEE_NAMESPACE \  --atomic \  --set env=$ENV_NAME \  -f overrides.yaml \  --dry-run=server
  8. If the dry run is successful, install the hotfix release for your environment:
    helm upgradeENV_RELEASE_NAME apigee-env/ \  --install \  --namespaceAPIGEE_NAMESPACE \  --atomic \  --set env=$ENV_NAME \  -f overrides.yaml
  9. Verify the environment chart by checking the state:
    kubectl -nAPIGEE_NAMESPACE get apigeeenv
Capacity PlannerCloud Asset Inventory
Feature

The following resource types are publicly available through theExportAssets,ListAssets,BatchGetAssetsHistory,QueryAssets,Feed,SearchAllResources,andSearchAllIamPoliciesAPIs.

  • Bigtable
    • bigtableadmin.googleapis.com/LogicalView
Cloud Monitoring
Feature

You can use theCloud Monitoring API MCP serverto let agents and AI applications interact with your time series data.This feature is inPreview.

Feature

You can now ingest OTLP metrics into Cloud Monitoring by using anOpenTelemetry Collector, an OTLP exporter, and the Telemetry API. For moreinformation, seeOTLP metric ingestion overview.The Telemetry API for metric ingestion is inPreview.

Cloud Run
Feature

Expanded coverage for compute flexible committed use discounts (CUDs) isavailable to all Cloud Billing accounts. Your Cloud Billing accounts havebeen automatically migrated to thenew spend-based CUD model and you no longer need to opt-into benefit from the expanded coverage. For the full list of eligible SKUsacross Compute Engine, GKE, and Cloud Run,seeSKU Groups - Compute Flexible CUD Eligible SKUs.

To learn more about compute flexible CUDs for Cloud Run and how they apply to your usage, seethecompute flexible CUDs documentation.

Cloud Workstations
Feature

You can providecustom metadata for aworkstation's host VM.

Use the--instance-metadata flag with thegcloud workstations configs createandgcloud workstations configs updatecommands. Format the metadata as a comma-separated list of key-value pairs—forexample,--instance-metadata=key1=value1,key2=value2.

Note that updating metadata replaces all existing custom metadata for theworkstation instance.

Feature

Cloud Workstations supports specifying a custom startup script to be executed onthe workstation's host VM during boot.

Provide the custom startup script as a Google Cloud Storage URL, such asgs://BUCKET/FILE, using the--startup-script-uri flag with thegcloud workstations configs create andgcloud workstations configs updatecommands.

Compute Engine
Change

Expanded coverage for compute flexible committed use discounts (CUDs) isavailable to all Cloud Billing accounts. All Cloud Billing accounts havebeen automatically migrated to thenew spend-based CUD model and you no longer need to optin to benefit from the expanded coverage. For the full list of eligible SKUsacross Compute Engine, GKE, and Cloud Run,seeSKU Groups - Compute Flexible CUD Eligible SKUs.

To learn more about compute flexible CUDs and how they apply to your usage, seethecompute flexible CUDs documentation.

Dataproc
Feature

Dataproc on Compute Engine:Sharing snapshot diagnostic data: Setting the--tarball-access=GOOGLE_DATAPROC_DIAGNOSE flag with thegcloud dataproc clusters diagnose command shares all of the output Cloud Storage bucket contents with Google Cloud support ifuniform bucket-level access is enabled on the output Cloud Storage bucket. If object-level access control is enabled on the output Cloud Storage bucket, only the generated diagnostic tar file is shared.

Announcement
Feature

Serverless for Apache Spark: Added support for removingconscrypt from Serverless for Apache Spark2.3+ runtimes using thedataproc.artifacts.removeproperty .

Developer Connect
Feature

You can nowconnect to Secure Source Manager using Developer Connect.

Gemini Enterprise
Security

Gemini Enterprise: Security update

CVE-ID:CVE-2026-1727

Vulnerability: Mitigation for Potential Cloud Storage Namespace Hijacking("Bucket Squatting")

Description: We have addressed a security vulnerability(CVE-2026-1727) in Gemini Enterprise related to the management ofCloud Storage bucket names. The issue, commonly known as "bucket squatting," can ariseif an attacker pre-emptively registers a bucket name that Gemini Enterpriseservices might be configured to use.

Potential impact: Exploitation of this vulnerability can let an attackerintercept, access, or manipulate data intended for a legitimateGemini Enterprise-related Cloud Storage bucket.

Status: This vulnerability has been remediated in Gemini Enterprise. We haveenhanced our systems to ensure the integrity and proper ownership ofCloud Storage resources used by the platform, which prevents thispotential issue.

Action required: No action is required from users. Thenecessary fixes and safeguards have been automatically deployed toGemini Enterprise.

Feature

Gemini Enterprise: Welcome emails

After a user signs in to Gemini Enterprise for the first time, the user receivesa welcome email with tips on how to get the most out of Gemini Enterprise.Gemini Enterprise admins can turn this feature on or off from the admin settings.

For more information, seeManage web appfeatures.

Feature

Gemini Enterprise: Data connector for Linear (Public preview)

You can connect Linear data stores to Gemini Enterprise. For more information,seeConnect Linear.

Support for Linear data sources is in Public preview.

Looker
Deprecated

The DataRobotaction is now deprecated. This action is no longer available in the Looker Action Hub.

NetApp Volumes
Feature

Google Cloud NetApp Volumes supports the all-squash feature for NFS exports.This option lets you enhance security by mapping all client user IDs to a singleanonymous user ID (UID=65534). For more information, seeUser ID squashing.

Secure Source Manager
Feature

You can nowconnect to Secure Source Manager using Developer Connect.

February 05, 2026

Access Approval
Feature

Google Cloud Managed Lustre is generally available(GA).

Access Transparency
Feature

Google Cloud Managed Lustre is generally available(GA).

AlloyDB for PostgreSQL
Feature

Virtual columns forexpressionsis a feature of the columnar engine inPreview thatsignificantly improves query performance and reduces CPU consumption. It cachesthe results of frequently used expressions, which is especially beneficial foranalytical workloads on large datasets. This feature is supported for PostgreSQLversion 16 and higher.

Cloud Run
Feature

You can configureDirect VPC ingress for Cloud Run worker pools. When you configure Direct VPC ingress,each worker instance receives a private IP address on your configured networkand subnet. To access private IP addresses between instances in your VPC network for secure internal communication, see Retrieve the private IP addresses using the metadata server (MDS)

Cluster Toolkit
Feature

Cluster Toolkit version v1.81.0 is available. This release addssupport for the Dynamic Workload Scheduler (DWS) Flex-start provisioning model on TPU7x and TPU v6e resources. This release also updates Slurm cluster blueprints touse the Cloud Storage FUSE profile feature for AI/ML Cloud Storage bucket mounts.

For more information about this release, see theReleaseannouncement on GitHub.

Compute Engine
Feature

Generally available: You can use Hyperdisk ML with the following machineseries and Cloud TPU versions:

  • C4A machine series
  • A4 machine series
  • A4X machine series
  • G4 machine series
  • TPU v5e
  • TPU v5p
  • TPU7x

For more information, seeAbout Hyperdisk ML.

Dataproc
Fixed

Fixed thespark.driver.extraClassPath delimiter for the Jupyter SparkMonitor Listener.

Feature

Added a newdataproc:pypi.repository property to customize the PyPI repository used for pip. The value can be a URL, orgoogle to use a Google-hosted cache of PyPI, accessible without public internet connectivity. Starting in image version 3.1,google will be the default; to opt out and return to public PyPI, use the valuepypi.

Announcement

NewDataproc on Compute Engine subminor image versions:

  • 2.0.158-debian10, 2.0.158-ubuntu18, 2.0.158-rocky8
  • 2.1.107-debian11, 2.1.107-ubuntu20, 2.1.107-ubuntu20-arm, 2.1.107-rocky8
  • 2.2.75-debian12, 2.2.75-ubuntu22, 2.2.75-ubuntu22-arm, 2.2.75-rocky9
  • 2.3.22-debian12, 2.3.22-ml-ubuntu22, 2.3.22-rocky9, 2.3.22-ubuntu22, 2.3.22-ubuntu22-arm
Feature

Parquet CLI version upgraded to 1.15.2 in 2.1 and 2.2 images.

Fixed

Fixed a bug in the ARM image that prevented connecting to a Dataproc Metastore instance with a gRPC protocol endpoint.

Feature

Apache Pig is now available in ARM images.

Feature

Delta subminor version upgraded to 3.2.1 in Dataproc on Compute Engine image 2.2 and 2.3.

Change

Removed use of deprecated Hadoop configuration propertiesfs.default.name andyarn.resourcemanager.system-metrics-publisher.enabled.

Google Distributed Cloud (software only) for VMware
Announcement

Google Distributed Cloud (software only) for VMware 1.32.800-gke.126 is now availablefor download. To upgrade, seeUpgrade clusters.Google Distributed Cloud 1.32.800-gke.126 runs on Kubernetes v1.32.11-gke.200.

If you are using a third-party storage vendor, check the Google Distributed Cloud-readystorage partners document to make sure the storage vendor has already passed thequalification for this release.

After a release, it takes approximately 7 to 14 days for the version to becomeavailable for use with GKE On-Prem API clients: the Google Cloud console, thegcloud CLI, and Terraform.

Google Distributed Cloud (software only) for bare metal
Announcement

Google Distributed Cloud (software only) for bare metal 1.32.800-gke.126 is nowavailable for download. To upgrade, seeUpgrade clusters.Google Distributed Cloud for bare metal 1.32.800-gke.126 runs on Kubernetesv1.32.11-gke.200.

After a release, it takes approximately 7 to 14 days for the version to becomeavailable for installations or upgrades with the GKE On-Prem API clients: theGoogle Cloud console, the gcloud CLI, and Terraform.

If you use a third-party storage vendor, check the Google Distributed Cloud-readystorage partners document to make sure the storage vendor has already passedthe qualification for this release of Google Distributed Cloud for bare metal.

Google Kubernetes Engine
Feature

Image streaming is now available in theasia-southeast3 region. For more information,see theImage streaming documentation.

Looker Studio
Feature

Looker Studio Pro for Google Workspace

You can purchase a Looker Studio Pro subscription from the Google Workspace Admin console.

Learn more about Looker Studio Pro for Workspace.

Feature

Export chart to image

You can now export a chart to an image by saving it as a PNG file or by copying it to your clipboard.

SeeExport data from a chart for more information.

Feature

Now displaying Conversational Analytics reasoning

After you enter your query, clickShow reasoning to see a plain text explanation of the steps that Conversational Analytics took to interpret your query.

SeeShow reasoning for more information.

Feature

Link to chart in report

You can now link to a specific component, like a chart or control, in your report.

SeeLink to a component for more information.

SAP on Google Cloud
Announcement

Google Cloud's Agent for SAP version 3.11

Version 3.11 of Google Cloud's Agent for SAP is generally available (GA). Thisversion introduces enhancements for optimizing performance of SAP HANA runningon X4 instances, disk snapshot based backup and recovery for SAP HANA, andVM Extension Manager support to install and manage the agent on yourVM fleet.

For more information, seeWhat's new with Google Cloud's Agent for SAP.

February 04, 2026

BigQuery
Change

Data transfers from theYouTube ChannelandYouTube Content Ownerdata sources now support reach reports. For more information, seeYouTube Channel report transformationandYouTube Content Owner report transformation.

Feature

You can now associatedata policies directly oncolumns. Thisfeature enables direct database administration for controlling access andapplying masking and transformation rules at the column level. This feature isnowgenerallyavailable (GA).

Dataproc
Announcement

Upcoming Spark data lineage changes See the upcoming May,2026 Dataproc and Serverless for Apache Spark release notes for an announcementof a change that will automatically enableDataproc Spark data lineage andServerless for Apache Spark data lineagewhen you enable the Data Lineage API (seeControl lineage ingestion for a service)without requiring additional project, cluster, batch workload, orinteractive session settings.

Gemini Enterprise
Feature

Gemini Enterprise and NotebookLM Enterprise: Usage audit logs available in Cloud Logging

Gemini Enterprise admins can access user query and response audit logs inCloud Logging for both Gemini Enterprise and NotebookLM Enterprise.

For more information, see:

Generative AI on Vertex AI
Feature

Anthropic's Claude Opus 4.6

Claude Opus 4.6is available in Model Garden.

Google Distributed Cloud (software only) for VMware
Announcement

Google Distributed Cloud (software only) for VMware 1.33.400-gke.113 is now availablefor download. To upgrade, seeUpgrade clusters.Google Distributed Cloud 1.33.400-gke.113 runs on Kubernetes v1.33.5-gke.1900.

If you are using a third-party storage vendor, check the Google Distributed Cloud-readystorage partners document to make sure the storage vendor has already passed thequalification for this release.

After a release, it takes approximately 7 to 14 days for the version to becomeavailable for use with GKE On-Prem API clients: the Google Cloud console, thegcloud CLI, and Terraform.

Google Distributed Cloud (software only) for bare metal
Announcement

Google Distributed Cloud (software only) for bare metal 1.33.400-gke.113 is nowavailable for download. To upgrade, seeUpgrade clusters. Google Distributed Cloud forbare metal 1.33.400-gke.113 runs on Kubernetes v1.33.5-gke.1900.

After a release, it takes approximately 7 to 14 days for the version to becomeavailable for installations or upgrades with the GKE On-Prem API clients: theGoogle Cloud console, the gcloud CLI, and Terraform.

If you use a third-party storage vendor, check the Google Distributed Cloud-readystorage partners document to make sure the storage vendor has already passedthe qualification for this release of Google Distributed Cloud for bare metal.

Google Kubernetes Engine
Change

(2026-R5) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and formanual control plane upgrades and node upgrades for existing clusters. For moreinformation about versioning and upgrades, seeGKE versioning andsupport andAbout GKEcluster upgrades.

Rapid channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Regular channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
  • Version1.34.3-gke.1051003 is now the default version for cluster creation in the Regular channel.
  • Version1.33.5-gke.2228001 is now available in the Regular channel.
  • The following versions are no longer available in the Regular channel:
    • 1.32.9-gke.1734000
    • 1.33.5-gke.2118001
    • 1.34.1-gke.3971002
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Stable channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
  • Version1.33.5-gke.2100001 is now the default version for cluster creation in the Stable channel.
  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.32.9-gke.1711000
    • 1.33.5-gke.2072001
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Extended channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

No channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Security

(2026-R5) Security updates

This release includes new GKE versions that use updatedContainer-Optimized OS images. These updated images are cumulative,incorporating security fixes from all Container-Optimized OSversions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updatedContainer-Optimized OS image, see theSecurity release notesfor that image. The following table includes links to the release notes foreach updated Container-Optimized OS image:

GKE versionContainer-Optimized OS versionDetails
1.30.14-gke.1991000cos-113-18244-521-88cos-113-18244-521-88 release notes
1.31.14-gke.1336000cos-117-18613-439-108cos-117-18613-439-108 release notes
1.33.5-gke.2392000cos-121-18867-294-100cos-121-18867-294-100 release notes
1.34.3-gke.1318000cos-125-19216-104-126cos-125-19216-104-126 release notes
1.35.0-gke.2398000cos-125-19216-104-126cos-125-19216-104-126 release notes

Change

(2026-R5) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R5) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R5) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R5) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
  • Version1.34.3-gke.1051003 is now the default version for cluster creation in the Regular channel.
  • Version1.33.5-gke.2228001 is now available in the Regular channel.
  • The following versions are no longer available in the Regular channel:
    • 1.32.9-gke.1734000
    • 1.33.5-gke.2118001
    • 1.34.1-gke.3971002
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
Change

(2026-R5) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
  • Version1.33.5-gke.2100001 is now the default version for cluster creation in the Stable channel.
  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.32.9-gke.1711000
    • 1.33.5-gke.2072001
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
Google SecOps
Announcement

New parser documentation now available

New parser documentation is available to help you ingest and normalize logs from the following sources:

Feature

The re.capture_all function is now available

The newre.capture_all YARA-L 2.0 function is available in Rules, Search, and Dashboards.

Use there.capture_all() function to extract every non-overlapping match of a regular expression from a string. While the standardre.capture function stops after the first match it finds, there.capture_all() function continues through the entire string to identify every instance that matches your pattern.

Google SecOps Marketplace
Change

Siemplify ThreatFuse: Version 16.0

  • Updated the configuration (Connector.def) of the following connector::

    • Siemplify ThreatFuse - Observables Connector
Change

Siemplify: Version 102.0

  • Refactored the following actions:

    • Get Case Details

    • Wait For Custom Fields

    • Set Custom Fields

    • Get Similar Cases

    • Get Custom Field Values

    • Export Case

  • Updated error handling in the following action:

    • Assign Case
Change

Google Chronicle: Version 75.0

  • Optimized performance for large data tables in the following actions:

    • Is Value In Data Table

    • Remove Rows From Data Table

Change

Azure Security Center: Version 13.0

  • Updated the configuration (Connector.def) of the following connector:

    • Azure Security Center - Security Alerts Connector
Google SecOps SIEM
Announcement

New parser documentation now available

New parser documentation is available to help you ingest and normalize logs from the following sources:

Feature

The re.capture_all function is now available

The newre.capture_all YARA-L 2.0 function is available in Rules, Search, and Dashboards.

Use there.capture_all() function to extract every non-overlapping match of a regular expression from a string. While the standardre.capture function stops after the first match it finds, there.capture_all() function continues through the entire string to identify every instance that matches your pattern.

Announcement

New parser documentation now available

New parser documentation is available to help you ingest and normalize logs from the following sources:

Feature

The re.capture_all function is now available

The newre.capture_all YARA-L 2.0 function is available in Rules, Search, and Dashboards.

Use there.capture_all() function to extract every non-overlapping match of a regular expression from a string. While the standardre.capture function stops after the first match it finds, there.capture_all() function continues through the entire string to identify every instance that matches your pattern.

Oracle Database@Google Cloud
Feature

For Exadata Database Service, Oracle Database@Google Cloud supports theasia-northeast2 (Osaka, Japan) region.

For a list of supported locations, seeSupported regions and zones.

Virtual Private Cloud
Feature

You can create individual static external IPv4 addresses frombring your own IP addresses (BYOIP) prefixes. This feature isavailable inGeneral Availability and only applies to IPv4regional v2 prefixes that are created afterDecember 13, 2025.

For more information, seeEnhanced IP address allocation.

February 03, 2026

Anti Money Laundering AI
Announcement

Copy an AML AI model to a separate AML AI instance. SeeCopy models to new instances to find out more about how this works.

Apigee Advanced API Security
Feature

Support for configuring two condition types within a single security action

Announcing the availability of support for two condition typesin a single security action. For example, you can include both IP addresses andASN numbers in the same security action.

This feature is available in Apigee and Apigee hybrid 1.16.0 and later.

Note: This feature is available when configuring the security actionvia the API, not the UI, at this time.

For usage information, seeConfigure multiple condition types in the documentation.

Announcement

On February 3, 2026 we released an updated version of Advanced API Securitysecurity actions

BigQuery
Announcement

Gemini in BigQuery now processes data in the same jurisdiction (US orEU) asyour BigQuery datasets, or based upon user-specified location settings. For moreinformation, seeWhere Gemini BigQuery processes yourdata.

Container Optimized OS
Change

cos-dev-129-19506-0-0

KernelDockerContainerdGPU Drivers
COS-6.12.67v27.5.1v2.2.0See List
Fixed

Upgraded chromeos-base/power_manager-client to v0.0.1-r2972.

Fixed

Upgraded net-libs/gnutls to v3.8.11.

Fixed

Upgraded sys-apps/dmidecode to v3.7.

Fixed

Upgraded chromeos-base/session_manager-client to v0.0.1-r2833.

Security

Fixed KCTF-50da4b9 in the Linux kernel.

Feature

Removed the futility program from the root file system.

Security

Fixed CVE-2025-61729 in dev-lang/go.

Fixed

Upgraded app-crypt/mit-krb5 from version 1.20.1 to version 1.22.1.

Change

Runtime sysctl changes:

  • Changed: net.ipv4.udp_mem: 188034 250715 376068 -> 188034 250714 376068

Security

Fixed CVE-2025-61727 in dev-lang/go.

Change

Upgrade dev-libs/json-c from 0.16-r1 to 0.18.0.

Fixed

Added binary auth-provider-gcp.

Change

Updated app-containers/runc to v1.4.0.

Fixed

Upgraded app-admin/fluent-bit to v4.2.2.

Fixed

Upgraded sys-apps/nvme-cli from version 1.6-r1 to version 2.16, added package sys-libs/libnvme.

Fixed

Updated cos-gpu-installer to v2.5.10.

Fixed

Upgraded sys-apps/less to v691.

Fixed

Upgraded app-admin/google-guest-configs to v20260112.00.

Fixed

Upgraded app-containers/docker-credential-gcr to v2.1.31

Fixed

Upgraded chromeos-base/google-breakpad to v2026.01.12.054131-r266.

Fixed

Upgraded app-containers/cni-plugins to v1.9.0.

Fixed

Upgraded app-shells/bash to v5.3.

Security

Fixed CVE-2025-13837 in dev-lang/python.

Fixed

Upgraded dev-db/sqlite to v3.51.1.

Security

Fixed CVE-2025-66471 and CVE-2025-66418 in dev-python/urllib3.

Feature

Added support for CASFS (Content Addressable Storage File System) as a kernel module.

Fixed

Upgraded chromeos-base/chromeos-common-script to v0.0.1-r671.

Fixed

Upgraded google-guest-configs to v20260121.00.

Fixed

Upgraded app-containers/docker-credential-helpers to v0.9.5.

Fixed

Updated kubelet and kubectl to v1.35.0.

Change

Made it so that /mnt/disks is mounted as noexec.

Fixed

Upgraded sys-apps/pv to v1.10.3.

Change

Updated dev-libs/openssl to v3.5.4.

Fixed

Upgraded chromeos-base/debugd-client to v0.0.1-r2737.

Fixed

Upgraded app-admin/sosreport to v4.10.2.

Security

Fixed CVE-2025-12084 in dev-lang/python.

Fixed

Updated sys-libs/readline to v8.3.

Change

Upgrade dev-libs/libuv from 1.43.0 to 1.51.0-r1.

Security

Fixed KCTF-2397e92 in the Linux kernel.

Change

Updated the Linux kernel to v6.12.67.

Fixed

Upgraded app-admin/oslogin to v20260116.00.

Fixed

Upgraded chromeos-base/google-breakpad to v2026.01.16.201758-r268.

Change

Updated CONFIG_BLK_DEV_LOOP_MIN_COUNT to 0. This allowsunlimited loop devices.

Fixed

Upgraded sys-apps/kmod to v34.2.

Fixed

Upgraded net-misc/socat to v1.8.1.0.

Change

Updated app-containers/containerd to v2.2.0.

Security

Fixed CVE-2026-21441 in dev-python/urllib3.

Fixed

Upgraded net-dns/c-ares to v1.34.6.

Fixed

Upgraded sys-libs/libseccomp to v2.6.0-r3.

Fixed

Upgraded app-benchmarks/microbenchmarks to v0.0.1-r21.

Security

Fixed CVE-2025-13836 in dev-lang/python.

Fixed

Upgraded chromeos-base/google-breakpad to v2025.12.22.204548-r263.

Change

Upgrade dev-util/cmake from 3.26.4 to 3.31.9.

Change

cos-125-19216-104-133

KernelDockerContainerdGPU Drivers
COS-6.12.55v27.5.1v2.1.5See List
Security

Fixed CVE-2025-71148 in the Linux kernel.

Security

Fixed CVE-2025-71151 in the Linux kernel.

Security

Fixed CVE-2026-22994 in the Linux kernel.

Security

Fixed CVE-2026-22979 in the Linux kernel.

Security

Fixed CVE-2026-22998 in the Linux kernel.

Security

Fixed CVE-2026-22980 in the Linux kernel.

Security

Fixed CVE-2026-23011 in the Linux kernel.

Security

Fixed CVE-2025-38591 in the Linux kernel.

Security

Fixed CVE-2026-23005 in the Linux kernel.

Security

Fixed CVE-2026-22976 in the Linux kernel.

Security

Fixed CVE-2026-23010 in the Linux kernel.

Security

Fixed KCTF-50da4b9 in the Linux kernel.

Security

Fixed CVE-2025-71160 in the Linux kernel.

Security

Fixed CVE-2025-71157 in the Linux kernel.

Security

Fixed CVE-2026-22996 in the Linux kernel.

Security

Fixed KCTF-2397e92 in the Linux kernel.

Security

Fixed CVE-2026-23003 in the Linux kernel.

Security

Fixed CVE-2026-22989 in the Linux kernel.

Security

Fixed CVE-2025-40149 in the Linux kernel.

Security

Fixed CVE-2026-22988 in the Linux kernel.

Security

Fixed CVE-2026-23002 in the Linux kernel.

Security

Fixed CVE-2025-71149 in the Linux kernel.

Security

Fixed CVE-2026-22977 in the Linux kernel.

Security

Fixed CVE-2026-22999 in the Linux kernel.

Security

Fixed CVE-2026-23001 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: kernel.tainted: 4096 -> 4608

Security

Fixed CVE-2025-71156 in the Linux kernel.

Security

Fixed CVE-2026-0915 in sys-apps/glibc.

Security

Fixed CVE-2026-23000 in the Linux kernel.

Change

cos-121-18867-294-112

KernelDockerContainerdGPU Drivers
COS-6.6.113v27.5.1v2.0.7See List
Security

Fixed CVE-2025-71148 in the Linux kernel.

Security

Fixed KCTF-2397e92 in the Linux kernel.

Security

Fixed CVE-2025-71151 in the Linux kernel.

Feature

Enabled TC Traffic Police as a module.

Security

Fixed CVE-2026-22994 in the Linux kernel.

Security

Fixed CVE-2026-22988 in the Linux kernel.

Security

Fixed CVE-2025-71160 in the Linux kernel.

Security

Fixed CVE-2026-22976 in the Linux kernel.

Security

Fixed CVE-2026-22979 in the Linux kernel.

Security

Fixed CVE-2026-22980 in the Linux kernel.

Security

Fixed CVE-2025-71149 in the Linux kernel.

Security

Fixed CVE-2026-22977 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: kernel.tainted: 4096 -> 4608

Security

Fixed KCTF-50da4b9 in the Linux kernel.

Security

Fixed CVE-2025-22111 in the Linux kernel.

Security

Fixed CVE-2026-0915 in sys-apps/glibc.

Change

cos-117-18613-439-120

KernelDockerContainerdGPU Drivers
COS-6.6.111v24.0.9v1.7.29See List
Security

Fixed CVE-2025-71151 in the Linux kernel.

Security

Fixed CVE-2026-22977 in the Linux kernel.

Security

Fixed CVE-2026-22979 in the Linux kernel.

Security

Fixed CVE-2026-22980 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: kernel.tainted: 4096 -> 4608

Security

Fixed KCTF-50da4b9 in the Linux kernel.

Security

Fixed KCTF-2397e92 in the Linux kernel.

Security

Fixed CVE-2026-0915 in sys-apps/glibc.

Security

Fixed CVE-2026-22994 in the Linux kernel.

Security

Fixed CVE-2025-71148 in the Linux kernel.

Security

Fixed CVE-2026-22988 in the Linux kernel.

Security

Fixed CVE-2026-22976 in the Linux kernel.

Security

Fixed CVE-2025-71149 in the Linux kernel.

Security

Fixed CVE-2025-71160 in the Linux kernel.

Change

cos-113-18244-521-98

KernelDockerContainerdGPU Drivers
COS-6.1.155v24.0.9v1.7.27See List
Security

Fixed CVE-2026-0915 in sys-apps/glibc.

Security

Fixed CVE-2026-22988 in the Linux kernel.

Fixed

Upgraded sys-apps/less to v691.

Security

Fixed KCTF-50da4b9 in the Linux kernel.

Security

Fixed KCTF-2397e92 in the Linux kernel.

Security

Fixed CVE-2026-22977 in the Linux kernel.

Security

Fixed CVE-2026-22979 in the Linux kernel.

Security

Fixed CVE-2024-49968 in the Linux kernel.

Security

Fixed CVE-2026-22994 in the Linux kernel.

Security

Fixed CVE-2026-22980 in the Linux kernel.

Security

Fixed CVE-2025-71149 in the Linux kernel.

Security

Fixed CVE-2026-22976 in the Linux kernel.

Google Cloud Contact Center as a Service
Fixed

The following issues were addressed in this release:

  • Fixed an issue on the Agent Performance dashboard where theDisconnectStatus field for chats incorrectly displayedUnknown or was empty.

  • Fixed an issue on the All Interactions - Calls dashboard where theSLA%andSLA% by 30 Minute Interval tiles displayed the wrong calculations.

  • Fixed an issue where theVoice Inbound (Direct) andVoice Outbound(Direct) values were missing from theInteraction Type filter on thefollowing dashboards:

    • Real-time Calls - Calls Queued

    • Real-time Queue Monitoring - Calls

  • Fixed an issue where theCall Type field on theAgent ProductivityDetailed - Calls table of the Agent Performance dashboard displayedUnknown instead ofVoice Inbound (Direct) orVoice Outbound (Direct).

  • Fixed the experience for filtering on the consumer phone number for thefollowing dashboards:

    • All Interactions - Calls

    • Real-time Calls - Calls Connected

    • Abandons - Calls

  • Fixed an issue on the All Interactions - Calls dashboard where widgetsweren't loading.

  • Fixed an issue on the Email dashboard where agent information was missingfor email sessions that were started by the end-user.

  • Fixed an issue where theConsumer Phone Number field was missing fromthe following dashboards:

    • Agent Activity

    • Failed Sessions - Calls

    • Missed Interactions - Calls

    • Abandons - Calls

    • CSAT - Calls

    We also renamed theCustomer ANI field toConsumer Phone Number.

Feature

Email dashboard

The Email dashboard now includes the following table:

  • Queue Transfers Detail: email transfer information at the instance,queue, and session levels

For more information, seeEmail.

Announcement

Advanced reporting dashboards 3.43

We've released version 3.43 of the advanced reporting dashboards.

Feature

Performance overview dashboard

The performance overview dashboard now includes the following tiles:

  • Avg Queue Time: the average time a session (call or chat) spent in aqueue until an agent accepted it or the end-user abandoned it

  • Avg Queue Abandon Time: the average time that sessions (calls or chats)waited in a queue before being disconnected without an agent accepting them

  • Sentiment Score: the average sentiment score for sessions (calls orchats)

For more information, seePerformance overviewdashboard.

Google Distributed Cloud connected
Libraries

The following Google Distributed Cloud connected components have been updated:

  • GDC software-only has been updated to version v1.33.300-gke.60.(This component was formerly known as GKE on Bare Metal and as Anthos Clusters on Bare Metal.)

  • Kubernetes has been updated to version 1.33.5-gke.900.

  • EdgeOS kernel has been updated to version6.12.31.

  • Symcloud Storage has been updated to version 5.4.18-278.

Deprecated

The following functionality has been deprecated in this release of Google Distributed Cloud connected:

  • GDC connected racks form factor. The Google Distributed Cloud connected racks form factor, also knownas Config 1 and Config 2, has been deprecated and all documentation for Google Distributed Cloud connectedfeatures related to this form factor has been removed from product documentation. The last minor releaseof Google Distributed Cloud connected that supports the racks form factor isGoogle Distributed Cloud connected 1.11.
Announcement

This is a minor release of Google Distributed Cloud connected (version 1.12.0). Google Distributed Cloud software updatesroll out gradually across regions. The latest version might not be immediately available on your Google Distributed Cloudconnected deployment.

Fixed

The following issues have been resolved in this release of Google Distributed Cloud connected:

  • Virtual machines no longer intermittently freeze. Through a combination of updates to Symcloud Storage andnew firmware for the integrated Dell Remote Access Controller (iDRAC),we have improved the resilience of virtual machine workloads against unstable mains power and resolved freezescaused by storage snapshotting. For more information, contactGoogle Support.

  • Auto-renewal of TLS certificates for Symcloud Storage no longer fails. Symcloud Storage host services no longerreport aCritical state if a Google Distributed Cloud connected node was restarted after the Symcloud Storage TLScertificate has expired. These certificates now renew automatically when the Google Distributed Cloud connected softwareon the cluster is upgraded.

  • Symcloud Storage volumes no longer intermittently enterDegraded state due to disk initialization failures.Disk initialization jobs now automatically retry until they succeed if transient control plane instability causes them to fail.

  • Single-node cluster upgrades no longer fail due to race conditions. A number of bugs inrunc have been resolved, eliminatingrace conditions that caused single-node cluster upgrade failures.

Security

Security mitigations for the following vulnerabilities have been implemented in this release of Google Distributed Cloud connected:

  • OS layer security mitigations: All CVEs that have been resolved up to the LTS kernel version 6.12.31 (inclusive).

  • GDC software-only security mitigations: All mitigations listed in theGDC software-only release notes up to version1.33.300-gke.60 (inclusive).

Feature

The following new functionality has been introduced in this release of Google Distributed Cloud connected:

  • Refreshed GDC connected servers G2 hardware. We are now shipping refreshed Google Distributed Cloud connectedservers G2 hardware based on the Dell XR8000 series platform. For more information, seePlan the hardware configuration.

  • Virtual machine image download with Workload Identity. You can now access Cloud Storage buckets that holdyour virtual machine images using a Kubernetes service account impersonating a Google service account. For moreinformation, seeCreate a Cloud Storage bucket for virtual machine images.

Issue

This release of Google Distributed Cloud connected contains the following known issues:

  • Symcloud Storage pods can enter aCrashLoopBackOff state due to bootstrapping failures.. The Symcloud Storageworker pods can intermittently restart multiple times while bootstrapping, preventing theconfig.ini file from beinggenerated, which causes the pods to fail repeatedly. To remedy this issue, contactGoogle Support.

  • Symcloud Storage jobs can stall due to thread lock contention. A race condition caused by lock contention betweenmultiple threads can prevent Symcloud Storage jobs, such as volume attachment, detachment, creation, or deletion to stall.To remedy this issue, contactGoogle Support.

  • Symcloud Storage activation can stall due to scheduling conflicts following transient pre-install job failures.The pre-installation job does not tolerate transient failures, such ascontainerd issues. If a job pod fails but isn'tautomatically deleted, existing pod affinity constraints prevent a replacement pod from being scheduled. This leaves thejob incomplete and stalls the Symcloud Storage activation process. To remedy this issue, contactGoogle Support.

  • RobinCluster status updates can be delayed after reconciliation. TheRobinCluster status may not immediatelyreflect a Ready state even after reconciliation has completed. This delay occurs because the Symcloud Storage Operator'sback-off timer can increase to over 10 minutes during reconciliation, causing a lag in reporting the final status.

  • Network Operator metrics missing in Cloud Monitoring. Metrics for Network Function operators are not reported inCloud Monitoring if the Google Cloud project hosting the cluster exceeds its Cloud Monitoring API ingestion quota limits.To remedy this issue, review your Cloud Monitoring API quota usage. If you consistently reach the limits, request a quotaincrease through the Google Cloud Console.

Libraries

The following Google Distributed Cloud connected components have been updated:

  • Symcloud Storage has been updated to version 5.4.16-166.
Fixed

The following issues have been resolved in this release of Google Distributed Cloud connected:

  • Single-node cluster upgrades no longer fail due to race conditions. A number of bugs inrunc have been resolved, eliminatingrace conditions that caused single-node cluster upgrade failures.

  • Virtual machines no longer intermittently freeze. Through a combination of updates to Symcloud Storage andnew firmware for the integrated Dell Remote Access Controller (iDRAC),we have improved the resilience of virtual machine workloads against unstable mains power and resolved freezescaused by storage snapshotting. For more information, contactGoogle Support.

  • Improved reliability of virtual machine workloads. This release addresses Symcloud Storage issues contributing tofreezing and slow recovery of VM workloads:iomgrbmap cache assertion,bmap repopulation performance, andbmapgarbage collection performance.

  • Virtual machine workloads no longer throw aSyncFailed error when reading large amounts of remote data. A racecondition was resolved that caused virtual machine workloads to stop responding to their clients if the network connectionfailed when reading large amounts of data remotely. The race condition caused the virtual machine to become unhealthy andreport the following event:SyncFailed virt-handler unknown error encountered sending command SyncVMI: rpc error: code = DeadlineExceeded desc = context deadline exceeded.

  • Patroni cluster now synchronizes properly when restarted after an ungraceful shutdown. If the Patroni cluster was not gracefullyshut down, it could fail to synchronize correctly upon restart, leading to an outage of the Robin Service.

  • Symcloud Storage pods now start up properly even if some pods are not ready when a node is cordoned or terminated. The PatroniStatefulSet used theOrdered pod management policy, which prevented remaining pods from starting up if the previous pod wasn't ready.The updated policy now allows each pod to recover regardless of the state of the other pods.

Issue

This release of Google Distributed Cloud connected contains the following known issues:

  • Robin Service fails after restarting a worker node due to expired TLS certificates. Symcloud Storage TLS certificatesdo not auto-renew. If a worker pod is restarted while the corresponding certificate is expired, all Robin host services reportaCritical state. To remedy this issue, contactGoogle Support.

  • Symcloud Storage jobs can stall due to thread lock contention. A race condition caused by lock contention between multiplethreads can cause Symcloud Storage jobs, such as volume creation, deletion, attachment, or detachment, to stall. To remedy thisissue, contactGoogle Support.

  • Symcloud Storage pods can enter aCrashLoopBackOff state due to bootstrapping failures. The Symcloud Storage worker podscan intermittently restart multiple times while bootstrapping, preventing theconfig.ini file from being generated, which causesthe pods to fail repeatedly. To remedy this issue, contactGoogle Support.

  • Symcloud Storage cluster in Degraded state after installation. Transient control plane instability can cause the diskinitialization job to fail and there is no automatic retry upon job failure. This results in the installation ending withthe Symcloud Storage cluster inDegraded state. To remedy this issue, contactGoogle Support.

  • Symcloud Storage activation can stall due to scheduling conflicts following transient pre-install job failures. The pre-installationjob does not tolerate transient failures, such as containerd issues. If a job pod fails but isn't automatically deleted, existing pod affinity constraints prevent a replacement pod from being scheduled. This leaves the job incomplete and stalls the Symcloud Storage activation process.To remedy this issue, contactGoogle Support.

  • RobinCluster status updates can be delayed after reconciliation. TheRobinCluster status may not immediately reflectaReady state even after reconciliation has completed. This delay occurs because the Symcloud Storage Operator's back-offtimer can increase to over 10 minutes during reconciliation, causing a lag in reporting the final status.

Announcement

This is a patch release of Google Distributed Cloud connected (version 1.11.1). Google Distributed Cloud software updatesroll out gradually across regions. The latest version might not be immediately available on your Google Distributed Cloudconnected deployment.

Google Kubernetes Engine
Feature

Image streaming and secondary boot disks are now generally available (GA) fornodes using the Ubuntu with containerd (UBUNTU_CONTAINERD) image type. Thesefeatures improve workload startup performance on GKE Standard and Autopilot clustersthrough image data streaming and preloaded disk data. To use these features onUbuntu nodes, your cluster must be running GKE version 1.35.0-gke.1403000 or later.

For more information, see the documentation forImage StreamingandUsing Secondary Boot Disks.

Google SecOps
Feature

Share custom column sets

Google SecOps now lets you share custom sets of columns in theEvents table forconsistent analysis across teams.

For more details, seeSearch for events and alerts

Deprecated

Mute an IoC deprecated

The Mute an IoC feature is deprecated, and theIOC details page no longer displays theMute indicator.

Announcement

Data RBAC global scope changes for ATI

To enhance data security, several features related to Indicators of Compromise(IOCs) and Emerging Threats now require global scope data RBAC permissions.Users without global scope will see restricted information in the following areas:

  • Emerging threats page: IOC match counts per campaign are no longer visible.

  • Entity widget overlay: TheIndicators table is hidden or appears empty.

  • Threat details page: The related entities, IOC matches, and GTI IOC tables are no longer visible.

  • Entity summary widget: GTI scores are excluded from the overlay.

  • IOC details page: TheIndicator Details tab doesn't populate.

API impact: API calls toIocService andThreatCollectionService nowrequire global scope. Direct calls made with the CLI or client libraries failwithout this permission.

Required: Google SecOps administrators should review user roles andgrant global scope to those who require continued access to these threatintelligence features.

Note: This change follows a phased rollout throughout the week ofFebruary 02, 2026 to February 08, 2026.
Google SecOps SIEM
Feature

Share custom column sets

Google SecOps now lets you share custom sets of columns in theEvents table forconsistent analysis across teams.

For more details, seeSearch for events and alerts

Deprecated

Mute an IoC deprecated

The Mute an IoC feature is deprecated, and theIOC details page no longer displays theMute indicator.

Announcement

Data RBAC global scope changes for ATI

To enhance data security, several features related to Indicators of Compromise(IOCs) and Emerging Threats now require global scope data RBAC permissions.Users without global scope will see restricted information in the following areas:

  • Emerging threats page: IOC match counts per campaign are no longer visible.

  • Entity widget overlay: TheIndicators table is hidden or appears empty.

  • Threat details page: The related entities, IOC matches, and GTI IOC tables are no longer visible.

  • Entity summary widget: GTI scores are excluded from the overlay.

  • IOC details page: TheIndicator Details tab doesn't populate.

API impact: API calls toIocService andThreatCollectionService nowrequire global scope. Direct calls made with the CLI or client libraries failwithout this permission.

Required: Google SecOps administrators should review user roles andgrant global scope to those who require continued access to these threatintelligence features.

Note: This change follows a phased rollout throughout the week ofFebruary 02, 2026 to February 08, 2026.
Announcement

Data RBAC global scope changes for ATI

To enhance data security, several features related to Indicators of Compromise(IOCs) and Emerging Threats now require global scope data RBAC permissions.Users without global scope will see restricted information in the following areas:

  • Emerging threats page: IOC match counts per campaign are no longer visible.

  • Entity widget overlay: TheIndicators table is hidden or appears empty.

  • Threat details page: The related entities, IOC matches, and GTI IOC tables are no longer visible.

  • Entity summary widget: GTI scores are excluded from the overlay.

  • IOC details page: TheIndicator Details tab doesn't populate.

API impact: API calls toIocService andThreatCollectionService nowrequire global scope. Direct calls made with the CLI or client libraries failwithout this permission.

Required: Google SecOps administrators should review user roles andgrant global scope to those who require continued access to these threatintelligence features.

Note: This change follows a phased rollout throughout the week ofFebruary 02, 2026 to February 08, 2026.
Secure Source Manager

February 02, 2026

API Gateway
Change

Connect API Gateway to Apigee API hub instances that use VPC Service Controls

API Gateway can now beconnected to Apigee API hub instances that useVPC Service Controls.

Apigee XApp Engine flexible environment PHP
Feature

Support for thePHP 8.5 runtime is inPreview.

App Engine standard environment PHP
Feature

Support for thePHP 8.5 runtime isinPreview.

Application Integration
Feature

FIFO message processing with Pub/Sub ordering keys

Application Integration now supports publishing messages to Google Cloud Pub/Sub topics using ordering keys, enabling First-In, First-Out (FIFO) message processing. By setting an ordering key in the Pub/Sub trigger'sPublish Message action, you can ensure messages are received in the correct order, enhancing reliability for integrations requiring ordered message processing. For more information on how to use ordering keys to publish messages, seeUsing ordering keys.

BigQuery
Feature

You can now passparameterized queriesfrom the BigQuery query editor in the Google Cloud console.

This feature isgenerally available(GA).

Cloud Logging
Libraries

Java

3.24.0 (2026-01-26)

Features
Cloud Run
Feature

Support forPHP 8.5 runtime is inPreview.

Feature

Support for NVIDIA RTX PRO 6000 Blackwell GPU is inPreview.For more information, see GPU support forservices,jobs, andworker pools.

Cloud Run functions
Feature

Support forPHP 8.5 runtime is inPreview.

Cloud SQL for MySQL
Feature

You can now update the server certificate authority (CA) mode of an existingCloud SQL instance. You can update existing instances that use the per-instanceCA option (GOOGLE_MANAGED_INTERNAL_CA) to use the shared CA option(GOOGLE_MANAGED_CAS_CA) or the customer-managed CA option (CUSTOMER_MANAGED_CAS_CA).

For more information about the different server CA mode options, seeCertificate authority (CA) hierarchies.

Cloud SQL for PostgreSQL
Feature

You can now update the server certificate authority (CA) mode of an existingCloud SQL instance. You can update existing instances that use the per-instanceCA option (GOOGLE_MANAGED_INTERNAL_CA) to use the shared CA option(GOOGLE_MANAGED_CAS_CA) or the customer-managed CA option (CUSTOMER_MANAGED_CAS_CA).

For more information about the different server CA mode options, seeCertificate authority (CA) hierarchies.

Cloud SQL for SQL Server
Feature

You can now update the server certificate authority (CA) mode of an existingCloud SQL instance. You can update existing instances that use the per-instanceCA option (GOOGLE_MANAGED_INTERNAL_CA) to use the shared CA option(GOOGLE_MANAGED_CAS_CA) or the customer-managed CA option (CUSTOMER_MANAGED_CAS_CA).

For more information about the different server CA mode options, seeCertificate authority (CA) hierarchies.

Cloud Trace
Feature

You can now analyze your trace data by using theLog Analyticspage in the Google Cloud console. This page supports SQL queries and lets you viewyour query results as a table or as a chart. Your SQL queries can also join yourtrace and log data. This feature is in Public Preview.

To learn more about analyzing and viewing trace data,see the following documents:

Feature

Cloud Trace now stores your trace data in an observability dataset. You cancontinue to view your trace data by using theTrace Explorer page.If you create a link on your dataset, then you can use services likeBigQuery to query and analyze your trace data.To learn more, see the following documents:

Dataflow
Feature

Dataflow Managed I/O now supports rolling upgrades for streaming jobs. With thisfeature, Dataflow upgrades your Managed I/O connectors in running pipelines asnew connector versions become available. For more information, seeAutomatic upgrades.

Eventarc
Change

Eventarc Standard is available in theasia-southeast3 (Bangkok, Thailand)region.

Firestore
Feature

The Firestore databases page in the Google Cloud console now includesa status column. Possible statuses include:

  • Ready
  • Cloning is in progress
  • Restoring from backup is in progress
  • Deleted
  • Failed

For the cloning and restore statuses, the status column updates upon completion.

Firestore in Datastore mode
Feature

The Firestore databases page in the Google Cloud console now includesa status column. Possible statuses include:

  • Ready
  • Cloning is in progress
  • Restoring from backup is in progress
  • Deleted
  • Failed

For the cloning and restore statuses, the status column updates upon completion.

Firestore with MongoDB compatibility
Feature

The Firestore databases page in the Google Cloud console now includesa status column. Possible statuses include:

  • Ready
  • Cloning is in progress
  • Restoring from backup is in progress
  • Deleted
  • Failed

For the cloning and restore statuses, the status column updates upon completion.

Gemini Enterprise
Feature

Fine-grained access control for individual Gemini Enterprise apps

Gemini Enterprise admins can control access to individual Gemini Enterprise appsusing app-level IAM policies. IAM permissions are often managed at the projectlevel, but app-level IAM allows for more granular control.

For more information, seeConfigure access controls for apps.

Google Cloud Contact Center as a Service
Fixed

The following issues were addressed in this release:

  • Fixed an issue where calls were incorrectly deflected to voicemail duringscheduled holidays instead of connecting to the virtual agent.

  • Fixed an issue where thequeue_id value passed to post-session virtualagents was incorrect during complex transfer flows, such as human-agent tovirtual-agent to human-agent transfers.

  • Fixed an Agent Assist issue where the autogenerated session summarydidn't include the conversation context from the virtual agent segmentafter a transfer to a human agent.

  • Fixed an issue where the virtual agent incorrectly terminated a chat sessionimmediately after escalating it to a human agent.

  • Fixed an issue causing inaccurate reporting for chats escalated from avirtual agent to a human agent. The system failed to record the initialvirtual agent to human agent escalation in the transfer history and used anincorrect originating queue for subsequent transfers.

  • Fixed an issue where source links were missing from knowledge assist answersin the agent adapter during calls.

  • Fixed an issue affecting Telnyx users where selectingStop Monitoringdidn't fully terminate monitoring sessions.

  • Fixed an issue where call transcript and session summary files saved toexternal storage had incorrect filenames. The variables in the filenames,such as{{date}} and{{session_start_time}}, didn't resolve correctly.

  • Fixed an issue for Salesforce users where cases were not generated duringcalls, even when theAlways use the admin user for all recordcreations/updates checkbox was selected.

  • Fixed an issue where photos received via blended SMS didn't display inthe agent adapter.

  • Fixed an issue that caused errors when creating CRM records for abandonedcalls in multi-language queues.

  • Fixed an issue where CRM skip options (for example, skipping CRM accountcreation or lookup) didn't correctly reset when switching between differentCRM integrations.

  • Fixed an issue for Salesforce users where the dialpad appeared duringclick-to-dial.

  • Fixed an issue where thecallParticipantFinished event didn't emit when anagent performed a cold transfer.

  • Fixed an issue where WhatsApp messages received after business hours weremishandled. The system queued messages to agents instead of sendingafter-hours messages and ending the sessions.

  • Fixed an issue where the status timer in the chat adapter displayedincorrect elapsed times.

  • Fixed an issue where the agent desktop displayed agent statuses that wereinconsistent with the standalone agent adapter.

  • Fixed an issue that caused 503 and 431 errors.

  • Fixed an issue in the chat adapter where theagent_joined_chat eventspecified the wrong chat ID when the agent was handling multiple chats.

  • Fixed an issue where the chat adapter incorrectly labeled SMS message eventsas chat inbound messages when agents sent SMS chat messages.

  • Fixed an issue where newly created instances didn't create a global contactlist, preventing the initial custom contact list from appearing.

  • Fixed an issue where attempting to copy a queue from the IVR channel to theSMS channel returned an error.

  • Fixed an issue where the menu language selected inSettings>Call> Fallback IVR Navigation reverted to English.

  • Fixed an issue where CRM records were created for outbound calls that endedwith aConnection Declined status, despite theCreate CRM records forabandoned calls checkbox being cleared.

  • Fixed an issue where theAgents dashboard filter incorrectly displayedagents in both parent and child queues.

  • Fixed an issue where notification rules based on average wait time didn'ttrigger alerts or send emails.

  • Improved the French Canadian translations for several default agentstatuses. The changes include the following:

    • "Appel entrant" is now "Appel en cours."

    • "Dans la discussion" is now "Clavardage en cours."

    • "Synthèse" is now "Conclusion."

    • "Synthèse prolongée" is now "Temps de conclusion dépassé."

  • Fixed an issue where theAgents dashboard stopped refreshing, causingagent statuses to appear outdated or incorrect.

  • Fixed an issue where the agent directory appeared empty when an agentattempted to start an internal call transfer, preventing the agent fromseeing available teammates.

  • Fixed a web SDK issue where theContent-Encoding response header wasmissing for the widget.

Feature

Edit email subject lines

Agents can now modify email subject lines when replying to or forwardingemail messages. This lets agents add context to the subject line, such as ticketnumbers or case details. The system maintains the session ID and keeps theconversation thread intact.

Administrators: In theSettings> Email> General> Email Management section, there's a newEnable Subject Line Editing checkbox.

For more information, seeLet agents edit the subject lines inemails.

Feature

Improvements to end-user to agent calling

The following improvements are available for end-user to agent calling:

  • You can control whether end-users can input an agent's extension number atthe beginning of a call.

  • You can add a message at the beginning of a call prompting the end-user toenter an extension number.

  • End-users can input an agent's extension number in the extension directory.

Administrators:

  • A newExtension Input Settings section appears in theSettings> Call> Agent Extensions>Consumer to Agent Calls section.

  • New and updated messages appear in theSettings> Languages &Messages> Audible Messages> Extension DirectoryMessages section.

For more information, seeEnd-user to agentcalling.

Announcement

Google Cloud CCaaS 3.44

We've released version 3.44 of Google Cloud CCaaS.

The timing of the update to your instance depends on the deployment schedulethat you have chosen. For more information, seeDeploymentschedules.

Feature

Assigned agent tags

Assigned agent tags let you see at a glance which agent is assigned to eachemail in an email list and which emails are unassigned. An agent assignment tagis a round tag containing an agent's initials, which indicate the agent assignedto an email.

Administrators: In theSettings> Email> General> Email Management section, there's a newEnable Assigned Agent Initials on Email List View checkbox.

For more information, seeAssigned agenttags.

Feature

Apps API: new endpoint for adding a third party to a call

The apps API now includes an endpoint(/calls/add/CALL_ID/dial) to add a third party toan ongoing call. When you make a request to this endpoint, the systemautomatically dials the third-party's phone number, and the agent's call adapterdisplays theCalling screen.

For more information, seeAdd a third party to acall.

Feature

Support for French Canadian in the Google Cloud CCaaS portal

You can now view the Google Cloud CCaaS portal in French Canadian.

Note: System messages and error messages aren't translated and appear in English.
Feature

Improvements to deflection message management

Agents can now upload message files from the call adapter to use for message andvoicemail greetings. These files support after-hours deflection, overcapacitydeflection, and automatic redirection.

A newUpload audio recording option appears in the call adapter in thefollowing locations:

  • Options> Agent Deflections> After hoursdeflection

  • Options> Agent Deflections> Overcapacitydeflection

  • Options> Agent Deflections> Automaticredirections

If you make changes to an agent's after-hours deflection settings, overcapacitydeflection settings, or automatic redirection settings, you can now revert tothe settings that the agent selected in the call adapter. TheRevert to agentsettings button appears in theAgent Call Deflections section on theagent'sEdit User page. To access the agent'sEdit User page, go to theSettings> Users & Teams page.

For more information, seeConfigure deflections at the agentlevelandSet deflections for extensioncalls.

Feature

Send DTMF tones in the agent adapter using the keyboard

An agent can now use their keyboard to type or paste alphanumeric stringsdirectly into the call adapter to play DTMF tones, with the appropriate pauses.This capability eliminates the need to click number buttons on a virtual keypad.This streamlines data entry during IVR, web, and mobile calls and improvesaccessibility.

User experience change: TheDial button on the call adapter has been renamedKeypad.

For more information, seeIn-callinterface.

Feature

Custom data-collection forms for chats are available in the web SDK

Your human agents and virtual agents can now send custom data-collection formsto end-users using the web SDK.

Administrators: TheWeb chat checkbox appears atSettings>Forms> Add template> Custom form.

For more information, seeAdd a customform.

Feature

Disable multicast for call routing

You can now disable multicast to ensure that the system offers calls to only oneagent at a time through deltacast. When you disable multicast, the system usesonly deltacast attempts to find an agent. If no agent accepts the deltacast, thecall isn't multicasted to all available agents. Instead, it follows your logicfor cascade groups or overcapacity deflection. All other deltacast rules, suchas maximum queue time, remain in effect.

Administrators: The newDisable Multicast fallback after all Deltacast attempts checkbox appears in the following places:

  • Settings> Operation Management> Routing> Call Routing

  • Settings> Operation Management> Routing> Chat Routing

  • Settings> Queue> IVR orMobile orWeb> Edit / View>QUEUE_NAME> Routing> Configure> Call Routing

  • Settings> Queue> IVR orMobile orWeb> Edit / View>QUEUE_NAME> Routing> Configure> Chat Routing

For more information, seeTurn on deltacast for callsgloballyandTurn on deltacast for calls at the queuelevel.

Feature

Apps API: new end_user.phone parameter

The apps API accepts an optionalend_user.phone parameter during chatcreation. This parameter enables CRM lookup using the end-user's phone number,which lets the chat adapter display the end-user's name.

For more information, seeCreatechat.

Feature

New @{END_USER_NUMBER} variable

You can use the new@{END_USER_NUMBER} variable to read out the end-user'sphone number in a message to leave a voicemail or request a callback. Readingout the end-user's phone number helps them confirm whether they want to use itor a different number. To use this capability, add the@{END_USER_NUMBER}variable to theCallback - Request Phone Number andVoicemail - RequestPhone Number text-to-speech message fields. You can configure this at theglobal or queue level.

For more information, seeRead out a phone number in a voicemail or callbackmessage.

Google SecOps
Change

Google SecOps has updated the list of supported default parsers. Updatespropagate gradually; changes typically appear in your region within one to fourbusiness days. For more information, seeSupported log types and default parsers.

The following supported default parsers have been updated. Each parser is listedby product name andlog_type value, where applicable. This list includes bothreleased default parsers and pending parser updates.

  • A10 Load Balancer (A10_LOAD_BALANCER)
  • AIX system (AIX_SYSTEM)
  • Akamai Cloud Monitor (AKAMAI_CLOUD_MONITOR)
  • AlgoSec Security Management (ALGOSEC)
  • Amazon API Gateway (AWS_API_GATEWAY)
  • Apache (APACHE)
  • Apple macOS (MACOS)
  • AppOmni (APPOMNI)
  • Arcsight CEF (ARCSIGHT_CEF)
  • Arista Switch (ARISTA_SWITCH)
  • Aruba (ARUBA_WIRELESS)
  • Aruba Airwave (ARUBA_AIRWAVE)
  • Aruba EdgeConnect SD-WAN (ARUBA_EDGECONNECT_SDWAN)
  • Aruba Switch (ARUBA_SWITCH)
  • Attivo Networks (ATTIVO)
  • Auth0 (AUTH_ZERO)
  • Automation Anywhere (AUTOMATION_ANYWHERE)
  • Avanan Email Security (AVANAN_EMAIL)
  • AWS Aurora (AWS_AURORA)
  • AWS Cloudtrail (AWS_CLOUDTRAIL)
  • AWS CloudWatch (AWS_CLOUDWATCH)
  • AWS Elastic Load Balancer (AWS_ELB)
  • AWS GuardDuty (GUARDDUTY)
  • AWS RDS (AWS_RDS)
  • AWS Security Hub (AWS_SECURITY_HUB)
  • AWS WAF (AWS_WAF)
  • Azure AD (AZURE_AD)
  • Azure AD Directory Audit (AZURE_AD_AUDIT)
  • Azure AD Sign-In (AZURE_AD_SIGNIN)
  • Azure Front Door (AZURE_FRONT_DOOR)
  • Barracuda Email (BARRACUDA_EMAIL)
  • Barracuda WAF (BARRACUDA_WAF)
  • BeyondTrust (BOMGAR)
  • BeyondTrust BeyondInsight (BEYONDTRUST_BEYONDINSIGHT)
  • BeyondTrust Endpoint Privilege Management (BEYONDTRUST_ENDPOINT)
  • BeyondTrust Secure Remote Access (BEYONDTRUST_REMOTE_ACCESS)
  • BIND (BIND_DNS)
  • Bindplane Agent (BINDPLANE_AGENT)
  • Blue Coat Proxy (BLUECOAT_WEBPROXY)
  • Box (BOX)
  • Carbon Black (CB_EDR)
  • Cato Networks (CATO_NETWORKS)
  • Check Point (CHECKPOINT_FIREWALL)
  • CipherTrust Manager (CIPHERTRUST_MANAGER)
  • Cisco Application Centric Infrastructure (CISCO_ACI)
  • Cisco ASA (CISCO_ASA_FIREWALL)
  • Cisco Email Security (CISCO_EMAIL_SECURITY)
  • Cisco Firepower NGFW (CISCO_FIREPOWER_FIREWALL)
  • Cisco Internetwork Operating System (CISCO_IOS)
  • Cisco ISE (CISCO_ISE)
  • Cisco Meraki (CISCO_MERAKI)
  • Cisco PIX Firewall (CISCO_PIX_FIREWALL)
  • Cisco Router (CISCO_ROUTER)
  • Cisco Stealthwatch (CISCO_STEALTHWATCH)
  • Cisco Switch (CISCO_SWITCH)
  • Cisco Umbrella Audit (CISCO_UMBRELLA_AUDIT)
  • Cisco Umbrella DNS (UMBRELLA_DNS)
  • Cisco vManage SD-WAN (CISCO_SDWAN)
  • Cisco WLC/WCS (CISCO_WIRELESS)
  • Cisco WSA (CISCO_WSA)
  • Citrix Netscaler (CITRIX_NETSCALER)
  • Claroty Continuous Threat Detection (CLAROTY_CTD)
  • Claroty Xdome (CLAROTY_XDOME)
  • Cloud SQL (GCP_CLOUDSQL)
  • Cloudflare (CLOUDFLARE)
  • Cloudflare Audit (CLOUDFLARE_AUDIT)
  • Compute Engine (GCP_COMPUTE)
  • Corelight (CORELIGHT)
  • CrowdStrike Alerts API (CS_ALERTS)
  • CrowdStrike Detection Monitoring (CS_DETECTS)
  • CrowdStrike Falcon (CS_EDR)
  • CrowdStrike Falcon Stream (CS_STREAM)
  • CyberArk (CYBERARK)
  • CyberArk Endpoint Privilege Manager (EPM) (CYBERARK_EPM)
  • CyberArk Privileged Access Manager (PAM) (CYBERARK_PAM)
  • Cyolo Secure Remote Access for OT (CYOLO_OT)
  • Darktrace (DARKTRACE)
  • Delinea Secret Server (DELINEA_SECRET_SERVER)
  • Dell ECS Enterprise Object Storage (DELL_ECS)
  • Dell Switch (DELL_SWITCH)
  • Duo Auth (DUO_AUTH)
  • ExtraHop RevealX (EXTRAHOP)
  • Extreme Wireless (EXTREME_WIRELESS)
  • F5 Advanced Firewall Management (F5_AFM)
  • F5 ASM (F5_ASM)
  • F5 BIGIP Access Policy Manager (F5_BIGIP_APM)
  • F5 BIGIP LTM (F5_BIGIP_LTM)
  • F5 Distributed Cloud Services (F5_DCS)
  • Fastly CDN (FASTLY_CDN)
  • FireEye ETP (FIREEYE_ETP)
  • FireEye NX (FIREEYE_NX)
  • Forcepoint Email Security (FORCEPOINT_EMAILSECURITY)
  • Forescout eyeInspect (FORESCOUT_EYEINSPECT)
  • FortiGate (FORTINET_FIREWALL)
  • Fortinet FortiAnalyzer (FORTINET_FORTIANALYZER)
  • Fortinet Fortimanager (FORTINET_FORTIMANAGER)
  • Fortinet Web Application Firewall (FORTINET_FORTIWEB)
  • GCP_APP_ENGINE (GCP_APP_ENGINE)
  • GCP_MODEL_ARMOR (GCP_MODEL_ARMOR)
  • GitHub (GITHUB)
  • GitHub Dependabot (GITHUB_DEPENDABOT)
  • Google Cloud Audit (GCP_CLOUDAUDIT)
  • Google Threat Intelligence (GCP_THREATINTEL)
  • H3C Comware Platform Switch (H3C_SWITCH)
  • Hashicorp Vault (HASHICORP)
  • HP Aruba (ClearPass) (CLEARPASS)
  • Huawei Switches (HUAWEI_SWITCH)
  • IBM DataPower Gateway (IBM_DATAPOWER)
  • IBM DB2 (DB2_DB)
  • Illumio Core (ILLUMIO_CORE)
  • Imperva (IMPERVA_WAF)
  • Imperva DRA (IMPERVA_DRA)
  • Island Browser logs (ISLAND_BROWSER)
  • Jamf pro context (JAMF_PRO_CONTEXT)
  • JumpCloud Directory Insights (JUMPCLOUD_DIRECTORY_INSIGHTS)
  • Juniper MX Router (JUNIPER_MX)
  • Keycloak (KEYCLOAK)
  • KnowBe4 PhishER (KNOWBE4_PHISHER)
  • Kolide Endpoint Security (KOLIDE)
  • Kubernetes Node (KUBERNETES_NODE)
  • Linux Auditing System (AuditD) (AUDITD)
  • McAfee DLP (MCAFEE_DLP)
  • McAfee ePolicy Orchestrator (MCAFEE_EPO)
  • McAfee Web Gateway (MCAFEE_WEBPROXY)
  • Microsoft AD FS (ADFS)
  • Microsoft Defender For Cloud (MICROSOFT_DEFENDER_CLOUD_ALERTS)
  • Microsoft Defender for Endpoint (MICROSOFT_DEFENDER_ENDPOINT)
  • Microsoft Graph API Alerts (MICROSOFT_GRAPH_ALERT)
  • Microsoft IIS (IIS)
  • Microsoft Intune (AZURE_MDM_INTUNE)
  • Microsoft PowerShell (POWERSHELL)
  • Microsoft SQL Server (MICROSOFT_SQL)
  • Mimecast Mail V2 (MIMECAST_MAIL_V2)
  • MISP Threat Intelligence (MISP_IOC)
  • Mobileiron (MOBILEIRON)
  • MySQL (MYSQL)
  • NetApp ONTAP (NETAPP_ONTAP)
  • Netfilter IPtables (NETFILTER_IPTABLES)
  • NetIQ Access Manager (NETIQ_ACCESS_MANAGER)
  • Netskope V2 (NETSKOPE_ALERT_V2)
  • Netskope Web Proxy (NETSKOPE_WEBPROXY)
  • Network Policy Server (MICROSOFT_NPS)
  • NGINX (NGINX)
  • Nozomi Networks Scada Guardian (NOZOMI_GUARDIAN)
  • Nutanix Prism (NUTANIX_PRISM)
  • Obsidian (OBSIDIAN)
  • Office 365 (OFFICE_365)
  • Okta (OKTA)
  • Onapsis (ONAPSIS)
  • One Identity TPAM (ONEIDENTITY_TPAM)
  • OneLogin (ONELOGIN_SSO)
  • Open Cybersecurity Schema Framework (OCSF) (OCSF)
  • Oracle (ORACLE_DB)
  • Palo Alto Networks Firewall (PAN_FIREWALL)
  • Palo Alto Panorama (PAN_PANORAMA)
  • Ping Identity (PING)
  • PostFix Mail (POSTFIX_MAIL)
  • PostgreSQL (POSTGRESQL)
  • Proofpoint CASB (PROOFPOINT_CASB)
  • Proofpoint Email Filter (PROOFPOINT_MAIL_FILTER)
  • Proofpoint On Demand (PROOFPOINT_ON_DEMAND)
  • Proofpoint Tap Alerts (PROOFPOINT_MAIL)
  • Pulse Secure (PULSE_SECURE_VPN)
  • QNAP Systems NAS (QNAP_NAS)
  • Radware Web Application Firewall (RADWARE_FIREWALL)
  • Recorded Future (RECORDED_FUTURE_IOC)
  • Red Hat OpenShift (REDHAT_OPENSHIFT)
  • Salesforce (SALESFORCE)
  • SAP Sybase Adaptive Server Enterprise Database (SAP_ASE)
  • Security Command Center Chokepoint (GCP_SECURITYCENTER_CHOKEPOINT)
  • Security Command Center Posture Violation (GCP_SECURITYCENTER_POSTURE_VIOLATION)
  • Security Command Center Threat (GCP_SECURITYCENTER_THREAT)
  • Security Command Center Toxic Combination (GCP_SECURITYCENTER_TOXIC_COMBINATION)
  • ServiceNow Audit (SERVICENOW_AUDIT)
  • Snare System Diagnostic Logs (SNARE_SOLUTIONS)
  • Snyk Group level audit/issues logs (SNYK_ISSUES)
  • Solaris system (SOLARIS_SYSTEM)
  • Sophos Central (SOPHOS_CENTRAL)
  • STIX Threat Intelligence (STIX)
  • Stormshield Firewall (STORMSHIELD_FIREWALL)
  • Sublime Security (SUBLIMESECURITY)
  • Suricata EVE (SURICATA_EVE)
  • Swift Alliance Messaging Hub (SWIFT_AMH)
  • Symantec DLP (SYMANTEC_DLP)
  • Symantec Endpoint Protection (SEP)
  • Symantec Messaging Gateway (SYMANTEC_MAIL)
  • Tableau (TABLEAU)
  • TCPWave DDI (TCPWAVE_DDI)
  • TeamViewer (TEAMVIEWER)
  • Tenable Active Directory Security (TENABLE_ADS)
  • Tenable OT (TENABLE_OT)
  • Tenable.io (TENABLE_IO)
  • Thinkst Canary (THINKST_CANARY)
  • ThreatConnect IOC V3 (THREATCONNECT_IOC_V3)
  • Trellix HX Event Streamer (TRELLIX_HX_ES)
  • Trend Micro (TIPPING_POINT)
  • Trend Micro Vision One (TRENDMICRO_VISION_ONE)
  • Trend Micro Vision One Workbench (TRENDMICRO_VISION_ONE_WORKBENCH)
  • TrendMicro Deep Discovery Inspector (TRENDMICRO_DDI)
  • TXOne Stellar (TRENDMICRO_STELLAR)
  • Unifi AP (UNIFI_AP)
  • Unix system (NIX_SYSTEM)
  • Vectra Detect (VECTRA_DETECT)
  • Vectra XDR (VECTRA_XDR)
  • Veritas NetBackup (VERITAS_NETBACKUP)
  • Versa Firewall (VERSA_FIREWALL)
  • VMware ESXi (VMWARE_ESX)
  • VMware NSX (VMWARE_NSX)
  • VMware vCenter (VMWARE_VCENTER)
  • WatchGuard (WATCHGUARD)
  • Windows DNS (WINDOWS_DNS)
  • Windows Event (WINEVTLOG)
  • Windows Event (XML) (WINEVTLOG_XML)
  • Wiz.io (WIZ_IO)
  • Workday Audit Logs (WORKDAY_AUDIT)
  • Workspace Activities (WORKSPACE_ACTIVITY)
  • Workspace Alerts (WORKSPACE_ALERTS)
  • Zimperium (ZIMPERIUM)
  • Zscaler (ZSCALER_WEBPROXY)
  • Zscaler CASB (ZSCALER_CASB)
  • Zscaler DLP (ZSCALER_DLP)
  • ZScaler DNS (ZSCALER_DNS)
  • Zscaler Internet Access Audit Logs (ZSCALER_INTERNET_ACCESS)
  • ZScaler NGFW (ZSCALER_FIREWALL)
  • Zscaler Private Access (ZSCALER_ZPA)
  • Zscaler Secure Private Access Audit Logs (ZSCALER_ZPA_AUDIT)
  • Zscaler Tunnel (ZSCALER_TUNNEL)
  • Zywall (ZYWALL)

The following log types were added without a default parser. Each parser is listed by product name andlog_type value, where applicable.

  • Aikido (AIKIDO)
  • Akamai API Security (AKAMAI_API_SECURITY)
  • Alkira IP Flow (ALKIRA_IP_FLOW)
  • Atlassian Guard Detect (ATLASSIAN_GUARD_DETECT)
  • BlinkOps (BLINKOPS)
  • Canvas LMS (CANVAS_LMS)
  • Cisco Secure Email Threat Defense (CISCO_SECURE_EMAIL_THREAT_DEFENSE)
  • Cisco StarOS (CISCO_STAR_OS)
  • Citadel Identity360 (CITADEL_IDENTITY360)
  • Cyware Threat Intelligence Exchange (CTIX)
  • Cyberark Identity Audit (CYBERARK_IDENTITY_AUDIT)
  • CyCognito ASM (CYCOGNITO_ASM)
  • Dell VxRail (DELL_VXRAIL)
  • Gene6 FTP Server (GENE6_FTP)
  • IBM Copy Services Manager (IBM_CSM)
  • LangSmith Audit (LANGSMITH_AUDIT)
  • Mellanox Switch (MELLANOX_SWITCH)
  • Microsoft Entra ID Protection (MICROSOFT_ENTRA_ID_PROTECTION)
  • NSFOCUS Next Generation Intrusion Prevention System (NSFOCUS_NGIPS)
  • Perplexity (PERPLEXITY)
  • Pleasant Password Server (PLEASANT_PASSWORD_SERVER)
  • Prompt Security (PROMPT_SECURITY)
  • Qualtrics Audit (QUALTRICS_AUDIT)
  • Rancher API Audit Log (RANCHER_API_AUDIT_LOG)
  • Rubrik Security Cloud (RUBRIK_SECURITY_CLOUD)
  • SAP Business Warehouse (SAP_BW)
  • SAP Change Document (SAP_CHANGE_DOCUMENT)
  • SAP Gateway (SAP_GATEWAY)
  • SAP Hana Audit (SAP_HANA_AUDIT)
  • Scale Computing (SCALE_COMPUTING)
  • Slack API (SLACK_API)
  • Snowplow (SNOWPLOW)
  • Sterling Order Management System Data (STERLING_OMS_DATA)
  • Strivacity (STRIVACITY)
  • Tencent CloudAudit (TENCENT_CLOUD_AUDIT)
  • Trellix EX (TRELLIX_EX)
  • Unifi System (UNIFI_SYSTEM)
  • Windows Bindplane (WINDOWS_BINDPLANE)
  • Witness AI Control (WITNESS_AI_CONTROL)
  • Zendesk Advanced Data Privacy and Protection (ZENDESK_ADPP)
Google SecOps SIEM
Change

Google SecOps has updated the list of supported default parsers. Updatespropagate gradually; changes typically appear in your region within one to fourbusiness days. For more information, seeSupported log types and default parsers.

The following supported default parsers have been updated. Each parser is listedby product name andlog_type value, where applicable. This list includes bothreleased default parsers and pending parser updates.

  • A10 Load Balancer (A10_LOAD_BALANCER)
  • AIX system (AIX_SYSTEM)
  • Akamai Cloud Monitor (AKAMAI_CLOUD_MONITOR)
  • AlgoSec Security Management (ALGOSEC)
  • Amazon API Gateway (AWS_API_GATEWAY)
  • Apache (APACHE)
  • Apple macOS (MACOS)
  • AppOmni (APPOMNI)
  • Arcsight CEF (ARCSIGHT_CEF)
  • Arista Switch (ARISTA_SWITCH)
  • Aruba (ARUBA_WIRELESS)
  • Aruba Airwave (ARUBA_AIRWAVE)
  • Aruba EdgeConnect SD-WAN (ARUBA_EDGECONNECT_SDWAN)
  • Aruba Switch (ARUBA_SWITCH)
  • Attivo Networks (ATTIVO)
  • Auth0 (AUTH_ZERO)
  • Automation Anywhere (AUTOMATION_ANYWHERE)
  • Avanan Email Security (AVANAN_EMAIL)
  • AWS Aurora (AWS_AURORA)
  • AWS Cloudtrail (AWS_CLOUDTRAIL)
  • AWS CloudWatch (AWS_CLOUDWATCH)
  • AWS Elastic Load Balancer (AWS_ELB)
  • AWS GuardDuty (GUARDDUTY)
  • AWS RDS (AWS_RDS)
  • AWS Security Hub (AWS_SECURITY_HUB)
  • AWS WAF (AWS_WAF)
  • Azure AD (AZURE_AD)
  • Azure AD Directory Audit (AZURE_AD_AUDIT)
  • Azure AD Sign-In (AZURE_AD_SIGNIN)
  • Azure Front Door (AZURE_FRONT_DOOR)
  • Barracuda Email (BARRACUDA_EMAIL)
  • Barracuda WAF (BARRACUDA_WAF)
  • BeyondTrust (BOMGAR)
  • BeyondTrust BeyondInsight (BEYONDTRUST_BEYONDINSIGHT)
  • BeyondTrust Endpoint Privilege Management (BEYONDTRUST_ENDPOINT)
  • BeyondTrust Secure Remote Access (BEYONDTRUST_REMOTE_ACCESS)
  • BIND (BIND_DNS)
  • Bindplane Agent (BINDPLANE_AGENT)
  • Blue Coat Proxy (BLUECOAT_WEBPROXY)
  • Box (BOX)
  • Carbon Black (CB_EDR)
  • Cato Networks (CATO_NETWORKS)
  • Check Point (CHECKPOINT_FIREWALL)
  • CipherTrust Manager (CIPHERTRUST_MANAGER)
  • Cisco Application Centric Infrastructure (CISCO_ACI)
  • Cisco ASA (CISCO_ASA_FIREWALL)
  • Cisco Email Security (CISCO_EMAIL_SECURITY)
  • Cisco Firepower NGFW (CISCO_FIREPOWER_FIREWALL)
  • Cisco Internetwork Operating System (CISCO_IOS)
  • Cisco ISE (CISCO_ISE)
  • Cisco Meraki (CISCO_MERAKI)
  • Cisco PIX Firewall (CISCO_PIX_FIREWALL)
  • Cisco Router (CISCO_ROUTER)
  • Cisco Stealthwatch (CISCO_STEALTHWATCH)
  • Cisco Switch (CISCO_SWITCH)
  • Cisco Umbrella Audit (CISCO_UMBRELLA_AUDIT)
  • Cisco Umbrella DNS (UMBRELLA_DNS)
  • Cisco vManage SD-WAN (CISCO_SDWAN)
  • Cisco WLC/WCS (CISCO_WIRELESS)
  • Cisco WSA (CISCO_WSA)
  • Citrix Netscaler (CITRIX_NETSCALER)
  • Claroty Continuous Threat Detection (CLAROTY_CTD)
  • Claroty Xdome (CLAROTY_XDOME)
  • Cloud SQL (GCP_CLOUDSQL)
  • Cloudflare (CLOUDFLARE)
  • Cloudflare Audit (CLOUDFLARE_AUDIT)
  • Compute Engine (GCP_COMPUTE)
  • Corelight (CORELIGHT)
  • CrowdStrike Alerts API (CS_ALERTS)
  • CrowdStrike Detection Monitoring (CS_DETECTS)
  • CrowdStrike Falcon (CS_EDR)
  • CrowdStrike Falcon Stream (CS_STREAM)
  • CyberArk (CYBERARK)
  • CyberArk Endpoint Privilege Manager (EPM) (CYBERARK_EPM)
  • CyberArk Privileged Access Manager (PAM) (CYBERARK_PAM)
  • Cyolo Secure Remote Access for OT (CYOLO_OT)
  • Darktrace (DARKTRACE)
  • Delinea Secret Server (DELINEA_SECRET_SERVER)
  • Dell ECS Enterprise Object Storage (DELL_ECS)
  • Dell Switch (DELL_SWITCH)
  • Duo Auth (DUO_AUTH)
  • ExtraHop RevealX (EXTRAHOP)
  • Extreme Wireless (EXTREME_WIRELESS)
  • F5 Advanced Firewall Management (F5_AFM)
  • F5 ASM (F5_ASM)
  • F5 BIGIP Access Policy Manager (F5_BIGIP_APM)
  • F5 BIGIP LTM (F5_BIGIP_LTM)
  • F5 Distributed Cloud Services (F5_DCS)
  • Fastly CDN (FASTLY_CDN)
  • FireEye ETP (FIREEYE_ETP)
  • FireEye NX (FIREEYE_NX)
  • Forcepoint Email Security (FORCEPOINT_EMAILSECURITY)
  • Forescout eyeInspect (FORESCOUT_EYEINSPECT)
  • FortiGate (FORTINET_FIREWALL)
  • Fortinet FortiAnalyzer (FORTINET_FORTIANALYZER)
  • Fortinet Fortimanager (FORTINET_FORTIMANAGER)
  • Fortinet Web Application Firewall (FORTINET_FORTIWEB)
  • GCP_APP_ENGINE (GCP_APP_ENGINE)
  • GCP_MODEL_ARMOR (GCP_MODEL_ARMOR)
  • GitHub (GITHUB)
  • GitHub Dependabot (GITHUB_DEPENDABOT)
  • Google Cloud Audit (GCP_CLOUDAUDIT)
  • Google Threat Intelligence (GCP_THREATINTEL)
  • H3C Comware Platform Switch (H3C_SWITCH)
  • Hashicorp Vault (HASHICORP)
  • HP Aruba (ClearPass) (CLEARPASS)
  • Huawei Switches (HUAWEI_SWITCH)
  • IBM DataPower Gateway (IBM_DATAPOWER)
  • IBM DB2 (DB2_DB)
  • Illumio Core (ILLUMIO_CORE)
  • Imperva (IMPERVA_WAF)
  • Imperva DRA (IMPERVA_DRA)
  • Island Browser logs (ISLAND_BROWSER)
  • Jamf pro context (JAMF_PRO_CONTEXT)
  • JumpCloud Directory Insights (JUMPCLOUD_DIRECTORY_INSIGHTS)
  • Juniper MX Router (JUNIPER_MX)
  • Keycloak (KEYCLOAK)
  • KnowBe4 PhishER (KNOWBE4_PHISHER)
  • Kolide Endpoint Security (KOLIDE)
  • Kubernetes Node (KUBERNETES_NODE)
  • Linux Auditing System (AuditD) (AUDITD)
  • McAfee DLP (MCAFEE_DLP)
  • McAfee ePolicy Orchestrator (MCAFEE_EPO)
  • McAfee Web Gateway (MCAFEE_WEBPROXY)
  • Microsoft AD FS (ADFS)
  • Microsoft Defender For Cloud (MICROSOFT_DEFENDER_CLOUD_ALERTS)
  • Microsoft Defender for Endpoint (MICROSOFT_DEFENDER_ENDPOINT)
  • Microsoft Graph API Alerts (MICROSOFT_GRAPH_ALERT)
  • Microsoft IIS (IIS)
  • Microsoft Intune (AZURE_MDM_INTUNE)
  • Microsoft PowerShell (POWERSHELL)
  • Microsoft SQL Server (MICROSOFT_SQL)
  • Mimecast Mail V2 (MIMECAST_MAIL_V2)
  • MISP Threat Intelligence (MISP_IOC)
  • Mobileiron (MOBILEIRON)
  • MySQL (MYSQL)
  • NetApp ONTAP (NETAPP_ONTAP)
  • Netfilter IPtables (NETFILTER_IPTABLES)
  • NetIQ Access Manager (NETIQ_ACCESS_MANAGER)
  • Netskope V2 (NETSKOPE_ALERT_V2)
  • Netskope Web Proxy (NETSKOPE_WEBPROXY)
  • Network Policy Server (MICROSOFT_NPS)
  • NGINX (NGINX)
  • Nozomi Networks Scada Guardian (NOZOMI_GUARDIAN)
  • Nutanix Prism (NUTANIX_PRISM)
  • Obsidian (OBSIDIAN)
  • Office 365 (OFFICE_365)
  • Okta (OKTA)
  • Onapsis (ONAPSIS)
  • One Identity TPAM (ONEIDENTITY_TPAM)
  • OneLogin (ONELOGIN_SSO)
  • Open Cybersecurity Schema Framework (OCSF) (OCSF)
  • Oracle (ORACLE_DB)
  • Palo Alto Networks Firewall (PAN_FIREWALL)
  • Palo Alto Panorama (PAN_PANORAMA)
  • Ping Identity (PING)
  • PostFix Mail (POSTFIX_MAIL)
  • PostgreSQL (POSTGRESQL)
  • Proofpoint CASB (PROOFPOINT_CASB)
  • Proofpoint Email Filter (PROOFPOINT_MAIL_FILTER)
  • Proofpoint On Demand (PROOFPOINT_ON_DEMAND)
  • Proofpoint Tap Alerts (PROOFPOINT_MAIL)
  • Pulse Secure (PULSE_SECURE_VPN)
  • QNAP Systems NAS (QNAP_NAS)
  • Radware Web Application Firewall (RADWARE_FIREWALL)
  • Recorded Future (RECORDED_FUTURE_IOC)
  • Red Hat OpenShift (REDHAT_OPENSHIFT)
  • Salesforce (SALESFORCE)
  • SAP Sybase Adaptive Server Enterprise Database (SAP_ASE)
  • Security Command Center Chokepoint (GCP_SECURITYCENTER_CHOKEPOINT)
  • Security Command Center Posture Violation (GCP_SECURITYCENTER_POSTURE_VIOLATION)
  • Security Command Center Threat (GCP_SECURITYCENTER_THREAT)
  • Security Command Center Toxic Combination (GCP_SECURITYCENTER_TOXIC_COMBINATION)
  • ServiceNow Audit (SERVICENOW_AUDIT)
  • Snare System Diagnostic Logs (SNARE_SOLUTIONS)
  • Snyk Group level audit/issues logs (SNYK_ISSUES)
  • Solaris system (SOLARIS_SYSTEM)
  • Sophos Central (SOPHOS_CENTRAL)
  • STIX Threat Intelligence (STIX)
  • Stormshield Firewall (STORMSHIELD_FIREWALL)
  • Sublime Security (SUBLIMESECURITY)
  • Suricata EVE (SURICATA_EVE)
  • Swift Alliance Messaging Hub (SWIFT_AMH)
  • Symantec DLP (SYMANTEC_DLP)
  • Symantec Endpoint Protection (SEP)
  • Symantec Messaging Gateway (SYMANTEC_MAIL)
  • Tableau (TABLEAU)
  • TCPWave DDI (TCPWAVE_DDI)
  • TeamViewer (TEAMVIEWER)
  • Tenable Active Directory Security (TENABLE_ADS)
  • Tenable OT (TENABLE_OT)
  • Tenable.io (TENABLE_IO)
  • Thinkst Canary (THINKST_CANARY)
  • ThreatConnect IOC V3 (THREATCONNECT_IOC_V3)
  • Trellix HX Event Streamer (TRELLIX_HX_ES)
  • Trend Micro (TIPPING_POINT)
  • Trend Micro Vision One (TRENDMICRO_VISION_ONE)
  • Trend Micro Vision One Workbench (TRENDMICRO_VISION_ONE_WORKBENCH)
  • TrendMicro Deep Discovery Inspector (TRENDMICRO_DDI)
  • TXOne Stellar (TRENDMICRO_STELLAR)
  • Unifi AP (UNIFI_AP)
  • Unix system (NIX_SYSTEM)
  • Vectra Detect (VECTRA_DETECT)
  • Vectra XDR (VECTRA_XDR)
  • Veritas NetBackup (VERITAS_NETBACKUP)
  • Versa Firewall (VERSA_FIREWALL)
  • VMware ESXi (VMWARE_ESX)
  • VMware NSX (VMWARE_NSX)
  • VMware vCenter (VMWARE_VCENTER)
  • WatchGuard (WATCHGUARD)
  • Windows DNS (WINDOWS_DNS)
  • Windows Event (WINEVTLOG)
  • Windows Event (XML) (WINEVTLOG_XML)
  • Wiz.io (WIZ_IO)
  • Workday Audit Logs (WORKDAY_AUDIT)
  • Workspace Activities (WORKSPACE_ACTIVITY)
  • Workspace Alerts (WORKSPACE_ALERTS)
  • Zimperium (ZIMPERIUM)
  • Zscaler (ZSCALER_WEBPROXY)
  • Zscaler CASB (ZSCALER_CASB)
  • Zscaler DLP (ZSCALER_DLP)
  • ZScaler DNS (ZSCALER_DNS)
  • Zscaler Internet Access Audit Logs (ZSCALER_INTERNET_ACCESS)
  • ZScaler NGFW (ZSCALER_FIREWALL)
  • Zscaler Private Access (ZSCALER_ZPA)
  • Zscaler Secure Private Access Audit Logs (ZSCALER_ZPA_AUDIT)
  • Zscaler Tunnel (ZSCALER_TUNNEL)
  • Zywall (ZYWALL)

The following log types were added without a default parser. Each parser is listed by product name andlog_type value, where applicable.

  • Aikido (AIKIDO)
  • Akamai API Security (AKAMAI_API_SECURITY)
  • Alkira IP Flow (ALKIRA_IP_FLOW)
  • Atlassian Guard Detect (ATLASSIAN_GUARD_DETECT)
  • BlinkOps (BLINKOPS)
  • Canvas LMS (CANVAS_LMS)
  • Cisco Secure Email Threat Defense (CISCO_SECURE_EMAIL_THREAT_DEFENSE)
  • Cisco StarOS (CISCO_STAR_OS)
  • Citadel Identity360 (CITADEL_IDENTITY360)
  • Cyware Threat Intelligence Exchange (CTIX)
  • Cyberark Identity Audit (CYBERARK_IDENTITY_AUDIT)
  • CyCognito ASM (CYCOGNITO_ASM)
  • Dell VxRail (DELL_VXRAIL)
  • Gene6 FTP Server (GENE6_FTP)
  • IBM Copy Services Manager (IBM_CSM)
  • LangSmith Audit (LANGSMITH_AUDIT)
  • Mellanox Switch (MELLANOX_SWITCH)
  • Microsoft Entra ID Protection (MICROSOFT_ENTRA_ID_PROTECTION)
  • NSFOCUS Next Generation Intrusion Prevention System (NSFOCUS_NGIPS)
  • Perplexity (PERPLEXITY)
  • Pleasant Password Server (PLEASANT_PASSWORD_SERVER)
  • Prompt Security (PROMPT_SECURITY)
  • Qualtrics Audit (QUALTRICS_AUDIT)
  • Rancher API Audit Log (RANCHER_API_AUDIT_LOG)
  • Rubrik Security Cloud (RUBRIK_SECURITY_CLOUD)
  • SAP Business Warehouse (SAP_BW)
  • SAP Change Document (SAP_CHANGE_DOCUMENT)
  • SAP Gateway (SAP_GATEWAY)
  • SAP Hana Audit (SAP_HANA_AUDIT)
  • Scale Computing (SCALE_COMPUTING)
  • Slack API (SLACK_API)
  • Snowplow (SNOWPLOW)
  • Sterling Order Management System Data (STERLING_OMS_DATA)
  • Strivacity (STRIVACITY)
  • Tencent CloudAudit (TENCENT_CLOUD_AUDIT)
  • Trellix EX (TRELLIX_EX)
  • Unifi System (UNIFI_SYSTEM)
  • Windows Bindplane (WINDOWS_BINDPLANE)
  • Witness AI Control (WITNESS_AI_CONTROL)
  • Zendesk Advanced Data Privacy and Protection (ZENDESK_ADPP)
Change

Google SecOps has updated the list of supported default parsers. Updatespropagate gradually; changes typically appear in your region within one to fourbusiness days. For more information, seeSupported log types and default parsers.

The following supported default parsers have been updated. Each parser is listedby product name andlog_type value, where applicable. This list includes bothreleased default parsers and pending parser updates.

  • A10 Load Balancer (A10_LOAD_BALANCER)
  • AIX system (AIX_SYSTEM)
  • Akamai Cloud Monitor (AKAMAI_CLOUD_MONITOR)
  • AlgoSec Security Management (ALGOSEC)
  • Amazon API Gateway (AWS_API_GATEWAY)
  • Apache (APACHE)
  • Apple macOS (MACOS)
  • AppOmni (APPOMNI)
  • Arcsight CEF (ARCSIGHT_CEF)
  • Arista Switch (ARISTA_SWITCH)
  • Aruba (ARUBA_WIRELESS)
  • Aruba Airwave (ARUBA_AIRWAVE)
  • Aruba EdgeConnect SD-WAN (ARUBA_EDGECONNECT_SDWAN)
  • Aruba Switch (ARUBA_SWITCH)
  • Attivo Networks (ATTIVO)
  • Auth0 (AUTH_ZERO)
  • Automation Anywhere (AUTOMATION_ANYWHERE)
  • Avanan Email Security (AVANAN_EMAIL)
  • AWS Aurora (AWS_AURORA)
  • AWS Cloudtrail (AWS_CLOUDTRAIL)
  • AWS CloudWatch (AWS_CLOUDWATCH)
  • AWS Elastic Load Balancer (AWS_ELB)
  • AWS GuardDuty (GUARDDUTY)
  • AWS RDS (AWS_RDS)
  • AWS Security Hub (AWS_SECURITY_HUB)
  • AWS WAF (AWS_WAF)
  • Azure AD (AZURE_AD)
  • Azure AD Directory Audit (AZURE_AD_AUDIT)
  • Azure AD Sign-In (AZURE_AD_SIGNIN)
  • Azure Front Door (AZURE_FRONT_DOOR)
  • Barracuda Email (BARRACUDA_EMAIL)
  • Barracuda WAF (BARRACUDA_WAF)
  • BeyondTrust (BOMGAR)
  • BeyondTrust BeyondInsight (BEYONDTRUST_BEYONDINSIGHT)
  • BeyondTrust Endpoint Privilege Management (BEYONDTRUST_ENDPOINT)
  • BeyondTrust Secure Remote Access (BEYONDTRUST_REMOTE_ACCESS)
  • BIND (BIND_DNS)
  • Bindplane Agent (BINDPLANE_AGENT)
  • Blue Coat Proxy (BLUECOAT_WEBPROXY)
  • Box (BOX)
  • Carbon Black (CB_EDR)
  • Cato Networks (CATO_NETWORKS)
  • Check Point (CHECKPOINT_FIREWALL)
  • CipherTrust Manager (CIPHERTRUST_MANAGER)
  • Cisco Application Centric Infrastructure (CISCO_ACI)
  • Cisco ASA (CISCO_ASA_FIREWALL)
  • Cisco Email Security (CISCO_EMAIL_SECURITY)
  • Cisco Firepower NGFW (CISCO_FIREPOWER_FIREWALL)
  • Cisco Internetwork Operating System (CISCO_IOS)
  • Cisco ISE (CISCO_ISE)
  • Cisco Meraki (CISCO_MERAKI)
  • Cisco PIX Firewall (CISCO_PIX_FIREWALL)
  • Cisco Router (CISCO_ROUTER)
  • Cisco Stealthwatch (CISCO_STEALTHWATCH)
  • Cisco Switch (CISCO_SWITCH)
  • Cisco Umbrella Audit (CISCO_UMBRELLA_AUDIT)
  • Cisco Umbrella DNS (UMBRELLA_DNS)
  • Cisco vManage SD-WAN (CISCO_SDWAN)
  • Cisco WLC/WCS (CISCO_WIRELESS)
  • Cisco WSA (CISCO_WSA)
  • Citrix Netscaler (CITRIX_NETSCALER)
  • Claroty Continuous Threat Detection (CLAROTY_CTD)
  • Claroty Xdome (CLAROTY_XDOME)
  • Cloud SQL (GCP_CLOUDSQL)
  • Cloudflare (CLOUDFLARE)
  • Cloudflare Audit (CLOUDFLARE_AUDIT)
  • Compute Engine (GCP_COMPUTE)
  • Corelight (CORELIGHT)
  • CrowdStrike Alerts API (CS_ALERTS)
  • CrowdStrike Detection Monitoring (CS_DETECTS)
  • CrowdStrike Falcon (CS_EDR)
  • CrowdStrike Falcon Stream (CS_STREAM)
  • CyberArk (CYBERARK)
  • CyberArk Endpoint Privilege Manager (EPM) (CYBERARK_EPM)
  • CyberArk Privileged Access Manager (PAM) (CYBERARK_PAM)
  • Cyolo Secure Remote Access for OT (CYOLO_OT)
  • Darktrace (DARKTRACE)
  • Delinea Secret Server (DELINEA_SECRET_SERVER)
  • Dell ECS Enterprise Object Storage (DELL_ECS)
  • Dell Switch (DELL_SWITCH)
  • Duo Auth (DUO_AUTH)
  • ExtraHop RevealX (EXTRAHOP)
  • Extreme Wireless (EXTREME_WIRELESS)
  • F5 Advanced Firewall Management (F5_AFM)
  • F5 ASM (F5_ASM)
  • F5 BIGIP Access Policy Manager (F5_BIGIP_APM)
  • F5 BIGIP LTM (F5_BIGIP_LTM)
  • F5 Distributed Cloud Services (F5_DCS)
  • Fastly CDN (FASTLY_CDN)
  • FireEye ETP (FIREEYE_ETP)
  • FireEye NX (FIREEYE_NX)
  • Forcepoint Email Security (FORCEPOINT_EMAILSECURITY)
  • Forescout eyeInspect (FORESCOUT_EYEINSPECT)
  • FortiGate (FORTINET_FIREWALL)
  • Fortinet FortiAnalyzer (FORTINET_FORTIANALYZER)
  • Fortinet Fortimanager (FORTINET_FORTIMANAGER)
  • Fortinet Web Application Firewall (FORTINET_FORTIWEB)
  • GCP_APP_ENGINE (GCP_APP_ENGINE)
  • GCP_MODEL_ARMOR (GCP_MODEL_ARMOR)
  • GitHub (GITHUB)
  • GitHub Dependabot (GITHUB_DEPENDABOT)
  • Google Cloud Audit (GCP_CLOUDAUDIT)
  • Google Threat Intelligence (GCP_THREATINTEL)
  • H3C Comware Platform Switch (H3C_SWITCH)
  • Hashicorp Vault (HASHICORP)
  • HP Aruba (ClearPass) (CLEARPASS)
  • Huawei Switches (HUAWEI_SWITCH)
  • IBM DataPower Gateway (IBM_DATAPOWER)
  • IBM DB2 (DB2_DB)
  • Illumio Core (ILLUMIO_CORE)
  • Imperva (IMPERVA_WAF)
  • Imperva DRA (IMPERVA_DRA)
  • Island Browser logs (ISLAND_BROWSER)
  • Jamf pro context (JAMF_PRO_CONTEXT)
  • JumpCloud Directory Insights (JUMPCLOUD_DIRECTORY_INSIGHTS)
  • Juniper MX Router (JUNIPER_MX)
  • Keycloak (KEYCLOAK)
  • KnowBe4 PhishER (KNOWBE4_PHISHER)
  • Kolide Endpoint Security (KOLIDE)
  • Kubernetes Node (KUBERNETES_NODE)
  • Linux Auditing System (AuditD) (AUDITD)
  • McAfee DLP (MCAFEE_DLP)
  • McAfee ePolicy Orchestrator (MCAFEE_EPO)
  • McAfee Web Gateway (MCAFEE_WEBPROXY)
  • Microsoft AD FS (ADFS)
  • Microsoft Defender For Cloud (MICROSOFT_DEFENDER_CLOUD_ALERTS)
  • Microsoft Defender for Endpoint (MICROSOFT_DEFENDER_ENDPOINT)
  • Microsoft Graph API Alerts (MICROSOFT_GRAPH_ALERT)
  • Microsoft IIS (IIS)
  • Microsoft Intune (AZURE_MDM_INTUNE)
  • Microsoft PowerShell (POWERSHELL)
  • Microsoft SQL Server (MICROSOFT_SQL)
  • Mimecast Mail V2 (MIMECAST_MAIL_V2)
  • MISP Threat Intelligence (MISP_IOC)
  • Mobileiron (MOBILEIRON)
  • MySQL (MYSQL)
  • NetApp ONTAP (NETAPP_ONTAP)
  • Netfilter IPtables (NETFILTER_IPTABLES)
  • NetIQ Access Manager (NETIQ_ACCESS_MANAGER)
  • Netskope V2 (NETSKOPE_ALERT_V2)
  • Netskope Web Proxy (NETSKOPE_WEBPROXY)
  • Network Policy Server (MICROSOFT_NPS)
  • NGINX (NGINX)
  • Nozomi Networks Scada Guardian (NOZOMI_GUARDIAN)
  • Nutanix Prism (NUTANIX_PRISM)
  • Obsidian (OBSIDIAN)
  • Office 365 (OFFICE_365)
  • Okta (OKTA)
  • Onapsis (ONAPSIS)
  • One Identity TPAM (ONEIDENTITY_TPAM)
  • OneLogin (ONELOGIN_SSO)
  • Open Cybersecurity Schema Framework (OCSF) (OCSF)
  • Oracle (ORACLE_DB)
  • Palo Alto Networks Firewall (PAN_FIREWALL)
  • Palo Alto Panorama (PAN_PANORAMA)
  • Ping Identity (PING)
  • PostFix Mail (POSTFIX_MAIL)
  • PostgreSQL (POSTGRESQL)
  • Proofpoint CASB (PROOFPOINT_CASB)
  • Proofpoint Email Filter (PROOFPOINT_MAIL_FILTER)
  • Proofpoint On Demand (PROOFPOINT_ON_DEMAND)
  • Proofpoint Tap Alerts (PROOFPOINT_MAIL)
  • Pulse Secure (PULSE_SECURE_VPN)
  • QNAP Systems NAS (QNAP_NAS)
  • Radware Web Application Firewall (RADWARE_FIREWALL)
  • Recorded Future (RECORDED_FUTURE_IOC)
  • Red Hat OpenShift (REDHAT_OPENSHIFT)
  • Salesforce (SALESFORCE)
  • SAP Sybase Adaptive Server Enterprise Database (SAP_ASE)
  • Security Command Center Chokepoint (GCP_SECURITYCENTER_CHOKEPOINT)
  • Security Command Center Posture Violation (GCP_SECURITYCENTER_POSTURE_VIOLATION)
  • Security Command Center Threat (GCP_SECURITYCENTER_THREAT)
  • Security Command Center Toxic Combination (GCP_SECURITYCENTER_TOXIC_COMBINATION)
  • ServiceNow Audit (SERVICENOW_AUDIT)
  • Snare System Diagnostic Logs (SNARE_SOLUTIONS)
  • Snyk Group level audit/issues logs (SNYK_ISSUES)
  • Solaris system (SOLARIS_SYSTEM)
  • Sophos Central (SOPHOS_CENTRAL)
  • STIX Threat Intelligence (STIX)
  • Stormshield Firewall (STORMSHIELD_FIREWALL)
  • Sublime Security (SUBLIMESECURITY)
  • Suricata EVE (SURICATA_EVE)
  • Swift Alliance Messaging Hub (SWIFT_AMH)
  • Symantec DLP (SYMANTEC_DLP)
  • Symantec Endpoint Protection (SEP)
  • Symantec Messaging Gateway (SYMANTEC_MAIL)
  • Tableau (TABLEAU)
  • TCPWave DDI (TCPWAVE_DDI)
  • TeamViewer (TEAMVIEWER)
  • Tenable Active Directory Security (TENABLE_ADS)
  • Tenable OT (TENABLE_OT)
  • Tenable.io (TENABLE_IO)
  • Thinkst Canary (THINKST_CANARY)
  • ThreatConnect IOC V3 (THREATCONNECT_IOC_V3)
  • Trellix HX Event Streamer (TRELLIX_HX_ES)
  • Trend Micro (TIPPING_POINT)
  • Trend Micro Vision One (TRENDMICRO_VISION_ONE)
  • Trend Micro Vision One Workbench (TRENDMICRO_VISION_ONE_WORKBENCH)
  • TrendMicro Deep Discovery Inspector (TRENDMICRO_DDI)
  • TXOne Stellar (TRENDMICRO_STELLAR)
  • Unifi AP (UNIFI_AP)
  • Unix system (NIX_SYSTEM)
  • Vectra Detect (VECTRA_DETECT)
  • Vectra XDR (VECTRA_XDR)
  • Veritas NetBackup (VERITAS_NETBACKUP)
  • Versa Firewall (VERSA_FIREWALL)
  • VMware ESXi (VMWARE_ESX)
  • VMware NSX (VMWARE_NSX)
  • VMware vCenter (VMWARE_VCENTER)
  • WatchGuard (WATCHGUARD)
  • Windows DNS (WINDOWS_DNS)
  • Windows Event (WINEVTLOG)
  • Windows Event (XML) (WINEVTLOG_XML)
  • Wiz.io (WIZ_IO)
  • Workday Audit Logs (WORKDAY_AUDIT)
  • Workspace Activities (WORKSPACE_ACTIVITY)
  • Workspace Alerts (WORKSPACE_ALERTS)
  • Zimperium (ZIMPERIUM)
  • Zscaler (ZSCALER_WEBPROXY)
  • Zscaler CASB (ZSCALER_CASB)
  • Zscaler DLP (ZSCALER_DLP)
  • ZScaler DNS (ZSCALER_DNS)
  • Zscaler Internet Access Audit Logs (ZSCALER_INTERNET_ACCESS)
  • ZScaler NGFW (ZSCALER_FIREWALL)
  • Zscaler Private Access (ZSCALER_ZPA)
  • Zscaler Secure Private Access Audit Logs (ZSCALER_ZPA_AUDIT)
  • Zscaler Tunnel (ZSCALER_TUNNEL)
  • Zywall (ZYWALL)

The following log types were added without a default parser. Each parser is listed by product name andlog_type value, where applicable.

  • Aikido (AIKIDO)
  • Akamai API Security (AKAMAI_API_SECURITY)
  • Alkira IP Flow (ALKIRA_IP_FLOW)
  • Atlassian Guard Detect (ATLASSIAN_GUARD_DETECT)
  • BlinkOps (BLINKOPS)
  • Canvas LMS (CANVAS_LMS)
  • Cisco Secure Email Threat Defense (CISCO_SECURE_EMAIL_THREAT_DEFENSE)
  • Cisco StarOS (CISCO_STAR_OS)
  • Citadel Identity360 (CITADEL_IDENTITY360)
  • Cyware Threat Intelligence Exchange (CTIX)
  • Cyberark Identity Audit (CYBERARK_IDENTITY_AUDIT)
  • CyCognito ASM (CYCOGNITO_ASM)
  • Dell VxRail (DELL_VXRAIL)
  • Gene6 FTP Server (GENE6_FTP)
  • IBM Copy Services Manager (IBM_CSM)
  • LangSmith Audit (LANGSMITH_AUDIT)
  • Mellanox Switch (MELLANOX_SWITCH)
  • Microsoft Entra ID Protection (MICROSOFT_ENTRA_ID_PROTECTION)
  • NSFOCUS Next Generation Intrusion Prevention System (NSFOCUS_NGIPS)
  • Perplexity (PERPLEXITY)
  • Pleasant Password Server (PLEASANT_PASSWORD_SERVER)
  • Prompt Security (PROMPT_SECURITY)
  • Qualtrics Audit (QUALTRICS_AUDIT)
  • Rancher API Audit Log (RANCHER_API_AUDIT_LOG)
  • Rubrik Security Cloud (RUBRIK_SECURITY_CLOUD)
  • SAP Business Warehouse (SAP_BW)
  • SAP Change Document (SAP_CHANGE_DOCUMENT)
  • SAP Gateway (SAP_GATEWAY)
  • SAP Hana Audit (SAP_HANA_AUDIT)
  • Scale Computing (SCALE_COMPUTING)
  • Slack API (SLACK_API)
  • Snowplow (SNOWPLOW)
  • Sterling Order Management System Data (STERLING_OMS_DATA)
  • Strivacity (STRIVACITY)
  • Tencent CloudAudit (TENCENT_CLOUD_AUDIT)
  • Trellix EX (TRELLIX_EX)
  • Unifi System (UNIFI_SYSTEM)
  • Windows Bindplane (WINDOWS_BINDPLANE)
  • Witness AI Control (WITNESS_AI_CONTROL)
  • Zendesk Advanced Data Privacy and Protection (ZENDESK_ADPP)
Looker
Feature

Conversational Analytics now displays its reasoning for how it analyzes queries. After you enter your query, clickShow reasoning to see a plain text explanation of the steps that Conversational Analytics took to interpret your query.

Resource Manager
Feature

Organization Policy Service custom constraints are available for someArtifact Analysis resources. For more information, seeUse custom organization policies.

Organization Policy Service custom constraints are available for some Storage Transfer Serviceresources. For more information, seeCustom organization policy constraints.

Feature

Access Resource Manager using our remote MCP server

You can use the Resource Manager remote MCP server to search for and identify allGoogle Cloud projects you have permission to access, so you have the correctidentifiers before configuring specific resources.

TheResource Manager remote MCP server is inPreview.

Secure Source Manager
Feature

Secure Source Manager is now available in the followingregions:

  • us-east1 (South Carolina)
Spanner
Feature

You can create and hostremote functionsin Cloud Run and call them from Spanner queriesusing the GoogleSQL dialect. This feature is inPreview.

Storage Transfer Service
Feature

Organization Policy Service custom constraints are now available forStorage Transfer Service. You can use custom constraints to control howStorage Transfer Service is used in your organization. For example, you can restricttransfers to only allow Cloud Storage to Cloud Storage transfers, orrestrict transfers to a specific list of approved source buckets.

SeeCustom organization policy constraintsfor details.

February 01, 2026

Google SecOps
Change

TheCase Federation feature is no longer dependent on theCase Federation integration in the primary platform.

The primary platform sync job is now disabled. Do not attempt to re-enable it.

For more information, seeSet up federated case access for SecOps.

Google SecOps SIEM
Change

TheCase Federation feature is no longer dependent on theCase Federation integration in the primary platform.

The primary platform sync job is now disabled. Do not attempt to re-enable it.

For more information, seeSet up federated case access for SecOps.

Change

TheCase Federation feature is no longer dependent on theCase Federation integration in the primary platform.

The primary platform sync job is now disabled. Do not attempt to re-enable it.

For more information, seeSet up case federation access for SOAR.

Announcement

Release 6.3.74 is being rolled out to the first phase of regions as listedhere.

This release contains the following changes:

Google SecOps SOAR
Change

TheCase Federation feature is no longer dependent on theCase Federation integration in the primary platform.

The primary platform sync job is now disabled. Do not attempt to re-enable it.

For more information, seeSet up case federation access for SOAR.

Announcement

Release 6.3.74 is being rolled out to the first phase of regions as listedhere.

This release contains the following changes:

January 31, 2026

App Engine standard environment Go
Deprecated

Go 1.11 isdeprecated.You won't be able to deploy Go 1.11 applications, even if your organizationpreviously used an organization policy to re-enable deployments of legacyruntimes. Your existing Go 1.11 applications will continue to run and receivetraffic. We recommend that youmigrate to the latest supported version ofGo.

App Engine standard environment Java
Deprecated

Java 8 isdeprecated.You won't be able to deploy Java 8 applications, even if your organizationpreviously used an organization policy to re-enable deployments of legacyruntimes. Your existing Java 8 applications will continue to run and receivetraffic. We recommend that youmigrate to the latest supported version ofJava.

App Engine standard environment PHP
Deprecated

PHP 5 isdeprecated.You won't be able to deploy PHP 5 applications, even if yourorganization previously used an organization policy to re-enabledeployments of legacy runtimes. Your existing PHP 5 applicationswill continue to run and receive traffic. We recommend that youmigrate to the latest supported version of PHP.

App Engine standard environment Python
Deprecated

Python 2.7 isdeprecated.You won't be able to deploy Python 2.7 applications, even if yourorganization previously used an organization policy to re-enabledeployments of legacy runtimes. Your existing Python 2.7 applicationswill continue to run and receive traffic. We recommend that youmigrate to the latest supported version of Python.

Cloud Workstations
Feature

Cloud Workstations supportsHyperdisk Balanced High Availability (hyperdisk-balanced-ha) for persistent directories on configurations using A3, C3, C4, G4, M3, N4, N4D, and Z3 machine series. You can specify the disk type using the--disk-type flag with thegcloud workstations configs create andgcloud workstations configs update commands.

Cloud Workstations supports A3 machine types with Hyperdisk only. For more details, seeAvailable machine types andAvailable GPUs.

Contact Center AI Insights
Feature

Customer Experience Insights offersanalysis rules for follow up analysis. A follow up analysis rule tells CX Insights to analyze a group of conversations based on the result from an analysis of a different group of conversations.

Google SecOps SIEM
Announcement

Release 6.3.73 is now available for all regions.

Google SecOps SOAR
Announcement

Release 6.3.73 is now available for all regions.

January 30, 2026

Anthos clusters on AWS
Security

Multiple security vulnerabilities have been identified in the OpenSSL library.The most significant finding is CVE-2025-15467, a critical vulnerability thatmight allow for remote code execution (RCE) or denial of service (DoS) attacksvia network-based vectors.

For more details, see theGCP-2026-006 security bulletin.

Anthos clusters on Azure
Security

Multiple security vulnerabilities have been identified in the OpenSSL library.The most significant finding is CVE-2025-15467, a critical vulnerability thatmight allow for remote code execution (RCE) or denial of service (DoS) attacksvia network-based vectors.

For more details, see theGCP-2026-006 security bulletin.

Bigtable
Feature

Bigtable has a unified, customizable system insights dashboard. This dashboardincludes predefined metrics and other Google Cloud metrics. Thisfeature isgenerally available (GA).For more information, seeCustomize the system insights dashboard.

Carbon Footprint
Fixed

We have corrected the issue resulting in incomplete Cloud Run emissions data forNovember and December 2025. Customers who used Cloud Run during this period cannow access the corrected data.

Action Required: To see the corrected Cloud Run emissions data,schedule a manual data backfill for Novemberand December 2025. Note that there is a half-month lag of our data release. Forexample, to backfill November and December 2025 data, run the backfill forDecember 15, 2025 and January 15, 2026, which will update the data for Novemberand December 2025 in your BigQuery table.

Cloud Asset Inventory
Feature

The following resource types are publicly available through theExportAssets,ListAssets,BatchGetAssetsHistory,QueryAssets,Feed,SearchAllResources,andSearchAllIamPoliciesAPIs.

  • BigQuery
    • bigquery.googleapis.com/Routine
Cloud Quotas
Feature

Folder level and organization level support for thequota adjuster feature is available inPreview through theCloud Quotas API,gcloud quotas betaCLI,Terraform, andCloud Client Libraries. For moreinformation, see the documentation about how toenable the quota adjuster through the Cloud Quotas API.

Cloud Storage
Announcement

Object change notification is deprecated on January 30, 2026. To generatenotifications for changes to objects, usePub/Sub notifications for Cloud Storage instead.

Dataproc
Announcement

Dataproc on Compute Engine: The following subminor image versions announced onJanuary 24, 2026 have been rolled back:

  • 2.0.157-debian10, 2.0.157-ubuntu18, 2.0.157-rocky8
  • 2.1.106-debian11, 2.1.106-ubuntu20, 2.1.106-ubuntu20-arm, 2.1.106-rocky8
  • 2.2.74-debian12, 2.2.74-ubuntu22, 2.2.74-ubuntu22-arm, 2.2.74-rocky9
  • 2.3.21-debian12, 2.3.21-ml-ubuntu22, 2.3.21-rocky9, 2.3.21-ubuntu22, 2.3.21-ubuntu22-arm
Gemini Enterprise
Feature

Gemini Enterprise: Support for new actions (Preview)

New actions are available for the following data stores:

For a list of actions for these data stores, seeSupported actions.

Google Distributed Cloud (software only) for VMware
Security

Multiple security vulnerabilities have been identified in the OpenSSL library.The most significant finding is CVE-2025-15467, a critical vulnerability thatmight allow for remote code execution (RCE) or denial of service (DoS) attacksvia network-based vectors.

For more details, see theGCP-2026-006 security bulletin.

Google Distributed Cloud (software only) for bare metal
Security

Multiple security vulnerabilities have been identified in the OpenSSL library.The most significant finding is CVE-2025-15467, a critical vulnerability thatmight allow for remote code execution (RCE) or denial of service (DoS) attacksvia network-based vectors.

For more details, see theGCP-2026-006 security bulletin.

Google SecOps
Announcement

The following v2 connectors, which utilize Google Storage Transfer Service (STS), are now in General Availability:

  • Google Cloud Storage v2
  • Amazon S3 v2
  • Google Cloud Storage (Event Driven)
  • Amazon SQS v2
  • Azure Blobstore v2
Google SecOps SIEM
Announcement

The following v2 connectors, which utilize Google Storage Transfer Service (STS), are now in General Availability:

  • Google Cloud Storage v2
  • Amazon S3 v2
  • Google Cloud Storage (Event Driven)
  • Amazon SQS v2
  • Azure Blobstore v2
Announcement

The following v2 connectors, which utilize Google Storage Transfer Service (STS), are now in General Availability:

  • Google Cloud Storage v2
  • Amazon S3 v2
  • Google Cloud Storage (Event Driven)
  • Amazon SQS v2
  • Azure Blobstore v2
Model Armor
Change

Theprompt injection and jailbreak detectionfilter for the Mumbai (asia-south1) and Singapore (asia-southeast1) regionsis upgraded to improve detection accuracy and reduce the rate of false positives.

Spanner
Feature

Spanner supports theUUID data type for bothGoogleSQL and PostgreSQL-dialect databases. Thisdata type stores universally unique identifiers (UUIDs) as 128-bit values.

You can use the GoogleSQLNEW_UUID()function or the PostgreSQLgen_random_uuid() tofunction to create UUID values.

For more information, seeUse a universally unique identifier (UUID).

reCAPTCHA
Change

The updated reCAPTCHA Mobile SDK improves the risk score. You should reviewand adjust your reCAPTCHA action thresholds as needed.

January 29, 2026

Anthos Config Management
Breaking

Upgraded the Open Telemetry image from v0.119.0 to v0.127.0. This version removes the deprecated OpenCensus receiver. This change impacts only custom metric solutions that use the OpenCensus receiver. To understand the changes in each release, review thechange logs

Fixed

Resolved an issue where metrics for deleted ResourceGroups continued to show outdated values.

Change

Addressed multiple Common Vulnerabilities and Exposures (CVEs) by updating dependencies.

Change

Upgraded bundled Helm version from v3.15.3 to3.18.6 to pick up vulnerability fixes. To understand the changes in each release, review thechangelogs.

BigQuery
Feature

BigQuery now supports aRANDOM_HASH predefined masking rule. This rule returnsa hash of the column's value using a salted hash algorithm, and it providesstronger security than the standardHash (SHA-256) rule.

For more information, seeData masking rules.

Feature

BigQuery now offersconversational analytics,which accelerates data analysis by enabling insights through natural language.Users can view a predefined sample agent, chat with their BigQuery data orcustom agents, and access those agents even outside of BigQuery. They can alsousesupported BigQuery ML functionsin verified queries and in chat. This feature is inPreview.

Cloud Composer
Feature

Environment snapshotsare available in environments with Airflow 3 (Preview).

This feature is gradually rolled out in several releases and is available inthe following regions in this release: africa-south1, asia-east1, asia-east2,asia-northeast2, asia-northeast3, asia-south2, asia-southeast2,australia-southeast2, europe-central2, europe-north1, europe-north2,europe-southwest1, europe-west10, europe-west12, europe-west3, europe-west4,europe-west6, europe-west8, europe-west9, me-central1, me-central2, me-west1,northamerica-northeast1, northamerica-northeast2, northamerica-south1,southamerica-east1, southamerica-west1, us-east1, us-east5, us-south1,us-west2, us-west3 and us-west4.

Deprecated

The following Cloud Composer versions and builds have reached theirend of support period:composer-3-airflow-2.9.3-build.14 and composer-2.11.1-*.

Feature

(Cloud Composer 2) Airflow component metrics are now availableon the Monitoring dashboardin the Google Cloud console. This feature was previously available only inCloud Composer 3.

Change

(Airflow 3.1.0 in Cloud Composer 3)Theapache-airflow-providers-google package was upgraded to version 19.4.0.For more information about changes, see theapache-airflow-providers-google changelog.

Fixed

(Available without upgrading) Cloud Composer 3 environment metadata in CloudAsset Inventory now matches the environment configuration available through theCloud Composer API, including the image version format.

Change

Newimagesare available in Cloud Composer 2:

Fixed

(Airflow 2) The Dag Details view in Airflow UI now scrolls correctly when the"Run config" field contains long values.

Feature

TheComposer Local Development CLI toolis now available for Airflow 3 (Preview).

Cloud Logging
Feature

You can now export your Crashlytics data and (optionally) Firebase sessionsdata to Cloud Logging. Once the data is exported, it's also available toCloud Monitoring, so you can filter your logs, build custom dashboards, setup custom alerts, and even export the data to other services. For information about how to export your Crashlytics data, seeExport Crashlytics data toCloud Logging,and for information about howyou can use this data, seeWhat can you do with Crashlytics data inCloud Logging.

Dataplex
Feature

You can control data lineage ingestion for Dataprocat the organization, folder, or project level. This feature is inPreview.For more information, seeControl lineage ingestion.

Google Cloud VMware Engine
Announcement

Stretched private clouds capable of hosting bothve1 andve2 node-familyclusters are now available in the following regions:

  • Sydney, Australia, Asia Pacific (australia-southeast1-a,australia-southeast1-b)
  • Frankfurt, Germany, Europe (europe-west3-a,europe-west3-b)

While a stretched private cloud can contain mixed node families, each individualstretched cluster must be comprised of nodes from the same family type.

Note: To create a new stretched cluster of a different node family, contactCloud Customer Care.
Google Kubernetes Engine
Security

(2026-R4) Security updates

This release includes new GKE versions that use updatedContainer-Optimized OS images. These updated images are cumulative,incorporating security fixes from all Container-Optimized OSversions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updatedContainer-Optimized OS image, see theSecurity release notesfor that image. The following table includes links to the release notes foreach updated Container-Optimized OS image:

GKE versionContainer-Optimized OS versionDetails
1.29.15-gke.2725000cos-113-18244-521-74cos-113-18244-521-74 release notes
1.30.14-gke.1973000cos-113-18244-521-74cos-113-18244-521-74 release notes
1.31.14-gke.1319000cos-117-18613-439-92cos-117-18613-439-92 release notes
1.35.0-gke.2180000cos-125-19216-104-45cos-125-19216-104-45 release notes

Change

(2026-R4) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and formanual control plane upgrades and node upgrades for existing clusters. For moreinformation about versioning and upgrades, seeGKE versioning andsupport andAbout GKEcluster upgrades.

Rapid channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Regular channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Stable channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Extended channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

No channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R4) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R4) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R4) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R4) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R4) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Google SecOps
Feature

Rule observability for detections and alerts

New metadata is now included in all detection and alert objects, indicating ifthe detection was produced during a primary rule run or through arule replay. This information can beused in dashboards and as a filter in theAlerts lister page using the fieldcollection.detection_timing_details.

Google SecOps SIEM
Feature

Enhanced rule observability for detections

Google SecOps now provides increased visibility into detection timing to helpimprove dashboard and reporting accuracy. You can now easily distinguish whethera detection was generated during a primary rule run or through arule replay. This data is availablein dashboards and as a filter in theAlerts lister page using the fieldcollection.detection_timing_details.

Feature

Rule observability for detections and alerts

New metadata is now included in all detection and alert objects, indicating ifthe detection was produced during a primary rule run or through arule replay. This information can beused in dashboards and as a filter in theAlerts lister page using the fieldcollection.detection_timing_details.

Network Intelligence Center
Feature

Connectivity Testsanalyzesfirewall policiesthat apply to managed Envoy proxies.

Vertex AI Workbench
Feature

M139 release

The M139 release of Vertex AI Workbench instances includes the following:

  • Removed a startup script dependency ongs://dl-platform-public-configs.

January 28, 2026

BigQuery
Change

The BigQuery change data capture feature has been renamed toBigQuery change data capture ingestion.

Feature

The BigQuery Data Transfer Service can nowtransfer data from Shopify to BigQuery.This feature is inPreview.

Cloud Load Balancing
Feature

To enhance security and help meet stringent compliance requirements likeFedRAMP, you can now apply a FIPS-compliant SSL policy to yourApplication Load Balancers and proxy Network Load Balancers. This update also introducesthe ability to enforce TLS 1.3 as the minimum protocol version.

NewFIPS_202205 profile

The newFIPS_202205 profile, available as a predefined SSL policy, restrictsthe load balancer to use only FIPS 140-2/140-3 validated cryptographic modulesand ciphers.

When this profile is selected, the load balancer:

  • Enforces strict TLS settings, negotiating connectionsonly using TLS 1.2 or TLS 1.3.
  • Uses a limited set of approved cipher suites for TLS 1.2,such as the cipher suites inECDHE-RSA-AES-GCMandECDHE-ECDSA-AES-GCM families.
  • Excludes non-FIPS ciphers for TLS 1.3, such asTLS_CHACHA20_POLY1305_SHA256.

Minimum TLS 1.3 Enforcement

You can now specify TLS 1.3 as the minimum version for your SSL policy, whichmust be paired with theRESTRICTED profile. If you mandate TLS 1.3 as theminimum version, any clients attempting to connect via TLS 1.2 or lower will berejected. Ensure your client ecosystem supports TLS 1.3 before enforcing thisminimum TLS version.

For more information, see the following:

This feature is inGeneral availability.

Cloud Storage
Feature

Previously, whenlisting buckets by using theclient libraries, JSON API, or RPC API, the request returned an error if somebuckets couldn't be reached because a location was temporarily unavailable. Youcan now use a partial success option to return a list of buckets that areavailable, as well as the names of any buckets that can't be reached.

Cluster Toolkit
Feature

Cluster Toolkit version v1.80.0 is available. This release addssupport for IPv6 and the Infrastructure Data-Plane Function (IDPF). This versionmakes the H4D blueprint more concise by refactoring thevpc andmultivpcmodules to support more variables. Additionally, this release integrates theReport and Replace (R&R) API with Slurm, which lets you report faulty nodes forrepair or replacement.

For more information about this release, see theRelease announcement on GitHub.

Contact Center AI Insights
Feature

Customer Experience Insights offersconfigurable dashboards to view usage and feedback metrics over time. Choose from a wide array of chart types to build your own, or use the AI assistant to build custom dashboards.

Container Optimized OS
Change

cos-117-18613-439-108

KernelDockerContainerdGPU Drivers
COS-6.6.111v24.0.9v1.7.29See List
Security

Fixed CVE-2025-22111 in the Linux kernel.

Security

Updated dev-libs/openssl to v3.0.19. This resolves CVE-2025-15467.

Security

Fixed CVE-2025-71084 in the Linux kernel.

Security

Fixed CVE-2025-68259 in the Linux kernel.

Security

Fixed CVE-2025-71118 in the Linux kernel.

Security

Fixed CVE-2025-68261 in the Linux kernel.

Security

Fixed CVE-2025-71131 in the Linux kernel.

Security

Fixed CVE-2025-13836 in dev-lang/python.

Security

Fixed CVE-2025-68814 in the Linux kernel.

Security

Fixed CVE-2025-68816 in the Linux kernel.

Security

Fixed CVE-2025-38129 in the Linux kernel.

Security

Fixed CVE-2025-71077 in the Linux kernel.

Security

Fixed CVE-2025-71125 in the Linux kernel.

Security

Fixed CVE-2025-38022 in the Linux kernel.

Security

Fixed CVE-2025-68821 in the Linux kernel.

Fixed

Upgraded sys-apps/less to v691.

Security

Fixed CVE-2025-68744 in the Linux kernel.

Security

Fixed CVE-2026-21441 in dev-python/urllib3.

Security

Fixed CVE-2024-57982 in the Linux kernel.

Security

Fixed CVE-2025-71068 in the Linux kernel.

Security

Fixed CVE-2025-71098 in the Linux kernel.

Security

Fixed CVE-2025-13837 in dev-lang/python.

Security

Fixed CVE-2025-71113 in the Linux kernel.

Security

Fixed CVE-2025-68794 in the Linux kernel.

Fixed

Installed app-misc/c_rehash, which was unintentionally removed after the dev-libs/openssl update.

Security

Fixed CVE-2025-71104 in the Linux kernel.

Security

Fixed CVE-2025-68798 in the Linux kernel.

Security

Fixed CVE-2025-68788 in the Linux kernel.

Security

Fixed CVE-2025-68813 in the Linux kernel.

Security

Fixed CVE-2025-68780 in the Linux kernel.

Security

Fixed CVE-2025-68265 in the Linux kernel.

Security

Fixed CVE-2025-68764 in the Linux kernel.

Security

Fixed CVE-2025-68756 in the Linux kernel.

Security

Fixed CVE-2025-68803 in the Linux kernel.

Security

Fixed CVE-2025-68795 in the Linux kernel.

Security

Fixed CVE-2025-68264 in the Linux kernel.

Security

Fixed CVE-2025-71089 in the Linux kernel.

Security

Fixed CVE-2025-68349 in the Linux kernel.

Security

Fixed CVE-2025-71123 in the Linux kernel.

Security

Fixed CVE-2025-68740 in the Linux kernel.

Security

Fixed CVE-2025-71096 in the Linux kernel.

Security

Fixed CVE-2025-71102 in the Linux kernel.

Security

Fixed CVE-2024-49968 in the Linux kernel.

Security

Fixed CVE-2025-71120 in the Linux kernel.

Security

Fixed CVE-2025-68820 in the Linux kernel.

Security

Fixed CVE-2025-68363 in the Linux kernel.

Security

Fixed CVE-2025-68782 in the Linux kernel.

Security

Fixed CVE-2025-68724 in the Linux kernel.

Security

Fixed CVE-2025-68775 in the Linux kernel.

Security

Fixed CVE-2025-68337 in the Linux kernel.

Security

Fixed CVE-2025-71097 in the Linux kernel.

Change

cos-121-18867-294-100

KernelDockerContainerdGPU Drivers
COS-6.6.113v27.5.1v2.0.7See List
Security

Fixed CVE-2025-68814 in the Linux kernel.

Security

Fixed CVE-2025-68740 in the Linux kernel.

Fixed

Upgraded sys-apps/less to v691.

Security

Fixed CVE-2025-68337 in the Linux kernel.

Security

Fixed CVE-2025-71068 in the Linux kernel.

Security

Fixed CVE-2025-71120 in the Linux kernel.

Security

Fixed CVE-2025-68780 in the Linux kernel.

Security

Fixed CVE-2025-68821 in the Linux kernel.

Security

Fixed CVE-2025-71097 in the Linux kernel.

Security

Fixed CVE-2025-68259 in the Linux kernel.

Security

Fixed CVE-2025-68363 in the Linux kernel.

Security

Updated dev-libs/openssl to v3.0.19. This resolves CVE-2025-15467.

Security

Fixed CVE-2025-71118 in the Linux kernel.

Security

Fixed CVE-2025-68775 in the Linux kernel.

Security

Fixed CVE-2025-68820 in the Linux kernel.

Security

Fixed CVE-2025-68724 in the Linux kernel.

Security

Fixed CVE-2025-68756 in the Linux kernel.

Security

Fixed CVE-2025-13837 in dev-lang/python.

Security

Fixed CVE-2025-68744 in the Linux kernel.

Security

Fixed CVE-2025-71104 in the Linux kernel.

Security

Fixed CVE-2025-71077 in the Linux kernel.

Fixed

Installed app-misc/c_rehash, which was unintentionally removed after the dev-libs/openssl update.

Security

Fixed CVE-2025-68816 in the Linux kernel.

Security

Fixed CVE-2025-13836 in dev-lang/python.

Security

Fixed CVE-2025-71125 in the Linux kernel.

Security

Fixed CVE-2025-71102 in the Linux kernel.

Security

Fixed CVE-2025-68349 in the Linux kernel.

Security

Fixed CVE-2025-71084 in the Linux kernel.

Security

Fixed CVE-2025-68264 in the Linux kernel.

Security

Fixed CVE-2025-68798 in the Linux kernel.

Security

Fixed CVE-2025-71123 in the Linux kernel.

Security

Fixed CVE-2025-68795 in the Linux kernel.

Security

Fixed CVE-2025-71131 in the Linux kernel.

Security

Fixed CVE-2025-38022 in the Linux kernel.

Security

Fixed CVE-2026-21441 in dev-python/urllib3.

Security

Fixed CVE-2025-68782 in the Linux kernel.

Security

Fixed CVE-2025-71098 in the Linux kernel.

Security

Fixed CVE-2025-68265 in the Linux kernel.

Security

Fixed CVE-2025-68794 in the Linux kernel.

Fixed

Upgraded app-admin/sosreport to v4.10.2.

Security

Fixed CVE-2025-68261 in the Linux kernel.

Security

Fixed CVE-2025-71089 in the Linux kernel.

Security

Fixed CVE-2025-68788 in the Linux kernel.

Security

Fixed CVE-2025-38129 in the Linux kernel.

Security

Fixed CVE-2025-71096 in the Linux kernel.

Security

Fixed CVE-2025-71113 in the Linux kernel.

Security

Fixed CVE-2025-68764 in the Linux kernel.

Security

Fixed CVE-2025-68813 in the Linux kernel.

Change

cos-113-18244-521-88

KernelDockerContainerdGPU Drivers
COS-6.1.155v24.0.9v1.7.27See List
Security

Fixed CVE-2026-21441 in dev-python/urllib3.

Security

Fixed CVE-2025-68816 in the Linux kernel.

Security

Fixed CVE-2025-68795 in the Linux kernel.

Security

Fixed CVE-2025-71125 in the Linux kernel.

Security

Fixed CVE-2025-13836 in dev-lang/python.

Security

Fixed CVE-2025-71113 in the Linux kernel.

Security

Fixed CVE-2025-13837 in dev-lang/python.

Security

Fixed CVE-2025-71118 in the Linux kernel.

Security

Fixed CVE-2025-71102 in the Linux kernel.

Fixed

Installed app-misc/c_rehash, which was unintentionally removed after the dev-libs/openssl update.

Security

Fixed CVE-2025-71131 in the Linux kernel.

Security

Fixed CVE-2025-71123 in the Linux kernel.

Security

Updated dev-libs/openssl to v3.0.19. This resolves CVE-2025-15467.

Security

Fixed CVE-2025-71120 in the Linux kernel.

Security

Fixed CVE-2025-71104 in the Linux kernel.

Change

cos-125-19216-104-126

KernelDockerContainerdGPU Drivers
COS-6.12.55v27.5.1v2.1.5See List
Fixed

Upgraded sys-apps/less to v691.

Security

Fixed CVE-2025-13836 in dev-lang/python.

Security

Updated dev-libs/openssl to v3.5.5. This resolves CVE-2025-15467.

Security

Fixed CVE-2026-21441 in dev-python/urllib3.

Fixed

Upgraded app-admin/sosreport to v4.10.2.

Dataform
Feature

You canorganize your code assets into a hierarchical structurewith folders and repositories using the Dataform API. This feature is inpreview.

Datastream
Feature

Datastream now supports Spanner as a source. For moreinformation, see theDatastream documentation.

Gemini Enterprise
Feature

Gemini Enterprise: Support for new data stores (Preview)

The following data stores are supported in Gemini Enterprise:

Download file action has been added toDropbox. For a list of actions for all available data stores, seeSupported actions.

Google SecOps Marketplace
Feature

Google Threat Intelligence: Version 8.0

  • The following new actions have been added:

    • Add ASM Issue Note

    • Add Tag To DTM Alert

Change

Google Chronicle: Version 74.0

  • Reverted the JSON result structure for aggregated queries in the followingaction:

    • Execute UDM Query
Change

Google Threat Intelligence: Version 8.0

  • Added the ability to automatically set theis_suspicious flag on entitiesbased on specific GTI score and Engine count thresholds in the followingaction:

    • Enrich Entities
  • Added the ability to flag entities asis_risky within the JSON output whenGTI scores or Engine counts meet specified criteria to the following action:

    • Submit File
Change

Siemplify: Version 101.0

  • Added support to set custom fields upon alert closure to the following action:

    • Close Alert
  • Added support to set custom fields upon case closure to the following action:

    • Close Case
Change

Salesforce: Version 14.0

  • Integration: Updated the Salesforce SDK to the latest version
Change

Proofpoint Cloud Threat Response: Version 2.0

  • Integration: Updated dependencies.
Change

Jira: Version 52.0

  • Optimized ticket processing workflows in the following job:

    • Sync Closure Job
Change

Azure Active Directory: Version 22.0

  • Added the ability to fetch MFA information to the following actions:

    • Enrich User

    • Get Manager Contact Details

Looker
Feature

You can now view the publicegress IP addresses for Looker (Google Cloud core) instances that use Private Service Connect and controlled native egress. These IP addresses may be used when setting upoutbound connections.

Spanner
Feature

Spanner supports the following compression functions:

These functions use the Zstandard (Zstd) lossless data compression algorithm tocompress and decompressSTRING orBYTES values. For more information, seeCompression functions.

January 27, 2026

AlloyDB for PostgreSQL
Feature

Database server compatibility with PostgreSQL version 18 is now available forpreview (Preview).You cancreate AlloyDB clusterswith PostgreSQL 18 compatibility.

Apigee UI
Fixed

Show all rows in the Debug properties panel

Fixed an issue where only the first 50 rows were displayed in the Debugproperties panel, including the variables tab. The Debug properties table nowdisplays up to 200 rows per page by default. Pagination controls are displayedif the total number of rows exceeds 200.

Announcement

On January 27, 2026, we released an updated version of the Apigee UI.

App Engine flexible environment .NET
Feature

Support for.NET 10 runtime is inPreview.

BigQuery
Feature

The BigQuery Data Transfer Service can nowtransfer data from Mailchimp to BigQuery.This feature is inPreview.

Change

An updated version of theSimba JDBC driver for BigQueryis now available.

Cloud Run
Feature

Support for.NET 10 runtime is inPreview.

Cloud Run functions
Feature

Support for.NET 10 runtime is inPreview.

Config Connector
Feature

#6065: Enabled Vertical Pod Autoscaler (VPA) support. You can enable VPA for Config Connector components viaControllerResource andNamespacedControllerResource to automatically adjust resource requests.

Announcement

Config Connector version 1.134.4 is now available.

Fixed

Bug Fixes:

  • #6035: Fixed an issue wheremanagedFields metadata could be incorrectly attributed to thestatus subresource during spec updates, causing "Location must be set" errors.
Document AIGemini Enterprise
Change

Gemini Enterprise: Autocomplete turned off in the chat box

The autocomplete menu no longer appears as a user types in the chat box. Userscan still use the mentions feature by typing@ in the chat box, followed bythe name of an agent, person, or file. For more information about mentions, seeAdd context with mentions.

Google Kubernetes Engine
Feature

Stream Control Transmission Protocol (SCTP) support on GKE Dataplane V2 is nowgenerally available (GA). You can now deploy workloads that use SCTP onGKE Standard clusters. This feature enables direct SCTPcommunication for Pod-to-Pod and Pod-to-Service traffic.

SCTP support requires clusters to use GKE Dataplane V2 and Ubuntu node images.This feature is available in GKE version 1.32.2-gke.1297000 orlater.

For more information, seeDeploy workloads withSCTP.

January 26, 2026

Backup and DR
Fixed

Backup/Recovery appliance non-disruptive update:

  • Database Restore & Management: Resolved SAP HANA differential restore failuresand Oracle "Mount and Migrate" disk eligibility issues, while enhancing Db2 logpurging and HANA /etc/fstab cleanup.
  • System Stability: Improved reliability by addressing gpdmgr memory leaks,preventing udpengine crashes during OnVault jobs, and enabling size-based logrotation.
  • API & Infrastructure: Optimized host discovery and API performance, includingsupport for duplicate VM names, subnet pagination, and the removal of deprecatedNFS options.
BigQuery
Feature

You can now use Gemini Cloud Assist todiscover resourcesacross your projects. For example, you can ask about a specific table's schema,or which tables contain demographic information about new users. This feature isinPreview.

Cloud Logging
Change

To support correlation between log and trace data, the following changes havebeen made:

  • The required format for theLogEntry.trace field has been relaxed. Thepreferred format for this field is the trace ID. However, you can continueto provide the full resource name. For more information, seeLogEntry.

  • If you open theTrace Details flyout page by using options provided in alog entry, then the resources listed in the default trace scope are searchedfor the trace data.

  • If you open theLogs Explorer page by using options on span data, thenthe resources listed in the default log scope are searched for log data.

To learn more about default scopes, seeConfigure observability scopes for multi-project queries.

Feature

You can now install and manage the Ops Agent on virtual machines across zones inyour Google Cloud project by using global VM Extension Manager extensionpolicies. Global and zonal extension policies can keep the installed versionof the agent current, keep a specified version of the agent installed, andother tasks. For more information, seeInstall and manage the Ops Agent by usingVM Extension Manager policies.

Cloud Monitoring
Feature

You can now install and manage the Ops Agent on virtual machines across zones inyour Google Cloud project by using global VM Extension Manager extensionpolicies. Global and zonal extension policies can keep the installed versionof the agent current, keep a specified version of the agent installed, andother tasks. For more information, seeInstall and manage the Ops Agent by usingVM Extension Manager policies.

Cloud SQL for MySQL
Feature

You can now assign database roles to built-in database users and IAM databaseusers when you create or update users. For more information about assigningroles, seebuilt-in database authenticationorIAM database authentication.

Cloud SQL for PostgreSQL
Feature

You can now assign database roles to built-in database users and IAM databaseusers when you create or update users. For more information about assigningroles, seebuilt-in database authenticationorIAM database authentication.

Cloud Trace
Change

To support correlation between log and trace data, the following changes havebeen made:

  • The required format for theLogEntry.trace field has been relaxed. Thepreferred format for this field is the trace ID. However, you can continueto provide the full resource name. For more information, seeLogEntry.

  • If you open theTrace Details flyout page by using options provided in alog entry, then the resources listed in the default trace scope are searchedfor the trace data.

  • If you open theLogs Explorer page by using options on span data, thenthe resources listed in the default log scope are searched for log data.

To learn more about default scopes, seeConfigure observability scopes for multi-project queries.

Compute Engine
Feature

Generally available: The N4A machine family is powered by Google's latestcustom-designed Axion processor, built on Arm Neoverse N3 compute core andpowered by Titanium IPU. This machine family has between 1-64 vCPUs with up to512 GB of memory, and supports Google Cloud Hyperdisk volume storage.It is available instandard,highmem,highcpu, and custom machine types.For detailed information, seeGeneral-purpose machines.SeeRegions and zones to learn where you cancreate N4A VMs.

Gemini Enterprise
Announcement

Gemini Enterprise: Visual flow builder for existing agents

The Agent Designer visual flow builder is available for all agents createdbefore January 12, 2026. You can manage these agents directly from theAgent Gallery page, or edit their logicusing the enhanced visual flow builder from theAgent Designer > Flow tab.

For more information, seeAgent Designer overview.

Google Kubernetes Engine
Feature

TheN4A machineseriesis generally available for GKE clusters in Autopilot andStandard modes. For more information, seeArm workloads onGKE.

Google SecOps SIEM
Feature

Timeline View for Alerts

Visualize alert patterns over time using the new timeline view in theAlerts section of theCases Overview tab.

Google SecOps SOAR
Feature

Timeline View for Alerts

Visualize alert patterns over time using the new timeline view in theAlerts section of theCases Overview tab.

Looker
Feature

Available January 29, 2026: Conversational Analytics includes aShow reasoning toggle that provides step-by-step insight into how the agent reaches its answers. This update also includes improvements to overall answer accuracy. See theConversational Analytics API documentation for details.

Feature

Updates to theContinuous Integration (CI) feature will be available in February, 2026.

Note: This item was added on January 28, 2026 and updated on January 30, 2026.

Feature
Feature

Now available in preview, theConfiguration tab of theProjects Settings page in the Looker IDE contains aDelete Developer Copy button that lets LookML developers delete their local developer copy of the project's Git repository. See theUsing version control and deploying documentation page for details.

Announcement

Looker 26.0 includes the following feature updates, which will start rolling out on January 26, 2026:

Feature

TheSelf-service Explores admin page now supports a connection test button so that Looker admins can verify that the BigQuery connection is able to support self-service Explores.

Feature

TheTabbed Dashboards Labs feature is now available. The Tabbed Dashboards Labs feature lets dashboard editors organize dashboard content across multiple tabs within a single dashboard. Adding tabs to dashboards lets you do the following:

  • Better organize content: Group related visualizations and tiles into separate tabs.
  • Improve data storytelling: Guide viewers through different aspects of your data in a structured way.
  • Enhance performance: Load only the tiles on an active tab, potentially speeding up initial dashboard load times.
  • Reduce clutter: Consolidate multiple related analyses into a single dashboard.

This feature is only for Looker (original) instances and is enabled by default.

Feature

TheDashboard Filter Enhancements Labs feature is now available. The Dashboard Filter Enhancements Labs feature includes the following improvements:

  • Persistent filter suggestion drop-down: Filter suggestion drop-downs remain open for easier multi-selection fortag list andadvanced filter type filters.
  • Select or deselect all filter values: Lets users select or deselect all values in tag list and advanced filter type filters.
  • Limit condition controls for advanced filters: Lets dashboard creators limit the condition options that are available to users for advanced filters.
  • EnableInclude custom filter values by default for boards: Admins can choose to enable Include custom filter values for boards by default instance-wide.

This feature is only for Looker (original) instances and is enabled by default.

Feature

TheCustom Tooltips Labs feature is now available. The Custom Tooltips Labs feature lets you configure tooltips within the Explorevisualization editor using a combination of UI settings and an HTML editor that supports Liquid templating.

This feature is only for Looker (original) instances and is enabled by default.

Spanner
Feature

Columnar engine for Spanner is now inPublicPreview. Columnarengine is a storage technique used with analytical queries to speed up scans upto 200 times faster on live operational data without affecting transactionworkloads. In databases or tables enabled with columnar engine, this release:

  • Supports the ability to execute columnar queries automatically and performfaster columnar scans using vectorized execution.
  • Provides a newmajor compaction APIto accelerate the conversion of non-columnar data into columnar data.

For more information, see theColumnar engine for Spanner overview.

Vertex AI Agent Builder
Announcement

Vertex AI Agent Builder

Sessions, Memory Bank, and Code Execution will begin charging for usage onFeburary 11, 2026 instead of January 28, 2026.

January 25, 2026

Google SecOps
Announcement

Integration Rollback

ThisIntegration Rollback feature is now in General Availability (GA).

Rollback is not supported for integrations built for Python 2.7 or 3.7. To perform a rollback, a snapshot must have been created during the previous upgrade process.For more information, seeRoll back response integration version.

Feature

Timeline View for Alerts

Visualize alert patterns over time using the new timeline view in the Alerts section of the Cases Overview tab.

Feature

Structured SOAR Python integration logs

Python integration logging has been upgraded to a structured format to eliminate visibility gaps and ensure comprehensive diagnostic coverage in Google Cloud.This upgrade changes how Python logs are interpreted in the Google Cloud Logging Explorer. Previously, logs were bundled into a single block per execution. Now, every log line is interpreted as a separate entry, allowing for granular filtering, better searchability, and easier debugging of specific events.

Recommended Actions:

  • Update Log-Based Alerts: Ensure alerts triggered by string matches are compatible with individual log entries rather than bundled blocks.
  • Review Automation Scripts: Test any external scripts or BigQuery exports that parse textPayload against the new granular format.
  • Verify Dashboards: Custom monitoring dashboards may show an increase in event counts as executions are no longer bundled.

For more information, seeCollect Google SecOps SOAR logs.

Google SecOps SIEM
Announcement

Integration Rollback

ThisIntegration Rollback feature is now in General Availability (GA).

Rollback is not supported for integrations built for Python 2.7 or 3.7. To perform a rollback, a snapshot must have been created during the previous upgrade process.For more information, seeRoll back response integration version.

Feature

Timeline View for Alerts

Visualize alert patterns over time using the new timeline view in the Alerts section of the Cases Overview tab.

Feature

Structured SOAR Python integration logs

Python integration logging has been upgraded to a structured format to eliminate visibility gaps and ensure comprehensive diagnostic coverage in Google Cloud.This upgrade changes how Python logs are interpreted in the Google Cloud Logging Explorer. Previously, logs were bundled into a single block per execution. Now, every log line is interpreted as a separate entry, allowing for granular filtering, better searchability, and easier debugging of specific events.

Recommended Actions:

  • Update Log-Based Alerts: Ensure alerts triggered by string matches are compatible with individual log entries rather than bundled blocks.
  • Review Automation Scripts: Test any external scripts or BigQuery exports that parse textPayload against the new granular format.
  • Verify Dashboards: Custom monitoring dashboards may show an increase in event counts as executions are no longer bundled.

For more information, seeCollect Google SecOps SOAR logs.

Announcement

Integration Rollback

ThisIntegration Rollback feature is now in General Availability (GA).

Rollback is not supported for integrations built for Python 2.7 or 3.7. To perform a rollback, a snapshot must have been created during the previous upgrade process.For more information, seeRoll back response integration version.

Feature

Structured SOAR Python integration logs

Python integration logging has been upgraded to a structured format to eliminate visibility gaps and ensure comprehensive diagnostic coverage in Google Cloud.
This upgrade changes how Python logs are interpreted in the GCP Cloud Logging Explorer. Previously, logs were bundled into a single block per execution. Now, every log line is interpreted as a separate entry, allowing for granular filtering, better searchability, and easier debugging of specific events.

Recommended Actions:

  • Update Log-Based Alerts: Ensure alerts triggered by string matches are compatible with individual log entries rather than bundled blocks.
  • Review Automation Scripts: Test any external scripts or BigQuery exports that parse textPayload against the new granular format.
  • Verify Dashboards: Custom monitoring dashboards may show an increase in event counts as executions are no longer bundled.

For more information, seeCollect SOAR logs.

Announcement

Release 6.3.73 is being rolled out to the first phase of regions as listedhere.

This release contains the following changes:

Google SecOps SOAR
Announcement

Integration Rollback

ThisIntegration Rollback feature is now in General Availability (GA).

Rollback is not supported for integrations built for Python 2.7 or 3.7. To perform a rollback, a snapshot must have been created during the previous upgrade process.For more information, seeRoll back response integration version.

Feature

Structured SOAR Python integration logs

Python integration logging has been upgraded to a structured format to eliminate visibility gaps and ensure comprehensive diagnostic coverage in Google Cloud.
This upgrade changes how Python logs are interpreted in the GCP Cloud Logging Explorer. Previously, logs were bundled into a single block per execution. Now, every log line is interpreted as a separate entry, allowing for granular filtering, better searchability, and easier debugging of specific events.

Recommended Actions:

  • Update Log-Based Alerts: Ensure alerts triggered by string matches are compatible with individual log entries rather than bundled blocks.
  • Review Automation Scripts: Test any external scripts or BigQuery exports that parse textPayload against the new granular format.
  • Verify Dashboards: Custom monitoring dashboards may show an increase in event counts as executions are no longer bundled.

For more information, seeCollect SOAR logs.

Announcement

Release 6.3.73 is being rolled out to the first phase of regions as listedhere.

This release contains the following changes:

January 24, 2026

Dataproc
Feature

Upgraded the Delta subminor version to3.2.1 in images2.2 and2.3.

Fixed

Fixed a bug in the ARM image that prevented connecting to a Dataproc Metastore instance with agRPC protocol endpoint.

Fixed

Fixed thespark.driver.extraClassPath delimiter for the Jupyter SparkMonitor Listener.

Announcement

NewDataproc on Compute Engine subminor image versions:

  • 2.0.157-debian10, 2.0.157-ubuntu18, 2.0.157-rocky8
  • 2.1.106-debian11, 2.1.106-ubuntu20, 2.1.106-ubuntu20-arm, 2.1.106-rocky8
  • 2.2.74-debian12, 2.2.74-ubuntu22, 2.2.74-ubuntu22-arm, 2.2.74-rocky9
  • 2.3.21-debian12, 2.3.21-ml-ubuntu22, 2.3.21-rocky9, 2.3.21-ubuntu22, 2.3.21-ubuntu22-arm

Rollback Notice: These image versions were rolled back onJanuary 30, 2026.

Feature

Added a newdataproc:pypi.repository property to customize the PyPI repository thatpip uses.The value can be a internet-accessible URL, or you can specifygoogle to use a Google-hosted cache of PyPI, whichis accessible without public internet connectivity. Starting with Dataproc image version3.1,google will be the default (you can specify thepypi property value to use public PyPI instead of the defaultgoogle 3.1 value).

Feature

Apache Pig is now available in ARM images.

Change

Removed the use of deprecated Hadoop configuration propertiesfs.default.name andyarn.resourcemanager.system-metrics-publisher.enabled.

Google SecOps SIEM
Announcement

Release 6.3.72 is now available for all regions.

Google SecOps SOAR
Announcement

Release 6.3.72 is now available for all regions.

January 23, 2026

Access Approval
Feature

Automotive AI Agent is generally available(GA).

Access Transparency
Feature

Automotive AI Agent is generally available(GA).

BigQuery
Change

You can now optionally specify which model to use by passing an endpointargument to theAI.IF,AI.SCORE,andAI.CLASSIFYfunctions.

Cloud Deploy
Change

The limit on deployment minutes per delivery pipeline has been removed. The onlyquota now enforced in Cloud Deploy is the system limit of 18,000 APIrequests per minute per region.Learn more.

Cloud Load Balancing
Feature

Application Load Balancers now support the configuration of atraffic durationsetting when you add backends to the backend services. You can configure thissetting asSHORT orLONG based on the response time needed by backends tocomplete HTTP requests.

Application Load Balancers also support the use of a newin-flight balancing modethat lets you configure the load balancer's traffic distribution to supportedbackends when requests take more than a second to complete.

This feature is available inPreview.

Cloud SQL for MySQL
Feature

Cloud SQL for MySQL now supports performance capture to help you diagnosetransient performance issues with your MySQL database. Performance capturelets you specify configurable thresholds for additional monitoring. If athreshold is reached, then performance capture takes snapshots of the databasestate, including in-flight transactions, InnoDB status, and, in the case ofreplication lag, detailed replication status. Performance capture outputs thesnapshots in a log format so you can review the state of the instance whenthe problem occurred.

For more information, seeCloud SQL performance capture overview.Performance capture is inPreview.

Config Connector
Feature

New Fields:

  • AlloyDBInstance
    • Addedspec.connectionPoolConfig field.
    • Addedstatus.connectionPoolConfig field.
Announcement

Config Connector version 1.143.0 is now available.

Feature

New Beta Resources (Direct Reconciler):

  • ArtifactRegistryRepository
  • LoggingLink
  • MemorystoreInstance
  • PrivateCACAPool
Feature

New Alpha Resources (Direct Reconciler):

  • ParameterManagerParameter
Feature

New Features:

  • SetGOMEMLIMIT for KCC workloads to improve memory management and stability.
Change

Reconciliation Improvements:

  • TagsTagBinding

    • Added support fororganizations inparentRef.
    • Added support for multiple targets inparentRef.
  • Resource References (refs.Ref) support added for the following resources to improve reference resolution:

    • BigQueryTable
    • BigQueryDataset
    • CloudRunService
    • CloudRunJob
    • ArtifactRegistryRepository
    • StorageBucket
Fixed

Bug Fixes:

  • Issue 6221:ComputeBackendService can now correctly refer toclientTLSPolicy.
  • Issue 6156:BigQueryTable now ignoresint64 toint32 schema changes when configured.
  • Issue 6026: Fixed identity parsing forTagsTagValue.
Container Optimized OS
Change

cos-125-19216-104-117

KernelDockerContainerdGPU Drivers
COS-6.12.55v27.5.1v2.1.5See List
Fixed

Fixed a performance issue in TCPX.

Security

Fixed CVE-2025-71141 in the Linux kernel.

Security

Fixed CVE-2025-13837 in dev-lang/python.

Dataproc
Fixed
Announcement
Gemini
Other

Bug fixes in VS Code

Various bug fixes and minor product enhancements.

Gemini Enterprise
Feature

Gemini Enterprise: New actions in the unified view (Preview)

New actions have been added to the following data stores:

Generative AI on Vertex AI
Feature

Virtual Try-On

Virtual Try-On is nowgenerally available(GA).The new endpoint,virtual-try-on-001,replaces the previous endpoint,virtual-try-on-preview-08-04. Werecommend changing to the new endpoint as soon as possible.

For more information, seeGenerate Virtual Try-On Images.

Memorystore for Valkey
Feature

Addedsupport for Valkey version9.0. As a result, you can now upgrade the version of your Memorystore for Valkeyinstance to 9.0. For more information, seeAbout upgrading the Valkey version of an instance. This feature is available inPreview.

January 22, 2026

BigQuery
Change

You can now run queries that use theAI.IF,AI.SCORE,andAI.CLASSIFYfunctions by using yourend-user credentials instead of aBigQuery connection.

Fixed
Buildpacks
Feature

The Python buildpack supports default entrypoint detection for theAgent Development Kit (ADK) framework inGeneral Availability. For more information, seeBuild a Python application.

Cloud Run
Feature

The Python buildpack supports default entrypoint detection for theAgent Development Kit (ADK) framework inGeneral Availability. For more information, seeBuild a Python application.

Generative AI on Vertex AI
Announcement

Codestral (25.01) and Mistral Large (24.11) are retired as of January 23, 2026.

SAP on Google Cloud
Announcement

BigQuery Connector for SAP version 2.12

Version 2.12 of the BigQuery Connector for SAP is generally available (GA).This version offers file-based replication to Cloud Storage,table schema caching for streaming replication to BigQuery,and enhanced Unicode data handling.

For more information, seeWhat's new with BigQuery Connector for SAP.

VPC Service Controls
Feature

General availability support for the following integration:

January 21, 2026

AlloyDB for PostgreSQL
Issue

Automatic IAM authentication is unavailable when you use managed connectionpooling with the AlloyDB Auth Proxy and Language Connectors. To sign into yourdatabase without a password, use manual IAM authentication. For moreinformation, seeConnect using an IAM account

Apigee X
Security
Bug IDDescription
471001896, 469829527, 470953822, 462478248, 474415498Security fix for Apigee infrastructure.

This addresses the following vulnerabilities:

Fixed
Bug IDDescription
433999957Implemented full TLS validation when fetching JWKS from remote URIs
467762922Quota enforcement logic for Server-Sent Events (SSE) updated

Quotas for SSE are now calculated strictly for events containing explicit token counts. The quota enforcement logic skips SSE that lack token usage metadata.

N/AUpdates to security, infrastructure, and libraries.
Artifact RegistryBigQuery
Feature

You can now use Gemini Cloud Assist toget information about your job history,such as why a particular query was slow or which queries were the mostresource-intensive in the past day. This feature is inPreview.

Change

BigQuery is now available in theBangkok (asia-southeast3) region.

Bigtable
Feature

Bigtable is available in theasia-southeast3 (Bangkok) region. For moreinformation, seeBigtable locations.

Cloud Billing
Feature

CUD recommendations support more machine types

Resource-based CUD recommendations for cores and RAM now support additionalmachine series. For a complete list, seeResource-based CUDs supported by recommendations.

You can access these recommendations using theFinOps hub userinterface, programmaticallyusing theRecommender API, or when youexport recommendations to BigQuery.

Cloud Monitoring
Feature

Your Application Monitoring dashboards now display the trace spans that areassociated with your registered App Hub applications. The displayincludes annotations that let you identify services and workloads. You can alsoopen the Trace Explorer page from your Application Monitoring dashboards.To learn more, see the following documents:

Cloud SQL for MySQL
Change

Cloud SQL for MySQL 8.0.43 is now thedefault minor versionof Cloud SQL for MySQL 8.0.

If you have automatic minor version upgrade enabled for your instance,then your instance is upgraded to the default minor version automatically duringits regularly scheduled maintenance update.

For more information about automatic minor version upgrade, seeUpgrade the database minor version of MySQL 8.0.

Cloud Storage
Feature

Bucket relocation with write downtime now supports completed multipart uploads.If a multipart upload is started before relocation begins and is completedbefore the final synchronization step, the objects are successfully relocated.In-progress multipart uploads continue to block the final synchronizationstep until they are either completed or cancelled. For more information, seeBucket relocation overview.

Cluster Toolkit
Feature

Cluster Toolkit version v1.79.0 is available. This release enablesDynamic Workload SchedulerFlex-start provisioning for G4 instances.

For more information about this release and other minor changes, see theRelease announcement onGitHub.

Colab Enterprise
Feature

BigFrames, BigQuery ML, and Google Cloud Serverless for Apache Spark

The Data Science Agent supports BigFrames, BigQuery ML, andGoogle Cloud Serverless for Apache Spark. Previously, these capabilities were supportedonly when using Colab Enterprise notebooks in BigQuery.

Google Kubernetes Engine
Security

(2026-R3) Security updates

This release includes new GKE versions that use updatedContainer-Optimized OS images. These updated images are cumulative,incorporating security fixes from all Container-Optimized OSversions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updatedContainer-Optimized OS image, see theSecurity release notesfor that image. The following table includes links to the release notes foreach updated Container-Optimized OS image:

GKE versionContainer-Optimized OS versionDetails
1.29.15-gke.2680000cos-113-18244-521-56cos-113-18244-521-56 release notes
1.30.14-gke.1922000cos-113-18244-521-56cos-113-18244-521-56 release notes
1.31.14-gke.1243000cos-117-18613-439-81cos-117-18613-439-81 release notes
1.32.11-gke.1075000cos-117-18613-439-81cos-117-18613-439-81 release notes
1.35.0-gke.1795000cos-125-19216-104-45cos-125-19216-104-45 release notes

Change

(2026-R3) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and formanual control plane upgrades and node upgrades for existing clusters. For moreinformation about versioning and upgrades, seeGKE versioning andsupport andAbout GKEcluster upgrades.

Rapid channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Regular channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Stable channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
  • Version1.33.5-gke.2019000 is now the default version for cluster creation in the Stable channel.
  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.31.14-gke.1081000
    • 1.31.14-gke.1114000
    • 1.32.9-gke.1632000
    • 1.33.5-gke.1956000
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Extended channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

No channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R3) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Feature

You can now determine which Kubernetes JobSets are scheduled on whichGKE node pools and nodes by monitoring the new generallyavailable system metrics:

  • kubernetes.io/jobset/assigned_node_pools: GKE node poolswhere a Kubernetes JobSet has scheduled Pods.
  • kubernetes.io/jobset/assigned_nodes: GKE nodes where aKubernetes JobSet has scheduled Pods.
  • kubernetes.io/node_pool/assigned_jobsets: Kubernetes JobSets that havescheduled Pods on a GKE node pool.
  • kubernetes.io/node/assigned_jobsets: Kubernetes JobSets that havescheduled Pods on a GKE node.
Change

(2026-R3) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R3) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R3) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R3) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
  • Version1.33.5-gke.2019000 is now the default version for cluster creation in the Stable channel.
  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.31.14-gke.1081000
    • 1.31.14-gke.1114000
    • 1.32.9-gke.1632000
    • 1.33.5-gke.1956000
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
Google SecOps
Announcement

New parser documentation now available

New parser documentation is available to help you ingest and normalize logs from the following sources:

Feature

Direct ingestion for Google Cloud Model Armor logs

You can now ingest Google Cloud Model Armor logs (GCP_MODEL_ARMOR) directly into GoogleSecOps. Use an export filter for direct ingestion and access the logs throughGoogle Cloud logging. Model Armor logs provide a unified window into AI-specificthreats, such as prompt injection and sensitive data leakage.

For more information, seeModel Armor Documentation to Configure Logging.

Google SecOps Marketplace
Feature

NewAzure API integration

Feature

Okta: Version 13.0

  • The following new action has been added:

    • Clear Okta User Session
Change

Azure Active Directory: Version 21.0

  • Updated the JSON result example of the following action:

    • List Members in The Group
  • Added more metadata to the JSON result example of the following action:

    • List Groups
Change

Google Cloud API: Version 7.0

  • UpdatedExpected Response Values description in the following action:

    • Execute HTTP Request
Change

Google Chronicle: Version 73.0

  • Updated the processing of queries in the following action:

    • Execute UDM Query
Change

QRadar: Version 62.0

  • Updated the event processing logic of the following connector:

    • QRadar Correlations Connector V2
Change

Microsoft 365 Defender: Version 22.0

  • Updated the tracking logic for alerts in the following connector:

    • Microsoft 365 Defender - Incidents Connector
Change

HTTP v2: Version 12.0

  • UpdatedExpected Response Values description in the following action:

    • Execute HTTP Request
Change

Netskope: Version 14.0

  • Refactored the following action:

    • Ping
Google SecOps SIEM
Announcement

New parser documentation now available

New parser documentation is available to help you ingest and normalize logs from the following sources:

Feature

Direct ingestion for Google Cloud Model Armor logs

You can now ingest Google Cloud Model Armor logs (GCP_MODEL_ARMOR) directly into GoogleSecOps. Use an export filter for direct ingestion and access the logs throughGoogle Cloud logging. Model Armor logs provide a unified window into AI-specificthreats, such as prompt injection and sensitive data leakage.

For more information, seeModel Armor Documentation to Configure Logging.

Announcement

New parser documentation now available

New parser documentation is available to help you ingest and normalize logs from the following sources:

Feature

Direct ingestion for Google Cloud Model Armor logs

You can now ingest Google Cloud Model Armor logs (GCP_MODEL_ARMOR) directly into GoogleSecOps. Use an export filter for direct ingestion and access the logs throughGoogle Cloud logging. Model Armor logs provide a unified window into AI-specificthreats, such as prompt injection and sensitive data leakage.

For more information, seeModel Armor Documentation to Configure Logging.

January 20, 2026

AlloyDB for PostgreSQL
Feature

You cancreate AlloyDB cluster instancesin Bangkok, Thailand (asia-southeast3). For more information, seeAlloyDB locations andAlloyDB for PostgreSQL pricing.

Apigee UI
Deprecated

Debug v1 turndown

As of January 20, 2026, Debug v1 has been turned down and is no longeravailable. Please useDebug v2(now referred to as Debug) for debugging API proxies.

Artifact Registry
Feature

Artifact Registry now calculates fingerprints for each version of a packagepushed to the Artifact Registry repository. You can use the fingerprint tovalidate that the package wasn't modified when moving between Google Cloudsystems, such as Compute Engine and Cloud Build.This feature is inpublic preview.For more information,seeUse fingerprints to verify package version identities.

Backup and DR
Feature

Cost reports are now generally available for Backup and DR Service. Use cost reportsto view resource specific Backup & DR Billing costs to gain granular insightsinto service spend and take actions to optimize resource allocation.

Cloud Interconnect
Feature

Dedicated Cloud Interconnect support is available in the following colocation facilities:

  • Bangkok, Thailand

For more information, see theLocations tableandGlobal locations.

Cloud Key Management Service
Feature

Cloud KMS is available in the following region:

  • asia-southeast3

For more information, seeCloud KMS locations.

Cloud Logging
Announcement

Cloud Logging adds support for theasia-southeast3 region. For a completelist of supported regions, seeSupported regions.

Cloud Run
Feature

The following new region is now available:asia-southeast3.

Cloud Service Mesh
Announcement

1.27.5-asm.0 is now available for in-cluster Cloud Service Mesh.

You can now download 1.27.5-asm.0 for in-cluster Cloud Service Mesh. It includesthe features ofIstio 1.27.5subject to the list ofsupported features.Cloud Service Mesh version 1.27.5-asm.0 uses envoy v1.35.9-dev.

For details on upgrading Cloud Service Mesh, seeUpgrade Cloud Service Mesh.

Announcement

1.28.2-asm.4 is now available for in-cluster Cloud Service Mesh.

You can now download 1.28.2-asm.4 for in-cluster Cloud Service Mesh. It includes the features ofIstio 1.28.0 subject to the list ofsupported features.

The following environment variables, fields, and annotations are not supported:

  • PILOT_SPAWN_UPSTREAM_SPAN_FOR_GATEWAY
  • Additional attributes forHTTPCookie in the DestinationRule API
  • caCertCredentialName field in ServerTLSSettings API
  • OptionalNetworkPolicy for Istiod deployment
  • Disable shadow host suffix
  • MAX_CONNECTIONS_PER_SOCKET_EVENT_LOOP

Istio dual stack is not supported

Istio's experimental feature to enable lazy subset creation of envoy statisticsis not supported.

TheENABLE_AUTO_SNI flag is still supported to stay aligned with legacybehavior.

For details on upgrading Cloud Service Mesh, seeUpgrade Cloud Service Mesh. Cloud Service Mesh version 1.28.2-asm.4 uses Envoy v1.36.5-dev.

Announcement

In-cluster Cloud Service Mesh 1.25 is no longer supported. For more information and to view the earliest end-of-life dates for other versions, seeSupported versions.

Announcement

1.26.8-asm.1 is now available for in-cluster Cloud Service Mesh.

