Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[NEUTRAL] Update dependency composer/composer to v1.10.27 #985

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

mend-for-github-com[bot]
Copy link

@mend-for-github-com mend-for-github-com bot commented Oct 3, 2023

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
composer/composer (source) 1.10.22 -> 1.10.27 age adoption passing confidence

By merging this PR, the issue #984 will be automatically resolved and closed:

Severity CVSS Score CVE
Critical Critical 9.8 CVE-2021-41116
High High 8.8 CVE-2022-24828
High High 8.8 CVE-2023-43655

Release Notes

composer/composer (composer/composer)

v1.10.27

Compare Source

! Reminder: if you are still using Composer 1.x, please upgrade. See https://blog.packagist.com/deprecating-composer-1-support/

Changelog:

  • Security: Fixed possible remote code execution vulnerability if composer.phar is publicly accessible, executable as PHP, and register_argc_argv is enabled in php.ini (GHSA-jm6m-4632-36hf / CVE-2023-43655)

v1.10.26

Compare Source

v1.10.25

Compare Source

  • Fixed selfupdate on Windows + PHP 8.1 regression (#​10446)

v1.10.24

Compare Source

v1.10.23

Compare Source


  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by WhiteSource label Oct 3, 2023
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/composer-composer-1.x-lockfile branch from be0ceff to da7f201 Compare October 4, 2023 18:19
@mend-for-github-com mend-for-github-com bot changed the title chore(deps): update dependency composer/composer to v1.10.27 [NEUTRAL] Update dependency composer/composer to v1.10.27 Mar 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security fix Security fix generated by WhiteSource
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants