Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Request for Update to Latest lz4 Version in lz4-java #229

Open
vipi-n opened this issue Feb 13, 2025 · 1 comment
Open

Request for Update to Latest lz4 Version in lz4-java #229

vipi-n opened this issue Feb 13, 2025 · 1 comment

Comments

@vipi-n
Copy link

vipi-n commented Feb 13, 2025

I wanted to inquire if there are any plans to update the lz4 version in the lz4-java project. Currently, version 1.8.0 of lz4-java uses lz4 version 1.9.2, which has known vulnerability:
https://nvd.nist.gov/vuln/detail/cve-2021-3520

Would it be possible to update the project to use lz4 version 1.9.4 or above to address this concern.

@HTHou
Copy link

HTHou commented Feb 20, 2025

Well, it seems that the maintainers of this repo are not active anymore. A new release from a fork repo may be the best solution for now.

See discussions in #217 lz4/lz4#1346

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants