Skip to content

Conversation

@labkey-martyp
Copy link
Contributor

Rationale

CVE-2025-54988

Changes

  • Bump to recommended version

@labkey-adam
Copy link
Contributor

Test failures indicate we need to update commons-compress as well: https://issues.apache.org/jira/browse/TIKA-4469. I'll address.

@labkey-adam
Copy link
Contributor

Test failures indicate we need to update commons-compress as well: https://issues.apache.org/jira/browse/TIKA-4469. I'll address.

We've already got the latest commons-compress on develop. In 25.7, there are a few other dependencies with lower versions than what Tika 3.2.2 lists (https://github.com/apache/tika/blob/3.2.2/tika-parent/pom.xml), but I think we can be judicious and update only if we see problems. We may need bump more than compress on 25.3, since that's on a much earlier version of Tika.

@labkey-adam
Copy link
Contributor

@labkey-jeckels labkey-jeckels merged commit dfbef52 into release25.7-SNAPSHOT Aug 31, 2025
9 checks passed
@labkey-jeckels labkey-jeckels deleted the 25.7_fb_tika_pdf_parser branch August 31, 2025 00:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants