[FLINK-39139] Update lz4-java to 1.10.3#27535
Conversation
|
@flinkbot run azure |
There was a problem hiding this comment.
Hi, thanks for removing the vulnerability!
I have one small comment:
could you please also update flink-dist/src/main/resources/META-INF/NOTICE:20 ?
Apart from that, LGTM.
Thanks. I missed that. |
|
@eschcam and @Savonitar , can you make sure this is backported to at least release 2.2 and release 2.1 branches? |
As requested I will try to backport to 2.0, 1.20 & 1.19 |
Done. |
|
@eschcam AFAIK there are no plans to release 1.19 |
The only reason I backported to the 1.19 branch is because I noticed another contributor backporting PRs to it |
|
@Savonitar Is there any reason why #27646 wasn't merged? |
Docs are pushed to the website automatically and don't require us to cut a new official Flink release, whereas bug fixes do.
We’ve just merged it. Thanks for the fix and the backports! |
What is the purpose of the change
lz4-java 1.8.0 has the following CVEs:
It has also been relocated to at.yawk.lz4
Brief change log
Verifying this change
Passes local tests
Does this pull request potentially affect one of the following parts:
@Public(Evolving): noDocumentation