Skip to content

fix(security): upgrade plexus-utils version to 4.0.3 to address CVE-2025-67030#8

Open
ShahimSharafudeen wants to merge 2 commits into
prestodb:masterfrom
ShahimSharafudeen:plexus-utils_cve_fix
Open

fix(security): upgrade plexus-utils version to 4.0.3 to address CVE-2025-67030#8
ShahimSharafudeen wants to merge 2 commits into
prestodb:masterfrom
ShahimSharafudeen:plexus-utils_cve_fix

Conversation

@ShahimSharafudeen
Copy link
Copy Markdown

Description

Upgrade plexus-utils version to 4.0.3 to address CVE-2025-67030.

The upgrade to plexus-utils 4.0.3 introduced a breaking change where XML parsing classes (e.g., XmlPullParserException) were removed from plexus-utils and moved to a separate library, plexus-xml. This caused test failures due to missing runtime dependencies required by Maven's internal components. Therefore, plexus-xml was added as a runtime dependency to resolve this issue.

Test Results :

Mavan Build Screenshot :

Screenshot 2026-04-01 at 1 06 36 PM

Mavan Test Run Screenshots :

Screenshot 2026-04-01 at 1 07 48 PM Screenshot 2026-04-01 at 1 07 56 PM

@linux-foundation-easycla
Copy link
Copy Markdown

linux-foundation-easycla Bot commented Apr 1, 2026

CLA Signed

The committers listed above are authorized under a signed CLA.

  • ✅ login: ShahimSharafudeen / name: Shahim Sharafudeen (293b251, c51ef71)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant