App Engine standard environment Java
Feature
For new deployments, the URL Fetch API validates the certificate of the host it contacts by default.
App Engine standard environment Python
Feature
For new deployments, the URL Fetch API validates the certificate of the host it contacts by default.
BigQuery
Libraries
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-bigquery
2.52.0 (2025-06-25)
Features
- bigquery: Integrate Otel in client lib (#3747) (6e3e07a)
- bigquery: Integrate Otel into retries, jobs, and more (#3842) (4b28c47)
Bug Fixes
Dependencies
- Remove version declaration of open-telemetry-bom (#3855) (6f9f77d)
- Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.66.0 (#3835) (69be5e7)
- Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.68.0 (#3858) (d4ca353)
- Update dependency com.google.cloud:sdk-platform-java-config to v3.49.2 (#3853) (cf864df)
- Update dependency com.google.cloud:sdk-platform-java-config to v3.50.0 (#3861) (eb26dee)
- Update dependency io.opentelemetry:opentelemetry-bom to v1.51.0 (#3840) (51321c2)
- Update ossf/scorecard-action action to v2.4.2 (#3810) (414f61d)
Feature
You can now create and manage scheduled notebooks using the Schedule details pane in BigQuery Studio. This feature is generally available (GA).
Bigtable
Libraries
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-bigtable
2.61.0 (2025-06-27)
Features
Bug Fixes
- Add name elements for the pom.xml files (a873719)
- Populate table ID for materialized view (#2610) (50c3fe2)
Dependencies
Cloud DNS
Feature
Using a fully qualified domain name (FQDN) forwarding target is available for outbound DNS forwarding in GA.
Cloud Database Migration Service
Announcement
Database Migration Service support for heterogeneous SQL Server to PostgreSQL migrations is now generally available (GA).
For more information, see:
- Database Migration Service for SQL Server to Cloud SQL for PostgreSQL
- Database Migration Service for SQL Server to AlloyDB for PostgreSQL
Cloud Key Management Service
Feature
Cloud HSM for Google Workspace now lets you use Cloud HSM keys for client-side encryption (CSE) to protect sensitive workloads in Google Workspace. For more information about Cloud HSM for Google Workspace, including how to get started, see Onboard to Cloud HSM for Google Workspace.
Cloud Logging
Libraries
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-logging
3.22.6 (2025-06-25)
Bug Fixes
- Regenerate gapic yaml and service yaml for logging by augmentation configs (9023895)
Dependencies
Cloud Run
Feature
You can apply maximum instance configuration at the service level (in Preview).
Cloud Storage
Libraries
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-storage
2.53.2 (2025-06-25)
Bug Fixes
- Fix Journaling BlobWriteSessionConfig to properly handle multiple consecutive retries (#3166) (895bfbd)
Dependencies
Colab Enterprise
Feature
Preview: You can consume reservations with Colab Enterprise runtimes. Reservations of Compute Engine zonal resources help you gain a high level of assurance that your runtimes have the necessary resources to run. For more information, see Use reservations with Colab Enterprise.
Compute Engine
Feature
Generally available: You can now modify licenses attached to your disks. Previously, licenses on disk resources were immutable. You had to delete and recreate disks, or engage our support team to change licenses.
This feature provides greater flexibility for managing your disk licenses. You can now:
- Append, remove, replace, and view the history of license updates.
- Perform in-place license upgrades, such as Ubuntu to Ubuntu Pro, using the
gcloud
CLI and REST. - Switch from PAYG to BYOS billing models.
- Review license changes and restrictions and append a RHEL ELS license to a newer version.
For more information on how to manage licenses, see Manage licenses.
Container Optimized OS
Changed
cos-dev-125-19126-0-0
Kernel | Docker | Containerd | GPU Drivers |
COS-6.6.94 | v27.5.1 | v2.0.4 | See List |
Changed
Updated nvidia-container-toolkit to v1.17.7.
Changed
Upgraded sys-apps/ethtool to version 6.11.
Fixed
Upgraded app-admin/google-guest-configs to v20250605.00.
Fixed
Added support for the Lustre 2.14.0_p212 drivers.
Fixed
drop marvell-pcie-ep-octeon driver
Fixed
Upgraded chromeos-base/shill-client to v0.0.1-r4872.
Fixed
Upgraded chromeos-base/google-breakpad to v2025.06.12.121629-r242.
Fixed
Upgraded chromeos-base/shill-client to v0.0.1-r4871.
Fixed
Upgraded chromeos-base/chromeos-common-script to v0.0.1-r667.
Fixed
Upgraded dev-lang/go to v1.23.10.
Fixed
Upgraded app-admin/sudo to v1.9.17.
Fixed
Upgraded sys-apps/less to v679.
Fixed
Upgraded dev-db/sqlite to v3.50.1.
Fixed
Upgraded sys-process/procps to v4.0.5-r2.
Fixed
Upgraded sys-libs/libcap to v2.76.
Security
Upgrade libarchive to version 3.8.1. This fixes CVE-2025-5914.
Changed
Runtime sysctl changes:
- Changed: fs.file-max: 811773 -> 811755
Changed
cos-117-18613-263-56
Kernel | Docker | Containerd | GPU Drivers |
COS-6.6.93 | v24.0.9 | v1.7.27 | See List |
Fixed
Added support for the Lustre 2.14.0_p212 drivers.
Fixed
Upgraded sys-apps/less to v679.
Fixed
Upgraded dev-libs/libusb to v1.0.29.
Security
Upgrade libarchive to version 3.8.1. This fixes CVE-2025-5914.
Security
Upgraded elfutils to version 0.193. This fixes CVE-2025-1365, CVE-2025-1371, CVE-2025-1372, and CVE-2025-1377.
Changed
Runtime sysctl changes:
- Changed: fs.file-max: 811785 -> 811719
Changed
cos-121-18867-90-75
Kernel | Docker | Containerd | GPU Drivers |
COS-6.6.93 | v27.5.1 | v2.0.4 | See List |
Fixed
Added support for the Lustre 2.14.0_p212 drivers.
Fixed
Upgraded sys-apps/less to v679.
Security
Upgrade libarchive to version 3.8.1. This fixes CVE-2025-5914.
Security
Upgraded elfutils to version 0.193. This fixes CVE-2025-1365, CVE-2025-1371, CVE-2025-1372, and CVE-2025-1377.
Changed
Runtime sysctl changes:
- Changed: fs.file-max: 811798 -> 811807
Changed
cos-113-18244-382-53
Kernel | Docker | Containerd | GPU Drivers |
COS-6.1.141 | v24.0.9 | v1.7.27 | See List |
Fixed
Upgraded dev-libs/libusb to v1.0.29.
Security
Upgrade libarchive to version 3.8.1. This fixes CVE-2025-5914.
Security
Upgraded elfutils to version 0.193. This fixes CVE-2025-1365, CVE-2025-1371, CVE-2025-1372, and CVE-2025-1377.
Changed
Runtime sysctl changes:
- Changed: fs.file-max: 812041 -> 812035
Changed
cos-109-17800-519-40
Kernel | Docker | Containerd | GPU Drivers |
COS-6.1.141 | v24.0.9 | v1.7.27 | See List |
Fixed
Upgraded dev-libs/libusb to v1.0.29.
Security
Upgrade libarchive to version 3.8.1. This fixes CVE-2025-5914.
Security
Upgraded elfutils to version 0.193. This fixes CVE-2025-1365, CVE-2025-1371, CVE-2025-1372, and CVE-2025-1377.
Changed
Runtime sysctl changes:
- Changed: fs.file-max: 812288 -> 812258
Datastream
Feature
Datastream is now available in the northamerica-south1
(Mexico) region. For the list of all available regions, see IP allowlists and regions.
Document AI
Feature
Custom Extractor model pretrained-foundation-model-v1.5-2025-05-05
is in General Availability (GA) and has fine-tuning available for the US and EU.
From version v1.4 and later, we will use a new quota for online processing called Number of online process document pages per minute per processor type and model version
. This quota will be enforced at a per-page and per-foundation model level. There will be no change to the batch processing quota.
These can be enabled in the console when creating labels and by using the DocumentSchema.EntityType
.
For more information, read Managing processor versions.
Google SecOps
Changed
Data tables are multicolumn constructs that let you input your own data into Google SecOps. You can create or import data tables to your Google SecOps account using the Google SecOps UI, the Data Tables API, or by using YARA-L queries in rules. This feature is now available to all customers.
What's new for this release:
- Multiple web interface enhancements have been made, including a new default table view for data table management.
- Support for the
number
data type is now available for data table columns. - Support for repeated fields in data table columns.
- The Limitations section has additional details.
Google SecOps SIEM
Changed
Data tables are multicolumn constructs that let you input your own data into Google SecOps. You can create or import data tables to your Google SecOps account using the Google SecOps UI, the Data Tables API, or by using YARA-L queries in rules. This feature is now available to all customers.
What's new for this release:
- Multiple web interface enhancements have been made, including a new default table view for data table management.
- Support for the
number
data type is now available for data table columns. - Support for repeated fields in data table columns.
- The Limitations section has additional details.
Looker
Feature
The Fast Dev Mode Transition feature is out of Labs and is now generally available. The Fast Dev Mode Transition feature improves the performance of Development Mode on your instance by loading LookML projects in read-only mode until a developer clicks the Create Developer Copy button for the project. Note: This item was added on July 8, 2025.
Feature
The Fast Dev Mode Transition feature is now available for Looker (Google Cloud core). The Fast Dev Mode Transition feature improves the performance of Development Mode on your instance by loading LookML projects in read-only mode until a developer clicks the Create Developer Copy button for the project. Note: This item was added on July 8, 2025.
Pub/Sub
Libraries
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-pubsub
1.140.2 (2025-06-25)
Dependencies
- Update dependency com.google.cloud:google-cloud-bigquery to v2.51.0 (#2457) (d74215a)
- Update dependency com.google.cloud:google-cloud-core to v2.58.0 (#2443) (d4599d9)
- Update dependency com.google.cloud:google-cloud-storage to v2.53.1 (#2452) (b4af237)
- Update dependency com.google.cloud:sdk-platform-java-config to v3.50.0 (#2461) (715916a)
- Update dependency com.google.cloud.opentelemetry:exporter-trace to v0.36.0 (#2440) (50a3eb9)
- Update dependency com.google.protobuf:protobuf-java-util to v4.31.1 (#2442) (a0be1bb)
- Update dependency org.easymock:easymock to v5.6.0 (#2069) (5f144a4)
- Update googleapis/sdk-platform-java action to v2.60.0 (#2462) (ee8e5c7)
- Update googleapis/sdk-platform-java action to v2.60.0 (#2464) (7a0af37)
Security Command Center
Feature
You can download risk reports as PDFs. Risk reports help you understand the results of the attack path simulations (virtual red teaming) that Security Command Center runs. This feature is in Preview and is available for customers on the Enterprise or Premium service tiers. For more information, see Risk reports overview.
Feature
The following Virtual Machine Threat Detection detectors are in General Availability.
Defense Evasion: Unexpected ftrace handler
Defense Evasion: Unexpected interrupt handler
Defense Evasion: Unexpected kernel modules
Defense Evasion: Unexpected kernel read-only data modification
Defense Evasion: Unexpected kprobe handler
Defense Evasion: Unexpected processes in runqueue
Defense Evasion: Unexpected system call handler
Deprecated
The Defense Evasion: Unexpected kernel code modification
detector of Virtual Machine Threat Detection is shut down. For more information, see Detector shutdowns.
Spanner
Feature
Spanner supports the following new client-side metrics to the Spanner API frontend (AFE) and Google frontend (GFE) for Java and Go applications:
- AFE connectivity error count
- AFE latencies
- GFE connectivity error count
- GFE latencies
These metrics can be used with server-side metrics to enable faster troubleshooting of performance and latency issues. For more information, see Client-side metrics descriptions.
Feature
To troubleshoot or understand your Spanner queries better, you can download and save your query execution plan as a JSON file. You can now use the content of this file to see a visualization of the query execution plan in Spanner Studio. For more information, see Take a tour of the query plan visualizer.
Libraries
A monthly digest of client library updates from across the Cloud SDK.
Go
Changes for spanner/admin/database/apiv1
1.83.0 (2025-06-27)
Features
- spanner/spansql: Add support for TOKENIZE_JSON. (#12338) (72225a5)
- spanner/spansql: Support EXISTS in query parsing (#12439) (f5cb67b)
- spanner: Add new change_stream.proto (40b60a4)
- spanner: Add option for how to call BeginTransaction (#12436) (2cba13b)
- spanner: Wrap proto mutation (#12497) (e655889)
Bug Fixes
Java
Changes for google-cloud-spanner
6.95.0 (2025-06-05)
Features
- Enable ALTS hard bound token in DirectPath (#3904) (2b0f2ff)
- Enable grpc and afe metrics (#3896) (706f794)
- Last statement sample (#3830) (2f62816)
- spanner: Add new change_stream.proto (f385698)
Bug Fixes
Dependencies
6.95.1 (2025-06-06)
Dependencies
- Update dependency com.google.cloud:sdk-platform-java-config to v3.49.0 (#3909) (3de8502)
- Update googleapis/sdk-platform-java action to v2.59.0 (#3910) (aed8bd6)
6.96.0 (2025-06-27)
Features
- Allow JDBC to configure directpath for connection (#3929) (d754f1f)
- Support getOrNull and getOrDefault in Struct (#3914) (1dc5a3e)
- Use multiplexed sessions for read-only transactions (#3917) (37fdc27)
Bug Fixes
Documentation
VPC Service Controls
Feature
Preview stage support for the following integration:
Vertex AI
Deprecated
Mistral Nemo, which is offered as a Model as a Service (MaaS) model in Model Garden, is deprecated. For details, see Model as a Service (MaaS) deprecations.
Deprecated
Anthropic's Claude 3 Opus, which is offered as a Model as a Service (MaaS) model in Model Garden, is deprecated. For details, see Model as a Service (MaaS) deprecations.
Feature
Vertex AI online inference now offers Preview support of PSC service automation that can automatically create PSC endpoints for dedicated private endpoints. For more information, see Create the online inference endpoint with PSC automation.
Feature
Vertex AI now offers GA support of Private Service Connect Interface and includes Private DNS Peering. For more information, see Use Private Service Connect interface for Vertex AI Training.
Feature
Private Service Connect interface (PSC-I) support for ML pipeline runs in Vertex AI Pipelines is now generally available. PSC-I is recommended for private connectivity because it reduces the chance of IP exhaustion, allows for transitive peering, and includes Private DNS Peering.
For more information, see Configure Private Service Connect interface for a pipeline.
Source: Google Cloud Platform
Latest Posts
- Amazon RDS for PostgreSQL supports minor versions 17.6, 16.10, 15.14, 14.19, and 13.22
- Noise suppression for dial-in participants in Teams audio conferences [MC1135397]
- Microsoft Teams | Manage voice and face recognition for rooms (MTR-W/MTRA) via device settings [MC1135396]
- Reporting labels retirement in Teams admin center [MC1135399]