1.4.3 - Security: bump httpcore5/httpcore5-h2 to 5.4.3 (CVE-2026-54399, CVE-2026-54428), httpclient5 to 5.6.4 (CVE-2026-64607), and log4j2 to 2.25.5 (CVE-2026-49844); all four were transitive DoS/format issues, no API change
1.4.3 - Security: bump httpcore5/httpcore5-h2 to 5.4.3 (CVE-2026-54399, CVE-2026-54428), httpclient5 to 5.6.4 (CVE-2026-64607), and log4j2 to 2.25.5 (CVE-2026-49844); all four were transitive DoS/format issues, no API change