dependabot[bot] opened a new pull request, #27059: URL: https://github.com/apache/camel/pull/27059
Bumps [at.yawk.lz4:lz4-java](https://github.com/yawkat/lz4-java) from 1.11.3 to 1.12.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/yawkat/lz4-java/releases">at.yawk.lz4:lz4-java's releases</a>.</em></p> <blockquote> <h2>lz4-java v1.12.0</h2> <p><strong>Note that lz4-java v1.11.4, also released today, contains security fixes.</strong> This minor release contains some additional tightening of input validation that could in theory be breaking but should be fine for most if not all users. I recommend you upgrade to 1.12.0, but 1.11.4 is an option if that breaks.</p> <h2>What's Changed</h2> <ul> <li>Render README tables on the website by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/150">yawkat/lz4-java#150</a></li> <li>Throw IOException for invalid or unsupported frame descriptors by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/133">yawkat/lz4-java#133</a></li> <li>Replace Codecov with a coverage badge from the documentation site by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/151">yawkat/lz4-java#151</a></li> <li>Reject short output in LZ4DecompressorWithLength safe paths by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/126">yawkat/lz4-java#126</a></li> <li>Make stream failures sticky in LZ4FrameInputStream and LZ4BlockInputStream by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/145">yawkat/lz4-java#145</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/yawkat/lz4-java/compare/v1.11.4...v1.12.0">https://github.com/yawkat/lz4-java/compare/v1.11.4...v1.12.0</a></p> <h2>lz4-java v1.11.4</h2> <p><strong>Security release for <a href="https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv">GHSA-gm45-99xc-r7wv</a>, <a href="https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr">GHSA-343h-94h5-c4wr</a> and <a href="https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g">GHSA-mcr4-qmvw-px4g</a>.</strong> Also includes general fixes for bugs found by AI.</p> <h2>What's Changed</h2> <ul> <li>Update astral-sh/setup-uv action to v10.2.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/yawkat/lz4-java/pull/97">yawkat/lz4-java#97</a></li> <li>Update dependency com.carrotsearch.randomizedtesting:randomizedtesting-runner to v2.9.2 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/yawkat/lz4-java/pull/98">yawkat/lz4-java#98</a></li> <li>Update cloudflare/wrangler-action digest to 953926a by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/yawkat/lz4-java/pull/99">yawkat/lz4-java#99</a></li> <li>Fix NPE in LZ4FrameInputStream on skippable-only streams by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/125">yawkat/lz4-java#125</a></li> <li>Release source critical array before throwing OOM in LZ4JNI by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/124">yawkat/lz4-java#124</a></li> <li>Fix stale OutOfMemoryError reference in XXHashJNI by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/127">yawkat/lz4-java#127</a></li> <li>Reject truncated block header in LZ4BlockInputStream by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/128">yawkat/lz4-java#128</a></li> <li>Don't restore the Maven cache in the release workflow by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/132">yawkat/lz4-java#132</a></li> <li>Read skippable frame size as unsigned in LZ4FrameInputStream by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/131">yawkat/lz4-java#131</a></li> <li>Only run test workflow on push to main by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/136">yawkat/lz4-java#136</a></li> <li>Document CPU cost of high HC compression levels by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/141">yawkat/lz4-java#141</a></li> <li>Fix int overflow in streaming XXHash update buffering check by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/138">yawkat/lz4-java#138</a></li> <li>docs: declare requires-python >= 3.12 in justfile scripts by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/130">yawkat/lz4-java#130</a></li> <li>Make docs manual-dispatch deploy branch explicit by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/137">yawkat/lz4-java#137</a></li> <li>Switch Maven wrapper to script-only and use strict checksums in CI by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/144">yawkat/lz4-java#144</a></li> <li>Verify SHA-256 of lz4 CLI downloaded in Windows release job by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/134">yawkat/lz4-java#134</a></li> <li>docs: validate version input and tag names before interpolating them by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/142">yawkat/lz4-java#142</a></li> <li>Test safe decompressors with destination offsets and buffer kinds by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/146">yawkat/lz4-java#146</a></li> <li>Document that StreamingXXHash32.asChecksum() returns only 28 bits by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/140">yawkat/lz4-java#140</a></li> <li>Declare explicit GITHUB_TOKEN permissions in workflows by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/135">yawkat/lz4-java#135</a></li> <li>Only publish to Central from v* tags by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/139">yawkat/lz4-java#139</a></li> <li>Test the darwin/aarch64 native library before publishing by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/143">yawkat/lz4-java#143</a></li> <li>Fix negative LZ4BlockInputStream.available() after an empty block by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/129">yawkat/lz4-java#129</a></li> <li>Delete .clinerules by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/148">yawkat/lz4-java#148</a></li> <li>Rework README, add contributing guide, Scorecard and coverage by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/147">yawkat/lz4-java#147</a></li> <li>Fix test compilation on main: remove duplicate testAvailableAfterEmptyBlock by <a href="https://github.com/yawkat"><code>@yawkat</code></a> in <a href="https://redirect.github.com/yawkat/lz4-java/pull/149">yawkat/lz4-java#149</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/yawkat/lz4-java/compare/v1.11.3...v1.11.4">https://github.com/yawkat/lz4-java/compare/v1.11.3...v1.11.4</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/yawkat/lz4-java/commit/b98ff902baf30b591d2a62a2cfa7ef25eb6f5b00"><code>b98ff90</code></a> Make stream failures sticky in LZ4FrameInputStream and LZ4BlockInputStream (#...</li> <li><a href="https://github.com/yawkat/lz4-java/commit/681f5036f0312bf499a46a2710c132d45e4601a7"><code>681f503</code></a> Reject short output in LZ4DecompressorWithLength safe paths (<a href="https://redirect.github.com/yawkat/lz4-java/issues/126">#126</a>)</li> <li><a href="https://github.com/yawkat/lz4-java/commit/58805ddf0b3070f8ef40c010efd8c44089951e5e"><code>58805dd</code></a> Replace Codecov with a coverage badge from the documentation site (<a href="https://redirect.github.com/yawkat/lz4-java/issues/151">#151</a>)</li> <li><a href="https://github.com/yawkat/lz4-java/commit/0538ca4fa57ecdc8c9d7e47ad426ec31996c09dd"><code>0538ca4</code></a> Throw IOException for invalid or unsupported frame descriptors (<a href="https://redirect.github.com/yawkat/lz4-java/issues/133">#133</a>)</li> <li><a href="https://github.com/yawkat/lz4-java/commit/f6e33045c7f3c462a59327358183d620636368bf"><code>f6e3304</code></a> Render README tables on the website (<a href="https://redirect.github.com/yawkat/lz4-java/issues/150">#150</a>)</li> <li><a href="https://github.com/yawkat/lz4-java/commit/4af910bc99c2f021f0cd56f6ca7f7600f4dda4a0"><code>4af910b</code></a> Remove duplicate testAvailableAfterEmptyBlock (<a href="https://redirect.github.com/yawkat/lz4-java/issues/149">#149</a>)</li> <li><a href="https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3"><code>7a48b7f</code></a> Merge commit from fork</li> <li><a href="https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8"><code>c8ebf97</code></a> Merge commit from fork</li> <li><a href="https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283"><code>2acc0ec</code></a> Merge commit from fork</li> <li><a href="https://github.com/yawkat/lz4-java/commit/e0178d2337105543715146431151244d2b436da7"><code>e0178d2</code></a> Rework README, add contributing guide, Scorecard and coverage (<a href="https://redirect.github.com/yawkat/lz4-java/issues/147">#147</a>)</li> <li>Additional commits viewable in <a href="https://github.com/yawkat/lz4-java/compare/v1.11.3...v1.12.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
