Skip to content

[fix][sec] Upgrade at.yawk.lz4:lz4-java to 1.11.4 - #26758

Merged
nodece merged 2 commits into
apache:masterfrom
lhotari:lh-fix-lz4-java-1.11.4
Sep 30, 2026
Merged

nodece merged 2 commits into
apache:masterfrom
lhotari:lh-fix-lz4-java-1.11.4

Conversation

@lhotari

@lhotari lhotari commented Sep 29, 2026

Copy link
Copy Markdown
Member

Motivation

Adopt the fixes published in the maintained at.yawk.lz4:lz4-java 1.11.4 release. Pulsar uses it for compression interoperability tests, and DistributedLog requires it transitively in the server distribution. Pulsar's own message compression continues to use Airlift.

Modifications

Upgrade at.yawk.lz4:lz4-java from 1.11.2 to 1.11.4 and update the server binary-license inventory. The existing version constraint aligns DistributedLog's transitive dependency with this version.

Verifying this change

  • Make sure that the change passes the CI checks.

help assemble sanityCheck checkBinaryLicense passed with configuration cache enabled, including compilation and Checkstyle/Spotless. All 51 cases in CompressorCodecBackwardCompatTest and CompressorCodecTest passed on Java 17 with retries disabled, covering interoperability between the lz4-java and Airlift codecs.

Does this pull request potentially affect one of the following parts:

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

@nodece
nodece merged commit 6e287e5 into apache:master Sep 30, 2026
42 checks passed
ascentstream-bot pushed a commit to ascentstream/pulsar that referenced this pull request Oct 1, 2026
ascentstream-bot pushed a commit to ascentstream/pulsar that referenced this pull request Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants