Introducing the google-ads-bom to the Google Ads API client library for Java

We are excited to announce the release of the google-ads-bom for the Google Ads API client library for Java, now available with v40.0.0 of the google-ads client library. This new Bill of Materials (BOM) is designed to significantly simplify your dependency management and enhance the stability of your Google Ads API integrations.

What is a BOM?

A BOM is a build-time tool that provides a centralized, authoritative "rulebook" for managing dependency versions. By importing our BOM, you ensure your project uses the exact set of compatible dependency versions that the Google Ads client was built and tested against. This significantly helps avoid dependency conflicts with libraries like Guava and GAX, which are also used by many other frameworks.

How to incorporate the google-ads-bom into your code

To leverage the benefits of the google-ads-bom, import it into the section of your build file (e.g., pom.xml for Maven or build.gradle for Gradle). You should then omit the version specification from the google-ads dependency in the section.

How to include the BOM in your Maven project:

<!-- Import the Bill of Materials (BOM) -->
<dependencyManagement>
    <dependencies>
        <dependency>
            <groupId>com.google.api-ads</groupId>
            <artifactId>google-ads-bom</artifactId>
            <version>40.0.0</version>
            <type>pom</type>
            <scope>import</scope>
        </dependency>
    </dependencies>
</dependencyManagement>

<!-- Add the google-ads dependency without a version -->
<dependencies>
    <dependency>
        <groupId>com.google.api-ads</groupId>
        <artifactId>google-ads</artifactId>
    </dependency>
</dependencies>

How to include the BOM in your Gradle project:

// Import the Bill of Materials (BOM).
implementation platform('com.google.api-ads:google-ads-bom:40.0.0')

// Add the google-ads dependency, without a version. The version is managed by the BOM.
implementation 'com.google.api-ads:google-ads'

Declaring dependencies covered by the google-ads-bom

The BOM automatically manages the versions for several common libraries–such as Guava, Protobuf, GAX, and gRPC–to make them compatible. To avoid potential dependency conflicts, you should not specify a version when declaring these dependencies. For example, if you are using Guava, you would declare it without a version:

In Maven:

<dependency>
    <groupId>com.google.guava</groupId>
    <artifactId>guava</artifactId>
</dependency>

Or in Gradle:

implementation 'com.google.guava:guava' // NO VERSION SPECIFIED.

To retrieve a list of constrained dependencies that can be imported using the BOM without a declared version, use the listAllDependencyConstraints gradle task.

To learn more about this new google-ads-bom offering and how to configure your Java client, check out our getting started guide.

Get proactive summaries of text responses in Forms

What’s changing 

Previously, users were able to request summaries of responses to specific questions in Google Forms using Gemini. Now, users will see proactive Gemini generated insights in Forms for short-answer or paragraph questions when reviewing responses. 

Using Gemini to summarize responses to longer questions helps users more quickly understand the sentiment, analyze feedback, or gain insights from the form without needing to review large amounts of text in detail. 


Getting started 


Rollout pace 


Availability 

Available for Google Workspace: 

  • Business Standard, and Plus
  • Enterprise Standard, and Plus 
  • Google AI Pro for Education 

Also available to: 

  • Google AI Pro and Ultra 
  • Gemini Business, Enterprise* 
*As of January 15, 2025, we’re no longer offering the Gemini Business and Gemini Enterprise add-ons for sale. Please refer to this announcement for more details. 

Resources 



Announcing the store widget: build shopper confidence and drive sales

When shoppers are online, knowing which store to buy from can be a tough decision. The new store widget powered by Google brings valuable information directly to a merchant's website, which can turn shopper hesitation into sales. It addresses two fundamental challenges ecommerce retailers face: boosting visibility and establishing legitimacy. The widget helps you attract customers and encourage them to make a purchase. Businesses using the store widget on their websites saw up to 8% higher sales within 90 days compared to similar businesses without it.

Chrome for Android Update

  Hi, everyone! We've just released Chrome 140 (140.0.7339.155) for Android. It'll become available on Google Play over the next few days. 

This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know by filing a bug.


Android releases contain the same security fixes as their corresponding Desktop releases (Windows & Mac: 140.0.7339.185/.186, Linux: 140.0.7339.185) unless otherwise noted.


Krishna Govind
Google Chrome

Launching Structured Data Files v9.1

Today we’re announcing the general availability of Structured Data Files v9.1. All users can now use SDF v9.1 to upload and download SDFs in the Display & Video 360 UI.

SDF v9.1 makes a number of small changes to files supporting Insertion Order, Line Item, and Ad Group resources:

  • Added the ability to configure whether certain targeting is set at the Line Item or Ad Group resource-level for Demand Gen Line Items.
  • Added a Combined Audience Targeting column to Ad Group files.
  • Made the Io Objective column required in Insertion Order files.
  • Updated the options available in the Bid Strategy Unit and TrueView Video Ad Formats columns in Line Item files.
  • Removed the Bid Multipliers column from Line Item files and the Measure DAR and Measure DAR Channel columns from Insertion Order files.

Full details on the changes between v9 and v9.1 can be found in the Structured Data Files release notes.

SDF v7 is deprecated and scheduled for sunset on November 4, 2025. SDF v7.1, v8, and v8.1 are deprecated and scheduled for sunset on March 3, 2026. If you are still using a deprecated SDF version, follow the instructions in our v9 migration guide to update your integration to use v9 or greater.

If you run into issues or need help with this new version, please follow the instructions in our support guide, or contact us using our contact form.

Stable Channel Update for Desktop

The Stable channel has been updated to 140.0.7339.185/.186 for Windows/Mac, and 140.0.7339.185 for Linux which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log.


Security Fixes and Rewards


Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.


This update includes 4 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information.



[NA][445380761] High CVE-2025-10585: Type Confusion in V8. Reported by Google Threat Analysis Group on 2025-09-16

[$15000][435875050] High CVE-2025-10500: Use after free in Dawn. Reported by Giunash (Gyujeong Jin) on 2025-08-03

[$10000][440737137] High CVE-2025-10501: Use after free in WebRTC. Reported by sherkito on 2025-08-23

[TBD][438038775] High CVE-2025-10502: Heap buffer overflow in ANGLE. Reported by Google Big Sleep on 2025-08-12


Google is aware that an exploit for CVE-2025-10585 exists in the wild.

We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.

Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista
Google Chrome

Android 16 QPR2 Beta 2 is Here

Posted by Matthew McCullough, VP of Product Management, Android Developer

Android 16 QPR2 has released Platform Stability today with Beta 2! That means that the API surface is locked, and the app-facing behaviors are final, so you can incorporate them into your apps and take advantage of our latest platform innovations.

New in the QPR2 Beta



At this later stage in the development cycle, we're focused on the critical work of readying the platform for release. Here are the few impactful changes we want to highlight:

Testing developer verification

To better protect Android users from repeat offenders, Android is introducing developer verification, a new requirement to make app installation safer by preventing the spread of malware and scams. Starting in September 2026 and in specific regions, Android will require apps to be registered by verified developers to be installed on certified Android devices, with an exception made for installs made through the Android Debug Bridge (ADB).

As a developer, you are free to install apps without verification by using ADB, so you can continue to test apps that are not intended or not yet ready to distribute to the wider consumer population.

For apps that enable user-initiated installation of app packages, Android 16 QPR2 Beta 2 contains new APIs that support developer verification during installation, along with a new adb command to let you force a verification outcome for testing purposes.

adb shell pm set-developer-verification-result

By using this command, (see adb shell pm help for full details)  you can now simulate verification failures. This allows you to understand the end-to-end user experience for both successful and unsuccessful verification, so you can prepare accordingly before enforcement begins.

We encourage all developers who distribute apps on certified Android devices to sign up for early access to get ready and stay updated.

SMS OTP Protection

The delivery of messages containing an SMS retriever hash will be delayed for most apps for three hours to help prevent OTP hijacking. The RECEIVE_SMS broadcast will be withheld and sms provider database queries will be filtered. The SMS will be available to these apps after the three hour delay.

Certain apps such as the default SMS, assistant, and dialer apps, along with connected device companion, system apps, etc will be exempt from this delay, and apps can continue to use the SMS retriever API to access messages intended for them in a timely manner.

Custom app icon shapes

Android 16 QPR2 allows users to select from a list of icon shapes that apply to all app icons and folder previews. Check to make sure that your adaptive icon works well with any shape the user selects.

More efficient garbage collection

The Android Runtime (ART) now includes a Generational Concurrent Mark-Compact (CMC) Garbage Collector in Android 16 QPR2 that focuses collection efforts on newly allocated objects, which are more likely to be garbage. You can expect reduced CPU usage from garbage collection, a smoother user experience with less jank, and improved battery efficiency.

Native step tracking and expanded exercise data in Health Connect

Health Connect now automatically tracks steps using the device's sensors. If your app has the READ_STEPS permission, this data will be available from the "android" package. Not only does this simplify the code needed to do step tracking, it's more power efficient as well.

Also, the ExerciseSegment and ExerciseSession data types have been updated. You can now record and read weight, set index, and Rate of Perceived Exertion (RPE) for exercise segments. Since Health Connect is updated independently of the platform, checking for feature availability before writing the data will ensure compatibility with the current local version of Health Connect.

// Check if the expanded exercise features are available
val newFieldsAvailable = healthConnectClient.features.getFeatureStatus(
    HealthConnectFeatures.FEATURE_EXPANDED_EXERCISE_RECORD
) == HealthConnectFeatures.FEATURE_STATUS_AVAILABLE

val segment = ExerciseSegment(
    //...
    // Conditionally add the new data fields
    weight = if (newFieldsAvailable) Mass.fromKilograms(50.0) else null,
    setIndex = if (newFieldsAvailable) 1 else null,
    rateOfPerceivedExertion = if (newFieldsAvailable) 7.0f else null
)

A minor SDK version

QPR2 marks the first Android release with a minor SDK version allowing us to more rapidly innovate with new platform APIs provided outside of our usual once-yearly timeline. Unlike the major platform release (Android 16) in 2025-Q2 that included behavior changes that impact app compatibility, the changes in this release are largely additive and designed to minimize the need for additional app testing.

Android 16 SDK release cadence

Your app can safely call the new APIs on devices where they are available by using SDK_INT_FULL and the respective value from the VERSION_CODES_FULL enumeration.

if (Build.VERSION.SDK_INT_FULL >= Build.VERSION_CODES_FULL.BAKLAVA_1) {
    // Call new APIs from the Android 16 QPR2 release
}

You can also use the Build.getMinorSdkVersion() method to get just the minor SDK version number.

val minorSdkVersion = Build.getMinorSdkVersion(VERSION_CODES_FULL.BAKLAVA)

The original VERSION_CODES enumeration can still be used to compare against the SDK_INT enumeration for APIs declared in non minor releases.

if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.BAKLAVA) {
    // Call new APIs from the Android 16 release
}

Since minor releases aren't intended to have breaking behavior changes, they cannot be used in the uses-sdk manifest attributes.

Get started with the Android 16 QPR2 beta

You can enroll any supported Pixel device to get this and future Android Beta updates over-the-air. If you don’t have a Pixel device, you can use the 64-bit system images with the Android Emulator in Android Studio.  If you are already in the Android Beta program, you will be offered an over-the-air update to Beta 2. We’ll update the system images and SDK regularly throughout the Android 16 QPR2 release cycle.

If you are in the Canary program and would like to enter the Beta program, you will need to wipe your device and manually flash it to the beta release.

For the best development experience with Android 16 QPR2, we recommend that you use the latest Canary version of Android Studio Narwhal Feature Drop.

We're looking for your feedback so please report issues and submit feature requests on the feedback page. The earlier we get your feedback, the more we can include in our work on the final release. Thank you for helping to shape the future of the Android platform.