[GitHub] [solr] janhoy commented on pull request #1806: Update dependency org.xerial.snappy:snappy-java to v1.1.10.3

2023-09-27 Thread via GitHub
janhoy commented on PR #1806: URL: https://github.com/apache/solr/pull/1806#issuecomment-1737755069 I created a blocker JIRA for it in https://issues.apache.org/jira/browse/SOLR-17002 that will hold the 9.4 release until this is merged. -- This is an automated message from the Apache Git

[GitHub] [solr] janhoy commented on pull request #1806: Update dependency org.xerial.snappy:snappy-java to v1.1.10.3

2023-09-26 Thread via GitHub
janhoy commented on PR #1806: URL: https://github.com/apache/solr/pull/1806#issuecomment-1735298638 See here https://github.com/apache/solr/blob/main/.github/renovate.json#L56 To avoid too quick upgrade to new versions, we have set stability-days to 5. Meaning, if a critical bug is discov

[GitHub] [solr] janhoy commented on pull request #1806: Update dependency org.xerial.snappy:snappy-java to v1.1.10.3

2023-09-26 Thread via GitHub
janhoy commented on PR #1806: URL: https://github.com/apache/solr/pull/1806#issuecomment-1735277795 > Hi, shouldn't it updated to 1.1.10.4 due to [CVE-2023-43642](https://github.com/advisories/GHSA-55g7-9cwv-5qfv)? We have a 3 day guard for adopting new versions. But you see v1.1.10.4