-
Notifications
You must be signed in to change notification settings - Fork 29k
[SPARK-54597][BUILD] Upgrade lz4-java to 1.10.0
#53327
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
This is a dependency-only PR, cc @dbtsai , @HyukjinKwon , @LuciferYang , @yawkat , @SteNicholas . To be clear, the security issue is not a scope of this PR. |
|
Thank you, @HyukjinKwon . I'm going to add one more commit to ban this library explicitly. |
HyukjinKwon
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
|
@dongjoon-hyun, does it still need to switch fastDecompressor to safeDecompressor after upgrade? |
Exactly, that's @dbtsai 's contribution, @SteNicholas . This PR doesn't aim to do that. He will rebase his PR after merging this independently. |
|
Thank you, @LuciferYang ! I'll update it. |
|
@dongjoon-hyun, I just confirm whether to switch fastDecompressor to safeDecompressor after upgrade to 1.10.0. |
@SteNicholas What I can say here is that it's beyond of this PR. Technically, we don't know what decision we are going to make eventually on the following yet because it's still |
|
Please don't get me wrong. I'm trying to help that PR move forward by reducing the gap. |
|
LGTM ~ |
|
Thank you all! Merged to master for Apache Spark 4.2.0 (for now) |

What changes were proposed in this pull request?
This PR aims to upgrade
lz4-javato 1.10.0 and exclude the legacy groupID version.Why are the changes needed?
Since
lz4-javachanged its repository, we had better depend on the live repository for future maintenance.Does this PR introduce any user-facing change?
No Spark behavior change.
How was this patch tested?
Pass the CIs.
Was this patch authored or co-authored using generative AI tooling?
No.