Skip to content

build(deps): bump at.yawk.lz4:lz4-java from 1.11.4 to 1.12.0 - #20547

Merged
FrankChen021 merged 1 commit into
masterfrom
dependabot/maven/at.yawk.lz4-lz4-java-1.12.0
Oct 11, 2026
Merged

FrankChen021 merged 1 commit into
masterfrom
dependabot/maven/at.yawk.lz4-lz4-java-1.12.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Bumps at.yawk.lz4:lz4-java from 1.11.4 to 1.12.0.

Release notes

Sourced from at.yawk.lz4:lz4-java's releases.

lz4-java v1.12.0

Note that lz4-java v1.11.4, also released today, contains security fixes. This minor release contains some additional tightening of input validation that could in theory be breaking but should be fine for most if not all users. I recommend you upgrade to 1.12.0, but 1.11.4 is an option if that breaks.

What's Changed

Full Changelog: yawkat/lz4-java@v1.11.4...v1.12.0

Commits
  • b98ff90 Make stream failures sticky in LZ4FrameInputStream and LZ4BlockInputStream (#...
  • 681f503 Reject short output in LZ4DecompressorWithLength safe paths (#126)
  • 58805dd Replace Codecov with a coverage badge from the documentation site (#151)
  • 0538ca4 Throw IOException for invalid or unsupported frame descriptors (#133)
  • f6e3304 Render README tables on the website (#150)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [at.yawk.lz4:lz4-java](https://github.com/yawkat/lz4-java) from 1.11.4 to 1.12.0.
- [Release notes](https://github.com/yawkat/lz4-java/releases)
- [Changelog](https://github.com/yawkat/lz4-java/blob/main/CHANGES.md)
- [Commits](yawkat/lz4-java@v1.11.4...v1.12.0)

---
updated-dependencies:
- dependency-name: at.yawk.lz4:lz4-java
  dependency-version: 1.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 10, 2026

@FrankChen021 FrankChen021 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is an automated review by Codex GPT-5.6 Luna(Max).

Compatibility analysis

Dependency: at.yawk.lz4:lz4-java, upgraded from 1.11.4 to 1.12.0. The published release path reviewed is v1.11.4 -> v1.12.0; the upstream GitHub release and tag history has no published release between those versions, and v1.12.0 was published on 2026-09-25. The carried-forward ROUND_1 compatibility verdict is SAFE.

API/ABI is SAFE: the five commits in this transition leave the public LZ4Factory, compressor, safe-decompressor, and block-stream APIs used by Druid available; no Druid source changes are needed. Runtime behavior is SAFE for valid data: the release tightens handling of malformed frame descriptors, short safe-with-length output, and failed block/frame streams, while Druid does not use LZ4DecompressorWithLength or LZ4FrameInputStream; its block-stream readers receive the intended stricter IOException failure behavior for corrupt input. Configuration is SAFE because no Druid setting or default changes. Serialization/wire and persistence are SAFE because the upstream diff does not change valid compressor output or the LZ4 block/frame formats; Druid's FrameCompression envelope, segment compression, cache values, archives, and spill files remain readable/writable without migration. Client behavior is SAFE because Caffeine/Memcached and other consumers use unchanged factory/compressor/decompressor APIs and no client protocol changes are present. Transitive dependency behavior is SAFE: the resolved artifact has no additional dependency in the reviewed Druid module trees. License evidence is SAFE: the target artifact remains Apache License 2.0 under the same coordinates, and the packaging/license-report path succeeded; the unchanged repository metadata still names 1.11.4 but does not indicate a license change. Extension/plugin SPI behavior is SAFE: no extension source or SPI changed, and the separate org.lz4:lz4-java exclusions are different coordinates.

Druid impact

The PR changes only pom.xml:1022-1024, the dependency-management version. The managed dependency is consumed by processing/pom.xml:256-258, server/pom.xml:147-149, and multi-stage-query/pom.xml:178-180 (provided scope for MSQ). Relevant unchanged consumers include processing compression utilities, frame-wire compression, segment CompressionStrategy, groupBy spill streams, and server cache LZ4 compressor/decompressor paths. No tracked production or test source code changed. Practical impact is adoption of upstream input-validation and sticky-failure hardening for malformed LZ4 data; valid Druid compression and persistence behavior is unchanged.

Validation

  • Reviewed the complete reserved PR diff and confirmed it is one pom.xml version line; git diff --check passed and the isolated worktree remained clean.
  • mvn -ntp -pl processing,server,multi-stage-query -DincludeScope=compile -Dincludes=at.yawk.lz4:lz4-java dependency:tree passed. Processing and server resolve at.yawk.lz4:lz4-java:1.12.0:compile; multi-stage-query resolves 1.12.0:provided; no transitive dependency was shown.
  • Compared the published upstream v1.11.4...v1.12.0 history, release notes, changed Java sources, and Druid call sites. The upstream target release contains five commits and the relevant changes are limited to malformed-input validation/failure handling plus documentation/build files.
  • The exact-head GitHub CI included unit/integration and QTest shards, strict compilation, packaging, static checks, CodeQL, Docker/web checks, and PR checks; all reported items succeeded. The packaging check completed BUILD SUCCESS and covers release license dependency reports; static checks completed BUILD SUCCESS with no reported errors.
  • No local unit test command was run; the exact-head CI test and validation suites were green.

CI gate

Exact current head: bc487a4713ae41413b8124e3358c8979a44ca290. The PR is OPEN, non-draft, and MERGEABLE with mergeStateStatus=CLEAN. The complete exact-head statusCheckRollup is SUCCESS, with 27 CheckRuns in COMPLETED/SUCCESS and 0 StatusContexts; every reported item succeeded. There were no failed, cancelled, skipped, neutral, pending, or unknown results, so no CI repair or rerun was required.

Automation actions

No files were changed by the automation, no commit was created or pushed, and no jobs were rerun. This approval is for the exact current head after the fresh pre-approval read. No merge was performed.

@FrankChen021
FrankChen021 merged commit d3ae867 into master Oct 11, 2026
27 checks passed
@dependabot
dependabot Bot deleted the dependabot/maven/at.yawk.lz4-lz4-java-1.12.0 branch October 11, 2026 01:37
@github-actions github-actions Bot added this to the 39.0.0 milestone Oct 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Area - Dependencies dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant