Skip to content

Conversation

@Meenu-Mariya
Copy link
Contributor

@Meenu-Mariya Meenu-Mariya commented Dec 30, 2025

This pull request upgrades lz4-java dependency from 1.8.0 to 1.8.1 to fix security vulnerability.

Resolves: CVE-2025-12183 and CVE-2025-66566

Contributes to: EVI-32161

Signed-off-by: Meenu Mariya I [email protected]

@Meenu-Mariya Meenu-Mariya changed the title fix: upgrade lz4-java to 1.8.1 to address CVE-2025-12183 fix: upgrade lz4-java to 1.10.1 to address CVE-2025-12183 and CVE-2025-66566 Dec 30, 2025
Copy link
Contributor

@Joel-hanson Joel-hanson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Meenu-Mariya Meenu-Mariya force-pushed the EVI-32161 branch 2 times, most recently from d849b55 to 0fe5f16 Compare December 30, 2025 10:56
Upgraded lz4-java from 1.8.0 to 1.10.1 to address security
vulnerabilities CVE-2025-12183 and CVE-2025-66566.

Resolves: ibm-messaging#379

Signed-off-by: Meenu Mariya <[email protected]>
@Joel-hanson Joel-hanson merged commit 0bb01f6 into ibm-messaging:master Jan 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants