Skip to content

KAFKA-20373: exclude plexus-utils-* from runtime jar's to fix CVE-2025-67030#21911

Open
averemee-si wants to merge 1 commit intoapache:trunkfrom
averemee-si:KAFKA-20373
Open

KAFKA-20373: exclude plexus-utils-* from runtime jar's to fix CVE-2025-67030#21911
averemee-si wants to merge 1 commit intoapache:trunkfrom
averemee-si:KAFKA-20373

Conversation

@averemee-si
Copy link
Copy Markdown
Contributor

exclude plexus-utils-* from runtime jar's to fix CVE-2025-67030.
Ref.: KAFKA-20373

@github-actions github-actions bot added triage PRs from the community dependencies Pull requests that update a dependency file build Gradle build or GitHub Actions small Small PRs labels Mar 31, 2026
@chia7712
Copy link
Copy Markdown
Member

chia7712 commented Apr 2, 2026

please fix the title ...

@averemee-si averemee-si changed the title KAFKA-20373 KAFKA-20373: exclude plexus-utils-* from runtime jar's to fix CVE-2025-67030 Apr 2, 2026
@github-actions
Copy link
Copy Markdown

github-actions bot commented Apr 8, 2026

A label of 'needs-attention' was automatically added to this PR in order to raise the
attention of the committers. Once this issue has been triaged, the triage label
should be removed to prevent this automation from happening again.

@FrankYang0529
Copy link
Copy Markdown
Member

@averemee-si
Copy link
Copy Markdown
Contributor Author

Hi @FrankYang0529

I added an exclude statement to all "copyDependantLibs" tasks for plexus-utils*.jar but "Verify license file" failed with

The following libs (from ./libs) are missing in the LICENSE file. These should be added to the LICENSE-binary file:
 - plexus-utils-3.6.0

Looking into it

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

build Gradle build or GitHub Actions ci-approved dependencies Pull requests that update a dependency file needs-attention small Small PRs triage PRs from the community

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants