Repository navigation
build(deps): bump at.yawk.lz4:lz4-java from 1.11.4 to 1.12.0 - #20547
Conversation
Bumps [at.yawk.lz4:lz4-java](https://github.com/yawkat/lz4-java) from 1.11.4 to 1.12.0. - [Release notes](https://github.com/yawkat/lz4-java/releases) - [Changelog](https://github.com/yawkat/lz4-java/blob/main/CHANGES.md) - [Commits](yawkat/lz4-java@v1.11.4...v1.12.0) --- updated-dependencies: - dependency-name: at.yawk.lz4:lz4-java dependency-version: 1.12.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
FrankChen021
left a comment
There was a problem hiding this comment.
This is an automated review by Codex GPT-5.6 Luna(Max).
Compatibility analysis
Dependency: at.yawk.lz4:lz4-java, upgraded from 1.11.4 to 1.12.0. The published release path reviewed is v1.11.4 -> v1.12.0; the upstream GitHub release and tag history has no published release between those versions, and v1.12.0 was published on 2026-09-25. The carried-forward ROUND_1 compatibility verdict is SAFE.
API/ABI is SAFE: the five commits in this transition leave the public LZ4Factory, compressor, safe-decompressor, and block-stream APIs used by Druid available; no Druid source changes are needed. Runtime behavior is SAFE for valid data: the release tightens handling of malformed frame descriptors, short safe-with-length output, and failed block/frame streams, while Druid does not use LZ4DecompressorWithLength or LZ4FrameInputStream; its block-stream readers receive the intended stricter IOException failure behavior for corrupt input. Configuration is SAFE because no Druid setting or default changes. Serialization/wire and persistence are SAFE because the upstream diff does not change valid compressor output or the LZ4 block/frame formats; Druid's FrameCompression envelope, segment compression, cache values, archives, and spill files remain readable/writable without migration. Client behavior is SAFE because Caffeine/Memcached and other consumers use unchanged factory/compressor/decompressor APIs and no client protocol changes are present. Transitive dependency behavior is SAFE: the resolved artifact has no additional dependency in the reviewed Druid module trees. License evidence is SAFE: the target artifact remains Apache License 2.0 under the same coordinates, and the packaging/license-report path succeeded; the unchanged repository metadata still names 1.11.4 but does not indicate a license change. Extension/plugin SPI behavior is SAFE: no extension source or SPI changed, and the separate org.lz4:lz4-java exclusions are different coordinates.
Druid impact
The PR changes only pom.xml:1022-1024, the dependency-management version. The managed dependency is consumed by processing/pom.xml:256-258, server/pom.xml:147-149, and multi-stage-query/pom.xml:178-180 (provided scope for MSQ). Relevant unchanged consumers include processing compression utilities, frame-wire compression, segment CompressionStrategy, groupBy spill streams, and server cache LZ4 compressor/decompressor paths. No tracked production or test source code changed. Practical impact is adoption of upstream input-validation and sticky-failure hardening for malformed LZ4 data; valid Druid compression and persistence behavior is unchanged.
Validation
- Reviewed the complete reserved PR diff and confirmed it is one
pom.xmlversion line;git diff --checkpassed and the isolated worktree remained clean. mvn -ntp -pl processing,server,multi-stage-query -DincludeScope=compile -Dincludes=at.yawk.lz4:lz4-java dependency:treepassed. Processing and server resolveat.yawk.lz4:lz4-java:1.12.0:compile; multi-stage-query resolves1.12.0:provided; no transitive dependency was shown.- Compared the published upstream
v1.11.4...v1.12.0history, release notes, changed Java sources, and Druid call sites. The upstream target release contains five commits and the relevant changes are limited to malformed-input validation/failure handling plus documentation/build files. - The exact-head GitHub CI included unit/integration and QTest shards, strict compilation, packaging, static checks, CodeQL, Docker/web checks, and PR checks; all reported items succeeded. The packaging check completed
BUILD SUCCESSand covers release license dependency reports; static checks completedBUILD SUCCESSwith no reported errors. - No local unit test command was run; the exact-head CI test and validation suites were green.
CI gate
Exact current head: bc487a4713ae41413b8124e3358c8979a44ca290. The PR is OPEN, non-draft, and MERGEABLE with mergeStateStatus=CLEAN. The complete exact-head statusCheckRollup is SUCCESS, with 27 CheckRuns in COMPLETED/SUCCESS and 0 StatusContexts; every reported item succeeded. There were no failed, cancelled, skipped, neutral, pending, or unknown results, so no CI repair or rerun was required.
Automation actions
No files were changed by the automation, no commit was created or pushed, and no jobs were rerun. This approval is for the exact current head after the fresh pre-approval read. No merge was performed.
Bumps at.yawk.lz4:lz4-java from 1.11.4 to 1.12.0.
Release notes
Sourced from at.yawk.lz4:lz4-java's releases.
Commits
b98ff90Make stream failures sticky in LZ4FrameInputStream and LZ4BlockInputStream (#...681f503Reject short output in LZ4DecompressorWithLength safe paths (#126)58805ddReplace Codecov with a coverage badge from the documentation site (#151)0538ca4Throw IOException for invalid or unsupported frame descriptors (#133)f6e3304Render README tables on the website (#150)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)