Skip to content

[SPARK-59820][BUILD] Upgrade lz4-java to 1.12.0 - #59093

Closed
dongjoon-hyun wants to merge 1 commit into
apache:masterfrom
dongjoon-hyun:SPARK-59820
Closed

dongjoon-hyun wants to merge 1 commit into
apache:masterfrom
dongjoon-hyun:SPARK-59820

Conversation

@dongjoon-hyun

Copy link
Copy Markdown
Member

What changes were proposed in this pull request?

This PR aims to upgrade at.yawk.lz4:lz4-java to 1.12.0.

Why are the changes needed?

To bring the latest security fixes of v1.11.4 and the stricter input validation of v1.12.0. The upstream recommends 1.12.0 over 1.11.4.

Note that Apache Spark's LZ4CompressionCodec reads streams via LZ4BlockInputStream with withStopOnEmptyBlock(false), which is the code path fixed by GHSA-343h-94h5-c4wr.

Full Changelog: yawkat/lz4-java@v1.11.3...v1.12.0

Does this PR introduce any user-facing change?

No. There is no behavior change for valid LZ4 streams.

How was this patch tested?

Pass the CIs.

Was this patch authored or co-authored using generative AI tooling?

Generated-by: Claude Opus 5.5

@uros-b

uros-b commented Sep 28, 2026

Copy link
Copy Markdown
Member

Thank you @dongjoon-hyun and @HyukjinKwon!

@dongjoon-hyun

Copy link
Copy Markdown
Member Author

Thank you, @HyukjinKwon and @uros-b !

@dongjoon-hyun

Copy link
Copy Markdown
Member Author

Merge Summary:

Posted by merge_spark_pr.py

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants