Skip to content

Commit fc23474

Browse files
committed
[CELEBORN-2218] Bump lz4-java version from 1.8.0 to 1.10.1 to resolve CVE‐2025‐12183 and CVE-2025-66566
1 parent 5789b4e commit fc23474

18 files changed

+55
-26
lines changed

client-mr/mr-shaded/pom.xml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -64,8 +64,8 @@
6464
<shadedPattern>${shading.prefix}.org.scala-lang</shadedPattern>
6565
</relocation>
6666
<relocation>
67-
<pattern>org.lz4</pattern>
68-
<shadedPattern>${shading.prefix}.org.lz4</shadedPattern>
67+
<pattern>at.yawk.lz4</pattern>
68+
<shadedPattern>${shading.prefix}.at.yawk.lz4</shadedPattern>
6969
</relocation>
7070
<relocation>
7171
<pattern>org.roaringbitmap</pattern>
@@ -81,7 +81,7 @@
8181
<include>io.netty:*</include>
8282
<include>org.apache.commons:commons-lang3</include>
8383
<include>org.scala-lang:scala-library</include>
84-
<include>org.lz4:lz4-java</include>
84+
<include>at.yawk.lz4:lz4-java</include>
8585
<include>com.github.luben:zstd-jni</include>
8686
<include>org.roaringbitmap:RoaringBitmap</include>
8787
</includes>

client-mr/mr-shaded/src/main/resources/META-INF/LICENSE

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -208,6 +208,7 @@ This project bundles the following dependencies under the Apache License 2.0 (ht
208208
Apache License 2.0
209209
--------------------------------------
210210

211+
at.yawk.lz4:lz4-java
211212
com.google.guava:failureaccess
212213
com.google.guava:guava
213214
io.netty:netty
@@ -240,7 +241,6 @@ io.netty:netty-transport-rxtx
240241
io.netty:netty-transport-sctp
241242
io.netty:netty-transport-udt
242243
org.apache.commons:commons-lang3
243-
org.lz4:lz4-java
244244
org.roaringbitmap:RoaringBitmap
245245
org.scala-lang:scala-library
246246

client-tez/tez-shaded/pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -94,7 +94,7 @@
9494
<include>org.roaringbitmap:RoaringBitmap</include>
9595
<include>org.scala-lang:scala-library</include>
9696
<include>org.scala-lang:scala-reflect</include>
97-
<include>org.lz4:lz4-java</include>
97+
<include>at.yawk.lz4:lz4-java</include>
9898
<include>io.dropwizard.metrics:metrics-core</include>
9999
<include>com.codahale.metrics:metrics-core</include>
100100
<include>com.github.luben:zstd-jni</include>

client-tez/tez-shaded/src/main/resources/META-INF/LICENSE

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -208,6 +208,7 @@ This project bundles the following dependencies under the Apache License 2.0 (ht
208208
Apache License 2.0
209209
--------------------------------------
210210

211+
at.yawk.lz4:lz4-java
211212
com.google.guava:failureaccess
212213
com.google.guava:guava
213214
io.netty:netty
@@ -240,7 +241,6 @@ io.netty:netty-transport-rxtx
240241
io.netty:netty-transport-sctp
241242
io.netty:netty-transport-udt
242243
org.apache.commons:commons-lang3
243-
org.lz4:lz4-java
244244
org.roaringbitmap:RoaringBitmap
245245
org.scala-lang:scala-library
246246

client/pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@
5151
<artifactId>guava</artifactId>
5252
</dependency>
5353
<dependency>
54-
<groupId>org.lz4</groupId>
54+
<groupId>at.yawk.lz4</groupId>
5555
<artifactId>lz4-java</artifactId>
5656
</dependency>
5757
<dependency>

dev/deps/dependencies-client-flink-1.16

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ jcl-over-slf4j/1.7.36//jcl-over-slf4j-1.7.36.jar
3232
jsr305/1.3.9//jsr305-1.3.9.jar
3333
jul-to-slf4j/1.7.36//jul-to-slf4j-1.7.36.jar
3434
leveldbjni-all/1.8//leveldbjni-all-1.8.jar
35-
lz4-java/1.8.0//lz4-java-1.8.0.jar
35+
lz4-java/1.10.1//lz4-java-1.10.1.jar
3636
maven-jdk-tools-wrapper/0.1//maven-jdk-tools-wrapper-0.1.jar
3737
metrics-core/4.2.25//metrics-core-4.2.25.jar
3838
metrics-graphite/4.2.25//metrics-graphite-4.2.25.jar

dev/deps/dependencies-client-flink-1.17

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ jcl-over-slf4j/1.7.36//jcl-over-slf4j-1.7.36.jar
3232
jsr305/1.3.9//jsr305-1.3.9.jar
3333
jul-to-slf4j/1.7.36//jul-to-slf4j-1.7.36.jar
3434
leveldbjni-all/1.8//leveldbjni-all-1.8.jar
35-
lz4-java/1.8.0//lz4-java-1.8.0.jar
35+
lz4-java/1.10.1//lz4-java-1.10.1.jar
3636
maven-jdk-tools-wrapper/0.1//maven-jdk-tools-wrapper-0.1.jar
3737
metrics-core/4.2.25//metrics-core-4.2.25.jar
3838
metrics-graphite/4.2.25//metrics-graphite-4.2.25.jar

dev/deps/dependencies-client-flink-1.18

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ jcl-over-slf4j/1.7.36//jcl-over-slf4j-1.7.36.jar
3232
jsr305/1.3.9//jsr305-1.3.9.jar
3333
jul-to-slf4j/1.7.36//jul-to-slf4j-1.7.36.jar
3434
leveldbjni-all/1.8//leveldbjni-all-1.8.jar
35-
lz4-java/1.8.0//lz4-java-1.8.0.jar
35+
lz4-java/1.10.1//lz4-java-1.10.1.jar
3636
maven-jdk-tools-wrapper/0.1//maven-jdk-tools-wrapper-0.1.jar
3737
metrics-core/4.2.25//metrics-core-4.2.25.jar
3838
metrics-graphite/4.2.25//metrics-graphite-4.2.25.jar

dev/deps/dependencies-client-flink-1.19

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ jcl-over-slf4j/1.7.36//jcl-over-slf4j-1.7.36.jar
3232
jsr305/1.3.9//jsr305-1.3.9.jar
3333
jul-to-slf4j/1.7.36//jul-to-slf4j-1.7.36.jar
3434
leveldbjni-all/1.8//leveldbjni-all-1.8.jar
35-
lz4-java/1.8.0//lz4-java-1.8.0.jar
35+
lz4-java/1.10.1//lz4-java-1.10.1.jar
3636
maven-jdk-tools-wrapper/0.1//maven-jdk-tools-wrapper-0.1.jar
3737
metrics-core/4.2.25//metrics-core-4.2.25.jar
3838
metrics-graphite/4.2.25//metrics-graphite-4.2.25.jar

dev/deps/dependencies-client-flink-1.20

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ jcl-over-slf4j/1.7.36//jcl-over-slf4j-1.7.36.jar
3232
jsr305/1.3.9//jsr305-1.3.9.jar
3333
jul-to-slf4j/1.7.36//jul-to-slf4j-1.7.36.jar
3434
leveldbjni-all/1.8//leveldbjni-all-1.8.jar
35-
lz4-java/1.8.0//lz4-java-1.8.0.jar
35+
lz4-java/1.10.1//lz4-java-1.10.1.jar
3636
maven-jdk-tools-wrapper/0.1//maven-jdk-tools-wrapper-0.1.jar
3737
metrics-core/4.2.25//metrics-core-4.2.25.jar
3838
metrics-graphite/4.2.25//metrics-graphite-4.2.25.jar

0 commit comments

Comments
 (0)