Skip to content

Conversation

@labkey-adam
Copy link

Rationale

In with the latest

@labkey-adam labkey-adam self-assigned this Dec 4, 2025
@labkey-adam
Copy link
Author

resolutionStrategy {
// Related to: https://nvd.nist.gov/vuln/detail/CVE-2025-12183
dependencySubstitution {
substitute module('org.lz4:lz4-java') using module("at.yawk.lz4:lz4-java:${lz4Version}")

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Usually versions are specified on both sides of the substitution, but this makes sense to me here since we won't be going backwards in versions (to before the library moved to its new coordinates).

@labkey-adam labkey-adam merged commit 777b32b into release25.7-SNAPSHOT Dec 4, 2025
9 of 10 checks passed
@labkey-adam labkey-adam deleted the 25.7_fb_lz4_cve branch December 4, 2025 15:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants