<!---
# Licensed to the Apache Software Foundation (ASF) under one
# or more contributor license agreements.  See the NOTICE file
# distributed with this work for additional information
# regarding copyright ownership.  The ASF licenses this file
# to you under the Apache License, Version 2.0 (the
# "License"); you may not use this file except in compliance
# with the License.  You may obtain a copy of the License at
#
#     http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
-->
# Apache Hadoop Third-party Libs Changelog

## Release thirdparty-1.4.0 - 2025-03-21



### BUG FIXES:

| JIRA | Summary | Priority | Component | Reporter | Contributor |
|:---- |:---- | :--- |:---- |:---- |:---- |
| [HADOOP-19360](https://issues.apache.org/jira/browse/HADOOP-19360) | Disable releases for apache.snapshots repo |  Major | build | Attila Doroszlai | Attila Doroszlai |
| [HADOOP-19510](https://issues.apache.org/jira/browse/HADOOP-19510) | Correct hadoop-thirdparty license and site for protobuf 3.25.5 |  Major | documentation | Chris Nauroth | Chris Nauroth |


### OTHER:

| JIRA | Summary | Priority | Component | Reporter | Contributor |
|:---- |:---- | :--- |:---- |:---- |:---- |
| [HADOOP-19289](https://issues.apache.org/jira/browse/HADOOP-19289) | upgrade to protobuf-java 3.25.5 due to CVE-2024-7254 |  Major | common | PJ Fanning | PJ Fanning |
| [HADOOP-19300](https://issues.apache.org/jira/browse/HADOOP-19300) | upgrade hadoop thirdparty avro to 1.11.4 |  Major | build | PJ Fanning | Steve Loughran |