Skip to content

Conversation

@clintropolis
Copy link
Member

Description

Bumps lz4-java to 1.8.1, apparently there is a CVE, though not sure we are much impacted since lz4 is only used to read segments as far as I know, which I would consider a trusted input, so it seems low risk.

@github-actions github-actions bot added Area - Batch Ingestion Area - MSQ For multi stage queries - https://github.com/apache/druid/issues/12262 labels Dec 3, 2025
@clintropolis clintropolis merged commit 12f6f31 into apache:master Dec 4, 2025
101 of 104 checks passed
@clintropolis clintropolis deleted the bump-lz4 branch December 4, 2025 21:37
clintropolis added a commit that referenced this pull request Dec 5, 2025
@clintropolis clintropolis added this to the 35.0.1 milestone Dec 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Area - Batch Ingestion Area - Dependencies Area - MSQ For multi stage queries - https://github.com/apache/druid/issues/12262

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants