From d66ce00fc3431b46e4245dcd01f4366f4e8e3942 Mon Sep 17 00:00:00 2001 From: Shahim Sharafudeen Date: Wed, 1 Apr 2026 13:13:50 +0530 Subject: [PATCH] fix(security): upgrade plexus-utils version to 4.0.3 to address CVE-2025-67030 Co-authored-by: Sayari Mukherjee --- pom.xml | 2 +- resolver/pom.xml | 13 +++++++++++++ 2 files changed, 14 insertions(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 893f9f5..b44c7ca 100644 --- a/pom.xml +++ b/pom.xml @@ -126,7 +126,7 @@ org.codehaus.plexus plexus-utils - 3.5.1 + 4.0.3 diff --git a/resolver/pom.xml b/resolver/pom.xml index a81416d..d3edb8e 100644 --- a/resolver/pom.xml +++ b/resolver/pom.xml @@ -80,6 +80,19 @@ maven-compat + + org.codehaus.plexus + plexus-utils + runtime + + + + org.codehaus.plexus + plexus-xml + 4.0.4 + runtime + + org.codehaus.plexus plexus-classworlds