GCP Release Note: June 30, 2025

GCP Release Note: June 30, 2025

App Engine standard environment Java

Feature

For new deployments, the URL Fetch API validates the certificate of the host it contacts by default.

App Engine standard environment Python

Feature

For new deployments, the URL Fetch API validates the certificate of the host it contacts by default.

BigQuery

Libraries

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-bigquery

2.52.0 (2025-06-25)

Features
  • bigquery: Integrate Otel in client lib (#3747) (6e3e07a)
  • bigquery: Integrate Otel into retries, jobs, and more (#3842) (4b28c47)
Bug Fixes
  • bigquery: Add MY_VIEW_DATASET_NAMETEST to resource clean up sample (#3838) (b1962a7)
Dependencies
  • Remove version declaration of open-telemetry-bom (#3855) (6f9f77d)
  • Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.66.0 (#3835) (69be5e7)
  • Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.68.0 (#3858) (d4ca353)
  • Update dependency com.google.cloud:sdk-platform-java-config to v3.49.2 (#3853) (cf864df)
  • Update dependency com.google.cloud:sdk-platform-java-config to v3.50.0 (#3861) (eb26dee)
  • Update dependency io.opentelemetry:opentelemetry-bom to v1.51.0 (#3840) (51321c2)
  • Update ossf/scorecard-action action to v2.4.2 (#3810) (414f61d)

Feature

You can now create and manage scheduled notebooks using the Schedule details pane in BigQuery Studio. This feature is generally available (GA).

Bigtable

Libraries

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-bigtable

2.61.0 (2025-06-27)

Features
  • Add getter for universe domain in JwtCredentialsWithAudience (#2598) (9ad66b1)
Bug Fixes
  • Add name elements for the pom.xml files (a873719)
  • Populate table ID for materialized view (#2610) (50c3fe2)
Dependencies

Cloud DNS

Feature

Using a fully qualified domain name (FQDN) forwarding target is available for outbound DNS forwarding in GA.

Cloud Database Migration Service

Announcement

Database Migration Service support for heterogeneous SQL Server to PostgreSQL migrations is now generally available (GA).

For more information, see:

Cloud Key Management Service

Feature

Cloud HSM for Google Workspace now lets you use Cloud HSM keys for client-side encryption (CSE) to protect sensitive workloads in Google Workspace. For more information about Cloud HSM for Google Workspace, including how to get started, see Onboard to Cloud HSM for Google Workspace.

Cloud Logging

Libraries

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-logging

3.22.6 (2025-06-25)

Bug Fixes
  • Regenerate gapic yaml and service yaml for logging by augmentation configs (9023895)
Dependencies
  • Update dependency com.google.cloud:sdk-platform-java-config to v3.50.0 (#1821) (af4edc5)
  • Update googleapis/sdk-platform-java action to v2.60.0 (#1822) (0a96dd5)

Cloud Run

Feature

You can apply maximum instance configuration at the service level (in Preview).

Cloud Storage

Libraries

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-storage

2.53.2 (2025-06-25)

Bug Fixes
  • Fix Journaling BlobWriteSessionConfig to properly handle multiple consecutive retries (#3166) (895bfbd)
Dependencies
  • Update dependency com.google.cloud.opentelemetry:exporter-trace to v0.36.0 (#3162) (41a1030)
  • Update sdk-platform-java dependencies (#3164) (c22a131)

Colab Enterprise

Feature

Preview: You can consume reservations with Colab Enterprise runtimes. Reservations of Compute Engine zonal resources help you gain a high level of assurance that your runtimes have the necessary resources to run. For more information, see Use reservations with Colab Enterprise.

Compute Engine

Feature

Generally available: You can now modify licenses attached to your disks. Previously, licenses on disk resources were immutable. You had to delete and recreate disks, or engage our support team to change licenses.

This feature provides greater flexibility for managing your disk licenses. You can now:

For more information on how to manage licenses, see Manage licenses.

Container Optimized OS

Changed

cos-dev-125-19126-0-0

Kernel Docker Containerd GPU Drivers
COS-6.6.94 v27.5.1 v2.0.4 See List

Changed

Updated nvidia-container-toolkit to v1.17.7.

Changed

Upgraded sys-apps/ethtool to version 6.11.

Fixed

Upgraded app-admin/google-guest-configs to v20250605.00.

Fixed

Added support for the Lustre 2.14.0_p212 drivers.

Fixed

drop marvell-pcie-ep-octeon driver

Fixed

Upgraded chromeos-base/shill-client to v0.0.1-r4872.

Fixed

Upgraded chromeos-base/google-breakpad to v2025.06.12.121629-r242.

Fixed

Upgraded chromeos-base/shill-client to v0.0.1-r4871.

Fixed

Upgraded chromeos-base/chromeos-common-script to v0.0.1-r667.

Fixed

Upgraded dev-lang/go to v1.23.10.

Fixed

Upgraded app-admin/sudo to v1.9.17.

Fixed

Upgraded sys-apps/less to v679.

Fixed

Upgraded dev-db/sqlite to v3.50.1.

Fixed

Upgraded sys-process/procps to v4.0.5-r2.

Fixed

Upgraded sys-libs/libcap to v2.76.

Security

Upgrade libarchive to version 3.8.1. This fixes CVE-2025-5914.

Changed

Runtime sysctl changes:

  • Changed: fs.file-max: 811773 -> 811755

Changed

cos-117-18613-263-56

Kernel Docker Containerd GPU Drivers
COS-6.6.93 v24.0.9 v1.7.27 See List

Fixed

Added support for the Lustre 2.14.0_p212 drivers.

Fixed

Upgraded sys-apps/less to v679.

Fixed

Upgraded dev-libs/libusb to v1.0.29.

Security

Upgrade libarchive to version 3.8.1. This fixes CVE-2025-5914.

Security

Upgraded elfutils to version 0.193. This fixes CVE-2025-1365, CVE-2025-1371, CVE-2025-1372, and CVE-2025-1377.

Changed

Runtime sysctl changes:

  • Changed: fs.file-max: 811785 -> 811719

Changed

cos-121-18867-90-75

Kernel Docker Containerd GPU Drivers
COS-6.6.93 v27.5.1 v2.0.4 See List

Fixed

Added support for the Lustre 2.14.0_p212 drivers.

Fixed

Upgraded sys-apps/less to v679.

Security

Upgrade libarchive to version 3.8.1. This fixes CVE-2025-5914.

Security

Upgraded elfutils to version 0.193. This fixes CVE-2025-1365, CVE-2025-1371, CVE-2025-1372, and CVE-2025-1377.

Changed

Runtime sysctl changes:

  • Changed: fs.file-max: 811798 -> 811807

Changed

cos-113-18244-382-53

Kernel Docker Containerd GPU Drivers
COS-6.1.141 v24.0.9 v1.7.27 See List

Fixed

Upgraded dev-libs/libusb to v1.0.29.

Security

Upgrade libarchive to version 3.8.1. This fixes CVE-2025-5914.

Security

Upgraded elfutils to version 0.193. This fixes CVE-2025-1365, CVE-2025-1371, CVE-2025-1372, and CVE-2025-1377.

Changed

Runtime sysctl changes:

  • Changed: fs.file-max: 812041 -> 812035

Changed

cos-109-17800-519-40

Kernel Docker Containerd GPU Drivers
COS-6.1.141 v24.0.9 v1.7.27 See List

Fixed

Upgraded dev-libs/libusb to v1.0.29.

Security

Upgrade libarchive to version 3.8.1. This fixes CVE-2025-5914.

Security

Upgraded elfutils to version 0.193. This fixes CVE-2025-1365, CVE-2025-1371, CVE-2025-1372, and CVE-2025-1377.

Changed

Runtime sysctl changes:

  • Changed: fs.file-max: 812288 -> 812258

Datastream

Feature

Datastream is now available in the northamerica-south1 (Mexico) region. For the list of all available regions, see IP allowlists and regions.

Document AI

Feature

Custom Extractor model pretrained-foundation-model-v1.5-2025-05-05 is in General Availability (GA) and has fine-tuning available for the US and EU.

From version v1.4 and later, we will use a new quota for online processing called Number of online process document pages per minute per processor type and model version. This quota will be enforced at a per-page and per-foundation model level. There will be no change to the batch processing quota.

These can be enabled in the console when creating labels and by using the DocumentSchema.EntityType.

For more information, read Managing processor versions.

Google SecOps

Changed

Data tables are multicolumn constructs that let you input your own data into Google SecOps. You can create or import data tables to your Google SecOps account using the Google SecOps UI, the Data Tables API, or by using YARA-L queries in rules. This feature is now available to all customers.

What's new for this release:

  • Multiple web interface enhancements have been made, including a new default table view for data table management.
  • Support for the number data type is now available for data table columns.
  • Support for repeated fields in data table columns.
  • The Limitations section has additional details.

Google SecOps SIEM

Changed

Data tables are multicolumn constructs that let you input your own data into Google SecOps. You can create or import data tables to your Google SecOps account using the Google SecOps UI, the Data Tables API, or by using YARA-L queries in rules. This feature is now available to all customers.

What's new for this release:

  • Multiple web interface enhancements have been made, including a new default table view for data table management.
  • Support for the number data type is now available for data table columns.
  • Support for repeated fields in data table columns.
  • The Limitations section has additional details.

Looker

Feature

The Fast Dev Mode Transition feature is out of Labs and is now generally available. The Fast Dev Mode Transition feature improves the performance of Development Mode on your instance by loading LookML projects in read-only mode until a developer clicks the Create Developer Copy button for the project. Note: This item was added on July 8, 2025.

Feature

The Fast Dev Mode Transition feature is now available for Looker (Google Cloud core). The Fast Dev Mode Transition feature improves the performance of Development Mode on your instance by loading LookML projects in read-only mode until a developer clicks the Create Developer Copy button for the project. Note: This item was added on July 8, 2025.

Pub/Sub

Libraries

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-pubsub

1.140.2 (2025-06-25)

Dependencies
  • Update dependency com.google.cloud:google-cloud-bigquery to v2.51.0 (#2457) (d74215a)
  • Update dependency com.google.cloud:google-cloud-core to v2.58.0 (#2443) (d4599d9)
  • Update dependency com.google.cloud:google-cloud-storage to v2.53.1 (#2452) (b4af237)
  • Update dependency com.google.cloud:sdk-platform-java-config to v3.50.0 (#2461) (715916a)
  • Update dependency com.google.cloud.opentelemetry:exporter-trace to v0.36.0 (#2440) (50a3eb9)
  • Update dependency com.google.protobuf:protobuf-java-util to v4.31.1 (#2442) (a0be1bb)
  • Update dependency org.easymock:easymock to v5.6.0 (#2069) (5f144a4)
  • Update googleapis/sdk-platform-java action to v2.60.0 (#2462) (ee8e5c7)
  • Update googleapis/sdk-platform-java action to v2.60.0 (#2464) (7a0af37)

Security Command Center

Feature

You can download risk reports as PDFs. Risk reports help you understand the results of the attack path simulations (virtual red teaming) that Security Command Center runs. This feature is in Preview and is available for customers on the Enterprise or Premium service tiers. For more information, see Risk reports overview.

Feature

The following Virtual Machine Threat Detection detectors are in General Availability.

  • Defense Evasion: Unexpected ftrace handler
  • Defense Evasion: Unexpected interrupt handler
  • Defense Evasion: Unexpected kernel modules
  • Defense Evasion: Unexpected kernel read-only data modification
  • Defense Evasion: Unexpected kprobe handler
  • Defense Evasion: Unexpected processes in runqueue
  • Defense Evasion: Unexpected system call handler

Deprecated

The Defense Evasion: Unexpected kernel code modification detector of Virtual Machine Threat Detection is shut down. For more information, see Detector shutdowns.

Spanner

Feature

Spanner supports the following new client-side metrics to the Spanner API frontend (AFE) and Google frontend (GFE) for Java and Go applications:

  • AFE connectivity error count
  • AFE latencies
  • GFE connectivity error count
  • GFE latencies

These metrics can be used with server-side metrics to enable faster troubleshooting of performance and latency issues. For more information, see Client-side metrics descriptions.

Feature

To troubleshoot or understand your Spanner queries better, you can download and save your query execution plan as a JSON file. You can now use the content of this file to see a visualization of the query execution plan in Spanner Studio. For more information, see Take a tour of the query plan visualizer.

Libraries

A monthly digest of client library updates from across the Cloud SDK.

Go

Changes for spanner/admin/database/apiv1

1.83.0 (2025-06-27)

Features
  • spanner/spansql: Add support for TOKENIZE_JSON. (#12338) (72225a5)
  • spanner/spansql: Support EXISTS in query parsing (#12439) (f5cb67b)
  • spanner: Add new change_stream.proto (40b60a4)
  • spanner: Add option for how to call BeginTransaction (#12436) (2cba13b)
  • spanner: Wrap proto mutation (#12497) (e655889)
Bug Fixes

Java

Changes for google-cloud-spanner

6.95.0 (2025-06-05)

Features
Bug Fixes
Dependencies
  • Update dependency io.opentelemetry:opentelemetry-bom to v1.50.0 (#3887) (94b879c)

6.95.1 (2025-06-06)

Dependencies
  • Update dependency com.google.cloud:sdk-platform-java-config to v3.49.0 (#3909) (3de8502)
  • Update googleapis/sdk-platform-java action to v2.59.0 (#3910) (aed8bd6)

6.96.0 (2025-06-27)

Features
  • Allow JDBC to configure directpath for connection (#3929) (d754f1f)
  • Support getOrNull and getOrDefault in Struct (#3914) (1dc5a3e)
  • Use multiplexed sessions for read-only transactions (#3917) (37fdc27)
Bug Fixes
  • Allow zero durations to be set for connections (#3916) (43ea4fa)
Documentation
  • Add snippet for Repeatable Read configuration at client and transaction (#3908) (ff3d212)
  • Update SpannerSample.java to align with best practices (#3625) (7bfc62d)

VPC Service Controls

Feature

Preview stage support for the following integration:

Vertex AI

Deprecated

Mistral Nemo, which is offered as a Model as a Service (MaaS) model in Model Garden, is deprecated. For details, see Model as a Service (MaaS) deprecations.

Deprecated

Anthropic's Claude 3 Opus, which is offered as a Model as a Service (MaaS) model in Model Garden, is deprecated. For details, see Model as a Service (MaaS) deprecations.

Feature

Vertex AI online inference now offers Preview support of PSC service automation that can automatically create PSC endpoints for dedicated private endpoints. For more information, see Create the online inference endpoint with PSC automation.

Feature

Vertex AI now offers GA support of Private Service Connect Interface and includes Private DNS Peering. For more information, see Use Private Service Connect interface for Vertex AI Training.

Feature

Private Service Connect interface (PSC-I) support for ML pipeline runs in Vertex AI Pipelines is now generally available. PSC-I is recommended for private connectivity because it reduces the chance of IP exhaustion, allows for transitive peering, and includes Private DNS Peering.

For more information, see Configure Private Service Connect interface for a pipeline.

Source: Google Cloud Platform

Latest Posts

Pass It On