Skip to content

build(deps): bump at.yawk.lz4:lz4-java from 1.11.3 to 1.11.4 - #20520

Open
dependabot[bot] wants to merge 2 commits into
masterfrom
dependabot/maven/at.yawk.lz4-lz4-java-1.11.4
Open

dependabot[bot] wants to merge 2 commits into
masterfrom
dependabot/maven/at.yawk.lz4-lz4-java-1.11.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps at.yawk.lz4:lz4-java from 1.11.3 to 1.11.4.

Release notes

Sourced from at.yawk.lz4:lz4-java's releases.

lz4-java v1.11.4

Security release for CVE-2026-106450, CVE-2026-106449 and CVE-2026-106451. Also includes general fixes for bugs found by AI.

What's Changed

Full Changelog: yawkat/lz4-java@v1.11.3...v1.11.4

Commits
  • 4af910b Remove duplicate testAvailableAfterEmptyBlock (#149)
  • 7a48b7f Merge commit from fork
  • c8ebf97 Merge commit from fork
  • 2acc0ec Merge commit from fork
  • e0178d2 Rework README, add contributing guide, Scorecard and coverage (#147)
  • 37ee3cc Delete .clinerules (#148)
  • 788980d Fix negative LZ4BlockInputStream.available() after an empty block (#129)
  • 5442f0e Test the darwin/aarch64 native library before publishing (#143)
  • 68d4bfc Only publish to Central from v* tags (#139)
  • 4c685a9 Declare explicit GITHUB_TOKEN permissions in workflows (#135)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [at.yawk.lz4:lz4-java](https://github.com/yawkat/lz4-java) from 1.11.3 to 1.11.4.
- [Release notes](https://github.com/yawkat/lz4-java/releases)
- [Changelog](https://github.com/yawkat/lz4-java/blob/main/CHANGES.md)
- [Commits](yawkat/lz4-java@v1.11.3...v1.11.4)

---
updated-dependencies:
- dependency-name: at.yawk.lz4:lz4-java
  dependency-version: 1.11.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 8, 2026

@amaechler amaechler left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🐻

@FrankChen021 FrankChen021 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is an automated review by Codex GPT-5.6 Luna(Max).

Compatibility analysis

Reviewed at.yawk.lz4:lz4-java from 1.11.3 to 1.11.4. Maven Central's published-version inventory contains no intervening release, so the complete reviewed path is 1.11.3 -> 1.11.4. ROUND_1 verdict: SAFE for this transition and the target's cumulative effect on Druid.

API/ABI and runtime: published JAR class inventories and Druid-used public APIs are identical; bytecode remains Java 7 and the automatic module name remains org.lz4.java. The upstream production diff fixes JNI out-of-memory cleanup and exception references, streaming XXHash overflow, native-library extraction, and block/frame stream handling. Native extraction now exclusively creates its temporary file and removes stale temporary libraries; the existing keep-library settings remain supported. These changes preserve Druid's factory, compressor, decompressor, and hash interfaces.

Configuration, serialization/wire, persistence, and clients: Druid's compression settings and envelopes are unchanged. Valid raw LZ4 blocks, LZ4Block streams, and XXHash values remained compatible in both directions in the published-artifact probes. The block checksum retains its existing low-28-bit mask. The target rejects truncated block headers when reading concatenated streams and handles long sequences of empty blocks iteratively; this is malformed-input hardening, not a change to valid segment, spill, or cache data. Frame-stream fixes do not alter Druid's raw-block or LZ4Block consumers.

Transitive dependencies, licenses, and extension/plugin SPI: the library has no production dependencies in either published POM; the changed randomized-testing runner is upstream test-only. Apache-2.0 licensing is unchanged and this PR aligns licenses.yaml to 1.11.4. The Java package/API surface is unchanged, with no Druid extension or plugin contract change.

Sources: published versions, upstream release, and complete upstream comparison.

Druid impact

Reviewed both changed files, pom.xml and licenses.yaml. Consumers inspected include CompressionStrategy for persisted segment columns, FrameCompression for frame envelopes, CompressionUtils and SpillingGrouper for block streams, StructuredData for XXHash64, and CaffeineCache/LZ4Transcoder for cache compression. No tracked production or test source changed. The practical effect is the library's runtime and malformed-input fixes while retaining valid stored-data and cache compatibility.

Validation

  • Compared the complete PR diff and upstream production changes, published-version inventory, source/target POMs, JAR class inventories, manifest, and Druid-used public APIs. No removed/added classes or public API changes; bytecode major version 51 in every target class.
  • Ran 462 published-artifact probes on Java 25: both-direction raw and LZ4Block compatibility, fast/high compression, direct ByteBuffers with destination offsets, and XXHash32/64 equality over seven input sizes using safe, unsafe, and native backends. All passed.
  • Maven dependency trees for processing and server both resolved at.yawk.lz4:lz4-java:1.11.4:compile; both module checks succeeded.
  • Verified unchanged Apache-2.0 POM/manifest licensing and matching Druid license metadata. git diff --check passed and the isolated checkout is clean.
  • Enumerated all current-head CI items; static checks, packaging, strict compilation, CodeQL, all reported unit/QTest partitions, Docker tests, coverage, web checks, and timeline checks succeeded. No separate local Druid test suite was run.

CI gate

Exact current head: 2ae932b7408c54bd1d331c61698e5c6c00606446. The PR is OPEN, non-draft, MERGEABLE, and CLEAN. The authoritative statusCheckRollup is SUCCESS: 27 CheckRuns are COMPLETED/SUCCESS and 0 StatusContexts are reported. Every reported item succeeded; contexts pagination is complete (hasNextPage=false). No failed or active CI item requires repair or rerun.

Automation actions

The automation changed no tracked files, pushed no commit, and reran no jobs. The existing license update was already present in the reviewed head. No merge was performed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Area - Dependencies dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants