Uploaded image for project: 'Quarkus'
  1. Quarkus
  2. QUARKUS-1768

Downstream io.quarkus:quarkus-bom manages org.lz4:lz4-java while upstream does not


      Recent downstream versions of io.quarkus:quarkus-bom manage org.lz4:lz4-java at version 1.7.1.redhat-00003:

      org.lz4:lz4-java is not managed in the underlying upstream versions

      So the change must have happened in the product branch or perhaps during productization.

      I wonder whether an equivalent change should not have been ported to upstream main and 2.7 branches at least to ensure forward compatibility for the end users?
      Not porting to main actually violates the "Upstream first" sustaining engineering rule.

      The bottom line is that by not getting lz4-java managed via Quarkus BOM, we get an older version 1.6.0 via kafka-clients in the upstream.

            olubyans@redhat.com Alexey Loubyansky
            ppalaga Peter Palaga
            Michal Vavrik Michal Vavrik
            0 Vote for this issue
            7 Start watching this issue
