zendesk / maxwell

Maxwell's daemon, a mysql-to-json kafka producer
https://maxwells-daemon.io/
Other
3.95k stars 996 forks source link

Fix lz4 security vuln #2073

Closed lukestephenson-zendesk closed 5 months ago

lukestephenson-zendesk commented 5 months ago

net.jpountz.lz4 is not a registered domain and is a theoritical security issue

https://blog.oversecured.com/Introducing-MavenGate-a-supply-chain-attack-method-for-Java-and-Android-applications