Skip to content

Commit 9aab536

Browse files
authored
GH-5052: use more recent version of snappy to fix CVEs (#5065)
GH-5052: upgrade snappy dependency to fix CVE
1 parent 3413423 commit 9aab536

1 file changed

Lines changed: 8 additions & 1 deletion

File tree

core/sail/solr/pom.xml

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,8 @@
1414
<enforce-javaee-provided.fail>false</enforce-javaee-provided.fail>
1515
<!-- use at least 3.7 to fix CVE -->
1616
<zookeeper.version>3.7.2</zookeeper.version>
17+
<!-- use ay least 1.1.10.4 to fix CVEs -->
18+
<snappy.version>1.1.10.5</snappy.version>
1719
</properties>
1820
<dependencies>
1921
<!-- use at least zookeeper 3.7.2 to fix CVE, can be removed if solr provides a newer version -->
@@ -27,7 +29,12 @@
2729
<artifactId>zookeeper-jute</artifactId>
2830
<version>${zookeeper.version}</version>
2931
</dependency>
30-
<!-- -->
32+
<!-- use at least snappy 1.1.10.4 to fix CVEs, can be removed if solr provides a newer version -->
33+
<dependency>
34+
<groupId>org.xerial.snappy</groupId>
35+
<artifactId>snappy-java</artifactId>
36+
<version>${snappy.version}</version>
37+
</dependency>
3138
<dependency>
3239
<groupId>${project.groupId}</groupId>
3340
<artifactId>rdf4j-sail-lucene-api</artifactId>

0 commit comments

Comments
 (0)