Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 12, 2026

Bumps com.google.crypto.tink:tink from 1.19.0 to 1.20.0.

Release notes

Sourced from com.google.crypto.tink:tink's releases.

Tink Java v1.20.0

Tink is a multi-language, cross-platform library that provides simple and misuse-proof APIs for common cryptographic tasks.

This is Tink Java 1.20.0

The complete list of changes since 1.19.0 can be found here.

  • Updated the Protobuf dependency to 4.33.0.
  • Improved performance for creating JWT signature primitives.
  • Dropped support for WORKSPACE Bazel files.
  • Allow using 32-byte keys in subtle AES-SIV primitive.
  • Fixed tink-crypto/tink-java#63

Maven:

<dependency>
    <groupId>com.google.crypto.tink</groupId>
    <artifactId>tink</artifactId>
    <version>1.20.0</version>
</dependency>

Gradle:

dependencies {
  implementation 'com.google.crypto.tink:tink-android:1.20.0'
}

Bazel:

Using bzlmod

bazel_dep(name = "tink_java")

git_override(
module_name = "tink_java",
remote = "https://github.com/tink-crypto/tink-java",
tag = "v1.20.0",
)

Commits
  • fe3e251 Tag version 1.20.0
  • efe61ad Move JwtNames.java to /jwt/internal/JwtNames.java
  • 2450984 Move JsonUtil to com.google.crypto.tink.jwt.internal.
  • 493a645 Add createWithProvider to internal SLH-DSA primitives.
  • 71f2a9b Implement the LowLevelCryptoCaller annotation.
  • d231253 Make SlhDsa available in SignatureConfigurationV1.
  • 47d37db Introduce SlhDsaSign/VerifyConscrypt to Tink Java.
  • 067cd7a Introduce SlhDsaProtoSerialization in Tink Java.
  • 074bbfb Introduce SlhDsaPrivateKeys to Tink Java.
  • ab3558c Introduce SlhDsaPublicKey to Tink Java.
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [com.google.crypto.tink:tink](https://github.com/tink-crypto/tink-java) from 1.19.0 to 1.20.0.
- [Release notes](https://github.com/tink-crypto/tink-java/releases)
- [Commits](tink-crypto/tink-java@v1.19.0...v1.20.0)

---
updated-dependencies:
- dependency-name: com.google.crypto.tink:tink
  dependency-version: 1.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Jan 12, 2026
@LarsEckart LarsEckart merged commit 4ef32ee into main Jan 12, 2026
4 checks passed
@dependabot dependabot bot deleted the dependabot/gradle/com.google.crypto.tink-tink-1.20.0 branch January 12, 2026 02:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants