Repository navigation
build(deps): bump at.yawk.lz4:lz4-java from 1.11.3 to 1.11.4 - #20520
dependabot[bot] wants to merge 2 commits into
Conversation
Bumps [at.yawk.lz4:lz4-java](https://github.com/yawkat/lz4-java) from 1.11.3 to 1.11.4. - [Release notes](https://github.com/yawkat/lz4-java/releases) - [Changelog](https://github.com/yawkat/lz4-java/blob/main/CHANGES.md) - [Commits](yawkat/lz4-java@v1.11.3...v1.11.4) --- updated-dependencies: - dependency-name: at.yawk.lz4:lz4-java dependency-version: 1.11.4 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
FrankChen021
left a comment
There was a problem hiding this comment.
This is an automated review by Codex GPT-5.6 Luna(Max).
Compatibility analysis
Reviewed at.yawk.lz4:lz4-java from 1.11.3 to 1.11.4. Maven Central's published-version inventory contains no intervening release, so the complete reviewed path is 1.11.3 -> 1.11.4. ROUND_1 verdict: SAFE for this transition and the target's cumulative effect on Druid.
API/ABI and runtime: published JAR class inventories and Druid-used public APIs are identical; bytecode remains Java 7 and the automatic module name remains org.lz4.java. The upstream production diff fixes JNI out-of-memory cleanup and exception references, streaming XXHash overflow, native-library extraction, and block/frame stream handling. Native extraction now exclusively creates its temporary file and removes stale temporary libraries; the existing keep-library settings remain supported. These changes preserve Druid's factory, compressor, decompressor, and hash interfaces.
Configuration, serialization/wire, persistence, and clients: Druid's compression settings and envelopes are unchanged. Valid raw LZ4 blocks, LZ4Block streams, and XXHash values remained compatible in both directions in the published-artifact probes. The block checksum retains its existing low-28-bit mask. The target rejects truncated block headers when reading concatenated streams and handles long sequences of empty blocks iteratively; this is malformed-input hardening, not a change to valid segment, spill, or cache data. Frame-stream fixes do not alter Druid's raw-block or LZ4Block consumers.
Transitive dependencies, licenses, and extension/plugin SPI: the library has no production dependencies in either published POM; the changed randomized-testing runner is upstream test-only. Apache-2.0 licensing is unchanged and this PR aligns licenses.yaml to 1.11.4. The Java package/API surface is unchanged, with no Druid extension or plugin contract change.
Sources: published versions, upstream release, and complete upstream comparison.
Druid impact
Reviewed both changed files, pom.xml and licenses.yaml. Consumers inspected include CompressionStrategy for persisted segment columns, FrameCompression for frame envelopes, CompressionUtils and SpillingGrouper for block streams, StructuredData for XXHash64, and CaffeineCache/LZ4Transcoder for cache compression. No tracked production or test source changed. The practical effect is the library's runtime and malformed-input fixes while retaining valid stored-data and cache compatibility.
Validation
- Compared the complete PR diff and upstream production changes, published-version inventory, source/target POMs, JAR class inventories, manifest, and Druid-used public APIs. No removed/added classes or public API changes; bytecode major version 51 in every target class.
- Ran 462 published-artifact probes on Java 25: both-direction raw and LZ4Block compatibility, fast/high compression, direct ByteBuffers with destination offsets, and XXHash32/64 equality over seven input sizes using safe, unsafe, and native backends. All passed.
- Maven dependency trees for
processingandserverboth resolvedat.yawk.lz4:lz4-java:1.11.4:compile; both module checks succeeded. - Verified unchanged Apache-2.0 POM/manifest licensing and matching Druid license metadata.
git diff --checkpassed and the isolated checkout is clean. - Enumerated all current-head CI items; static checks, packaging, strict compilation, CodeQL, all reported unit/QTest partitions, Docker tests, coverage, web checks, and timeline checks succeeded. No separate local Druid test suite was run.
CI gate
Exact current head: 2ae932b7408c54bd1d331c61698e5c6c00606446. The PR is OPEN, non-draft, MERGEABLE, and CLEAN. The authoritative statusCheckRollup is SUCCESS: 27 CheckRuns are COMPLETED/SUCCESS and 0 StatusContexts are reported. Every reported item succeeded; contexts pagination is complete (hasNextPage=false). No failed or active CI item requires repair or rerun.
Automation actions
The automation changed no tracked files, pushed no commit, and reran no jobs. The existing license update was already present in the reviewed head. No merge was performed.
Bumps at.yawk.lz4:lz4-java from 1.11.3 to 1.11.4.
Release notes
Sourced from at.yawk.lz4:lz4-java's releases.
Commits
4af910bRemove duplicate testAvailableAfterEmptyBlock (#149)7a48b7fMerge commit from forkc8ebf97Merge commit from fork2acc0ecMerge commit from forke0178d2Rework README, add contributing guide, Scorecard and coverage (#147)37ee3ccDelete .clinerules (#148)788980dFix negative LZ4BlockInputStream.available() after an empty block (#129)5442f0eTest the darwin/aarch64 native library before publishing (#143)68d4bfcOnly publish to Central from v* tags (#139)4c685a9Declare explicit GITHUB_TOKEN permissions in workflows (#135)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.