Bump bundeled plexus-utils version to 3.6.1 to fix CVE-2025-67030
envgap__DependencyTrack__dependency-track-6025
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
d6e87bddd138afe1edd5cbe3a35ac6ffffa1e197- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
DependencyTrack/dependency-track #6025 · read the original issue
### Current Behavior Scanning DependencyTrack containers for version 4.14.1 shows it has plexus-utils which is affected by CVE-2025-67030 or GHSA-6fmv-xxpf-w3cw . File is plexus-utils-3.6.0.jar part of the dependency-track-apiserver.jar ### Steps to Reproduce ```grype dependencytrack/apiserver:4.14.1``` ### Expected Behavior No critical or high on the dependency track files on SCA scans. ### Dependency-Track Version 4.14.1 ### Dependency-Track Distribution Container Image, Executable WAR ### Database Server N/A ### Database Server Version _No response_ ### Browser Google Chrome ### Checklist - [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues) - [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]