lz4 / lz4-java

LZ4 compression for Java
Apache License 2.0
1.1k stars 253 forks source link

Release-Timeline for next version #150

Closed patrick246 closed 4 years ago

patrick246 commented 4 years ago

The latest released version, 1.6.0 contains a vulnerable LZ4 version (1.9.1, CVE-2019-17543). When will a new version with LZ4 1.9.2 be released? This vulnerability turns up in our dependency security check.

odaira commented 4 years ago

I'm shooting for early November.

ijuma commented 4 years ago

Do we have an updated ETA?

odaira commented 4 years ago

I was fixing issues on macOS and Windows. Will release a new version in a few days unless I hit a new problem.

odaira commented 4 years ago

Released 1.7.0.