You can now download 1.26.8-asm.1 for in-cluster Cloud Service Mesh. It includesthe features ofIstio 1.26.8subject to the list ofsupported features.Cloud Service Mesh version 1.26.8-asm.1 uses envoy v1.34.11.

For details on upgrading Cloud Service Mesh, seeUpgrade Cloud Service Mesh.

Cloud Storage
Feature

Cloud Storage now offers support in the Thailand, Bangkok (asia-southeast3)region. To learn more about supported locations, seeCloud Storage bucketlocations.

Cloud VPN
Feature

Cloud VPN is now available inregionasia-southeast3 (Bangkok, Thailand).For more information, seeGlobal locations.

Pricing is available on theCloud VPN pricing page.

Compute Engine
Feature

Generally available: You can create N4, C4, M4, and M3 VM instances inBangkok, Thailandasia-southeast3-a,b,c. To learn more about thesemachine types, seeGeneral-purpose machines andMemory-optimized machines.

Container Optimized OS
Change

cos-125-19216-104-113

KernelDockerContainerdGPU Drivers
COS-6.12.55v27.5.1v2.1.5See List
Security

Fixed CVE-2025-68810 in the Linux kernel.

Security

Fixed CVE-2025-71098 in the Linux kernel.

Security

Fixed CVE-2025-68261 in the Linux kernel.

Security

Fixed CVE-2025-68259 in the Linux kernel.

Change

Applied ethtool ring length changes to a4x's first Diorite interface.

Security

Fixed CVE-2025-71113 in the Linux kernel.

Security

Fixed CVE-2025-68816 in the Linux kernel.

Security

Fixed CVE-2025-68372 in the Linux kernel.

Security

Fixed CVE-2025-71067 in the Linux kernel.

Security

Fixed CVE-2025-71068 in the Linux kernel.

Security

Fixed CVE-2025-68374 in the Linux kernel.

Security

Fixed CVE-2025-71104 in the Linux kernel.

Security

Fixed CVE-2025-68778 in the Linux kernel.

Security

Applied urllib3 patch for CVE-2024-37891.

Security

Fixed CVE-2025-68206 in the Linux kernel.

Feature

Enabled guest support for NVIDIA virtual command queues (CMDQV).

Security

Fixed CVE-2025-68775 in the Linux kernel.

Security

Fixed CVE-2025-61727 in dev-lang/go.

Security

Fixed CVE-2025-68363 in the Linux kernel.

Security

Fixed CVE-2025-71131 in the Linux kernel.

Security

Fixed CVE-2025-71072 in the Linux kernel.

Security

Fixed CVE-2025-61729 in dev-lang/go.

Security

Fixed CVE-2025-71089 in the Linux kernel.

Security

Fixed CVE-2025-68801 in the Linux kernel.

Fixed

Updated cos-gpu-installer to v2.5.10.

Security

Fixed CVE-2025-68814 in the Linux kernel.

Security

Fixed CVE-2025-71118 in the Linux kernel.

Security

Fixed CVE-2025-68803 in the Linux kernel.

Security

Fixed CVE-2025-68740 in the Linux kernel.

Security

Fixed CVE-2025-68782 in the Linux kernel.

Security

Fixed CVE-2025-68366 in the Linux kernel.

Security

Fixed CVE-2025-68780 in the Linux kernel.

Security

Fixed CVE-2025-68349 in the Linux kernel.

Security

Fixed CVE-2025-71097 in the Linux kernel.

Security

Fixed CVE-2025-71125 in the Linux kernel.

Security

Fixed CVE-2025-68369 in the Linux kernel.

Security

Fixed CVE-2025-68265 in the Linux kernel.

Security

Fixed CVE-2025-12084 in dev-lang/python.

Security

Fixed CVE-2025-68744 in the Linux kernel.

Security

Fixed CVE-2025-71134 in the Linux kernel.

Security

Fixed CVE-2025-68724 in the Linux kernel.

Security

Fixed CVE-2025-68794 in the Linux kernel.

Security

Fixed CVE-2025-68821 in the Linux kernel.

Security

Fixed CVE-2025-68727 in the Linux kernel.

Security

Fixed CVE-2025-71080 in the Linux kernel.

Security

Fixed CVE-2025-22111 in the Linux kernel.

Security

Fixed CVE-2025-71096 in the Linux kernel.

Security

Fixed CVE-2025-71135 in the Linux kernel.

Security

Fixed CVE-2025-68795 in the Linux kernel.

Fixed

Updated dev-libs/openssl to v3.5.4.

Security

Fixed CVE-2025-68820 in the Linux kernel.

Security

Fixed CVE-2025-71123 in the Linux kernel.

Security

Fixed CVE-2025-68264 in the Linux kernel.

Security

Fixed CVE-2025-38234 in the Linux kernel.

Security

Fixed CVE-2025-71077 in the Linux kernel.

Security

Fixed CVE-2025-68788 in the Linux kernel.

Security

Fixed CVE-2025-68728 in the Linux kernel.

Security

Fixed CVE-2025-68811 in the Linux kernel.

Security

Fixed CVE-2025-68348 in the Linux kernel.

Security

Fixed CVE-2025-68800 in the Linux kernel.

Security

Fixed CVE-2025-71102 in the Linux kernel.

Security

Fixed CVE-2025-68813 in the Linux kernel.

Security

Fixed CVE-2025-71120 in the Linux kernel.

Security

Fixed CVE-2025-68337 in the Linux kernel.

Security

Fixed CVE-2025-68742 in the Linux kernel.

Security

Fixed CVE-2025-71084 in the Linux kernel.

Security

Fixed CVE-2025-40325 in the Linux kernel.

Security

Fixed CVE-2025-68798 in the Linux kernel.

Change

cos-113-18244-521-74

KernelDockerContainerdGPU Drivers
COS-6.1.155v24.0.9v1.7.27See List
Security

Fixed CVE-2025-71096 in the Linux kernel.

Security

Fixed CVE-2025-61727 in dev-lang/go.

Security

Applied urllib3 patch for CVE-2024-37891.

Security

Fixed CVE-2025-68782 in the Linux kernel.

Security

Fixed CVE-2025-68813 in the Linux kernel.

Security

Fixed CVE-2025-61729 in dev-lang/go.

Security

Fixed CVE-2025-68788 in the Linux kernel.

Security

Fixed CVE-2025-68780 in the Linux kernel.

Security

Fixed CVE-2025-68264 in the Linux kernel.

Security

Fixed CVE-2025-68821 in the Linux kernel.

Security

Fixed CVE-2025-22111 in the Linux kernel.

Security

Fixed CVE-2025-71084 in the Linux kernel.

Security

Fixed CVE-2025-71077 in the Linux kernel.

Security

Fixed CVE-2025-68740 in the Linux kernel.

Security

Fixed CVE-2025-68803 in the Linux kernel.

Security

Fixed CVE-2025-68814 in the Linux kernel.

Security

Fixed CVE-2025-71098 in the Linux kernel.

Security

Fixed CVE-2025-12084 in dev-lang/python.

Security

Fixed CVE-2025-68798 in the Linux kernel.

Security

Fixed CVE-2025-68261 in the Linux kernel.

Security

Fixed CVE-2025-38022 in the Linux kernel.

Security

Fixed CVE-2025-71097 in the Linux kernel.

Security

Fixed CVE-2025-68724 in the Linux kernel.

Security

Fixed CVE-2025-68349 in the Linux kernel.

Security

Fixed CVE-2025-38129 in the Linux kernel.

Security

Fixed CVE-2025-68363 in the Linux kernel.

Security

Fixed CVE-2025-68337 in the Linux kernel.

Fixed

Updated dev-libs/openssl to v3.0.18

Security

Fixed CVE-2025-68820 in the Linux kernel.

Change

cos-117-18613-439-92

KernelDockerContainerdGPU Drivers
COS-6.6.111v24.0.9v1.7.29See List
Security

Fixed CVE-2025-40350 in the Linux kernel.

Security

Fixed CVE-2025-61727 in dev-lang/go.

Security

Applied urllib3 patch for CVE-2024-37891.

Security

Fixed CVE-2025-61729 in dev-lang/go.

Security

Fixed CVE-2025-40350 in the Linux kernel.

Security

Fixed CVE-2025-12084 in dev-lang/python.

Security

Fixed CVE-2025-40350 in the Linux kernel.

Change

cos-121-18867-294-88

KernelDockerContainerdGPU Drivers
COS-6.6.113v27.5.1v2.0.7See List
Security

Applied urllib3 patch for CVE-2024-37891.

Security

Fixed CVE-2025-61729 in dev-lang/go.

Change

Updated dev-libs/openssl to v3.0.18.

Security

Fixed CVE-2025-12084 in dev-lang/python.

Security

Fixed CVE-2025-61727 in dev-lang/go.

Dataflow
Feature

Dataflow is available in the Bangkok (asia-southeast3) region. Learn moreaboutGoogle Cloud locations.

Filestore
Feature

Filestore is available inasia-southeast3 (Bangkok). For more information, seeFilestore regions and zones.

Generative AI on Vertex AI
Feature

GLM 4.7 GA is now available in Model Garden. This modelis designed for core or vibe coding, tool use, and complex reasoning.GLM 4.7 is available as a managed API in Model Garden. To learn more, seeGLM 4.7.

Google Kubernetes Engine
Feature

Theasia-southeast3 region in Bangkok, Thailand is available. For moreinformation, see theGlobal Locations.

Issue

In some GKE versions earlier than 1.34.0-gke.2011000, using theCloud Storage FUSE CSI driver with streaming writes enabled might cause filewrites to fail with an Input/Output error on the application side accompanied by503 errors in the gke-gcsfuse-sidecar logs. This issue occurs when streamingwrites are enabled, and is caused by stalls during write operations. Streamingwrites are enabled by default in GKE versions 1.33.2-gke.4655000and later.

To work around this limitation, you can perform one of the following actions:

  • Upgrade your cluster to GKE version 1.34.1-gke.3849001 orlater.
  • If you can't upgrade your cluster, disable streaming writes by passing the--enable-streaming-writes=false orwrite:enable-streaming-writes:falseflags when youconfigure mountoptionsfor Cloud Storage FUSE CSI driver. These flags only prevent error reliablywhen staging writes use fast media types such as SSD or tmpfs. tmpfs isspecified using--temp-dir orfile-system:temp-dir flags when youconfigure mount options.
Memorystore for Memcached
Deprecated

Memorystore for Memcached is being deprecated and will be shut down on January 31, 2029. After February 1, 2027, you can't create Memorystore for Memcached instances in new projects unless these instances already exist in these projects. We recommend that you migrate your workloads toMemorystore for Valkey, which offers superior performance and features.

Pub/Sub
Feature

Pub/Sub is now available in the Bangkok region (asia-southeast3). For moreinformation, seeCloud locations.

Secret Manager
Feature

Secret Manager is available in the following region:

  • asia-southeast3 (Bangkok)

For more information, seeSecret Manager locations.

Sensitive Data Protection
Feature

Sensitive Data Protection is available in theasia-southeast3 (Bangkok) region. For more information, seeSensitive Data Protection locations.

Spanner
Feature

You can create Spannerregional instance configurationsin Bangkok, Thailand (asia-southeast3). For more information, seeGoogle Cloud locations andSpanner pricing.

Virtual Private Cloud
Feature

For auto mode VPC networks, added a new subnet10.232.0.0/20 for the Bangkokasia-southeast3 region. For more information, seeGlobal locationsandAuto mode IP ranges.

January 19, 2026

AlloyDB for PostgreSQL
Feature

AlloyDB now supports the Z3 machine series, which are powered by 4th generation Intel x86 processors (Sapphire Rapids) with Titanium SSD. These instances offer machine sizes, with up to 88 vCPU and 704 GiB RAM, that let you run storage-intensive workloads with large working datasets. For more information, seeChoose an AlloyDB machine type. This feature isgenerally available (GA).

BigQuery
Breaking

Dataform workflows,BigQuery notebooks,pipelines,anddata preparationsare enforcing strict act-as mode at the project level. To avoid failures andmaintain automatic releases, you must use custom service accounts instead of thedefault Dataform service agent across all repositories. You must also grant theService Account User role (roles/iam.serviceAccountUser) to the defaultDataform service agent and relevant principals. For more information and toverify act-as permissions, seeUse strict act-as mode.

Bigtable
Libraries

Java

2.71.0 (2026-01-15)

Features
Bug Fixes
  • bigtable: Add handling for gauge metrics (#2719) (87aa4d5)
  • Create stub with BigtableClientContext so otels are closed (#2747) (3d0a6d9)
  • Update BigtableChannelPool to use the background executor (#2753) (8f6e2df)
  • Use the same background executor in otel reader and monitoring c… (#2746) (3a58f9b)
Dependencies
  • Update dependency com.google.cloud:gapic-libraries-bom to v1.76.0 (#2754) (be54ef6)
  • Update shared dependencies (#2752) (fe1074c)
Cloud Asset Inventory
Feature

The following resource types are publicly available through theExportAssets,ListAssets,BatchGetAssetsHistory,QueryAssets,Feed,SearchAllResources,andSearchAllIamPoliciesAPIs.

  • Bigtable
    • bigtableadmin.googleapis.com/AuthorizedView
Cloud Load Balancing
Feature

Backend buckets are available forregional external Application Load Balancers and regional internal Application Load Balancers.

This feature enables to serve static content (such as images, video, and CSS)confined to a specific region, helping you meet strict data residency andcompliance requirements for regulated workloads. This update ensures backendbucket availability across the entire Application Load Balancers portfolio.

For more information, see the following:

This feature is inPreview.

Cloud Logging
Libraries

Java

3.23.10 (2026-01-15)

Bug Fixes
  • deps: Update the Java code generator (gapic-generator-java) to 2.65.1 (e0ca81e)
Dependencies
  • Update dependency com.google.cloud:sdk-platform-java-config to v3.55.1 (#1911) (93eadba)
  • Update googleapis/sdk-platform-java action to v2.65.1 (#1910) (3853159)
Dataform
Breaking

Dataform workflows,BigQuery notebooks,pipelines,anddata preparationsare enforcing strict act-as mode at the project level. To avoid failures andmaintain automatic releases, you must use custom service accounts instead of thedefault Dataform service agent across all repositories. You must also grant theService Account User role (roles/iam.serviceAccountUser) to the defaultDataform service agent and relevant principals. For more information and toverify act-as permissions, seeUse strict act-as mode.

January 18, 2026

Google SecOps
Feature

Integration Rollback

This feature is currently in Preview.

You can now roll back commercial response integrations to their previously installed version. This action reverts all integration content, including standard code and any custom modifications, to the state of the last installed version. For more information, seeRoll back response integration version.

Google SecOps SIEM
Feature

Integration Rollback

This feature is currently in Preview.

You can now roll back commercial response integrations to their previously installed version. This action reverts all integration content, including standard code and any custom modifications, to the state of the last installed version. For more information, seeRoll back response integration version.

Announcement

Release 6.3.72 is being rolled out to the first phase of regions as listedhere.

This release contains the following changes:

Feature

Integration Rollback

This feature is currently in Preview.

You can now roll back commercial response integrations to their previously installed version. This action reverts all integration content, including standard code and any custom modifications, to the state of the last installed version. For more information, seeRoll back response integration version.

Google SecOps SOAR
Announcement

Release 6.3.72 is being rolled out to the first phase of regions as listedhere.

This release contains the following changes:

Feature

Integration Rollback

This feature is currently in Preview.

You can now roll back commercial response integrations to their previously installed version. This action reverts all integration content, including standard code and any custom modifications, to the state of the last installed version. For more information, seeRoll back response integration version.

January 17, 2026

Google SecOps SIEM
Announcement

Release 6.3.71 is now available for all regions.

Google SecOps SOAR
Announcement

Release 6.3.71 is now available for all regions.

January 16, 2026

Cloud DNS
Feature

Monitoring your internet-bound DNS queries for malicious activity using DNS Armor is generally available (GA).

For more information, seeAdvanced threat detection with DNS Armor.

Cloud Load Balancing
Feature

Managed workload identity is available forbackend mutual TLS (mTLS) inglobal external Application Load Balancers.

This feature allows to:

  • Streamline certificate management: Managed workload identity enablesautomated certificate and trust management for backend mTLS through seamlessintegration with Certificate Authority Service and Certificate Manager.

  • Eliminate operational toil: Certificates are automatically rotated basedon the workload identity pool's configuration, removing the complexity andmanual bottleneck of private key provisioning and maintenance.

  • Improve visibility and governance: Gain visibility into communicationbetween distributed services and proactively apply governance to workloadsacross environments.

For more information, seeBackend mTLS with managed workload identity overview

This feature is inPreview.

Cloud Storage
Feature

You can now usedry run modeto simulate storage batch operations jobs without modifying or deleting data.Dry run helps you to validate your job configuration before running the actualoperation.

To learn how to configure a dry run job, seeCreate and manage batch operationsjobs.

Google Distributed Cloud (software only) for bare metal
Change

Updated themultiple network interfaces for Podsandbundled load balancing with BGPfeatures to support admin clusters for version 1.34 or higher. Admin clustersupport for these features has also been added to the GKE On-Prem API, so youcan specify these features with clients likeTerraform.

Google SecOps
Feature

Perform all-time searches

You can now run searches over your full retention period by clicking theTime Pickeron theSearch editor panel and selectingAll Time. This functionality issupported for event searches, and results remain limited to a maximum of 1M events.

For more information, seeSearch for events and alerts.

Google SecOps SIEM
Feature

Perform all-time searches

You can now run searches over your full retention period by clicking theTime Pickeron theSearch editor panel and selectingAll Time. This functionality issupported for event searches, and results remain limited to a maximum of 1M events.

For more information, seeSearch for events and alerts.

Feature

Perform all-time searches

You can now run searches over your full retention period by clicking theTime Pickeron theSearch editor panel and selectingAll Time. This functionality issupported for event searches, and results remain limited to a maximum of 1M events.

For more information, seeSearch for events and alerts.

Sensitive Data Protection
Feature

The following infoType detectors are available inglobal and theasia,europe, andus multi-regions:

  • IMAGE_TYPE/CONTEXT/VIOLENCE
  • IMAGE_TYPE/CONTEXT/SEXUALLY_EXPLICIT
  • IMAGE_TYPE/CONTEXT/SEXUALLY_SUGGESTIVE

For more information about all infoTypes, seeInfoTypedetector reference.

Vertex AI Workbench
Feature

Preview:The Gemini CLI is available in Vertex AI Workbench instances.The Gemini CLI is an open source AI agent that provides access toGemini directly in a terminal. You can use the Gemini CLIto do tasks like the following:

  • Create a new notebook.
  • Run notebook cells.
  • Write and edit a notebook's code and text cells.
  • Explain code and technical concepts.
  • Interact with a Vertex AI Workbench instance's local file system,including performing complex file operations that span multiple filesbased on a single, high-level instruction.
  • Run basic shell commands.
  • Run commands to interact with other Google Cloud services, such asVertex AI and BigQuery.

To get started, seeUse the Gemini CLI.

January 15, 2026

AlloyDB for PostgreSQL
Fixed

Memory usage estimation is more accurate for high-dimensional vector indexes. Thisfix prevents out of memory (OOM) errors by enforcing defined memory constraintsthroughout the index build process. You might need to increase yourmaintenance_work_mem settings to align with the real usage estimates.

Cloud Asset Inventory
Feature

The location granularity for the followingBigtable Backupresource type has changed from global to regional.

  • bigtableadmin.googleapis.com/Backup
Cloud SQL for MySQL
Feature

Cloud SQL for MySQL now supports fast clone operations within the same zone (GA).

For more information, seeClone an instance.

Cloud SQL for PostgreSQL
Feature

Cloud SQL for PostgreSQL now supports fast clone operations within the same zone (GA).

For more information, seeClone an instance.

Cloud Service Mesh
Announcement

The following images are now rolling out for managed Cloud Service Mesh:

  • 1.21.6-asm.8 is rolling out to the rapid release channel.
  • 1.20.8-asm.60 is rolling out to the regular release channel.
  • 1.19.10-asm.55 is rolling out to the stable release channel.

These patch releases contain the fixes for the following managed Cloud Service Mesh CVEs:

CVEProxyControl PlaneCNIDistroless
CVE-2025-61729YesYes-Yes
CVE-2025-61727YesYes-Yes
Cloud Storage
Feature

When youbulk restore soft-deleted objects,you can restore objects that were live at a specific time. You can also choosethe objects to restore based on the object creation time.

Firestore
Feature

Firestore Enterprise edition now supports Native mode and the Pipeline operations interface.

Pipeline operations are a new query interface for Firestore.This interface provides advanced query functionality that includes complexexpressions. It also adds support for many new functions likemin,max,substring,regex_match andarray_contains_all.

With Firestore Enterprise edition in Native mode,index creation is also completely optional, streamlining the process of developing new queries.

To learn more about Pipeline operations,see thequery interfaces overview.

This feature is available inPreview.

Google Kubernetes Engine
Security

(2026-R2) Security updates

This release includes new GKE versions that use updatedContainer-Optimized OS images. These updated images are cumulative,incorporating security fixes from all Container-Optimized OSversions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updatedContainer-Optimized OS image, see theSecurity release notesfor that image. The following table includes links to the release notes foreach updated Container-Optimized OS image:

GKE versionContainer-Optimized OS versionDetails
1.35.0-gke.1624000cos-125-19216-104-45cos-125-19216-104-45 release notes

Change

(2026-R2) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and formanual control plane upgrades and node upgrades for existing clusters. For moreinformation about versioning and upgrades, seeGKE versioning andsupport andAbout GKEcluster upgrades.

Rapid channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Regular channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Stable channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Extended channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

No channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R2) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R2) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R2) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R2) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R2) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Google SecOps
Feature

OneMCP for Google SecOps

You can use theGoogle SecOps remote MCP server to enable LLM agents to perform a range of data-related tasks.

This feature is in Preview.

Google SecOps SIEM
Feature

OneMCP for Google SecOps

You can use theGoogle SecOps remote MCP server to enable LLM agents to perform a range of data-related tasks.

This feature is in Preview.

Looker Studio
Feature

Cross data source filtering

This feature lets you override default field IDs so that controls on a report can filter charts that are based on different data sources.

Learn more about using controls across data sources.

Feature

Show and hide individual charts and components

You can hide individual charts and components for all viewers or for a subset of viewers.

SeeHide report components for viewers for more information.

Feature

Histogram chart

You can visualize your data using histogram charts. Histograms are useful for understanding the shape, center, and spread of your data, which in turn can lead to insights that might be hidden in other types of charts, such as pie charts and bar charts.

See theHistogram reference for more information.

January 14, 2026

Cloud Composer
Feature

Database retention policy is now availablein environments with Airflow 3, starting with composer-3-airflow-3.1.0-build.5.This change is now rolled out to all regions supported by Cloud Composer 3.

Change

Newimagesare available in Cloud Composer 2:

Change

(Airflow 3.1.0 in Cloud Composer 3)Theapache-airflow-providers-google package was upgraded to version 19.2.0.

For more information about changes, see theapache-airflow-providers-google changelog.

Deprecated

The following Cloud Composer versions and builds have reached theirend of support period:composer-3-airflow-2.9.3-build.12, composer-2.10.2-airflow-2.9.3,composer-2.10.2-airflow-2.10.2.

Change

Cloud Composer 3 environments no longer consume the Cloud SQL Admin API quotain the customer project.

Fixed

Improved error handling when an invalid Airflow version is specified during environment creation.

Change

(Airflow 3.1.0 in Cloud Composer 3)Theapache-airflow-providers-cncf-kubernetespackage wasupgraded to version 10.11.1.For changes in other packages, see thepreinstalled packages changelog.

Cluster Toolkit
Feature

Cluster Toolkit version v1.78.0 is available. This release adds adeprecation notice for the Parallelstore module. This version also adds supportfor gIB versions v1.1.1 and v1.1.0 for the Arm64-based architecture.

For more information about this release and other minor changes, see theReleaseannouncement on GitHub.

Container Optimized OS
Change

cos-125-19216-104-95

KernelDockerContainerdGPU Drivers
COS-6.12.55v27.5.1v2.1.5See List
Security

Fixed CVE-2025-40350 in the Linux kernel.

Security

Fixed CVE-2025-68764 in the Linux kernel.

Security

Fixed CVE-2025-68758 in the Linux kernel.

Security

Fixed CVE-2025-68766 in the Linux kernel.

Security

Fixed CVE-2025-68763 in the Linux kernel.

Security

Fixed CVE-2025-40350 in the Linux kernel.

Security

Fixed CVE-2025-68756 in the Linux kernel.

Security

Fixed CVE-2025-40350 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: net.ipv4.udp_mem: 188034 250714 376068 -> 188034 250715 376068

Security

Fixed CVE-2025-68329 in the Linux kernel.

Change

cos-121-18867-294-78

KernelDockerContainerdGPU Drivers
COS-6.6.113v27.5.1v2.0.7See List
Security

Fixed CVE-2025-40350 in the Linux kernel.

Security

Fixed CVE-2025-40350 in the Linux kernel.

Security

Fixed CVE-2025-40350 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: net.ipv4.tcp_mem: 94044 125392 188088 -> 94041 125391 188082
  • Changed: net.ipv4.udp_mem: 188088 250784 376176 -> 188085 250783 376170

Change

cos-117-18613-439-82

KernelDockerContainerdGPU Drivers
COS-6.6.111v24.0.9v1.7.29See List
Fixed

Added bcache clock cache replacement policy.

Google SecOps Marketplace
Change

Azure Active Directory: Version 20.0

  • Updated the action to include the email ID in the action output and expandedcapabilities to return all metadata fields in the following action:

    • Get Manager Contact Details
  • Integration: Updated the code to handle special characters in identifiersby implementing URL encoding and OData escaping.

Change

Slack: Version 26.0

  • Updated the Base URL construction logic for the following action:

    • Build Block
Change

Okta: Version 12.0

  • Updated the pagination processing mechanismthe in following action:

    • List Users
Change

Microsoft Graph Mail Delegated: Version 12.0

  • Improved the "mark emails as read" functionality in the following connector:

    • Microsoft Graph Mail Delegated Connector
Change

Microsoft Graph Mail: Version 35.0

  • Improved the "mark emails as read" functionality in the following connector:

    • Microsoft Graph Mail Connector
Change

Siemplify: Version 100.0

  • Updated the following action to include the JSON result in the action output:

    • Get Custom Field Values
Looker
Feature

Looker (Google Cloud core) is now available in the asia-southeast3 (Bangkok) region. For more information, see theLooker (Google Cloud core) locations documentation.

Network Security Integration
Feature

You can now integrate your network security appliances directly in the network traffic path for inspection and identify any threats before the traffic reaches its destination. For more information, seeIn-band integration overview. This feature is available inGeneral Availability.

Storage Transfer Service
Feature

Storage Transfer Service event-driven transfers are now available for Azure BlobStorage and Data Lake Storage Gen2 sources. Event-driven transfers listento Azure Event Grid notifications via Azure Storage Queues to automaticallytransfer new or updated objects from your Azure container toCloud Storage.

For more information, seeEvent-driven transfers from Azure Blob Storage or Data Lake Storage Gen2.

Tools for PowerShell
Deprecated

Effective immediately, Cloud Tools for PowerShell is deprecated and can nolonger be installed using the Google Cloud CLI. For more information, seeCloud Tools for PowerShell deprecation.

Vertex AI Workbench
Feature

M138 release

The M138 release of Vertex AI Workbench instances includes the following:

  • Fixed an issue where daemon processes launched by post-startup scripts, suchas gcsfuse mounts, did not persist after the script finished executing.
reCAPTCHA
Change

reCAPTCHA Mobile SDK v18.9.0-beta01 is available for iOS. This version includesimprovements to SDK latency and reliability.

January 13, 2026

Buildpacks
Feature

Cloud Run and Cloud Run functions source deployments support thepyproject.tomlfile for managing dependencies. This feature is inGeneral Availability for allsupported Python versions.For more information, seeDeploy Python applications with apyproject.tomlfile.

Cloud Location Finder
Feature
Cloud NGFW
Feature

You can now create regional firewall policies that apply to managed Envoy proxies used by internal Application Load Balancers and internal proxy Network Load Balancers. For more information, seeUse regional network firewall policies to protect internal Application Load Balancers and internal proxy Network Load Balancers. This feature is available inPreview.

Cloud Run
Feature

Cloud Run and Cloud Run functions source deployments support thepyproject.tomlfile for managing dependencies. This feature is inGeneral Availability for allsupported Python versions.For more information, seeDeploy Python applications with apyproject.tomlfile.

Dataflow
Feature

Dataflow now serves a notice for when the DataflowRunner v2 container image of a streaming pipelinewill be upgraded. To use a new image and avoid the scheduled maintenance, launcha replacement job before the upgrade. For more information, seeRunner v2 harness update.

Dataproc
Announcement

Dataproc on Compute Engine: The following subminor image versions announced onJanuary 06, 2026 have been rolled back:

  • 2.0.156-debian10, 2.0.156-ubuntu18, 2.0.156-rocky8
  • 2.1.105-debian11, 2.1.105-ubuntu20, 2.1.105-ubuntu20-arm, 2.1.105-rocky8
  • 2.2.73-debian12, 2.2.73-ubuntu22, 2.2.73-ubuntu22-arm, 2.2.73-rocky9
  • 2.3.20-debian12, 2.3.20-ml-ubuntu22, 2.3.20-rocky9, 2.3.20-ubuntu22, 2.3.20-ubuntu22-arm
Dataproc Metastore
Deprecated

Multi-region and custom dual region support for Dataproc Metastore is deprecated. You can no longer create new multi-region or custom dual region services. Existing services will continue to function.

Generative AI on Vertex AI
Feature

Veo 3.1 reference-to-video update

Veo 3.1 Preview models now support the following features:

  • 9:16 aspect ratio for reference-to-video.
  • Upsampling for videos generated at 1080p and 4k resolutions.

For more information, see the following:

Google Cloud VMware Engine
Announcement

Private clouds capable of hosting bothve1 andve2 node-family clusters areavailable in the following additional regions:

  • London, England, Europe (europe-west2-a,europe-west2-b)
  • São Paulo, Brazil, South America (southamerica-east1-a)
  • Dallas, Texas, North America (us-south1-b)

While a private cloud can contain mixed node families, each individual clustermust be comprised of nodes from the same family type.

Note: To create a new cluster of a different node family, contactCloud Customer Care.
Google SecOps
Announcement

Auto extraction general availability

As part of the GA release for the auto extraction feature, customers now need to opt-in and choose which fields to extract. (Full auto extraction is no longer supported.) Theopt-in functionality does not impact the extracted fields that are already in use (in saved searches and rules), because those fields have been automatically opted-in as part of the GA migration.

For more information, seeAuto Extraction overview.

Google SecOps SIEM
Announcement

Self-service deprovisioning general availability

The self-service deprovisioning feature is now GA.

For more information, seeSelf-service deprovisioning for Google SecOps.

Announcement

Auto extraction general availability

As part of the GA release for the auto extraction feature, customers now need to opt-in and choose which fields to extract. (Full auto extraction is no longer supported.) Theopt-in functionality does not impact the extracted fields that are already in use (in saved searches and rules), because those fields have been automatically opted-in as part of the GA migration.

For more information, seeAuto Extraction overview.

Announcement

Self-service deprovisioning general availability

The self-service deprovisioning feature is now GA.

For more information, seeSelf-service deprovisioning for Google SecOps.

Announcement

Auto extraction general availability

As part of the GA release for the auto extraction feature, customers now need to opt-in and choose which fields to extract. (Full auto extraction is no longer supported.) Theopt-in functionality does not impact the extracted fields that are already in use (in saved searches and rules), because those fields have been automatically opted-in as part of the GA migration.

For more information, seeAuto Extraction overview.

Spanner
Feature

Several updates have been made tofull-text search:

VPC Service Controls
Feature

Preview stage support for the following integration:

January 12, 2026

API Gateway
Feature

Centralize API Gateway API management using Apigee API hub

Connect API Gateway to Apigee API hub to enable seamless publishing of API metadata from your API Gateway project to API hub. This integration provides a centralized, unified view of your APIs across different gateways, simplifying API discovery, governance, and management.

Key benefits include:

  • Centralized API discovery: All your API Gateway APIs are discoverable in API hub alongside APIs from other sources
  • Enhanced visibility: Gain insights into your API landscape with consolidated metadata
  • Streamlined management: Simplify API governance and lifecycle management across your diverse API ecosystem

For more detail, seeCentralize API management using API hub.

Note: Rollouts of this release to production instances might take up to 5 business days to complete across all Google Cloud zones. Your instances might not have the feature available until the rollout is complete.

Apigee API hub
Feature

Ingest API Gateway metadata into API hub

API hub now supports automatic metadata ingestion fromGoogle Cloud API Gateway. You can nowattach your API Gateway projects to API hub to enable auto-ingestion for all your APIs. For more information seeCentralize API management using API hub.

Note: Rollouts of this release to production instances might take up to 5 business days to complete across all Google Cloud zones. Your instances might not have the feature available until the rollout is complete.
Apigee Advanced API Security
Announcement

On January 12, 2026 we released an updated version of Advanced API Security Abuse Detection

Apigee UI
Announcement

On January 12, 2026, we released an updated version of the Apigee UI.

Feature

Manage environment-level resources in the Apigee UI

You can now manage environment-level resources using the Apigee UI.Previously, environment-level resources could only be managed using the API.For more information, seeManaging resources.

Cloud Build
Change

Cloud Build now supports OCI artifacts. OCI artifacts for a buildare shown in the following locations:

  • The Artifacts column of Build history page
  • The Execution details tab of the Build details page
  • The Build Artifacts tab of the Build details page

For more information, seeView build results.

Contact Center AI Insights
Announcement

This product has a new name. The same product with the same features is now called Customer Experience Insights, or CX Insights for short.

Dataplex
Breaking

Some of the metadata that is stored in Dataplex Universal Catalog is changing.This change brings the metadata stored in Dataplex into consistency withmetadata from the original source systems such as Vertex AI, Bigtable, Spanner,Pub/Sub, Dataform, and Dataproc Metastore. If you have workloads that depend onsuch Dataplex metadata, you must adjust them to preserve continuity. For moreinformation about the scope of this change and what you need to do, seeChanges to metadata stored in Dataplex Universal Catalog.

Document AI
Feature

Document AI is introducing document-level prompting for custom documentprocessors. This feature allows you to provide an overall description of thedocument to inject deep business knowledge into the model, leading to improvedextraction quality.

Document-level prompting offers improved accuracy by giving the model necessarycontext for extraction at the document level. This allows for easily suppliedgeneral information, such as geographical limitations (for example,all theaddress fields are located in the USA), to guide the model.

For more details, refer to the documentation on custom extractor mechanismsanddocument-level prompting.

Gemini Enterprise
Announcement

Agent Designer is generally available (GA).

Google SecOps
Feature

Copy instance metadata

To enable Google support to test and troubleshoot customer issues, a new option to copy SOAR information and share with Support has been added to the platform. This option, entitledCopy instance metadata, can be accessed from the question mark at the top of the platform.

Google SecOps SIEM
Feature

Copy instance metadata

To enable Google support to test and troubleshoot customer issues, a new option to copy SOAR information and share with Support has been added to the platform. This option, entitledCopy instance metadata, can be accessed from the question mark at the top of the platform.

Infrastructure Manager
Change

Infrastructure Manager is available in the following regions:

  • me-central2

For more information about regions, seeInfrastructure Manager locations.

January 11, 2026

Google SecOps SIEM
Feature

Custom Transformers and Logical Operators

This feature is currently in Preview.

Playbook engineers can now extend platform capabilities by creating custom Python-based transformation functions and logical operators as part of Extension Packs directly within the IDE. For more information, seeCustom transformation functions and logical operators.

Announcement

Release 6.3.71 is being rolled out to the first phase of regions as listedhere.

This release contains the following changes:

Change

Terminate Playbook capability

You can now manually terminate a running playbook directly from the Playbook Viewer in the Case Overview. This provides a mechanism to immediately end execution if a loop encounters unwanted or excessive iterations.

Change

Increased iteration and step limits for Playbook Loops

To support larger automation requirements, the maximum number of iterations for a single loop has been increased to 1,000, and the number of supported steps within a loop has been increased to 100.

Announcement

Playbook Loops

This feature is now in General Availability (GA).For more information, seeAutomate tasks with Playbook Loops.

Google SecOps SOAR
Feature

Custom Transformers and Logical Operators

This feature is currently in Preview.

Playbook engineers can now extend platform capabilities by creating custom Python-based transformation functions and logical operators as part of Extension Packs directly within the IDE. For more information, seeCustom transformation functions and logical operators.

Announcement

Release 6.3.71 is being rolled out to the first phase of regions as listedhere.

This release contains the following changes:

Change

Terminate Playbook capability

You can now manually terminate a running playbook directly from the Playbook Viewer in the Case Overview. This provides a mechanism to immediately end execution if a loop encounters unwanted or excessive iterations.

Change

Increased iteration and step limits for Playbook Loops

To support larger automation requirements, the maximum number of iterations for a single loop has been increased to 1,000, and the number of supported steps within a loop has been increased to 100.

Announcement

Playbook Loops

This feature is now in General Availability (GA).For more information, seeAutomate tasks with Playbook Loops.

January 10, 2026

Agent Assist
Change

Agent Assist offerssentiment analysis version 3 in GA. Sentiment analysis V3 analyzes individual messages with conversation context and can even analyze an audio stream to provide precise end user sentiment scores.

Google SecOps SIEM
Announcement

Release 6.3.70 is now available for all regions.

Google SecOps SOAR
Announcement

Release 6.3.70 is now available for all regions.

January 09, 2026

Config Connector
Change

Reconciliation Improvements:

Added support for direct reconciliation to more resources, with opt-inbehaviour. The API is unchanged. To use the direct reconciler, add thealpha.cnrm.cloud.google.com/reconciler: direct annotation to the correspondingConfig Connector object. The following resources now have direct reconciliationsupport:

  • TagsLocationTagBinding: Now supports direct reconciliation.
Feature

New Features:

  • IAM: Added support foriam.cnrm.cloud.google.com/disable-dependent-services annotation.
  • Added support for Cilium cluster-wide network policy.
Feature

New Fields:

  • AlloyDBInstance
    • Addedspec.observabilityConfig andspec.queryInsightsConfig fields.
  • ContainerNodePool
    • Addedspec.nodeConfig.enableNestedVirtualization field.
  • MonitoringDashboard
    • Added support forspec.charts[].dataSets[].timeSeriesQuery.opsAnalyticsQuery.sqlQueryRef
Fixed

Bug Fixes:

  • BatchJob: Fixed a bug where the resource could not be created.
  • FirewallPolicyRule: Fixed an issue with updating the resource.
  • IAMServiceAccountKey: Fixed an issue causing unnecessary re-reconciliation.
  • Fixed a bug whereComputeBackendService could not refer toclientTLSPolicy due to an invalid format.
  • Fixed a bug where interconnect attachments were not ignored.
  • Fixed a bug in the GitHub MCP server.
  • Fixed a bug in the private cluster endpoint formockgcp.
Announcement

Config Connector version 1.142.0 is now available.

Feature

New Beta Resources (Direct Reconciler):

  • AlloyDBBackup
  • AccessContextManagerAccessLevel
Dataproc
Announcement
VPC Service Controls
Feature

General availability support for the following integration:

January 08, 2026

GeminiLooker
Fixed

An issue has been fixed where Looker would generate inefficient SQL for some Databricks queries that included date manipulation for weekly data. Looker now uses Databricks functions likedate_trunc when generating SQL.

Fixed

For the Spanish (es_ES) locale, the weekday initials for Sunday and Tuesday in the schedule dashboard dialog have been set to the correct values (D andM).

Feature

The JDBC driver forApache Spark 3+ connections has been updated to version 2.7.6.

Fixed

An issue has been fixed where applying filters to a Google Map visualization would require a refresh before the filters would take effect. This feature now performs as expected.

Feature

Custom mail settings that are configured for SMTP servers now support OAuth 2.0 authentication.

Fixed

An issue has been fixed where some columns in the Query Concurrency System Activity Explore were displaying null values. This feature now performs as expected.

Feature

Forcreating self-service Explores from Excel files that contain multiple worksheets, theData upload dialog now lets you specify which Excel worksheet to upload. Previously, the self-service Explore was always based on the first worksheet in the Excel file.Note: This item was added on January 15, 2026.

Fixed

An issue has been fixed where a join wouldn't be added to the query, even if one was required by a measure of typecount_distinct,sum_distinct, oravg_distinct.

Fixed

An issue has been fixed where Looker would prevent users from uploading data if they lacked theexplore permission. This feature now performs as expected.

Fixed

An issue has been fixed where testing a connection could fail to return an error message in cases where the user had insufficient permissions or if the connection no longer existed. This feature now performs as expected.

Feature

The LookML dashboards folder is now paginated, showing 30 dashboards per page.

Fixed

When you use the Field Picker to clear all fields, the chart type no longer changes to Table (Legacy).

Fixed

An issue has been fixed where strings with accented characters were not being displayed properly in the Y-Axis of a visualization. This feature now performs as expected.

Fixed

An issue has been fixed where the Get LookML Model Explore API endpoint could time out without returning results. This feature now performs as expected.

Fixed

An issue has been fixed where manually resetting column widths from a dashboard grid tile header had no effect. This feature now performs as expected.

Fixed

An issue has been fixed where long content in tooltips could not be scrolled. This feature now performs as expected.

Fixed

A retry limit has been added for scheduled jobs. If a scheduled job fails five times in a row, then it's skipped until the next time the schedule is triggered.

Breaking

HTML characters are now displayed in plaintext in table visualizations to match other visualization types. For example," is no longer rendered as".

Announcement

Looker 26.0 is expected to include the following changes, features, and fixes:

  • Expected Looker (original) deployment start:Monday, January 12, 2026
  • Expected Looker (original) final deployment and download available:Monday, January 19, 2026
  • Expected Looker (Google Cloud core) deployment start:Monday, January 12, 2026
  • Expected Looker (Google Cloud core) final deployment:Friday, January 23, 2026
Fixed

An issue has been fixed where, after you uploaded data, Looker would not redirect you to the uploaded file. This feature now performs as expected.

Feature

Looker now supports encrypted files forkey-pair authentication for Snowflake connections.

Fixed

TheSkip to Main Content accessibility link for dashboards has been removed for embedded dashboards.

Feature

When youview folders on embedded content, LookML dashboards are now visible. The LookML dashboards folder, however, will not be visible.

Fixed

An issue has been fixed where a SQL Runner query against a model would fail if the user had not yet opened the model in Development Mode. This feature now performs as expected.

Fixed

An issue has been fixed where merged queries could disappear if a user edited one of the settings in the Values tab for a field. This feature now performs as expected.

Fixed

An issue has been identified and fixed in search where the latency in fetching search results spiked, causing search to be slow in returning results. A layer of caching has been added, causing search results to be more performant.Note: This item was added on January 13, 2026.

Fixed

An issue has been fixed where the custom tooltip editor was unable to scroll to edit long tooltip templates. This feature now performs as expected.

Fixed

An issue has been fixed where tooltip background colors were not being correctly rendered. This feature now performs as expected.

Fixed

An issue has been fixed where certain fields in dialogs, such as the Format field in the Download dialog, were incorrectly labeled as read-only to screen readers. This feature now performs as expected.

Fixed

An issue has been fixed where the dialog to select a folder would attempt to load a second page of results without being prompted by the user. This feature now performs as expected.

Fixed

An issue has been fixed wherevalue_format was not respected in table visualizations for numeric values larger than 16 digits. This feature now performs as expected.

Fixed

An issue has been fixed where selecting the filter option "is before N hours ago" incorrectly displayed "is before N hours" in the filter.

Fixed

An issue has been fixed where Looker extensions could not access webpack development servers. This feature now performs as expected.

Fixed

An issue has been fixed where filters with commas were not including all filter conditions on Safari browsers. This feature now performs as expected.

Fixed

An issue has been fixed where a table visualization could become unresponsive if a fixed column width was specified for multiple columns. This feature now performs as expected.

Fixed

An issue has been fixed where downloading pivoted queries with table calculations while using an Exasol database could return an error. This feature now performs as expected.

Fixed

An issue has been fixed where any Liquid usage in a derived table SQL resulted in full suggestions behavior. This feature now performs as expected.

Fixed

An issue has been fixed where clickingStatus details in the connection setup page without first selecting a dialect caused the page to crash. This feature now performs as expected.

Fixed

An issue has been fixed where modifying conditional formatting rules other than the first one incorrectly affected the first rule. This fix has been backported to Looker versions 25.18.41 and 25.20.17.

Fixed

An issue has been fixed where theShow More button wouldn't appear for large lists when a user was managing folder access. This feature now performs as expected.

Fixed

An issue has been fixed where custom measures with invalid field references could cause queries to fail, even if those measures weren't selected in the query. This feature now performs as expected.

Fixed

An issue has been fixed where the LookML Validator was not surfacing errors if an invalid field name was referenced in asuggest_dimension field. This feature now performs as expected.

Fixed

An issue has been fixed where very long dashboard names were not properly truncated. This feature now performs as expected.

Fixed

An issue has been fixed where an emptysorts: property in a LookMLexplore file definition could cause Looker to return a 500 error. This feature now performs as expected.

Breaking

When you useElite System Activity, the System Activity fieldscheduled_plan.filters_string is limited to a length of 1.9 MB. Any data beyond the 1.9 MB limit is truncated.

Fixed

An issue has been fixed where tooltips incorrectly displayed the text[object Object]. This feature now performs as expected.

Fixed

An issue has been fixed where theExplore from SQL Runner query feature could return an error if it found Liquid syntax in the query. The feature now exports the query as plaintext.

Feature

The new LookML parameterautogenerate_primary_keys parameter is now supported. When a view or Explore is defined withautogenerate_primary_keys: yes, Looker generates a temporary, distinct key for a view, allowing symmetric aggregates and one-to-many counts to be calculated correctly without any changes to your underlying database table. The primary key is generated at query runtime; it does not persist across queries.Note: This item was added on January 12, 2026.

Feature

The JDBC driver forDatabricks connections has been updated to version 3.0.5.

Fixed

An issue has been fixed where filtered custom measures could fail to load if they referenced a dimension that used thealias parameter in their filter. This feature now performs as expected.

Fixed

An issue has been fixed where theShow Totals option in the Plot menu was not correctly hiding totals when a user downloaded results. This feature now performs as expected.

Feature

The user interface for configuring group mappings for LDAP, SAML, and OpenID Connect has been updated for improved management. The new interface allows administrators to more easily add, edit, remove, and search for group mappings.

Feature

Looker now supports conditional formatting rules for string types in single value and table visualizations.

Feature

Looker now supports key-pair authentication in thePDT overrides for Snowflake connections.

Fixed

An issue has been fixed where downloaded reports with pivoted tables could contain extra whitespace. This feature now performs as expected.

Fixed

An issue has been fixed where creating a custom dimension with a single letter name could cause the query to fail. This feature now performs as expected.

Feature

TheTabbed Dashboards Labs feature lets dashboard editors organize dashboard content across multiple tabs within a single dashboard. Adding tabs to dashboards lets you do the following:

  • Better organize content: Group related visualizations and tiles into separate tabs.
  • Improve data storytelling: Guide viewers through different aspects of your data in a structured way.
  • Enhance performance: Load only the tiles on an active tab, potentially speeding up initial dashboard load times.
  • Reduce clutter: Consolidate multiple related analyses into a single dashboard.

This feature will be available beginning January 26, for Looker (Original) instances, and will be disabled by default.

Note: This item was updated on January 20, 2026.

Feature

Looker admins can now create dedicatedservice accounts for API-only access. Additionally, eligible standard user accounts that are being used for API access can bemigrated to the new service account type from the Users page in the Admin panel.

Feature

TheFavoriting LookML Dashboards Labs feature, which enables LookML dashboards to bemarked as favorites and displays them on the Looker Favorites tab, is now out of Labs and generally available.

Feature

TheCustom Tooltips Labs feature lets you configure tooltips within theExplore visualization editor using a combination of UI settings and an HTML editor that supports Liquid templating.

This feature will be available beginning January 26, for Looker (Original) instances, and will be enabled by default.

Note: This item was updated on January 20, 2026.

Feature

The API endpointsearch_lookml_dashboards is out of Labs and now generally available.

Feature

TheDashboard Filter Enhancements Labs feature includes the following improvements:

  • Persistent filter suggestion drop-down: Filter suggestion drop-downs remain open for easier multi-selection fortag list andadvanced filter type filters.
  • Select or deselect all filter values: Lets users select or deselect all values in tag list and advanced filter type filters.
  • Limit condition controls for advanced filters: Lets dashboard creators limit the condition options that are available to users for advanced filters.
  • EnableInclude custom filter values by default for boards: Admins can choose to enableInclude custom filter values for boards by default instance-wide.

This feature will be available beginning January 26, for Looker (Original) instances, and will be enabled by default.

Note: This item was updated on January 20, 2026.

Feature

LookML dashboards can now bemarked as favorites, allowing the LookML dashboards to appear on the Looker Favorites tab.

Feature

Looker (Google Cloud core) instances that use Private Service Connect can now connect to Google APIs throughcontrolled native egress.

Feature

The API endpointsearch_lookml_dashboards is now generally available.

VPC Service Controls
Feature

Preview stage support for the following integration:

January 07, 2026

Apigee Operator for kubernetes
Announcement

On January 7, 2026, we released an updated version of Apigee.

Security
Bug IDDescription
471150886, 471150271, 471150102, 426783172Security fixes for the Apigee Operator for Kubernetes.

This addresses the following vulnerabilities:

Feature

The Apigee Operator for Kubernetes version 1.1.1 is now available.

Backup and DR
Announcement

Protection summary is now generally available for Backup and DR Service. UseProtection summary to identify and fix data protection gaps across your projects.

Feature

You can now use cost reports to view resource-specific Backup and DRbilling costs to gain granular insights into service spending and to takeactions to optimize resource allocation.

BigQuery
Feature

You can now use the Google-developed, open sourceJava Database Connectivity (JDBC) driver for BigQueryto connect your Java applications to BigQuery. This feature is inPreview.

Cloud Asset Inventory
Feature

The following resource types are publicly available through theExportAssets,ListAssets,BatchGetAssetsHistory,QueryAssets,Feed,SearchAllResources,andSearchAllIamPoliciesAPIs.

  • Network Connectivity
    • networkconnectivity.googleapis.com/InternalRange
  • Network Security Integration
    • networksecurity.googleapis.com/InterceptDeploymentGroup
    • networksecurity.googleapis.com/InterceptDeployment
    • networksecurity.googleapis.com/InterceptEndpointGroup
    • networksecurity.googleapis.com/InterceptEndpointGroupAssociation
Cluster Toolkit
Feature

Cluster Toolkit version v1.77.0 is available. This release introducesa robust destroy process to help ensure that you can reliably delete resources fromthe Cluster Toolkit. This version also adds an automated Google Cloudresource cleanup script and integrates a Cloud Build pipeline to let youremove resources that are no longer required.

For more informationabout this release and other minor changes, see theRelease announcement onGitHub.

Compute Engine
Feature

Generally available: You can view future resource availability before youcreate a future reservation request in calendar mode. This action helps increasethe likelihood that Google Cloud approves your request. For more information,seeView resource future availability.

Google Kubernetes Engine
Change

(2026-R1) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and formanual control plane upgrades and node upgrades for existing clusters. For moreinformation about versioning and upgrades, seeGKE versioning andsupport andAbout GKEcluster upgrades.

Rapid channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Regular channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Stable channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Extended channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

No channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Security

(2026-R1) Security updates

This release includes new GKE versions that use updatedContainer-Optimized OS images. These updated images are cumulative,incorporating security fixes from all Container-Optimized OSversions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updatedContainer-Optimized OS image, see theSecurity release notesfor that image. The following table includes links to the release notes foreach updated Container-Optimized OS image:

GKE versionContainer-Optimized OS versionDetails
1.35.0-gke.1403000cos-125-19216-104-45cos-125-19216-104-45 release notes

Change

(2026-R1) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Feature

NodeLocal DNSCache is enabled by default on new StandardGKE clusters which are created running version 1.34.1-gke.3720000or later. NodeLocal DNSCache is a GKE add-on that improves DNSperformance by running a DNS cache directly on each cluster node as a DaemonSet.To learn more, seeSet up NodeLocalDNSCache.

Change

(2026-R1) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R1) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R1) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Change

(2026-R1) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Google SecOps
Change

Expanded capabilities for Gemini in SecOps

You can now use the Gemini assistant in Google SecOps to answer questions beyond the scope of security or the product. You can integrate the full power of Gemini (for example, general knowledge, coding, and data analysis) without switching tabs or leaving your workflow.

For more information, seeGemini in Google SecOps.

Google SecOps Marketplace
Feature

Microsoft Defender ATP: Version 27.0

  • The following new action has been added:

    • Execute Live Response Command
Feature

Palo Alto Cortex XDR: Version 21.0

  • The following new job has been added:

    • Sync Incidents
Change

Exchange: Version 118.0

  • Added new parameters (Event Fields to Exclude andExclude Attachments) tothe following connectors:

    • Exchange - Mail Connector v2

    • Exchange - Mail Connector v2 with OAuth Authentication

Change

Siemplify: Version 99.0

  • Updated the TIPCommon method in the following action:

    • Get Case Details
Change

Updated the file management logic of theDownload Attachment From Emailaction in the following integrations:

  • Microsoft Graph Mail: Version 34.0

  • Microsoft Graph Mail Delegated: Version 11.0

Change

SCC Enterprise: Version 19.0

  • Integration: Refactored code to work with the updated API.
Change

Updated the dependencies of the following integrations:

  • BMC Helix RemedyForce: Version 14.0

  • EmailV2: Version 37.0

  • Google Cloud Storage: Version 12.0

  • HTTP v2: Version 11.0

  • Jira: Version 51.0

  • JuniperVSRX: Version 9.0

  • McAfee Active Response: Version 8.0

  • PassiveTotal: Version 12.0

  • Salesforce: Version 13.0

  • SCCM: Version 18.0

  • SiemplifyUtilities: Version 25.0

  • ThreatConnect: Version 15.0

  • Websense: Version 13.0

  • WMI: Version 11.0

Change

Google Chronicle: Version 72.0

  • Added support for curated rules in the following action:

    • Get Rule Details
  • Updated rule severity filter logic in the following connector:

    • Google Chronicle - Chronicle Alerts Connector
Google SecOps SIEM
Change

Expanded capabilities for Gemini in SecOps

You can now use the Gemini assistant in Google SecOps to answer questions beyond the scope of security or the product. You can integrate the full power of Gemini (for example, general knowledge, coding, and data analysis) without switching tabs or leaving your workflow.

For more information, seeGemini in Google SecOps.

Change

Expanded capabilities for Gemini in SecOps

You can now use the Gemini assistant in Google SecOps to answer questions beyond the scope of security or the product. You can integrate the full power of Gemini (for example, general knowledge, coding, and data analysis) without switching tabs or leaving your workflow.

For more information, seeGemini in Google SecOps.

VPC Service Controls
Feature

General availability support for the following integration:

January 06, 2026

BigQuery
Feature

TheCREATE EXTERNAL TABLEandLOAD DATAstatements now support the following options:

  • time_zone: specify a time zone to use when loading data
  • date_format,datetime_format,time_format, andtimestamp_format: define how date and time values are formatted in your source files
  • null_markers: define the strings that representNULL values in CSV files.
  • source_column_match: specify how loaded columns are matched to the schema. You can match columns by position or by name.

These features aregenerallyavailable (GA).

Cloud Run functions
Feature

You can now configureDirect VPC egress for 2nd gen functions. This support is at thePreview release level.

Dataproc
Change

Removed use of deprecated Hadoop configuration propertiesfs.default.name andyarn.resourcemanager.system-metrics-publisher.enabled.

Announcement

NewDataproc on Compute Engine subminor image versions:

  • 2.0.156-debian10, 2.0.156-ubuntu18, 2.0.156-rocky8
  • 2.1.105-debian11, 2.1.105-ubuntu20, 2.1.105-ubuntu20-arm, 2.1.105-rocky8
  • 2.2.73-debian12, 2.2.73-ubuntu22, 2.2.73-ubuntu22-arm, 2.2.73-rocky9
  • 2.3.20-debian12, 2.3.20-ml-ubuntu22, 2.3.20-rocky9, 2.3.20-ubuntu22, 2.3.20-ubuntu22-arm

Rollback Notice: These image versions were rolled back onJanuary 13, 2026.

Fixed

Fixed thespark.driver.extraClassPath delimiter for the Jupyter SparkMonitor Listener.

Feature

Added a new propertydataproc:pypi.repository to customize the PyPI repository used for pip. The value can be a URL, orgoogle to use a Google-hosted cache of PyPI, accessible without public internet connectivity. Starting in image version 3.1,google will be the default; to opt out and return to public PyPI, use the valuepypi.

Generative AI on Vertex AI
Feature

GLM 4.7 is available as an experimental launch in Model Garden. This modelis designed for core or vibe coding, tool use, and complex reasoning.GLM 4.7 is available as a managed API in Model Garden. To learn more, seeGLM 4.7.

Google Cloud VMware Engine
Feature

VMware Engine introduces enhancements to simplify using external NFSdatastores. External NFS datastores let you scale storage independently ofcompute resources for your VMware workloads. You can use Filestore orGoogle Cloud NetApp Volumes as external NFS datastores for ESXi hosts inGoogle Cloud VMware Engine. For more information, seeNFS datastores overview.

Google Kubernetes Engine
Fixed

A fix is available for theDecember 16, 2025 issue in whichAutopilot nodes enter into a state where new system Pods and user Pods areunable to run due to NRI RunPodSandbox failures. For more details, includinginstructions on how to confirm if you're affected by this, seePods unable torun on a Node due to NRI RunPodSandbox failed.

The fix is available with GKE version 1.34.1-gke.3899000 andlater.

reCAPTCHA
Change

reCAPTCHA Mobile SDK v18.9.0-beta01 is available for Android. This version includes improvements to SDK latency and reliability.

January 05, 2026

Access Approval
Feature

Workflows is generally available(GA).

Access Transparency
Feature

Workflows is generally available(GA).

Agent Assist
Change

Agent Assist offers abest practices guide for summarization automatic evaluation.

Capacity Planner
Feature

Preview: You can use client libraries to access the Capacity Planner APIusing C#, Go, Java, Node.js, PHP, Python, or Ruby. For more information, seeCapacity Planner client libraries.

Cloud Trace
Feature

You can now collect, view, and analyze multimodal prompts and responses fromyour agentic applications that use the LangGraph or Agent Development Kit (ADK)frameworks. This feature is inPublic Preview.

To learn more, see the following documents:

Container Optimized OS
Change

cos-125-19216-104-89

KernelDockerContainerdGPU Drivers
COS-6.12.55v27.5.1v2.1.5See List
Security

Fixed CVE-2025-68208 in the Linux kernel.

Security

Fixed CVE-2025-68317 in the Linux kernel.

Security

Fixed CVE-2025-66471 and CVE-2025-66418 in dev-python/urllib3.

Security

Fixed CVE-2025-68173 in the Linux kernel.

Change

Updated app-admin/sosreport to v4.10.1. Enabled containerd stack dump by default.

Security

Fixed CVE-2025-68292 in the Linux kernel.

Security

Fixed CVE-2025-68183 in the Linux kernel.

Security

Fixed CVE-2025-40360 in the Linux kernel.

Security

Fixed CVE-2025-40348 in the Linux kernel.

Security

Fixed CVE-2025-40361 in the Linux kernel.

Security

Fixed CVE-2025-68200 in the Linux kernel.

Security

Fixed CVE-2025-68219 in the Linux kernel.

Security

Fixed CVE-2025-68324 in the Linux kernel.

Security

Fixed CVE-2025-68188 in the Linux kernel.

Security

Fixed CVE-2025-68185 in the Linux kernel.

Security

Fixed CVE-2025-68213 in the Linux kernel.

Security

Fixed CVE-2025-68295 in the Linux kernel.

Fixed

Upgraded sys-apps/dmidecode to v3.7.

Security

Fixed CVE-2025-68171 in the Linux kernel.

Security

Fixed CVE-2025-68191 in the Linux kernel.

Security

Fixed CVE-2025-68178 in the Linux kernel.

Security

Fixed CVE-2025-68214 in the Linux kernel.

Security

Fixed CVE-2025-68293 in the Linux kernel.

Security

Fixed CVE-2025-68242 in the Linux kernel.

Security

Fixed CVE-2025-68199 in the Linux kernel.

Security

Fixed CVE-2025-68325 in the Linux kernel.

Security

Fixed CVE-2025-68231 in the Linux kernel.

Security

Fixed CVE-2025-68186 in the Linux kernel.

Security

Fixed CVE-2025-68241 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811475 -> 811504
  • Changed: net.ipv4.udp_mem: 188034 250715 376068 -> 188034 250714 376068

Security

Fixed CVE-2025-68229 in the Linux kernel.

Security

Fixed CVE-2025-40359 in the Linux kernel.

Fixed

Upgraded net-misc/socat to v1.8.1.0.

Security

Fixed CVE-2025-40346 in the Linux kernel.

Security

Fixed CVE-2025-68224 in the Linux kernel.

Security

Fixed CVE-2025-68321 in the Linux kernel.

Security

Fixed CVE-2025-40353 in the Linux kernel.

Security

Fixed CVE-2025-68198 in the Linux kernel.

Security

Fixed CVE-2025-68313 in the Linux kernel.

Change

cos-117-18613-439-81

KernelDockerContainerdGPU Drivers
COS-6.6.111v24.0.9v1.7.29See List
Security

Fixed CVE-2025-68178 in the Linux kernel.

Security

Fixed CVE-2025-68191 in the Linux kernel.

Security

Fixed CVE-2025-68219 in the Linux kernel.

Change

Updated app-admin/sosreport to v4.10.1. Enabled containerd stack dump by default.

Security

Fixed CVE-2025-68171 in the Linux kernel.

Security

Fixed CVE-2025-68224 in the Linux kernel.

Security

Fixed CVE-2025-68200 in the Linux kernel.

Security

Fixed CVE-2025-68241 in the Linux kernel.

Security

Fixed CVE-2025-68229 in the Linux kernel.

Security

Fixed CVE-2025-68198 in the Linux kernel.

Security

Fixed CVE-2025-68295 in the Linux kernel.

Security

Fixed CVE-2025-68183 in the Linux kernel.

Fixed

Upgraded sys-apps/dmidecode to v3.7.

Security

Fixed CVE-2025-66471 and CVE-2025-66418 in dev-python/urllib3.

Security

Fixed CVE-2025-68321 in the Linux kernel.

Security

Fixed CVE-2025-68231 in the Linux kernel.

Security

Fixed CVE-2025-68185 in the Linux kernel.

Security

Fixed CVE-2025-40361 in the Linux kernel.

Security

Fixed CVE-2025-68214 in the Linux kernel.

Security

Fixed CVE-2025-68208 in the Linux kernel.

Fixed

Upgraded net-misc/socat to v1.8.1.0.

Security

Fixed CVE-2025-40346 in the Linux kernel.

Security

Fixed CVE-2025-40360 in the Linux kernel.

Security

Fixed CVE-2025-68173 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811737 -> 811699

Change

cos-121-18867-294-76

KernelDockerContainerdGPU Drivers
COS-6.6.113v27.5.1v2.0.7See List
Security

Fixed CVE-2025-68178 in the Linux kernel.

Security

Fixed CVE-2025-68191 in the Linux kernel.

Security

Fixed CVE-2025-68219 in the Linux kernel.

Change

Updated app-admin/sosreport to v4.10.1. Enabled containerd stack dump by default.

Security

Fixed CVE-2025-68171 in the Linux kernel.

Security

Fixed CVE-2025-68224 in the Linux kernel.

Security

Fixed CVE-2025-68200 in the Linux kernel.

Security

Fixed CVE-2025-68241 in the Linux kernel.

Security

Fixed CVE-2025-68229 in the Linux kernel.

Security

Fixed CVE-2025-68198 in the Linux kernel.

Security

Fixed CVE-2025-68295 in the Linux kernel.

Security

Fixed CVE-2025-68183 in the Linux kernel.

Fixed

Upgraded sys-apps/dmidecode to v3.7.

Security

Fixed CVE-2025-66471 and CVE-2025-66418 in dev-python/urllib3.

Security

Fixed CVE-2025-68321 in the Linux kernel.

Security

Fixed CVE-2025-68231 in the Linux kernel.

Security

Fixed CVE-2025-68185 in the Linux kernel.

Security

Fixed CVE-2025-40361 in the Linux kernel.

Security

Fixed CVE-2025-68214 in the Linux kernel.

Security

Fixed CVE-2025-68208 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811762 -> 811813
  • Changed: net.ipv4.tcp_mem: 94041 125391 188082 -> 94044 125392 188088
  • Changed: net.ipv4.udp_mem: 188085 250783 376170 -> 188088 250784 376176

Fixed

Upgraded net-misc/socat to v1.8.1.0.

Security

Fixed CVE-2025-40346 in the Linux kernel.

Security

Fixed CVE-2025-40360 in the Linux kernel.

Security

Fixed CVE-2025-68173 in the Linux kernel.

Change

cos-113-18244-521-65

KernelDockerContainerdGPU Drivers
COS-6.1.155v24.0.9v1.7.27See List
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 812054 -> 812031

Security

Fixed CVE-2025-68321 in the Linux kernel.

Security

Fixed CVE-2025-68229 in the Linux kernel.

Security

Fixed CVE-2025-68241 in the Linux kernel.

Security

Fixed CVE-2025-68295 in the Linux kernel.

Change

Updated app-admin/sosreport to v4.10.1. Enabled containerd stack dump by default.

Security

Fixed CVE-2025-68191 in the Linux kernel.

Security

Fixed CVE-2025-68224 in the Linux kernel.

Security

Fixed CVE-2025-66471 and CVE-2025-66418 in dev-python/urllib3.

Security

Fixed CVE-2025-68173 in the Linux kernel.

Security

Fixed CVE-2025-68171 in the Linux kernel.

Security

Fixed CVE-2025-40361 in the Linux kernel.

Security

Fixed CVE-2025-68200 in the Linux kernel.

Security

Fixed CVE-2025-68185 in the Linux kernel.

Fixed

Upgraded sys-apps/dmidecode to v3.7.

Security

Fixed CVE-2025-68231 in the Linux kernel.

Fixed

Upgraded net-misc/socat to v1.8.1.0.

Security

Fixed CVE-2025-40346 in the Linux kernel.

Generative AI on Vertex AI
Deprecated

Anthropic's Claude 3.5 Haiku

Anthropic's Claude 3.5 Haiku is deprecated as of January 5, 2026 and will beshut down on July 5, 2026. For more information, seePartner model deprecations.

Google Kubernetes Engine
Change

(2025-R54) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and formanual control plane upgrades and node upgrades for existing clusters. For moreinformation about versioning and upgrades, seeGKE versioning andsupport andAbout GKEcluster upgrades.

Rapid channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Regular channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Stable channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

There are no new releases in the Stable channel.

Extended channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

No channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Security

(2025-R54) Security updates

This release includes new GKE versions that use updatedContainer-Optimized OS images. These updated images are cumulative,incorporating security fixes from all Container-Optimized OSversions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updatedContainer-Optimized OS image, see theSecurity release notesfor that image. The following table includes links to the release notes foreach updated Container-Optimized OS image:

GKE versionContainer-Optimized OS versionDetails
1.35.0-gke.1340000cos-125-19216-104-45cos-125-19216-104-45 release notes

Infrastructure Manager
Announcement

Infrastructure Manager will deprecate support for Terraform version1.2.3 onJanuary 8, 2026.

If you haveenabled auto-migration, your deployments using Terraform version1.2.3 will be migrated automatically toTerraform version1.5.7.

We recommend that you upgrade your deployment Terraform version from1.2.3 to version1.5.7 before the version1.2.3. end of support date onFebruary 8, 2026.

For more information, seeTerraform version management policydocumentation.

Sensitive Data Protection
Feature

General infoType functionality and the following infoTypes are now available in all regions:

  • CREDIT_CARD_DATA
  • DEMOGRAPHIC_DATA
  • DRIVERS_LICENSE_NUMBER
  • FINANCIAL_ID
  • GEOGRAPHIC_DATA
  • GOVERNMENT_ID
  • MEDICAL_DATA
  • MEDICAL_ID
  • SECURITY_DATA
  • TECHNICAL_ID

For more information about all built-in infoTypes, see theInfoType detector reference.

Spanner
Feature

You can useSQL views to create a graph. Forrequirements, considerations, and the benefits of using SQL views to create agraph, seeOverview of graphs created from SQL views.To learn how to create a graph from views, seeCreate a property graph from SQL views.

January 01, 2026

Carbon Footprint
Issue

We have identified an issue resulting in incomplete Cloud Run emissions data forNovember and December 2025. Customers may observe lower than actual emissionsfor Cloud Run during this period. We are actively working on a fix and willprovide an update when the data correction is available.

Gemini Cloud Assist
Announcement

Gemini Cloud Assist documentation migration

Gemini Cloud Assist release notes are now published here. If you arelooking for Gemini Cloud Assist release notes prior to January 2026,see theGemini for Google Cloud release notes.

December 30, 2025

Text-to-Speech
Feature

Chirp 3: HD voices now support speech synthesis in Preview for the Chinese (Hong Kong)yue-HK language. For more information, seeChirp 3: Language Availability.

December 29, 2025

Apigee XBare Metal Solution
Deprecated

Support for OS imageSLES12SP5SAP on Bare Metal Solution is now deprecated. For information, seeAvailable OS images.

Gemini Enterprise
Feature

Semantic search in sessions

Gemini Enterprise and Business have expanded search capabilities to includesemantic similarity, which lets you find relevant content in your chat historybased on meaning rather than just keywords.

Google Kubernetes Engine
Announcement

Kubernetes 1.35 is now available in the Rapid channel

Kubernetes 1.35 is now available in the Rapid channel. For more information about the content of Kubernetes 1.35, read theKubernetes 1.35 Release Notes and Kubernetes1.35 Release Blog.

Deprecated

Deprecated in 1.35

  • ThePreferClose value for aKubernetes Service'strafficDistribution field is now deprecated in favor of the more explicitPreferSameZone.

Removed in 1.35

  • Kubernetes hasdeprecated cgroup v1 support.
  • GKE is removing cgroup v1 support in 1.35. If you have specifically configured your node pools to use cgroup v1 then upgrades will be blocked until you configure cgroup v2. To migrate to cgroup v2, seeMigrate to cgroup v2.
Change

Other changes in 1.35

  • Windows containerd 2.1: GKE Windows nodes will use containerd 2.1 in 1.35, upgraded from containerd 1.7 in GKE 1.34. Clusters containing Windows nodes will have auto-upgrades to 1.35 delayed until 1.34 EOL due to possible compatibility issues introduced in containerd 2.0. Check if you're using deprecated containerd features removed in 2.0 and migrate off of them, seeMigrate nodes to containerd 2. After all deprecated features are removed, manually upgrade your cluster to 1.35.
Change

(2025-R53) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and formanual control plane upgrades and node upgrades for existing clusters. For moreinformation about versioning and upgrades, seeGKE versioning andsupport andAbout GKEcluster upgrades.

Rapid channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Regular channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

Stable channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

There are no new releases in the Stable channel.

Extended channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.

No channel

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Feature

New features in 1.35

  • In-place Pod Resize:In-place Pod Resize is now GA. This feature allows Pod CPU and memory requests and limits to be modified in-place without Pod or container restart.
  • Writable cgroups: GKEWritable cgroups for containers is now GA. This feature allows workloads to manage resources for child processes using the Linux cgroups API, improving reliability for applications likeRay.
Change

(2025-R53) Version updates

Note: Your clusters might not have these versions available.Rollouts are already in progress when we publish the release notes, and can takemultiple days to complete across all Google Cloud zones.
Pub/Sub
Libraries

Java

1.144.1 (2025-12-22)

Bug Fixes
  • Lower the Subscriber protocol version to disable the streaming pull keepalive feature (#2652) (ca99c2a)

December 26, 2025

Bigtable
Feature

Continuous materialized views support up to five continuous materialized viewsper table. This lets you create multiple asynchronous secondary indexes on atable or have a mix of precomputed aggregate views and asynchronous secondaryindexes on the same base table. For more information, seeContinuous materialized views.

Google Cloud Contact Center as a Service
Announcement

Google Cloud CCaaS 3.42.121 and 3.43.153 patches

These patches fix a security vulnerability that could expose customers'Personally Identifiable Information (PII). There is no change to the agentexperience.

December 25, 2025

Google Cloud VMware Engine
Announcement

VMware Engineve2 nodes are now available in the Milan, Italy (europe-west8-b) zone in the Milan, Italy, Europe region (europe-west8).

December 24, 2025

AlloyDB for PostgreSQL
Change

The extensionvector, which includespgvector functions and operators, is updated to version 0.8.1.

Google SecOps
Announcement

Understand your Google SecOps billing components

A new document is available that helps you understand your Google Security Operations billing components. The document provides information about how to track your usage and the related cost.For more information, seeUnderstand your Google SecOps billing.

Feature

ThreatConnect IOC V3 Connector

Google SecOps now supports the ingestion of Indicators of Compromise (IOCs) from ThreatConnect using the v3 REST API. This updated connector replaces the existing v2-based integration and introduces several enhancements:

  • Advanced Filtering with TQL: Use ThreatConnect Query Language (TQL) to perform highly targeted searches based on complex criteria like confidence scores, tags, or specific timeframes.
  • Efficient Single-Call Data Ingestion: Ingest complete indicator objects—including attributes, tags, and security labels—in a single API call to reduce overhead and improve performance.
  • Synchronization Gaps: Changes in ThreatConnect (for example, ThreatAssessmentScore, confidence, tags) are now replicated into the platform every 30 minutes.

Data ingested through this connector is identified by the new log typeTHREATCONNECT_IOC_V3.

For more information, seeCollect ThreatConnect IOC logs using the v3 API.

Google SecOps Marketplace
Feature

NewOpenSearch integration

Feature

NewProofpoint Cloud Threat Response integration

Feature

Siemplify: Version 98.0

  • The following new action has been added:

    • Export Case
Change

Google Chronicle: Version 71.0

  • Updated event processing and ontology mapping in the following connector:

    • Google Chronicle - Chronicle Alerts Connector
  • Added support for returning raw logs related to UDM events to the followingactions:

    • Get Detection Details

    • Execute UDM Search

Change

Fortigate: Version 17.0

  • Expanded the supported log filter in the following connector:

    • Fortigate - Threat Logs Connector
Google SecOps SIEM
Announcement

Understand your Google SecOps billing components

A new document is available that helps you understand your Google Security Operations billing components. The document provides information about how to track your usage and the related cost.For more information, seeUnderstand your Google SecOps billing.

Feature

ThreatConnect IOC V3 Connector

Google SecOps now supports the ingestion of Indicators of Compromise (IOCs) from ThreatConnect using the v3 REST API. This updated connector replaces the existing v2-based integration and introduces several enhancements:

  • Advanced Filtering with TQL: Use ThreatConnect Query Language (TQL) to perform highly targeted searches based on complex criteria like confidence scores, tags, or specific timeframes.
  • Efficient Single-Call Data Ingestion: Ingest complete indicator objects—including attributes, tags, and security labels—in a single API call to reduce overhead and improve performance.
  • Synchronization Gaps: Changes in ThreatConnect (for example, ThreatAssessmentScore, confidence, tags) are now replicated into the platform every 30 minutes.

Data ingested through this connector is identified by the new log typeTHREATCONNECT_IOC_V3.

For more information, seeCollect ThreatConnect IOC logs using the v3 API.

Announcement

Understand your Google SecOps billing components

A new document is available that helps you understand your Google Security Operations billing components. The document provides information about how to track your usage and the related cost.For more information, seeUnderstand your Google SecOps billing.

Feature

ThreatConnect IOC V3 Connector

Google SecOps now supports the ingestion of Indicators of Compromise (IOCs) from ThreatConnect using the v3 REST API. This updated connector replaces the existing v2-based integration and introduces several enhancements:

  • Advanced Filtering with TQL: Use ThreatConnect Query Language (TQL) to perform highly targeted searches based on complex criteria like confidence scores, tags, or specific timeframes.
  • Efficient Single-Call Data Ingestion: Ingest complete indicator objects—including attributes, tags, and security labels—in a single API call to reduce overhead and improve performance.
  • Synchronization Gaps: Changes in ThreatConnect (for example, ThreatAssessmentScore, confidence, tags) are now replicated into the platform every 30 minutes.

Data ingested through this connector is identified by the new log typeTHREATCONNECT_IOC_V3.

For more information, seeCollect ThreatConnect IOC logs using the v3 API.

December 23, 2025

Apigee X
Feature

New Apigee policies for LLM Token Management are now Generally Available (GA)

Two new Apigee policies for managing Large Language Model (LLM) workloads are now Generally Available (GA). These policies provide fine-grained control and rate-limiting for AI application traffic as follows:

Related documents:

Cloud Composer
Issue

Environments with Cloud Composer 2 versions 2.16.0 and 2.16.1 might experienceaknown issuewith the reporting of metrics. You can observe a few skipped data points in thereported metrics and see error messages about the airflow-monitoring podrestarts in the environment logs.

This issue doesn't affect the environment's functionality. The environment isstill operational and the environment health and monitoring information isreported correctly. You can ignore the error messages.

Gemini Enterprise
Feature

Gemini Enterprise: Manage actions using the updated flow (Public preview)

Use the new capabilities on theActions page to:

  • Add new actions skipped during the data store creation process.

  • Enable or disable the existing actions.

  • Re-authenticate actions and verify authentication parameters.

For more information, seeManageactions.

Google Cloud Contact Center as a Service
Announcement

Web SDK version 2 will be shut down on June 26, 2026

On June 26, 2025, we announced the launch ofWeb SDK version3. Starting onJune 26, 2026, the web SDK v2 will no longer function. Be sure toupdateyour website to use theweb SDK v3 before that date to avoid breaking your integration with the web SDK.We are no longer adding new features to the web SDK v2.

Looker
Feature

Historical data cannot be accessed with the API Usage System Activity Explore for Looker instances that are running Looker 25.16 or later. Looker instances that are running Looker 25.16 or later must use theAPI Usage Hourly System Activity Explore.

Looker Studio
Feature

Partner connection launch update

The following partner connectors have been added to theLooker Studio Connector Gallery:

SAP on Google Cloud
Change

Updated IpAddr2 resource configuration for HA clusters

To make the SAP HANA and SAP NetWeaver HA cluster configurations forwardcompatible with OS version updates, we recommend that you update theIpAddr2resource configuration to usenic=lo instead ofnic=eth0.

For updated guidance, see the HA cluster configuration for your scenario:

December 22, 2025

Access Approval
Feature

Backup and DR Service is generally available(GA).

Access Transparency
Feature

Backup and DR Service is generally available(GA).

Agent Assist
Feature

Agent Assist offers a UI connector to integrate withNice CXOne Voice for Salesforce. This integration provides agent suggestions for Salesforce customers using NICE CXOne for their voice channel.

App Engine flexible environment Java
Feature
App Engine standard environment Java
Feature
App Hub
Feature

App Hub now lets you view extended metadata schemas. This feature helps you visualize rich, structured, and schema-driven information about your resources. For more details, seeView extended metadata schemas.

Backup and DR
Feature

Enhanced performance for restore and clone of VMware VMs.

Expanded Linux CBT support for new kernels on RHEL 8 and 9.

Security

Addressed multiple OpenSSH vulnerabilities, including CVE-2025-26465 and CVE-2025-26466.

Fixed

Backup/Recovery appliance non-disruptive update:

  • Resolved issues with Db2 migration scripts and various SAP HANA backup failures, including differential and log backups.
  • Improved system stability and diagnostics by enhancing logging, adding log rotation, and correcting unit reporting in dashboards.
  • Corrected the data copy reporting for Persistent Disk (PD) based backups, ensuring it accurately reflects zero data copied.
BigQuery
Feature

The BigQuery Data Transfer Service can nowtransfer data from PostgreSQL toBigQuery. This feature isgenerallyavailable (GA).

Libraries

Java

2.58.0-rc1 (2025-12-17)

Features
  • Add ability to specify RetryOptions and BigQueryRetryConfig when create job and waitFor (#3398) (1f91ae7)
  • add additional parameters to CsvOptions and ParquetOptions (#3370) (34f16fb)
  • add columnNameCharacterMap to LoadJobConfiguration (#3356) (2f3cbe3)
  • add max staleness to ExternalTableDefinition (#3499) (f1ebd5b)
  • add MetadataCacheMode to ExternalTableDefinition (#3351) (2814dc4)
  • add remaining Statement Types (#3381) (5f39b19)
  • add WRITE_TRUNCATE_DATA as an enum value for write disposition (#3752) (acea61c)
  • bigquery: Add custom ExceptionHandler to BigQueryOptions (#3937) (de0914d)
  • bigquery: Add OpenTelemetry Samples (#3899) (e3d9ed9)
  • bigquery: Add OpenTelemetry support to BQ rpcs (#3860) (e2d23c1)
  • bigquery: Add otel metrics to request headers (#3900) (4071e4c)
  • bigquery: Add support for custom timezones and timestamps (#3859) (e5467c9)
  • bigquery: Add support for reservation field in jobs. (#3768) (3e97f7c)
  • bigquery: Implement getArray in BigQueryResultImpl (#3693) (e2a3f2c)
  • bigquery: Integrate Otel in client lib (#3747) (6e3e07a)
  • bigquery: Integrate Otel into retries, jobs, and more (#3842) (4b28c47)
  • bigquery: job creation mode GA (#3804) (a21cde8)
  • bigquery: Support Fine Grained ACLs for Datasets (#3803) (bebf1c6)
  • bigquery: support IAM conditions in datasets in Java client. (#3602) (6696a9c)
  • bigquery: Support resource tags for datasets in java client (#3647) (01e0b74)
  • configure rc releases to be on prerelease mode (93700c8)
  • Enable Lossless Timestamps in BQ java client lib (#3589) (c0b874a)
  • Enable maxTimeTravelHours in BigQuery java client library (#3555) (bd24fd8)
  • implement wasNull for BigQueryResultSet (#3650) (c7ef94b)
  • introducejava.time methods and variables (#3586) (31fb15f)
  • new queryWithTimeout method for customer-side wait (#3995) (9c0df54)
  • next release from main branch is 2.49.0 (#3706) (b46a6cc)
  • next release from main branch is 2.53.0 (#3879) (c47a062)
  • Relax client-side validation for BigQuery entity IDs (#4000) (c3548a2)
  • update with latest from main (#4034) (ec447b5)
Bug Fixes
Dependencies
  • exclude io.netty:netty-common from org.apache.arrow:arrow-memor… (#3715) (11b5809)
  • fix update dependency com.google.cloud:google-cloud-bigquerystorage-bom to v3.17.2 (b25095d)
  • remove version declaration of open-telemetry-bom (#3855) (6f9f77d)
  • rollback netty.version to v4.1.119.Final (#3827) (94c71a0)
  • update actions/checkout action to v4.1.6 (#3309) (c7d6362)
  • update actions/checkout action to v4.1.7 (#3349) (0857234)
  • update actions/checkout action to v4.2.0 (#3495) (b57fefb)
  • update actions/checkout action to v4.2.1 (#3520) (ad8175a)
  • update actions/checkout action to v4.2.2 (#3541) (c36c123)
  • update actions/upload-artifact action to v4.3.4 (#3382) (efa1aef)
  • update actions/upload-artifact action to v4.3.5 (#3420) (d5ec87d)
  • update actions/upload-artifact action to v4.3.5 (#3422) (c7d07b3)
  • update actions/upload-artifact action to v4.3.5 (#3424) (a9d6869)
  • update actions/upload-artifact action to v4.3.5 (#3427) (022eb57)
  • update actions/upload-artifact action to v4.3.5 (#3430) (c7aacba)
  • update actions/upload-artifact action to v4.3.5 (#3432) (b7e8244)
  • update actions/upload-artifact action to v4.3.5 (#3436) (ccefd6e)
  • update actions/upload-artifact action to v4.3.5 (#3440) (916fe9a)
  • update actions/upload-artifact action to v4.3.5 (#3443) (187f099)
  • update actions/upload-artifact action to v4.3.5 (#3444) (04aea5e)
  • update actions/upload-artifact action to v4.3.5 (#3449) (c6e93cd)
  • update actions/upload-artifact action to v4.3.5 (#3455) (fbfc106)
  • update actions/upload-artifact action to v4.3.5 (#3456) (f00977c)
  • update actions/upload-artifact action to v4.3.5 (#3462) (e1c6e92)
  • update actions/upload-artifact action to v4.3.6 (#3463) (ba91227)
  • update actions/upload-artifact action to v4.4.0 (#3467) (08b28c5)
  • update actions/upload-artifact action to v4.4.1 (#3521) (dc21975)
  • update actions/upload-artifact action to v4.4.2 (#3524) (776a554)
  • update actions/upload-artifact action to v4.4.3 (#3530) (2f87fd9)
  • update actions/upload-artifact action to v4.5.0 (#3620) (cc25099)
  • update actions/upload-artifact action to v4.6.0 (#3633) (ca20aa4)
  • update actions/upload-artifact action to v4.6.1 (#3691) (9c0edea)
  • update actions/upload-artifact action to v4.6.2 (#3724) (426a59b)
  • update actions/upload-artifact action to v4.6.2 (#3724) (483f930)
  • update bigquerystorage-bom to 3.20.0-rc1 (#4035) (cb44b5f)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.46.0 (#3328) (a6661ad)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.47.0 (#3342) (79e34c2)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.48.0 (#3374) (45b7f20)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.49.0 (#3417) (66336a8)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.50.0 (#3448) (2c12839)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.51.0 (#3480) (986b036)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.53.0 (#3504) (57ce901)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.54.0 (#3532) (25be311)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.55.0 (#3559) (950ad0c)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.56.0 (#3582) (616ee2a)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.57.0 (#3617) (51370a9)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.58.0 (#3631) (b0ea0d5)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.59.0 (#3660) (3a6228b)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.60.0 (#3680) (6d9a40d)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.61.0 (#3703) (53b07b0)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.62.0 (#3726) (38e004b)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.63.0 (#3770) (934389e)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.65.0 (#3787) (0574ecc)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.66.0 (#3835) (69be5e7)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.68.0 (#3858) (d4ca353)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.69.0 (#3870) (a7f1007)
  • update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.70.0 (#3890) (84207e2)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20240602-2.0.0 (#3273) (7b7e52b)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20240616-2.0.0 (#3368) (ceb270c)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20240623-2.0.0 (#3384) (e1de34f)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20240629-2.0.0 (#3392) (352562d)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20240714-2.0.0 (#3412) (8a48fd1)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20240727-2.0.0 (#3421) (91d780b)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20240727-2.0.0 (#3423) (16f350c)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20240727-2.0.0 (#3428) (9ae6eca)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20240803-2.0.0 (#3435) (b4e20db)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20240815-2.0.0 (#3454) (8796aee)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20240905-2.0.0 (#3483) (a6508a2)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20240919-2.0.0 (#3514) (9fe3829)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20241013-2.0.0 (#3544) (0c42092)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20241027-2.0.0 (#3568) (b5ccfcc)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20241111-2.0.0 (#3591) (3eef3a9)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20241115-2.0.0 (#3601) (41f9adb)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20241222-2.0.0 (#3623) (4061922)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20250112-2.0.0 (#3651) (fd06100)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20250128-2.0.0 (#3667) (0b92af6)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20250216-2.0.0 (#3688) (e3beb6f)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20250302-2.0.0 (#3720) (c0b3902)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20250313-2.0.0 (#3723) (b8875a8)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20250404-2.0.0 (#3754) (1381c8f)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20250427-2.0.0 (#3773) (c0795fe)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20250511-2.0.0 (#3794) (d3bf724)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20250615-2.0.0 (#3872) (f081589)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20250706-2.0.0 (#3910) (ae5c971)
  • update dependency com.google.apis:google-api-services-bigquery to v2-rev20251012-2.0.0 (#3923) (1d8977d)
  • update dependency com.google.cloud:google-cloud-bigquerystorage-bom to v3.10.0 (0bd3c86)
  • update dependency com.google.cloud:google-cloud-bigquerystorage-bom to v3.10.1 (c03a63a)
  • update dependency com.google.cloud:google-cloud-bigquerystorage-bom to v3.10.2 (19fc184)
  • update dependency com.google.cloud:google-cloud-bigquerystorage-bom to v3.17.0 (#3954) (e73deed)
  • update dependency com.google.cloud:google-cloud-bigquerystorage-bom to v3.9.0 (c4afbef)
  • update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.50.0 (#3330) (cabb0ab)
  • update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.51.0 (#3343) (e3b934f)
  • update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.52.0 (#3375) (2115c04)
  • update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.53.0 (#3418) (6cff7f0)
  • update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.54.0 (#3450) (cc9da95)
  • update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.55.0 (#3481) (8908cfd)
  • update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.57.0 (#3505) (6e78f56)
  • update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.58.0 (#3533) (cad2643)
  • update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.59.0 (#3561) (1bd24a1)
  • update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.60.0 (#3583) (34dd8bc)
  • update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.61.0 (#3618) (6cba626)
  • update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.62.0 (#3632) (e9ff265)
  • update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.63.0 (#3661) (9bc8c01)
  • update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.64.0 (#3681) (9e4e261)
  • update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.65.0 (#3704) (53b68b1)
  • update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.66.0 (#3727) (7339f94)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.31.0 (#3335) (0623455)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.32.0 (#3360) (4420996)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.33.0 (#3405) (a4a9999)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.34.0 (#3433) (801f441)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.35.0 (#3472) (fa9ac5d)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.36.0 (#3490) (a72c582)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.36.1 (#3496) (8f2e5c5)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.37.0 (bf4d37a)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.38.0 (#3542) (16448ee)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.39.0 (#3548) (616b2f6)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.40.0 (#3576) (d5fa951)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.41.0 (#3607) (11499d1)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.41.1 (#3628) (442d217)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.42.0 (#3653) (1a14342)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.43.0 (#3669) (4d9e0ff)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.44.0 (#3694) (f69fbd3)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.45.1 (#3714) (e4512aa)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.46.0 (#3753) (a335927)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.46.2 (#3756) (907e39f)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.46.3 (#3772) (ab166b6)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.47.0 (#3779) (b27434b)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.48.0 (#3790) (206f06d)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.49.0 (#3811) (2c5ede4)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.49.2 (#3853) (cf864df)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.50.0 (#3861) (eb26dee)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.50.1 (#3878) (0e971b8)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.50.2 (#3901) (8205623)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.51.0 (#3924) (cb66be5)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.0 (#3939) (794bf83)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.1 (#3952) (79b7557)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.2 (#3964) (6775fce)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.3 (#3971) (f8cf508)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.53.0 (#3980) (a961247)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.54.1 (#3994) (4e09f6b)
  • update dependency com.google.oauth-client:google-oauth-client-java6 to v1.36.0 (#3305) (d05e554)
  • update dependency com.google.oauth-client:google-oauth-client-java6 to v1.37.0 (#3614) (f5faa69)
  • update dependency com.google.oauth-client:google-oauth-client-java6 to v1.38.0 (#3685) (53bd7af)
  • update dependency com.google.oauth-client:google-oauth-client-java6 to v1.39.0 (#3710) (c0c6352)
  • update dependency com.google.oauth-client:google-oauth-client-jetty to v1.36.0 (#3306) (0eeed66)
  • update dependency com.google.oauth-client:google-oauth-client-jetty to v1.37.0 (#3615) (a6c7944)
  • update dependency com.google.oauth-client:google-oauth-client-jetty to v1.38.0 (#3686) (d71b2a3)
  • update dependency com.google.oauth-client:google-oauth-client-jetty to v1.39.0 (#3711) (43b86e9)
  • update dependency io.opentelemetry:opentelemetry-api to v1.52.0 (#3902) (772407b)
  • update dependency io.opentelemetry:opentelemetry-bom to v1.51.0 (#3840) (51321c2)
  • update dependency io.opentelemetry:opentelemetry-bom to v1.52.0 (#3903) (509a6fc)
  • update dependency io.opentelemetry:opentelemetry-context to v1.52.0 (#3904) (96c1bae)
  • update dependency io.opentelemetry:opentelemetry-exporter-logging to v1.52.0 (#3905) (28ee4c9)
  • update dependency node to v22 (#3713) (251def5)
  • update dependency org.graalvm.buildtools:junit-platform-native to v0.10.2 (#3311) (3912a92)
  • update dependency org.graalvm.buildtools:native-maven-plugin to v0.10.2 (#3312) (9737a5d)
  • update dependency org.junit.vintage:junit-vintage-engine to v5.10.3 (#3371) (2e804c5)
  • update dependency ubuntu to v24 (#3498) (4f87ade)
  • update github/codeql-action action to v2.25.10 (#3348) (8b6feff)
  • update github/codeql-action action to v2.25.11 (#3376) (f1e0014)
  • update github/codeql-action action to v2.25.12 (#3387) (af60b30)
  • update github/codeql-action action to v2.25.13 (#3395) (95c8d6f)
  • update github/codeql-action action to v2.25.15 (#3402) (a61ce7d)
  • update github/codeql-action action to v2.25.6 (#3307) (8999d33)
  • update github/codeql-action action to v2.25.7 (#3334) (768342d)
  • update github/codeql-action action to v2.25.8 (#3338) (8673fe5)
  • update github/codeql-action action to v2.26.10 (#3506) (ca71294)
  • update github/codeql-action action to v2.26.11 (#3517) (ac736bb)
  • update github/codeql-action action to v2.26.12 (#3522) (fdf8dc4)
  • update github/codeql-action action to v2.26.13 (#3536) (844744f)
  • update github/codeql-action action to v2.26.2 (#3426) (0a6574f)
  • update github/codeql-action action to v2.26.3 (#3438) (390e182)
  • update github/codeql-action action to v2.26.5 (#3446) (58aacc5)
  • update github/codeql-action action to v2.26.6 (#3464) (2aeb44d)
  • update github/codeql-action action to v2.26.7 (#3482) (e2c94b6)
  • update github/codeql-action action to v2.26.8 (#3488) (a6d75de)
  • update github/codeql-action action to v2.26.9 (#3494) (8154043)
  • update github/codeql-action action to v2.27.0 (#3540) (1616a0f)
  • update github/codeql-action action to v2.27.1 (#3567) (e154ee3)
  • update github/codeql-action action to v2.27.3 (#3569) (3707a40)
  • update github/codeql-action action to v2.27.4 (#3572) (2c7b4f7)
  • update github/codeql-action action to v2.27.5 (#3588) (3f94075)
  • update github/codeql-action action to v2.27.6 (#3597) (bc1f3b9)
  • update github/codeql-action action to v2.27.7 (#3603) (528426b)
  • update github/codeql-action action to v2.27.9 (#3608) (567ce01)
  • update github/codeql-action action to v2.28.0 (#3621) (e0e09ec)
  • update github/codeql-action action to v2.28.1 (#3637) (858e517)
  • update netty.version to v4.1.119.final (#3717) (08a290a)
  • update netty.version to v4.2.0.final (#3745) (bb811c0)
  • update netty.version to v4.2.1.final (#3780) (6dcd858)
  • update ossf/scorecard-action action to v2.4.0 (#3408) (66777a2)
  • update ossf/scorecard-action action to v2.4.1 (#3690) (cdb61fe)
  • update ossf/scorecard-action action to v2.4.2 (#3810) (414f61d)
  • update sdk-platform-java-config to 3.55.0-rc1 (#4033) (580427d)
Documentation
  • add short mode query sample (#3397) (6dca6ff)
  • add simple query connection read api sample (#3394) (d407baa)
  • bigquery: Add javadoc description of timestamp() parameter. (#3604) (6ee0c10)
  • bigquery: Update TableResult.getTotalRows() docstring (#3785) (6483588)
  • fix BigQuery documentation formating (#3565) (552f491)
  • reformat javadoc (#3545) (4763f73)
  • update CONTRIBUTING.md for users without branch permissions (#3670) (009b9a2)
  • update error handling comment to be more precise in samples (#3712) (9eb555f)
  • update iam policy sample user to be consistent with other languages (#3429) (2fc15b3)
  • update maven format command (#3877) (d2918da)
  • Update SimpleApp to explicitly set project id (#3534) (903a0f7)
Bigtable
Libraries

Python

2.35.0 (2025-12-16)

Features
  • add basic interceptor to client (#1206) (6561cfac)

  • Add encodings for STRUCT and the Timestamp type (72dfdc44)

  • add PeerInfo proto in Bigtable API (72dfdc44)

  • Add Type API updates needed to support structured keys in materialized views (72dfdc44)

  • support mTLS certificates when available (#1249) (ca20219c)

Bug Fixes
  • re-export AddToCell for consistency (#1241) (2a5baf11)

  • async client uses fixed grace period (#1236) (544db1cd)

  • Deprecate credentials_file argument (72dfdc44)

  • Add ReadRows/SampleRowKeys bindings for materialized views (72dfdc44)

  • retry cancelled errors (#1235) (e3fd5d86)

Java

2.71.0-rc1 (2025-12-19)

Features
Dependencies
  • update sdk-platform-java-config to 3.55.0-rc1 (#2738) (136f164)
Cloud Healthcare API
Feature
  • The Cloud Healthcare API now supports transcoding DICOM data with thefollowing transfer syntaxes:

  • 1.2.840.10008.1.2.1.99 (Deflated Explicit VR Little Endian)

  • 1.2.840.10008.1.2.4.51 (JPEG Extended)

  • 1.2.840.10008.1.2.4.80 (JPEG-LS Lossless)

  • 1.2.840.10008.1.2.4.81 (JPEG-LS Near-Lossless)

  • 1.2.840.10008.1.2.4.110 (JPEG XL Lossless)

  • 1.2.840.10008.1.2.4.111 (JPEG XL JPEG Recompression)

  • 1.2.840.10008.1.2.4.112 (JPEG XL)

  • 1.2.840.10008.1.2.4.201 (HTJ2K Lossless Only)

  • 1.2.840.10008.1.2.4.202 (HTJ2K Lossless Only with RPCL Options)

  • 1.2.840.10008.1.2.4.203 (HTJ2K)

  • 1.2.840.10008.1.2.8.1 (Deflated Image Frame Compression)

Cloud Logging
Libraries

Python

3.13.0 (2025-12-15)

Features
  • Add support for python 3.14 (#1065) (6be3df6a)
Bug Fixes
  • remove setup.cfg configuration for creating universal wheels (#981) (70f612c3)

Java

3.24.0-rc1 (2025-12-16)

Features
Bug Fixes
  • deps: Update the Java code generator (gapic-generator-java) to 2.31.0 (#1502) (c7a20de)
  • deps: Update the Java code generator (gapic-generator-java) to 2.32.0 (#1511) (e2f574c)
  • deps: Update the Java code generator (gapic-generator-java) to 2.37.0 (#1553) (15b05fc)
  • deps: Update the Java code generator (gapic-generator-java) to 2.39.0 (#1587) (848418b)
  • deps: update the Java code generator (gapic-generator-java) to 2.47.0 (90b88ee)
  • deps: update the Java code generator (gapic-generator-java) to 2.49.0 (a1ec68d)
  • deps: update the Java code generator (gapic-generator-java) to 2.50.0 (afcf63c)
  • deps: update the Java code generator (gapic-generator-java) to 2.51.0 (04d8868)
  • deps: update the Java code generator (gapic-generator-java) to 2.51.1 (705dba2)
  • deps: update the Java code generator (gapic-generator-java) to 2.52.0 (888a885)
  • deps: update the Java code generator (gapic-generator-java) to 2.54.0 (67fa9fb)
  • deps: update the Java code generator (gapic-generator-java) to 2.55.1 (dd25992)
  • deps: update the Java code generator (gapic-generator-java) to 2.56.2 (7cce5b5)
  • deps: update the Java code generator (gapic-generator-java) to 2.56.3 (844f4fa)
  • deps: update the Java code generator (gapic-generator-java) to 2.58.0 (45b4878)
  • deps: update the Java code generator (gapic-generator-java) to 2.59.0 (f2362fb)
  • deps: update the Java code generator (gapic-generator-java) to 2.60.2 (6a268f8)
  • deps: update the Java code generator (gapic-generator-java) to 2.61.0 (0a21b83)
  • deps: update the Java code generator (gapic-generator-java) to 2.62.1 (1438bff)
  • deps: update the Java code generator (gapic-generator-java) to 2.62.2 (eeca440)
  • deps: update the Java code generator (gapic-generator-java) to 2.62.3 (5d5d8a7)
  • deps: update the Java code generator (gapic-generator-java) to 2.63.0 (385a1dc)
  • deps: update the Java code generator (gapic-generator-java) to 2.64.1 (9187dcd)
  • enable v2.LogEntry Protobufs converter functions (#1509) (9ef4d90)
  • Fixed outdated link to X-Cloud-Trace-Context header description (#1713) (d474313)
  • java: handle empty modules (09eeff0)
  • java: skip fixing poms for special modules (#1744) (#1256) (09eeff0)
  • next release candidate (31ee5a3)
  • regenerate gapic yaml and service yaml for logging by augmentation configs (9023895)
  • Remove org.jspecify dependency (#1364) (8138f46)
  • Replace internal Structs class with google-cloud-core version (#1501) (21e1929)
Dependencies
  • update actions/checkout action to v4 (#1570) (ea0db35)
  • update actions/github-script action to v7 (#1571) (16d6192)
  • update actions/setup-java action to v4 (#1572) (9eb8834)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.1.1 (#1243) (fdf6b7a)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.1.2 (#1258) (d4bc663)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.10.1 (#1354) (b2f1111)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.11.0 (#1367) (8cd2a53)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.12.0 (#1382) (8241302)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.13.0 (#1388) (03179b0)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.13.1 (#1395) (1a29b9d)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.14.0 (#1409) (f9af381)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.15.0 (#1424) (4f82f33)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.16.1 (#1434) (e9e9835)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.17.0 (#1444) (748e8a2)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.18.0 (#1454) (dc25a87)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.19.0 (#1468) (5835a7d)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.2.0 (#1269) (e196a80)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.20.0 (#1484) (f3227db)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.21.0 (#1500) (6cce3c9)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.22.0 (#1510) (b40e846)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.23.0 (#1518) (30ba9ed)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.3.0 (#1282) (58ac608)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.4.0 (#1290) (84d42ae)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.5.0 (#1301) (9fa6f05)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.6.0 (#1308) (febcf49)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.7.0 (#1318) (973d260)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.8.0 (#1326) (5a56f1b)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.9.0 (#1342) (8b14ae1)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.24.0 (#1526) (235f1aa)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.25.0 (#1535) (7fde779)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.27.0 (#1552) (6c5464d)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.28.0 (#1560) (d52e623)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.28.1 (#1563) (81aa3e6)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.28.1 (#1569) (8eb0781)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.29.0 (#1586) (edcaf8d)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.30.0 (#1603) (16967e5)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.30.1 (#1611) (e7a0904)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.31.0 (#1625) (9db8f3b)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.32.0 (#1649) (cb428d1)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.33.0 (#1664) (cb6de76)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.34.0 (#1677) (dbd050c)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.35.0 (#1683) (31ec2b9)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.36.1 (#1698) (9491512)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.37.0 (#1702) (1f7da17)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.41.1 (#1745) (6a7280d)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.42.0 (#1755) (d404381)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.43.0 (#1763) (e0f9f27)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.44.0 (#1768) (a69e699)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.45.1 (#1779) (a643ab0)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.46.2 (#1796) (1f88271)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.46.3 (#1801) (d7aa7bc)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.47.0 (#1803) (5967ffe)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.48.0 (#1808) (6327c51)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.49.0 (#1813) (c15da84)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.50.0 (#1821) (af4edc5)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.50.1 (#1828) (44c3094)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.50.2 (#1834) (2e46f6e)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.51.0 (#1843) (975d8ae)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.0 (#1848) (162ef56)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.1 (#1853) (c21a635)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.2 (#1858) (0252352)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.3 (#1869) (94405fa)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.53.0 (#1875) (b79fd2b)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.54.1 (#1883) (acc56db)
  • update dependency io.opentelemetry:opentelemetry-bom to v1.45.0 (#1638) (7e007d4)
  • update dependency io.opentelemetry:opentelemetry-bom to v1.46.0 (#1747) (5ef2853)
  • update dependency org.apache.maven.plugins:maven-deploy-plugin to v3.1.3 (2b6ea70)
  • update dependency org.easymock:easymock to v5.2.0 (#1421) (f931544)
  • update dependency org.easymock:easymock to v5.5.0 (#1639) (f559d89)
  • update dependency org.graalvm.buildtools:junit-platform-native to v0.10.0 (#1528) (b3e4f9b)
  • update dependency org.graalvm.buildtools:junit-platform-native to v0.9.20 (#1279) (296cce1)
  • update dependency org.graalvm.buildtools:junit-platform-native to v0.9.21 (#1319) (5aef8d6)
  • update dependency org.graalvm.buildtools:junit-platform-native to v0.9.22 (#1340) (b3b9d5f)
  • update dependency org.graalvm.buildtools:junit-platform-native to v0.9.23 (#1374) (dce3c4c)
  • update dependency org.graalvm.buildtools:junit-platform-native to v0.9.24 (#1411) (0487cdf)
  • update dependency org.graalvm.buildtools:junit-platform-native to v0.9.26 (#1420) (ff581a6)
  • update dependency org.graalvm.buildtools:junit-platform-native to v0.9.27 (#1430) (9e750a3)
  • update dependency org.graalvm.buildtools:junit-platform-native to v0.9.28 (#1455) (3080cec)
  • update dependency org.graalvm.buildtools:native-maven-plugin to v0.10.0 (#1456) (f27713e)
  • update dependency org.graalvm.buildtools:native-maven-plugin to v0.10.1 (#1542) (af784bc)
  • update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.20 (#1280) (6363196)
  • update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.21 (#1320) (fc2d065)
  • update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.22 (#1341) (cfc0106)
  • update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.23 (#1375) (a15c73c)
  • update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.26 (#1412) (bd9be4e)
  • update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.27 (#1431) (7c2aa2c)
  • update dependency org.junit.vintage:junit-vintage-engine to v5.10.0 (#1397) (f15d246)
  • update dependency org.junit.vintage:junit-vintage-engine to v5.10.1 (#1471) (debc77f)
  • update dependency org.junit.vintage:junit-vintage-engine to v5.10.2 (#1530) (20981dc)
  • update dependency org.junit.vintage:junit-vintage-engine to v5.9.2 (#1245) (e73a704)
  • update dependency org.junit.vintage:junit-vintage-engine to v5.9.3 (#1329) (dfb98f4)
  • update googleapis/sdk-platform-java action to v2.51.1 (#1742) (3c7a2c7)
  • update googleapis/sdk-platform-java action to v2.52.0 (#1753) (3dcf86a)
  • update googleapis/sdk-platform-java action to v2.54.0 (#1762) (d50a8d2)
  • update googleapis/sdk-platform-java action to v2.55.1 (#1780) (505557e)
  • update googleapis/sdk-platform-java action to v2.57.0 (#1804) (e9a27ec)
  • update googleapis/sdk-platform-java action to v2.58.0 (#1806) (b94da77)
  • update googleapis/sdk-platform-java action to v2.60.0 (#1822) (0a96dd5)
  • update googleapis/sdk-platform-java action to v2.62.1 (#1855) (b6ce498)
  • update googleapis/sdk-platform-java action to v2.62.3 (#1868) (cac5cd9)
  • update googleapis/sdk-platform-java action to v2.64.1 (#1882) (abdd374)
  • update sdk platform java dependencies (#1707) (2359040)
  • update sdk platform java dependencies (#1717) (ee9ef91)
  • update sdk platform java dependencies (#1725) (531f8c5)
  • update sdk platform java dependencies (#1736) (88b4cdf)
  • update sdk-platform-java-config to 3.55.0-rc1 (#1903) (750a9d7)
Documentation

Python

3.13.0 (2025-12-15)

Features
  • Add support for python 3.14 (#1065) (6be3df6a)
Bug Fixes
  • remove setup.cfg configuration for creating universal wheels (#981) (70f612c3)

Python

3.13.0 (2025-12-15)

Features
  • Add support for python 3.14 (#1065) (6be3df6a)
Bug Fixes
  • remove setup.cfg configuration for creating universal wheels (#981) (70f612c3)

Python

3.13.0 (2025-12-15)

Features
  • Add support for python 3.14 (#1065) (6be3df6a)
Bug Fixes
  • remove setup.cfg configuration for creating universal wheels (#981) (70f612c3)

Python

3.13.0 (2025-12-15)

Features
  • Add support for python 3.14 (#1065) (6be3df6a)
Bug Fixes
  • remove setup.cfg configuration for creating universal wheels (#981) (70f612c3)

Python

3.13.0 (2025-12-15)

Features
  • Add support for python 3.14 (#1065) (6be3df6a)
Bug Fixes
  • remove setup.cfg configuration for creating universal wheels (#981) (70f612c3)

Python

3.13.0 (2025-12-15)

Features
  • Add support for python 3.14 (#1065) (6be3df6a)
Bug Fixes
  • remove setup.cfg configuration for creating universal wheels (#981) (70f612c3)
Cloud Run
Feature
Cloud Run functions
Feature
Cloud Storage
Libraries

Java

2.61.0 (2025-12-15)

Features
  • Add support for partial success in ListBuckets for json (#3415) (37ef7f3)
  • Modifying getters and setters to be more inline with s3 interface. (0a8bbea)
  • mpu: Breaking change modifying getters and setters in MPU to be more inline with s3 interface. (66d54e2)
Bug Fixes
  • deps: Update the Java code generator (gapic-generator-java) to 2.64.1 (511ff51)
Dependencies
  • Update actions/checkout action to v6 (d934ad9)
  • Update actions/checkout action to v6 (d99dd53)
  • Update dependency com.google.apis:google-api-services-storage to v1-rev20251118-2.0.0 (f48fa3f)
  • Update dependency com.google.apis:google-api-services-storage to v1-rev20251118-2.0.0 (#3427) (4612e72)
  • Update dependency com.google.cloud:sdk-platform-java-config to v3.54.2 (90a71be)
  • Update dependency com.google.cloud:sdk-platform-java-config to v3.54.2 (#3424) (c989dc3)
  • Update gcr.io/cloud-devrel-public-resources/storage-testbench docker tag to v0.59.0 (f5d8337)
  • Update gcr.io/cloud-devrel-public-resources/storage-testbench docker tag to v0.59.0 (5480ce3)
  • Update googleapis/sdk-platform-java action to v2.64.2 (23494d7)
  • Update googleapis/sdk-platform-java action to v2.64.2 (#3425) (fad2d7a)

Java

2.62.0-rc1 (2025-12-17)

Features
  • breaking behavior rewrite Storage.blobAppendableUpload to be non-blocking and have improved throughput (#3231) (7bd73d3)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (62b6248)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (c3a0aaa)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (fac7839)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (8332e1b)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (e4688a0)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (b426e7d)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (c601cca)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (c58fe1f)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (616256a)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (ba3af58)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (e12d2ad)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (d6044a1)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (eebc6c6)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (12507e2)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (58557a0)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (c109fdb)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (d98ecc7)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (6858a9d)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (bb7e1b4)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (e89ae27)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (8beaa03)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (ff8fd8f)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (944e0bc)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (eb8c5c8)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (50e4589)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (a751971)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (befff3b)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (ac950ad)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (f381795)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (84ffb6d)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (b95e51d)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (03aa3e7)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (23f9a79)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (e2a3e3c)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (bee4308)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (28f2759)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (775ad24)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (f29d825)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (2e8a0ee)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (5c2cf19)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (2431ee1)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (aeb621a)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (3d2520d)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (3e38109)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (8453281)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (4170803)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (f8e54b5)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (85049b9)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (2a92e35)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (3b195fe)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (ae31163)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (b1499d6)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (1085216)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (3616097)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (6a80994)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (69d01d4)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (fa0df98)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (3eec2e3)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (1bf497e)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (bc7a931)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (c6f5b57)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (8d4d7a3)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (affb14f)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (09c426b)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (af52279)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (72491e7)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (2968790)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (a4d919e)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (f437c0a)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (ba70fd8)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (95d46a5)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (413d65f)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (52639da)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (961f3cb)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (98dbb02)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (cbc22f2)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (f7c37f5)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (a7a8945)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (26db9e3)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (3ca4123)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (8553cb9)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (758756f)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (065d249)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (61824e6)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (67482f7)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (d540a83)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (8e516e6)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (0a2fac5)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (35c2fbf)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (e5e1107)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (79bea2c)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (9416a8f)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (411615d)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (51af43e)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (0bfb9ff)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (c648d38)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (b8dda33)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (264683e)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (c653bb6)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (24be97d)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (a0535c5)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (be3be3f)
  • add @BetaApi Storage#blobAppendableUpload for gRPC Transport (ec59078)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (62b6248)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (c3a0aaa)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (fac7839)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (8332e1b)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (e4688a0)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (b426e7d)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (c601cca)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (c58fe1f)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (616256a)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (ba3af58)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (e12d2ad)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (d6044a1)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (eebc6c6)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (12507e2)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (58557a0)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (c109fdb)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (d98ecc7)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (6858a9d)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (bb7e1b4)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (e89ae27)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (8beaa03)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (ff8fd8f)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (944e0bc)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (eb8c5c8)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (50e4589)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (a751971)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (befff3b)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (ac950ad)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (f381795)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (84ffb6d)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (b95e51d)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (03aa3e7)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (23f9a79)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (e2a3e3c)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (bee4308)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (28f2759)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (775ad24)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (f29d825)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (2e8a0ee)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (5c2cf19)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (2431ee1)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (aeb621a)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (3d2520d)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (3e38109)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (8453281)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (4170803)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (f8e54b5)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (85049b9)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (2a92e35)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (3b195fe)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (ae31163)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (b1499d6)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (1085216)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (3616097)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (6a80994)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (69d01d4)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (fa0df98)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (3eec2e3)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (1bf497e)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (bc7a931)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (c6f5b57)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (8d4d7a3)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (affb14f)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (09c426b)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (af52279)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (72491e7)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (2968790)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (a4d919e)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (f437c0a)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (ba70fd8)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (95d46a5)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (413d65f)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (52639da)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (961f3cb)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (98dbb02)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (cbc22f2)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (f7c37f5)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (a7a8945)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (26db9e3)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (3ca4123)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (8553cb9)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (758756f)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (065d249)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (61824e6)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (67482f7)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (d540a83)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (8e516e6)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (0a2fac5)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (35c2fbf)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (e5e1107)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (79bea2c)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (9416a8f)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (411615d)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (51af43e)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (0bfb9ff)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (c648d38)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (b8dda33)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (264683e)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (c653bb6)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (24be97d)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (a0535c5)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (be3be3f)
  • add @BetaApi Storage#blobReadSession for gRPC Transport (ec59078)
  • Add Anywhere cache control APIs (81c8c61)
  • Add Anywhere cache control APIs (81c8c61)
  • add AppendableUploadWriteableByteChannel#flush() (#3261) (950c56f)
  • add BlobInfo.ObjectContexts (#3259) (485aefd)
  • add BucketInfo.IpFilter (#3177) (14a91ec)
  • add default end-to-end checksumming for JournalingBlobWriteSessionConfig#3180 (fa0f6a0)
  • add default end-to-end crc32c checksumming for several upload methods via grpc transport#3176 (fa0f6a0)
  • add MinFlushSizeFlushPolicy#withMaxPendingBytes(long) (#3231) (7bd73d3)
  • add MoveObject RPC (34b8ac4)
  • add new Options to allow per method header values (#2941) (297802d)
  • add new preview Bucket encryption policy configuration (#3204) (7b250dd)
  • add new Storage#moveBlob method to atomically rename an object (#2882) (c49fd08)
  • add per-message checksum validation for gRPC ReadObject operations (#3336) (6eef1b0)
  • add preview MultipartUploadClient#abortMultipartUpload https://github.com/googleapis/java-storage/pull/3361 (160fa9a)
  • add preview MultipartUploadClient#completeMultipartUpload https://github.com/googleapis/java-storage/pull/3372 (160fa9a)
  • add preview MultipartUploadClient#createMultipartUpload https://github.com/googleapis/java-storage/pull/3356 (160fa9a)
  • add preview MultipartUploadClient#listParts https://github.com/googleapis/java-storage/pull/3359 (160fa9a)
  • add preview MultipartUploadClient#uploadPart https://github.com/googleapis/java-storage/pull/3375 (160fa9a)
  • add preview MultipartUploadSettings (160fa9a)
  • add Storage.BlobListOption#includeTrailingDelimiter (#3038) (0b7a0df)
  • add StorageChannelUtils to provide helper methods to perform blocking read/write to/from non-blocking channels (#3231) (7bd73d3)
  • expose BucketInfo.getProject as a BigInteger (#3119) (64bbb60), closes#3023
  • implement improved retry context information (62b6248)
  • implement improved retry context information (c3a0aaa)
  • implement improved retry context information (fac7839)
  • implement improved retry context information (8332e1b)
  • implement improved retry context information (e4688a0)
  • implement improved retry context information (b426e7d)
  • implement improved retry context information (c601cca)
  • implement improved retry context information (c58fe1f)
  • implement improved retry context information (616256a)
  • implement improved retry context information (ba3af58)
  • implement improved retry context information (e12d2ad)
  • implement improved retry context information (d6044a1)
  • implement improved retry context information (eebc6c6)
  • implement improved retry context information (12507e2)
  • implement improved retry context information (58557a0)
  • implement improved retry context information (c109fdb)
  • implement improved retry context information (d98ecc7)
  • implement improved retry context information (6858a9d)
  • implement improved retry context information (bb7e1b4)
  • implement improved retry context information (e89ae27)
  • implement improved retry context information (8beaa03)
  • implement improved retry context information (ff8fd8f)
  • implement improved retry context information (944e0bc)
  • implement improved retry context information (eb8c5c8)
  • implement improved retry context information (50e4589)
  • implement improved retry context information (a751971)
  • implement improved retry context information (befff3b)
  • implement improved retry context information (ac950ad)
  • implement improved retry context information (f381795)
  • implement improved retry context information (84ffb6d)
  • implement improved retry context information (b95e51d)
  • implement improved retry context information (03aa3e7)
  • implement improved retry context information (23f9a79)
  • implement improved retry context information (e2a3e3c)
  • implement improved retry context information (bee4308)
  • implement improved retry context information (28f2759)
  • implement improved retry context information (775ad24)
  • implement improved retry context information (f29d825)
  • implement improved retry context information (2e8a0ee)
  • implement improved retry context information (5c2cf19)
  • implement improved retry context information (2431ee1)
  • implement improved retry context information (aeb621a)
  • implement improved retry context information (3d2520d)
  • implement improved retry context information (3e38109)
  • implement improved retry context information (8453281)
  • implement improved retry context information (4170803)
  • implement improved retry context information (f8e54b5)
  • implement improved retry context information (85049b9)
  • implement improved retry context information (2a92e35)
  • implement improved retry context information (3b195fe)
  • implement improved retry context information (ae31163)
  • implement improved retry context information (b1499d6)
  • implement improved retry context information (1085216)
  • implement improved retry context information (3616097)
  • implement improved retry context information (6a80994)
  • implement improved retry context information (69d01d4)
  • implement improved retry context information (fa0df98)
  • implement improved retry context information (3eec2e3)
  • implement improved retry context information (1bf497e)
  • implement improved retry context information (bc7a931)
  • implement improved retry context information (c6f5b57)
  • implement improved retry context information (8d4d7a3)
  • implement improved retry context information (affb14f)
  • implement improved retry context information (09c426b)
  • implement improved retry context information (af52279)
  • implement improved retry context information (72491e7)
  • implement improved retry context information (2968790)
  • implement improved retry context information (a4d919e)
  • implement improved retry context information (f437c0a)
  • implement improved retry context information (ba70fd8)
  • implement improved retry context information (95d46a5)
  • implement improved retry context information (413d65f)
  • implement improved retry context information (52639da)
  • implement improved retry context information (961f3cb)
  • implement improved retry context information (98dbb02)
  • implement improved retry context information (cbc22f2)
  • implement improved retry context information (f7c37f5)
  • implement improved retry context information (a7a8945)
  • implement improved retry context information (26db9e3)
  • implement improved retry context information (3ca4123)
  • implement improved retry context information (8553cb9)
  • implement improved retry context information (758756f)
  • implement improved retry context information (065d249)
  • implement improved retry context information (61824e6)
  • implement improved retry context information (67482f7)
  • implement improved retry context information (d540a83)
  • implement improved retry context information (8e516e6)
  • implement improved retry context information (0a2fac5)
  • implement improved retry context information (35c2fbf)
  • implement improved retry context information (e5e1107)
  • implement improved retry context information (79bea2c)
  • implement improved retry context information (9416a8f)
  • implement improved retry context information (411615d)
  • implement improved retry context information (51af43e)
  • implement improved retry context information (0bfb9ff)
  • implement improved retry context information (c648d38)
  • implement improved retry context information (b8dda33)
  • implement improved retry context information (264683e)
  • implement improved retry context information (c653bb6)
  • implement improved retry context information (24be97d)
  • implement improved retry context information (a0535c5)
  • implement improved retry context information (be3be3f)
  • implement improved retry context information (ec59078)
  • introductory beta level support for OpenTelemetry tracing on c.g.c.storage.Storage methods (#2837) (dd889ea)
  • next release from main branch is 2.48.0 (#2885) (34e5903)
  • next release from main branch is 2.50.0 (#2968) (4a69fcc)
  • storagecontrol: Add Anywhere cache control APIs (06572b7)
  • storagecontrol: Add Client Libraries Storage IntelligenceConfig (06572b7)
  • storagecontrol: add GetIamPolicy, SetIamPolicy, and TestIamPermissions RPCs (c884551)
  • transfer-manager: add ParallelUploadConfig.Builder#setUploadBlobInfoFactory (#2936) (86e9ae8), closes#2638
Bug Fixes
  • add case insensitive check for X-Goog-Content-SHA256 in SignatureInfo (#3337) (54bc2c1)
  • add new system property (com.google.cloud.storage.grpc.bound_token) to allow disabling bound token use with grpc (#3365) (ebf5e6d)
  • call response.disconnect() after resolving resumable upload url (#3385) (ac3be4b)
  • cancel the future in RemoteStorageHelper#forceDelete when TimeoutException happens (#3136) (e6007d5)
  • categorize a WatchdogTimeoutException as retriable for grpc ReadObject (#2954) (b53bd53)
  • de-beta storage-v2 artifacts (#2852) (77a2e8a)
  • deps: update the Java code generator (gapic-generator-java) to 2.51.0 (34b8ac4)
  • deps: update the Java code generator (gapic-generator-java) to 2.51.1 (09ed029)
  • deps: update the Java code generator (gapic-generator-java) to 2.52.0 (00754bc)
  • deps: update the Java code generator (gapic-generator-java) to 2.53.0 (9946d6b)
  • deps: update the Java code generator (gapic-generator-java) to 2.54.0 (22e7e3d)
  • deps: update the Java code generator (gapic-generator-java) to 2.55.1 (81c8c61)
  • deps: update the Java code generator (gapic-generator-java) to 2.56.0 (8f9f5ec)
  • deps: update the Java code generator (gapic-generator-java) to 2.56.2 (74c46dd)
  • deps: update the Java code generator (gapic-generator-java) to 2.58.0 (06572b7)
  • deps: update the Java code generator (gapic-generator-java) to 2.59.0 (7dba9f0)
  • deps: update the Java code generator (gapic-generator-java) to 2.60.2 (bd1f199)
  • deps: update the Java code generator (gapic-generator-java) to 2.61.0 (f98b686)
  • deps: update the Java code generator (gapic-generator-java) to 2.62.1 (0e348db)
  • deps: update the Java code generator (gapic-generator-java) to 2.62.2 (984f8ca)
  • deps: update the Java code generator (gapic-generator-java) to 2.62.3 (ba84793)
  • deps: update the Java code generator (gapic-generator-java) to 2.63.0 (c1a8968)
  • deps: update the Java code generator (gapic-generator-java) to 2.64.1 (511ff51)
  • deps: update the Java code generator (gapic-generator-java) to 2.65.0-rc1 (c3267aa)
  • enable ALTS bound token (for DirectPath) in the grpc channel provider (#2919) (38d248d)
  • ensure object generation is sent for Storage#update(BlobInfo) using HTTP Transport (#3006) (2a3e0e7), closes#2980
  • fix a possible NPE that could happen when shutting down a grpc Storage instance (#3089) (56f5d0a)
  • fix appendable upload finalization race condition (#3295) (485be18)
  • fix DefaultBlobWriteSessionConfig init to work when grpc classes are excluded (#3147) (8571ba8)
  • fix grpc ReadObject memory leak introduced in 2.51.0 (#3080) (7057629)
  • fix IllegalMonitorStateException thrown from BlobAppendableUpload.isOpen() (#3302) (aa90468)
  • fix interrupt spiral in grpc ReadObject drainQueue (#2850) (c1dac83)
  • fix Journaling BlobWriteSessionConfig to properly handle multiple consecutive retries (#3166) (895bfbd)
  • give user provided checksum precondition priority for Storage#create methods that accept byte[]#3182 (fa0f6a0)
  • improve 503 handling for json resumable uploads (#2987) (9bc2b14)
  • make FlushPolicy${Min,Max}FlushSizeFlushPolicy constructors private (#3217) (7bd73d3)
  • migrate away from GoogleCredentials.fromStream() usages (#3339) (7e42c2f)
  • move crc32c computation before writing to disk for BufferToDiskThenUpload BlobWriteSession config#3187 (fa0f6a0)
  • next release candidate (eec9efa)
  • update 416 handling for ReadChannel (#3018) (4a9c3e4)
  • update batch handling to ensure each operation has its own unique idempotency-token (#2905) (8d79b8d)
  • update BlobAppendableUpload implementation to periodically flush for large writes (#3278) (d0ffe18)
  • update BlobAppendableUploadConfig and FlushPolicy.MinFlushSizeFlushPolicy to default to 4MiB minFlushSize and 16MiB maxPendingBytes (#3249) (7bd73d3)
  • update BlobReadSession channels to not implicitly close once EOF is observed (#3344) (9f0a93e)
  • update BlobReadSession ScatteringByteChannel projection to use less CPU (#3324) (678fecc)
  • update DefaultRetryContext to trap and forward RejectedExceptionException to onFailure (#3327) (1be31bd)
  • update grpc based Storage to defer project id validation (#2930) (cc03784)
  • update gRPC Bidi resumable upload to have more robust error message generation (#2998) (79b5d85)
  • update grpc client side metrics detection to be graceful when not running on gcp (#3097) (10cd32d)
  • update gRPC implementation for storage.buckets.get to translate NOT_FOUND to null (#3005) (704af65)
  • update grpc single-shot uploads to attach the callers stracktrace as suppressed exception if an error happens in the background (#3330) (64e2b2e)
  • update kms key handling when opening a resumable upload to clear the value in the json to be null rather than empty string (#2939) (43553de)
  • update object context diff logic to be shallow rather than deep (#3287) (2fd15f6)
  • update otel integration to properly activate span context for lazy RPCs such as reads & writes (#3255) (d6587f4)
  • update otel integration to properly activate span context for lazy RPCs such as reads & writes pt.2 (#3277) (3240f67)
  • update PCU request building logic to properly clear crc32c and md5 (#3323) (4da9f31)
  • update request handling of gRPC based CopyWriter (#2858) (093cb87)
  • update retry lifecycle when attempting to decompress a gzip object (#2840) (7dba13c)
  • update retry logic for grpc start resumable upload to properly handle client side deadline_exceeded (#3354) (6eb3331)
  • update Signed URL default scheme to resolve from storage options host (#2880) (7ae7e39), closes#2870
  • update StorageException translation of an ApiException to include error details (#2872) (8ad5010)
  • update usages of String.format to explicitly pass Locale.US (#2974) (8bcb2de), closes#2972
Dependencies
  • remove explicit version declarations for packages that are in shared-dependencies (#3014) (61cdb30)
  • update actions/checkout action to v5 (#3239) (33f024b)
  • update dependency com.google.apis:google-api-services-storage to v1-rev20241206-2.0.0 (#2839) (8f3cdd3)
  • update dependency com.google.apis:google-api-services-storage to v1-rev20250224-2.0.0 (#2969) (80a40c4)
  • update dependency com.google.apis:google-api-services-storage to v1-rev20250312-2.0.0 (#3000) (78fc076)
  • update dependency com.google.apis:google-api-services-storage to v1-rev20250416-2.0.0 (#3063) (d496d5b)
  • update dependency com.google.apis:google-api-services-storage to v1-rev20250420-2.0.0 (#3070) (1ef50f2)
  • update dependency com.google.apis:google-api-services-storage to v1-rev20250424-2.0.0 (#3084) (c7afbde)
  • update dependency com.google.apis:google-api-services-storage to v1-rev20250509-2.0.0 (#3103) (1fd1090)
  • update dependency com.google.apis:google-api-services-storage to v1-rev20250521-2.0.0 (#3118) (e1be49e)
  • update dependency com.google.apis:google-api-services-storage to v1-rev20250524-2.0.0 (#3127) (2a4499d)
  • update dependency com.google.apis:google-api-services-storage to v1-rev20250605-2.0.0 (#3143) (17a80d8)
  • update dependency com.google.apis:google-api-services-storage to v1-rev20250629-2.0.0 (#3185) (4ce8281)
  • update dependency com.google.apis:google-api-services-storage to v1-rev20250718-2.0.0 (#3203) (18978e4)
  • update dependency com.google.apis:google-api-services-storage to v1-rev20250815-2.0.0 (#3245) (87afe1a)
  • update dependency com.google.apis:google-api-services-storage to v1-rev20250925-2.0.0 (#3313) (ab310eb)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.42.0 (#2895) (145afb0)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.46.2 (#3061) (cb43a6c)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.50.1 (#3189) (7fbfb01)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.50.2 (#3201) (782c3c4)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.51.0 (#3213) (86ff697)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.0 (#3250) (0782e62)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.1 (#3280) (d046ea3)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.2 (#3298) (1489f3a)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.3 (#3325) (4d3e3be)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.53.0 (#3351) (e64565a)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.54.1 (#3381) (e3d3700)
  • update dependency com.google.cloud.opentelemetry:exporter-trace to v0.33.0 (#2873) (39509d5)
  • update dependency com.google.cloud.opentelemetry:exporter-trace to v0.33.0 (#2904) (2a5242e)
  • update dependency com.google.cloud.opentelemetry:exporter-trace to v0.34.0 (#2938) (ff6f696)
  • update dependency com.google.cloud.opentelemetry:exporter-trace to v0.36.0 (#3162) (41a1030)
  • update gcr.io/cloud-devrel-public-resources/storage-testbench docker tag to v0.51.0 (#2860) (980ac4e)
  • update gcr.io/cloud-devrel-public-resources/storage-testbench docker tag to v0.52.0 (#2883) (a64a3d5)
  • update gcr.io/cloud-devrel-public-resources/storage-testbench docker tag to v0.59.0 (f5d8337)
  • update gcr.io/cloud-devrel-public-resources/storage-testbench docker tag to v0.59.0 (5480ce3)
  • update googleapis/sdk-platform-java action to v2.51.1 (#2864) (b731c06)
  • update googleapis/sdk-platform-java action to v2.55.1 (#2985) (e22a2de)
  • update googleapis/sdk-platform-java action to v2.56.2 (#3055) (7025ad7)
  • update googleapis/sdk-platform-java action to v2.60.1 (#3196) (6ba56e5)
  • update googleapis/sdk-platform-java action to v2.62.1 (#3281) (c9078bb)
  • update googleapis/sdk-platform-java action to v2.62.2 (#3299) (c3b05ac)
  • update googleapis/sdk-platform-java action to v2.62.3 (#3322) (a5808ea)
  • update sdk-platform-java dependencies (#2841) (2a70481)
  • update sdk-platform-java dependencies (#2866) (562df7f)
  • update sdk-platform-java dependencies (#2921) (fa9b0a8)
  • update sdk-platform-java dependencies (#2957) (40cfda6)
  • update sdk-platform-java dependencies (#2983) (9eeb82a)
  • update sdk-platform-java dependencies (#2986) (10b922a)
  • update sdk-platform-java dependencies (#3046) (861f958)
  • update sdk-platform-java dependencies (#3053) (921d1ba)
  • update sdk-platform-java dependencies (#3087) (762ca13)
  • update sdk-platform-java dependencies (#3102) (3b53b94)
  • update sdk-platform-java dependencies (#3129) (31cd058)
  • update sdk-platform-java dependencies (#3152) (2f78192)
  • update sdk-platform-java dependencies (#3164) (c22a131)
  • update sdk-platform-java-config to 3.55.0-rc1 (#3434) (25283cb)
Documentation
  • add explicit Optional annotations to fields that have always been treated as optional (53b6927)
  • add note about HNS support to moveBlob (#2929) (c461546)
  • add note that Bucket.project output format is always project number format (53b6927)
  • add note that managedFolders are supported for GetIamPolicy and SetIamPolicy (53b6927)
  • add samples for soft delete (objects) (#2754) (41bc807)
  • Create OpenTelemetry Quickstart Sample (#2861) (31df9b7)
  • update storage_copy_file to include MegabytesCopiedPerChunk (#2910) (971ca5d)
Compute Engine
Feature

When you autoscale a regional managed instance group (MIG), you can view thereasons why the autoscaler adds or removes VMs in your MIG. Autoscalingreasons were previously available only for zonal MIGs. For more information, seeViewing autoscaler logs.

Database Center
Feature

You can use Database Center to monitor your Cloud SQL databaseresources for enhanced backup protection. Enhanced protection is aBackup and DR Service feature. For more information, seeUse enhanced backup protection.To configure enhanced backups for Cloud SQL resources, seeEnhanced backups.

Dataproc
Announcement
Firestore in Datastore mode
Libraries

Python

2.22.0 (2025-12-12)

Bug Fixes
  • remove setup.cfg configuration for creating universal wheels (#601) (df729015)

Python

2.23.0 (2025-12-16)

Features
  • support mTLS certificates when available (#658) (85c02328)

Java

2.34.0-rc1 (2025-12-16)

Features
  • Add FindNearest API to the stable branch (3512ba2)
  • Add firestoreInDatastoreMode for datastore emulator (#1698) (50f106d)
  • add getNumber to AggregationResult (https://github.com/googleapis/java-datastore/issues/1851) (#1861) (b9c2c3f)
  • Add sample code for connection pooling (#1947) (57981db)
  • add sample code for multiple inequalities indexing consideration query (#1579) (1286792)
  • enable flag for report generation (#1991) (767a558)
  • enable grpc configurator for client-side tracing (#1886) (97004c8)
  • enable hermetic library generation (#1462) (d142d9c)
  • implement query profile (#1365) (2515ed6)
  • introducejava.time methods and variables (#1671) (5a78a80)
  • Introducing Tracing with OpenTelemetry API#1537 (#1576) (5440c22)
  • Java datastore gapic upgrade (#1824) (a296d43)
  • New PropertyMask field which allows partial commits, lookups, and query results (#1455) (ff5e397)
  • next release from main branch is 2.27.0 (#1781) (d29f47c)
  • next release from main branch is 2.31.0 (#1912) (a74c46b)
  • remove@BetaApi annotations from get/setDatabaseId methods (#1272) (2bd9a51)
  • Support for field update operators in the Datastore API and resolution strategies when there is a conflict at write time (b299266)
  • update with latest from main (#2018) (3a0daed)
  • Upgrade protobuf gen code to 4.33 (#2019) (c783809)
Bug Fixes
  • checksum format (#1178) (410b939)
  • deprecatedatabaseId on datastore-v1-proto-client DatastoreOptions (#1190) (12a3d27)
  • deps: Update the Java code generator (gapic-generator-java) to 2.31.0 (#1278) (01cced6)
  • deps: Update the Java code generator (gapic-generator-java) to 2.32.0 (#1293) (f4ee0cb)
  • deps: Update the Java code generator (gapic-generator-java) to 2.37.0 (#1355) (bcc5668)
  • deps: Update the Java code generator (gapic-generator-java) to 2.39.0 (#1406) (b265fb3)
  • deps: update the Java code generator (gapic-generator-java) to 2.46.1 (678eee2)
  • deps: update the Java code generator (gapic-generator-java) to 2.47.0 (b299266)
  • deps: update the Java code generator (gapic-generator-java) to 2.51.0 (106ee4d)
  • deps: update the Java code generator (gapic-generator-java) to 2.51.1 (90d8b30)
  • deps: update the Java code generator (gapic-generator-java) to 2.52.0 (9594024)
  • deps: update the Java code generator (gapic-generator-java) to 2.53.0 (be0d0cd)
  • deps: update the Java code generator (gapic-generator-java) to 2.53.0 (93e45ed)
  • deps: update the Java code generator (gapic-generator-java) to 2.54.0 (b9b302b)
  • deps: update the Java code generator (gapic-generator-java) to 2.55.1 (ba1ad98)
  • deps: update the Java code generator (gapic-generator-java) to 2.56.2 (1210f32)
  • deps: update the Java code generator (gapic-generator-java) to 2.59.0 (910a6c2)
  • deps: update the Java code generator (gapic-generator-java) to 2.60.2 (06372cd)
  • deps: update the Java code generator (gapic-generator-java) to 2.61.0 (c7bd68d)
  • deps: update the Java code generator (gapic-generator-java) to 2.62.0 (90f5526)
  • deps: update the Java code generator (gapic-generator-java) to 2.63.0 (b9b95cb)
  • deps: update the Java code generator (gapic-generator-java) to 2.64.1 (216e771)
  • doc: Add discriptions for TransactionCallable interface (#1644) (173a883)
  • doc: Fix return types for batch interface (#1645) (1189211)
  • Fix emulator command arg data-dir (#1695) (9d53195)
  • Migrate off TextPrinter's deprecated methods (#1452) (c3c1317)
  • next release candidate (4824f2b)
  • remove 500 char path name limit (#1865) (1097175)
  • remove deprecateddatabaseId field in DatastoreOptions (#1237) (05e25e5)
  • remove QueryMode field from RunAggregationQueryRequest (c1e7c62)
  • remove QueryMode field from RunQueryRequest (c1e7c62)
  • remove ResultSetStats field from RunAggregationQueryResponse (c1e7c62)
  • remove ResultSetStats field from RunQueryResponse (c1e7c62)
  • remove types QueryMode, QueryPlan, ResultSetStats (#1304) (c1e7c62)
  • sample: change update entity sample to use transaction (#1633) (c44f17a)
  • set the correct database id on the key parent when calling Key#getParent (#1457) (992815d)
  • Update opentelemetry-sdk dependency to be test-only (#1595) (9d719e8)
  • Update opentelemetry.version to 1.42.1 to match the BOM version (#1598) (23c5c26)
Dependencies
  • autogen: set packed = false on field_behavior extension (#1320) (9cfa1c3)
  • Manage Opentelemetry version from Shared-Deps (#1995) (5f6c500)
  • update actions/checkout action to v4 (#1390) (80dbca1)
  • update dependency com.google.cloud:gapic-libraries-bom to v1.43.0 (#1584) (fae3b74)
  • update dependency com.google.cloud:gapic-libraries-bom to v1.48.0 (#1605) (5c6a678)
  • update dependency com.google.cloud:gapic-libraries-bom to v1.49.0 (#1693) (8160c28)
  • update dependency com.google.cloud:gapic-libraries-bom to v1.50.0 (#1708) (b78660f)
  • update dependency com.google.cloud:gapic-libraries-bom to v1.51.0 (#1726) (89f31a8)
  • update dependency com.google.cloud:gapic-libraries-bom to v1.52.0 (#1747) (592072b)
  • update dependency com.google.cloud:gapic-libraries-bom to v1.53.0 (#1779) (8369118)
  • update dependency com.google.cloud:gapic-libraries-bom to v1.60.0 (#1799) (bf2a33c)
  • update dependency com.google.cloud:gapic-libraries-bom to v1.61.0 (#1901) (beeb125)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.16.0 (#1195) (6f0cad7)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.16.1 (#1198) (8062be9)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.17.0 (#1206) (2ad068b)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.18.0 (#1215) (aa82f01)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.19.0 (#1226) (970ac96)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.20.0 (#1247) (c4e3533)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.21.0 (#1280) (ac253dc)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.22.0 (#1291) (5a5c78e)
  • update dependency com.google.cloud:google-cloud-shared-dependencies to v3.23.0 (#1301) (ac947a5)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.24.0 (#1310) (26e5f98)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.25.0 (#1333) (0e64a7d)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.27.0 (#1352) (124d7ca)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.28.0 (#1372) (09db2a7)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.28.1 (#1373) (c6e63e5)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.29.0 (#1403) (d23dc4c)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.30.0 (#1426) (ac3a1c1)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.30.1 (#1443) (79f6c46)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.31.0 (#1471) (42c643d)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.32.0 (#1492) (d940c93)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.33.0 (#1531) (9e52395)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.34.0 (#1547) (8c5f595)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.35.0 (#1561) (5a79fd8)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.36.0 (#1590) (2db9e43)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.36.1 (#1602) (e1b7d4b)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.38.0 (#1632) (6453f1e)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.39.0 (#1640) (fe61f66)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.41.1 (#1703) (bf9537f)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.42.0 (#1725) (1cbaf22)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.43.0 (#1737) (7272a41)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.44.0 (#1769) (7a86509)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.45.1 (#1791) (ab5ac8e)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.46.2 (#1823) (4d2026c)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.47.0 (#1841) (ac393e6)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.48.0 (#1847) (7ed3232)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.49.0 (#1860) (0eff028)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.50.0 (#1897) (a8d99cd)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.50.1 (#1908) (b10e0f0)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.50.2 (#1926) (1ecdf37)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.51.0 (#1936) (a25433f)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.0 (#1944) (30a6e28)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.1 (#1963) (833a34a)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.2 (#1969) (2243471)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.3 (#1973) (141ec94)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.53.0 (#1980) (1520b7c)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.54.1 (#1994) (11265fd)
  • update dependency com.google.errorprone:error_prone_core to v2.22.0 (#1194) (b8f108a)
  • update dependency com.google.errorprone:error_prone_core to v2.23.0 (#1213) (c57db43)
  • update dependency com.google.errorprone:error_prone_core to v2.24.1 (#1274) (86cd785)
  • update dependency com.google.errorprone:error_prone_core to v2.25.0 (#1339) (0c6702e)
  • update dependency com.google.errorprone:error_prone_core to v2.26.0 (#1361) (9442766)
  • update dependency com.google.errorprone:error_prone_core to v2.26.1 (#1363) (05fe5bc)
  • update dependency com.google.errorprone:error_prone_core to v2.27.0 (#1411) (a3f5a2c)
  • update dependency com.google.errorprone:error_prone_core to v2.27.1 (#1421) (48d7daf)
  • update dependency com.google.errorprone:error_prone_core to v2.28.0 (#1469) (e3fac2b)
  • update dependency com.google.errorprone:error_prone_core to v2.31.0 (#1523) (8d3af32)
  • update dependency com.google.guava:guava-testlib to v33.1.0-jre (#1368) (0195345)
  • update dependency com.google.guava:guava-testlib to v33.2.0-jre (#1422) (5a5dfdf)
  • update dependency com.google.guava:guava-testlib to v33.2.1-jre (#1470) (614e930)
  • update dependency com.google.guava:guava-testlib to v33.3.0-jre (#1548) (18ba37f)
  • update dependency com.google.guava:guava-testlib to v33.3.1-jre (#1592) (5d078a4)
  • update dependency com.google.guava:guava-testlib to v33.4.0-jre (#1694) (b91a2af)
  • update dependency com.google.testparameterinjector:test-parameter-injector to v1.17 (#1585) (8f74a49)
  • update dependency org.easymock:easymock to v5.4.0 (#1482) (ee788a1)
  • update dependency org.easymock:easymock to v5.5.0 (#1666) (0333b07)
  • update dependency org.easymock:easymock to v5.6.0 (#1858) (acc1513)
  • update dependency org.graalvm.buildtools:junit-platform-native to v0.9.26 (#1176) (76e3a71)
  • update dependency org.graalvm.buildtools:junit-platform-native to v0.9.27 (#1192) (aa3bca1)
  • update dependency org.graalvm.buildtools:junit-platform-native to v0.9.28 (#1216) (ce4eff2)
  • update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.26 (#1177) (7733004)
  • update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.27 (#1193) (a628255)
  • update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.28 (#1217) (7d56b3c)
  • update dependency org.junit.vintage:junit-vintage-engine to v5.10.1 (#1230) (05c7fc6)
  • Update gapic-generator-java to 2.26.0 (#1197) (2540282)
  • update googleapis/sdk-platform-java action to v2.48.0 (#1628) (d3bce79)
  • update googleapis/sdk-platform-java action to v2.49.0 (#1638) (57598d7)
  • update googleapis/sdk-platform-java action to v2.53.0 (#1738) (b8a7a5d)
  • update googleapis/sdk-platform-java action to v2.57.0 (#1842) (0745906)
  • update googleapis/sdk-platform-java action to v2.58.0 (#1853) (eef820d)
  • update googleapis/sdk-platform-java action to v2.59.1 (#1880) (4fb9929)
  • update googleapis/sdk-platform-java action to v2.60.0 (#1898) (0921f86)
  • Update protobuf to 25.2 in WORKSPACE (#1311) (3f4ae83)
  • update sdk platform java dependencies (#1617) (6eaff23)
  • update sdk platform java dependencies (#1662) (b4d3ab9)
  • update sdk platform java dependencies (#1685) (4372350)
  • update sdk-platform-java-config to 3.55.0-rc1 (#2017) (a67694b)
Documentation
  • Update gapic upgrade installation instructions (#1677) (b3fbfcc)
Pub/Sub
Libraries

Python

2.34.0 (2025-12-16)

Features
  • support mTLS certificates when available (#1566) (24761a2f)

Java

1.145.0-rc1 (2025-12-16)

Features
  • [java] allow passing libraries_bom_version from env (#1967) (#2033) (825c5f8)
  • Add IngestionFailureEvent to the external proto (6c67798)
  • Add Kafka-based sources to IngestionDataSourceSettings proto and IngestionFailureEvent proto (2947169)
  • add keepalive feature to tear down streams in their absence (#2605) (99aca4f)
  • Add MessageTransformationFailureReason to IngestionFailureEvent (8271399)
  • Add OpenTelemetry tracing to the Publisher and Subscriber (#2086) (db522b6)
  • Add SchemaViolationReason to IngestionFailureEvent (21cc376)
  • add service_account_email for export subscriptions (#2054) (670db3e)
  • add support for message transforms to Topic and Subscription (3889a05)
  • add use_topic_schema for Cloud Storage Subscriptions (#2082) (11d67d4)
  • Annotate some resource fields with their corresponding API types (ab60afa)
  • deprecateenabled field for message transforms and adddisabled field (76b2a3d)
  • enable hermetic library generation (#2048) (283a5e8)
  • generate renamed go pubsub admin clients (4472d7b)
  • Implement SubscriberShutdownSettings (#2569) (8195f6f)
  • introducejava.time variables and methods (#2271) (7edfd9c)
  • next release from main branch is 1.138.0 (#2361) (b6ba56c)
  • next release from main branch is 1.141.0 (#2481) (bd9f385)
  • support the protocol version in StreamingPullRequest (af40810)
  • track batch size using serialized size of PublishRequest (#2113) (be78e64)
  • update with latest from main (#2644) (96513b2)
  • Upgrade protobuf gen code to 4.33 (#2645) (db3c75f)
Bug Fixes
  • Add retries for ack and modack operations that don't return with a metadata map (#2385) (00070b7)
  • Deflake WaiterTest (#2600) (298c8db)
  • deps: update the Java code generator (gapic-generator-java) to 2.47.0 (ccd23af)
  • deps: update the Java code generator (gapic-generator-java) to 2.49.0 (77546e0)
  • deps: update the Java code generator (gapic-generator-java) to 2.50.0 (3f21af3)
  • deps: update the Java code generator (gapic-generator-java) to 2.51.0 (0b0d52c)
  • deps: update the Java code generator (gapic-generator-java) to 2.51.1 (9c166f7)
  • deps: update the Java code generator (gapic-generator-java) to 2.52.0 (0d8c8bf)
  • deps: update the Java code generator (gapic-generator-java) to 2.53.0 (b952e58)
  • deps: update the Java code generator (gapic-generator-java) to 2.54.0 (ccf670f)
  • deps: update the Java code generator (gapic-generator-java) to 2.55.1 (76b2a3d)
  • deps: update the Java code generator (gapic-generator-java) to 2.56.2 (4472d7b)
  • deps: update the Java code generator (gapic-generator-java) to 2.56.3 (2b928a8)
  • deps: update the Java code generator (gapic-generator-java) to 2.57.0 (017eb0f)
  • deps: update the Java code generator (gapic-generator-java) to 2.58.0 (3713edb)
  • deps: update the Java code generator (gapic-generator-java) to 2.59.0 (0eece50)
  • deps: update the Java code generator (gapic-generator-java) to 2.60.1 (c9ef2cd)
  • deps: update the Java code generator (gapic-generator-java) to 2.60.2 (7afae21)
  • deps: update the Java code generator (gapic-generator-java) to 2.61.0 (42eb599)
  • deps: update the Java code generator (gapic-generator-java) to 2.62.0 (65e324e)
  • deps: update the Java code generator (gapic-generator-java) to 2.62.1 (ac08d5f)
  • deps: update the Java code generator (gapic-generator-java) to 2.62.2 (c02d304)
  • deps: update the Java code generator (gapic-generator-java) to 2.62.3 (af40810)
  • deps: update the Java code generator (gapic-generator-java) to 2.63.0 (ab60afa)
  • deps: update the Java code generator (gapic-generator-java) to 2.64.1 (b210251)
  • next release candidate (cf06e2d)
  • Prevent excessive string parsing when publishing and receiving messages to improve performance (#2317) (07b1350)
  • Remove element_count_limit and request_byte_limit from pubsub_gapic.yaml (7afae21)
  • Update .OwlBot-hermetic.yaml to preserve SubscriberShutdownSettings files (#2583) (f3cf5e7)
  • Use a separate cached thread pool for handling ack and modack response callback for EOD-enabled subscriptions (#2505) (224c269)
  • Use the system executor instead of a separate thread pool for EOD ack/modack callbacks (#2526) (ffeb017)
Dependencies
  • Change scope of grpc-inprocess dependency from runtime to test (#2038) (1ab45c9)
  • Remove OpenTelemetry semconv dependency (#2611) (240fc37)
  • update actions/checkout action to v5 (#2520) (409398a)
  • update actions/checkout action to v5 (#2531) (f687f11)
  • update actions/checkout action to v5 (#2539) (83144e6)
  • update actions/checkout action to v5 (#2562) (b7fa499)
  • update actions/checkout action to v5 (#2573) (4153dba)
  • update actions/checkout action to v5 (#2576) (1375f6d)
  • update actions/checkout action to v5 (#2584) (25059ce)
  • update actions/checkout action to v5 (#2592) (6ca466d)
  • update actions/checkout action to v5 (#2613) (a69ffdd)
  • update actions/github-script action to v8 (#2542) (0e6f0da)
  • update actions/setup-java action to v5 (#2535) (2ed87d2)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.40.1 (#2021) (0873594)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.40.2 (#2046) (f81c5e1)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.40.3 (#2071) (0844bfb)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.41.0 (#2093) (217b8a3)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.42.0 (#2124) (24ebe24)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.42.1 (#2152) (1457489)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.42.2 (#2157) (d671347)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.42.3 (#2173) (294d039)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.43.1 (#2202) (acaf5f2)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.43.3 (#2256) (f7fbc6c)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.44.0 (#2270) (a5f70a9)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.45.0 (#2292) (79a8982)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.46.0 (#2309) (97bd44e)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.47.0 (#2331) (216feef)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.48.0 (#2343) (3bbd7e1)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.48.1 (#2356) (7d3d2e4)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.49.0 (#2380) (405e485)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.49.2 (#2399) (ff48708)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.50.0 (#2422) (993b2d0)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.50.1 (#2435) (b37c557)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.51.0 (#2457) (d74215a)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.52.0 (#2467) (fe08a6f)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.53.0 (#2489) (5a454b9)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.54.0 (#2506) (6bf8e62)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.54.1 (#2523) (0678a74)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.54.2 (#2538) (10a8283)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.55.0 (#2553) (15b9e66)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.55.1 (#2566) (66c9ec4)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.55.2 (#2582) (d0f9673)
  • update dependency com.google.cloud:google-cloud-bigquery to v2.55.3 (#2602) (d14106c)
  • update dependency com.google.cloud:google-cloud-core to v2.38.1 (#2027) (535edf6)
  • update dependency com.google.cloud:google-cloud-core to v2.39.0 (#2057) (43446d2)
  • update dependency com.google.cloud:google-cloud-core to v2.40.0 (#2087) (26b01c9)
  • update dependency com.google.cloud:google-cloud-core to v2.41.0 (#2120) (1f6428a)
  • update dependency com.google.cloud:google-cloud-core to v2.42.0 (#2140) (80dca35)
  • update dependency com.google.cloud:google-cloud-core to v2.43.0 (#2161) (05a37b7)
  • update dependency com.google.cloud:google-cloud-core to v2.44.0 (#2184) (faecb3b)
  • update dependency com.google.cloud:google-cloud-core to v2.44.1 (#2190) (9ea45dc)
  • update dependency com.google.cloud:google-cloud-core to v2.45.0 (#2213) (5ee969b)
  • update dependency com.google.cloud:google-cloud-core to v2.46.0 (#2238) (dc06d54)
  • update dependency com.google.cloud:google-cloud-core to v2.47.0 (#2249) (3df5729)
  • update dependency com.google.cloud:google-cloud-core to v2.48.0 (#2263) (d7e5588)
  • update dependency com.google.cloud:google-cloud-core to v2.49.0 (#2285) (cd94a19)
  • update dependency com.google.cloud:google-cloud-core to v2.49.1 (#2300) (cf2822b)
  • update dependency com.google.cloud:google-cloud-core to v2.50.0 (#2321) (5c40bcd)
  • update dependency com.google.cloud:google-cloud-core to v2.51.0 (#2338) (ac2403e)
  • update dependency com.google.cloud:google-cloud-core to v2.52.0 (#2348) (f0977b4)
  • update dependency com.google.cloud:google-cloud-core to v2.53.1 (#2365) (748058f)
  • update dependency com.google.cloud:google-cloud-core to v2.54.3 (#2393) (0ffa26a)
  • update dependency com.google.cloud:google-cloud-core to v2.55.0 (#2413) (3e181e7)
  • update dependency com.google.cloud:google-cloud-core to v2.56.0 (#2427) (b2a3e35)
  • update dependency com.google.cloud:google-cloud-core to v2.58.0 (#2443) (d4599d9)
  • update dependency com.google.cloud:google-cloud-core to v2.58.1 (#2476) (96a2354)
  • update dependency com.google.cloud:google-cloud-core to v2.58.2 (#2493) (9a1c17e)
  • update dependency com.google.cloud:google-cloud-core to v2.59.0 (#2507) (070cf07)
  • update dependency com.google.cloud:google-cloud-core to v2.60.0 (#2527) (0166e21)
  • update dependency com.google.cloud:google-cloud-core to v2.60.1 (#2543) (fbb45ce)
  • update dependency com.google.cloud:google-cloud-core to v2.60.2 (#2557) (460bcd9)
  • update dependency com.google.cloud:google-cloud-core to v2.60.3 (#2571) (ac2c85a)
  • update dependency com.google.cloud:google-cloud-core to v2.61.0 (#2588) (244cf75)
  • update dependency com.google.cloud:google-cloud-core to v2.62.1 (#2608) (fee0500)
  • update dependency com.google.cloud:google-cloud-storage to v2.39.0 (#2040) (eb6bd9c)
  • update dependency com.google.cloud:google-cloud-storage to v2.40.0 (#2066) (dfcaeb5)
  • update dependency com.google.cloud:google-cloud-storage to v2.40.1 (#2095) (0d64d6c)
  • update dependency com.google.cloud:google-cloud-storage to v2.41.0 (#2129) (2348d20)
  • update dependency com.google.cloud:google-cloud-storage to v2.42.0 (#2145) (77c3e78)
  • update dependency com.google.cloud:google-cloud-storage to v2.43.0 (#2174) (ae800d7)
  • update dependency com.google.cloud:google-cloud-storage to v2.43.1 (#2194) (979e420)
  • update dependency com.google.cloud:google-cloud-storage to v2.43.2 (#2226) (eb87c04)
  • update dependency com.google.cloud:google-cloud-storage to v2.44.1 (#2240) (f8dae4d)
  • update dependency com.google.cloud:google-cloud-storage to v2.45.0 (#2268) (80a09e6)
  • update dependency com.google.cloud:google-cloud-storage to v2.46.0 (#2291) (7b60884)
  • update dependency com.google.cloud:google-cloud-storage to v2.47.0 (#2303) (707f842)
  • update dependency com.google.cloud:google-cloud-storage to v2.48.0 (#2322) (93b9419)
  • update dependency com.google.cloud:google-cloud-storage to v2.48.1 (#2332) (23fd7a8)
  • update dependency com.google.cloud:google-cloud-storage to v2.48.2 (#2341) (eeb99a9)
  • update dependency com.google.cloud:google-cloud-storage to v2.49.0 (#2358) (81d3435)
  • update dependency com.google.cloud:google-cloud-storage to v2.50.0 (#2372) (b81164a)
  • update dependency com.google.cloud:google-cloud-storage to v2.52.1 (#2396) (283a6e1)
  • update dependency com.google.cloud:google-cloud-storage to v2.52.2 (#2421) (1224ee5)
  • update dependency com.google.cloud:google-cloud-storage to v2.52.3 (#2436) (4f309d1)
  • update dependency com.google.cloud:google-cloud-storage to v2.53.1 (#2452) (b4af237)
  • update dependency com.google.cloud:google-cloud-storage to v2.53.2 (#2469) (fa51a01)
  • update dependency com.google.cloud:google-cloud-storage to v2.53.3 (#2486) (9416cc9)
  • update dependency com.google.cloud:google-cloud-storage to v2.54.0 (#2510) (0fd589e)
  • update dependency com.google.cloud:google-cloud-storage to v2.55.0 (#2517) (b67acf1)
  • update dependency com.google.cloud:google-cloud-storage to v2.56.0 (#2536) (80d9ca1)
  • update dependency com.google.cloud:google-cloud-storage to v2.57.0 (#2547) (133f8c7)
  • update dependency com.google.cloud:google-cloud-storage to v2.58.0 (#2561) (0189388)
  • update dependency com.google.cloud:google-cloud-storage to v2.58.1 (#2580) (d156cdb)
  • update dependency com.google.cloud:google-cloud-storage to v2.59.0 (#2603) (d9d05bf)
  • update dependency com.google.cloud:google-cloud-storage to v2.60.0 (#2610) (1cae247)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.30.1 (#2028) (aedcffd)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.31.0 (#2058) (a998ef5)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.32.0 (#2088) (aebc3ed)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.33.0 (#2121) (7fbea6d)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.34.0 (#2141) (273fbf3)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.35.0 (#2162) (27eaffd)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.36.0 (#2185) (5ca2c7c)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.36.1 (#2191) (555216e)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.37.0 (#2214) (d938709)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.39.0 (#2251) (083cc7c)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.41.0 (#2286) (0c0a1b9)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.41.1 (#2301) (53c1a8a)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.42.0 (#2324) (84e8562)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.43.0 (#2336) (996f4eb)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.44.0 (#2349) (90ed10b)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.45.1 (#2366) (15899d1)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.46.2 (#2394) (17f7fd7)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.46.3 (#2406) (8963ed0)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.47.0 (#2414) (d78823f)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.47.0 (#2418) (5f87661)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.48.0 (#2428) (cfa91fa)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.49.0 (#2444) (a59135c)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.49.0 (#2446) (6434be1)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.49.0 (#2448) (d89a14d)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.50.0 (#2461) (715916a)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.50.1 (#2477) (e1657cb)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.50.2 (#2494) (9f73ef0)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.51.0 (#2508) (a7be2a7)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.0 (#2528) (e424d11)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.1 (#2544) (9fe7550)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.2 (#2558) (0623ac5)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.52.3 (#2572) (0785ee4)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.53.0 (#2589) (ce7cb09)
  • update dependency com.google.cloud:sdk-platform-java-config to v3.54.1 (#2609) (c99373f)
  • update dependency com.google.cloud.opentelemetry:exporter-trace to v0.32.0 (#2205) (76f17e4)
  • update dependency com.google.cloud.opentelemetry:exporter-trace to v0.33.0 (#2225) (cc1b072)
  • update dependency com.google.cloud.opentelemetry:exporter-trace to v0.34.0 (#2376) (06768cd)
  • update dependency com.google.cloud.opentelemetry:exporter-trace to v0.36.0 (#2440) (50a3eb9)
  • update dependency com.google.protobuf:protobuf-java-util to v4.27.0 (#2044) (37e94ce)
  • update dependency com.google.protobuf:protobuf-java-util to v4.27.1 (#2065) (6baf69a)
  • update dependency com.google.protobuf:protobuf-java-util to v4.27.2 (#2091) (9859f11)
  • update dependency com.google.protobuf:protobuf-java-util to v4.27.3 (#2127) (8523b4f)
  • update dependency com.google.protobuf:protobuf-java-util to v4.27.4 (#2153) (32c78b3)
  • update dependency com.google.protobuf:protobuf-java-util to v4.28.0 (#2155) (5f61fe1)
  • update dependency com.google.protobuf:protobuf-java-util to v4.28.1 (#2167) (bb8ea71)
  • update dependency com.google.protobuf:protobuf-java-util to v4.28.2 (#2179) (c9bbd2c)
  • update dependency com.google.protobuf:protobuf-java-util to v4.28.3 (#2237) (75abe83)
  • update dependency com.google.protobuf:protobuf-java-util to v4.29.0 (#2276) (54ef88d)
  • update dependency com.google.protobuf:protobuf-java-util to v4.29.1 (#2279) (de3c9e1)
  • update dependency com.google.protobuf:protobuf-java-util to v4.29.2 (#2294) (48d4ac1)
  • update dependency com.google.protobuf:protobuf-java-util to v4.29.3 (#2302) (9e90e2c)
  • update dependency com.google.protobuf:protobuf-java-util to v4.30.1 (#2364) (05eb9c0)
  • update dependency com.google.protobuf:protobuf-java-util to v4.30.2 (#2383) (4119cc0)
  • update dependency com.google.protobuf:protobuf-java-util to v4.31.0 (#2430) (232fac1)
  • update dependency com.google.protobuf:protobuf-java-util to v4.31.1 (#2442) (a0be1bb)
  • update dependency com.google.protobuf:protobuf-java-util to v4.32.0 (#2524) (44ff087)
  • update dependency com.google.protobuf:protobuf-java-util to v4.32.1 (#2551) (49722cb)
  • update dependency com.google.protobuf:protobuf-java-util to v4.33.0 (#2587) (33724ce)
  • update dependency com.google.protobuf:protobuf-java-util to v4.33.1 (#2612) (e92debc)
  • update dependency org.apache.avro:avro to v1.11.4security (31f276b)
  • update dependency org.assertj:assertj-core to v3.26.3 (#2204) (71c2e76)
  • update dependency org.assertj:assertj-core to v3.27.2 (#2296) (e5b68a5)
  • update dependency org.assertj:assertj-core to v3.27.3 (#2313) (5e80b57)
  • update dependency org.assertj:assertj-core to v3.27.4 (#2518) (67695bc)
  • update dependency org.assertj:assertj-core to v3.27.6 (#2560) (c82766a)
  • update dependency org.easymock:easymock to v5.6.0 (#2069) (5f144a4)
  • update dependency org.graalvm.buildtools:native-maven-plugin to v0.10.2 (#2035) (40fdd7a)
  • update dependency org.junit.vintage:junit-vintage-engine to v5.10.3 (#2096) (42f12ed)
  • update dependency org.xerial.snappy:snappy-java to v1.1.10.6 (#2135) (102ff84)
  • update dependency org.xerial.snappy:snappy-java to v1.1.10.7 (#2165) (e7fb60e)
  • update dependency org.xerial.snappy:snappy-java to v1.1.10.8 (#2492) (a55e214)
  • update dependency ubuntu to v24 (#2193) (f295b01)
  • update googleapis/sdk-platform-java action to v2.47.0 (#2212) (6a9723d)
  • update googleapis/sdk-platform-java action to v2.49.0 (#2250) (af0f194)
  • update googleapis/sdk-platform-java action to v2.50.0 (#2261) (d0aab7d)
  • update googleapis/sdk-platform-java action to v2.51.0 (#2284) (0be820e)
  • update googleapis/sdk-platform-java action to v2.51.1 (#2298) (16e0144)
  • update googleapis/sdk-platform-java action to v2.52.0 (#2320) (01dd3de)
  • update googleapis/sdk-platform-java action to v2.54.0 (#2347) (ac8db2d)
  • update googleapis/sdk-platform-java action to v2.55.1 (#2367) (de6f84a)
  • update googleapis/sdk-platform-java action to v2.57.0 (#2415) (1ddf9b8)
  • update googleapis/sdk-platform-java action to v2.59.0 (#2445) (12d4cfb)
  • update googleapis/sdk-platform-java action to v2.60.0 (#2462) (ee8e5c7)
  • update googleapis/sdk-platform-java action to v2.60.0 (#2464) (7a0af37)
  • update googleapis/sdk-platform-java action to v2.60.0 (#2471) (2b0e8e0)
  • update googleapis/sdk-platform-java action to v2.60.1 (#2475) (e7c0b5d)
  • update googleapis/sdk-platform-java action to v2.61.0 (#2509) (32df6b6)
  • update googleapis/sdk-platform-java action to v2.62.1 (#2545) (17f28ef)
  • update googleapis/sdk-platform-java action to v2.62.2 (#2559) (3f1d901)
  • update sdk platform java dependencies (#2239) (8f4f855)
  • update sdk platform java dependencies (#2262) (b689fe2)
  • update sdk-platform-java-config to 3.55.0-rc1 (#2642) (ed86f36)
Documentation
  • A comment for fieldcode in message.google.pubsub.v1.JavaScriptUDF is changed (3889a05)
  • Add ingestion from GCS sample (#2211) (ddb7391)
  • Add OpenTelemetry samples (#2208) (c447fe5)
  • Add samples and tests for ingestion from Kafka sources (#2315) (eea603b)
  • Fix repository URL in samples README (#2280) (8aeff1a)
  • sample: Add samples for topic and subscription SMTs (#2388) (f35de28)
  • samples: Optimistic subscribe sample (#2063) (53a4844)
  • sample: Update the subscribe with error listener and subscribe with exactly-once samples (#2437) (17c142b)
  • update documentation for JavaScriptUDF to indicate that themessage_id metadata field is optional instead of required (f904786)
  • Update emulator sample to create a topic and publish to it (#2039) (21d5cfc)

Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.

Last updated 2026-02-19 UTC.