dependabot[bot] opened a new pull request, #3208:
URL: https://github.com/apache/jackrabbit-oak/pull/3208

   Bumps [at.yawk.lz4:lz4-java](https://github.com/yawkat/lz4-java) from 1.11.2 
to 1.11.4.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/yawkat/lz4-java/releases";>at.yawk.lz4:lz4-java's 
releases</a>.</em></p>
   <blockquote>
   <h2>lz4-java v1.11.4</h2>
   <p><strong>Security release for <a 
href="https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv";>CVE-2026-106450</a>,
 <a 
href="https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr";>CVE-2026-106449</a>
 and <a 
href="https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g";>CVE-2026-106451</a>.</strong>
 Also includes general fixes for bugs found by AI.</p>
   <h2>What's Changed</h2>
   <ul>
   <li>Update astral-sh/setup-uv action to v10.2.0 by <a 
href="https://github.com/renovate";><code>@​renovate</code></a>[bot] in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/97";>yawkat/lz4-java#97</a></li>
   <li>Update dependency 
com.carrotsearch.randomizedtesting:randomizedtesting-runner to v2.9.2 by <a 
href="https://github.com/renovate";><code>@​renovate</code></a>[bot] in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/98";>yawkat/lz4-java#98</a></li>
   <li>Update cloudflare/wrangler-action digest to 953926a by <a 
href="https://github.com/renovate";><code>@​renovate</code></a>[bot] in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/99";>yawkat/lz4-java#99</a></li>
   <li>Fix NPE in LZ4FrameInputStream on skippable-only streams by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/125";>yawkat/lz4-java#125</a></li>
   <li>Release source critical array before throwing OOM in LZ4JNI by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/124";>yawkat/lz4-java#124</a></li>
   <li>Fix stale OutOfMemoryError reference in XXHashJNI by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/127";>yawkat/lz4-java#127</a></li>
   <li>Reject truncated block header in LZ4BlockInputStream by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/128";>yawkat/lz4-java#128</a></li>
   <li>Don't restore the Maven cache in the release workflow by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/132";>yawkat/lz4-java#132</a></li>
   <li>Read skippable frame size as unsigned in LZ4FrameInputStream by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/131";>yawkat/lz4-java#131</a></li>
   <li>Only run test workflow on push to main by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/136";>yawkat/lz4-java#136</a></li>
   <li>Document CPU cost of high HC compression levels by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/141";>yawkat/lz4-java#141</a></li>
   <li>Fix int overflow in streaming XXHash update buffering check by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/138";>yawkat/lz4-java#138</a></li>
   <li>docs: declare requires-python &gt;= 3.12 in justfile scripts by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/130";>yawkat/lz4-java#130</a></li>
   <li>Make docs manual-dispatch deploy branch explicit by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/137";>yawkat/lz4-java#137</a></li>
   <li>Switch Maven wrapper to script-only and use strict checksums in CI by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/144";>yawkat/lz4-java#144</a></li>
   <li>Verify SHA-256 of lz4 CLI downloaded in Windows release job by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/134";>yawkat/lz4-java#134</a></li>
   <li>docs: validate version input and tag names before interpolating them by 
<a href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/142";>yawkat/lz4-java#142</a></li>
   <li>Test safe decompressors with destination offsets and buffer kinds by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/146";>yawkat/lz4-java#146</a></li>
   <li>Document that StreamingXXHash32.asChecksum() returns only 28 bits by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/140";>yawkat/lz4-java#140</a></li>
   <li>Declare explicit GITHUB_TOKEN permissions in workflows by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/135";>yawkat/lz4-java#135</a></li>
   <li>Only publish to Central from v* tags by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/139";>yawkat/lz4-java#139</a></li>
   <li>Test the darwin/aarch64 native library before publishing by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/143";>yawkat/lz4-java#143</a></li>
   <li>Fix negative LZ4BlockInputStream.available() after an empty block by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/129";>yawkat/lz4-java#129</a></li>
   <li>Delete .clinerules by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/148";>yawkat/lz4-java#148</a></li>
   <li>Rework README, add contributing guide, Scorecard and coverage by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/147";>yawkat/lz4-java#147</a></li>
   <li>Fix test compilation on main: remove duplicate 
testAvailableAfterEmptyBlock by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/149";>yawkat/lz4-java#149</a></li>
   </ul>
   <p><strong>Full Changelog</strong>: <a 
href="https://github.com/yawkat/lz4-java/compare/v1.11.3...v1.11.4";>https://github.com/yawkat/lz4-java/compare/v1.11.3...v1.11.4</a></p>
   <h2>lz4-java v1.11.3</h2>
   <p>Not a security release. This is the second attempt at this release due to 
a javadoc issue.</p>
   <h2>What's Changed</h2>
   <ul>
   <li>Update junit-framework monorepo to v6.1.3 by <a 
href="https://github.com/renovate";><code>@​renovate</code></a>[bot] in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/80";>yawkat/lz4-java#80</a></li>
   <li>Update workflows to Java 25 by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/82";>yawkat/lz4-java#82</a></li>
   <li>Update dependency org.apache.maven.plugins:maven-javadoc-plugin to 
v3.12.0 by <a 
href="https://github.com/renovate";><code>@​renovate</code></a>[bot] in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/68";>yawkat/lz4-java#68</a></li>
   <li>Update astral-sh/setup-uv action to v10 by <a 
href="https://github.com/renovate";><code>@​renovate</code></a>[bot] in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/84";>yawkat/lz4-java#84</a></li>
   <li>Update dependency org.apache.maven.plugins:maven-compiler-plugin to 
v3.16.0 by <a 
href="https://github.com/renovate";><code>@​renovate</code></a>[bot] in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/89";>yawkat/lz4-java#89</a></li>
   <li>Update dependency org.mvel:mvel2 to v2.5.4.Final by <a 
href="https://github.com/renovate";><code>@​renovate</code></a>[bot] in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/88";>yawkat/lz4-java#88</a></li>
   <li>Update astral-sh/setup-uv action to v10.1.0 by <a 
href="https://github.com/renovate";><code>@​renovate</code></a>[bot] in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/85";>yawkat/lz4-java#85</a></li>
   <li>Update bnd.maven.plugin.version to v7.4.0 by <a 
href="https://github.com/renovate";><code>@​renovate</code></a>[bot] in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/86";>yawkat/lz4-java#86</a></li>
   <li>Update dependency org.codehaus.mojo:build-helper-maven-plugin to v3.6.2 
by <a href="https://github.com/renovate";><code>@​renovate</code></a>[bot] in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/92";>yawkat/lz4-java#92</a></li>
   <li>Make default decompression limit configurable by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/93";>yawkat/lz4-java#93</a></li>
   <li>Restore Javadoc output directory by <a 
href="https://github.com/yawkat";><code>@​yawkat</code></a> in <a 
href="https://redirect.github.com/yawkat/lz4-java/pull/95";>yawkat/lz4-java#95</a></li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/yawkat/lz4-java/commit/4af910bc99c2f021f0cd56f6ca7f7600f4dda4a0";><code>4af910b</code></a>
 Remove duplicate testAvailableAfterEmptyBlock (<a 
href="https://redirect.github.com/yawkat/lz4-java/issues/149";>#149</a>)</li>
   <li><a 
href="https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3";><code>7a48b7f</code></a>
 Merge commit from fork</li>
   <li><a 
href="https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8";><code>c8ebf97</code></a>
 Merge commit from fork</li>
   <li><a 
href="https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283";><code>2acc0ec</code></a>
 Merge commit from fork</li>
   <li><a 
href="https://github.com/yawkat/lz4-java/commit/e0178d2337105543715146431151244d2b436da7";><code>e0178d2</code></a>
 Rework README, add contributing guide, Scorecard and coverage (<a 
href="https://redirect.github.com/yawkat/lz4-java/issues/147";>#147</a>)</li>
   <li><a 
href="https://github.com/yawkat/lz4-java/commit/37ee3cc6d93ba4a767c78becdc8398f4e4f07126";><code>37ee3cc</code></a>
 Delete .clinerules (<a 
href="https://redirect.github.com/yawkat/lz4-java/issues/148";>#148</a>)</li>
   <li><a 
href="https://github.com/yawkat/lz4-java/commit/788980d4c16ca0a769c33c93619e01147ad3905c";><code>788980d</code></a>
 Fix negative LZ4BlockInputStream.available() after an empty block (<a 
href="https://redirect.github.com/yawkat/lz4-java/issues/129";>#129</a>)</li>
   <li><a 
href="https://github.com/yawkat/lz4-java/commit/5442f0ee3aa2db9627ca6e076b38cc6c827aa934";><code>5442f0e</code></a>
 Test the darwin/aarch64 native library before publishing (<a 
href="https://redirect.github.com/yawkat/lz4-java/issues/143";>#143</a>)</li>
   <li><a 
href="https://github.com/yawkat/lz4-java/commit/68d4bfc66c559f77e694caed5d340166e4de4d2f";><code>68d4bfc</code></a>
 Only publish to Central from v* tags (<a 
href="https://redirect.github.com/yawkat/lz4-java/issues/139";>#139</a>)</li>
   <li><a 
href="https://github.com/yawkat/lz4-java/commit/4c685a99c741dba697c069664befd0af0db5c732";><code>4c685a9</code></a>
 Declare explicit GITHUB_TOKEN permissions in workflows (<a 
href="https://redirect.github.com/yawkat/lz4-java/issues/135";>#135</a>)</li>
   <li>Additional commits viewable in <a 
href="https://github.com/yawkat/lz4-java/compare/v1.11.2...v1.11.4";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=at.yawk.lz4:lz4-java&package-manager=maven&previous-version=1.11.2&new-version=1.11.4)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   You can disable automated security fix PRs for this repo from the [Security 
Alerts page](https://github.com/apache/jackrabbit-oak/network/alerts).
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to