Skip to content

🚨 [Conductor] Security update composer/composer to 1.10.27 #26

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

private-packagist[bot]
Copy link

This PR was automatically generated by Conductor.

The PR contains the changes generated by running the following command:

composer update --with-all-dependencies --minimal-changes composer/composer:1.10.27

Changelog

composer/composer (Source: GitHub Releases))

1.10.27

! Reminder: if you are still using Composer 1.x, please upgrade. See https://blog.packagist.com/deprecating-composer-1-support/

Changelog:

  • Security: Fixed possible remote code execution vulnerability if composer.phar is publicly accessible, executable as PHP, and register_argc_argv is enabled in php.ini (GHSA-jm6m-4632-36hf / CVE-2023-43655)

Task options

If you close the PR, the task will be skipped and Conductor will schedule the next task. Clicking the "Skip" button in the UI has the same effect. Conductor won't attempt to update the dependency to this exact version again but it will schedule updates to newer versions.


Powered by Private Packagist

Copy link
Author

composer.lock

Dev Package changes

Package Operation From To About
composer/composer upgrade 1.10.26 ⚠️ 1.10.27 ✅ diff

Important Metadata Changes

Package Version Metadata From To
justinrainbow/json-schema 5.2.12 dist url https://api.github.com/repos/justinrainbow/json-schema/zipball/ad87d5a5ca981228e0e205c2bc7dfb8e24559b60 https://api.github.com/repos/jsonrainbow/json-schema/zipball/ad87d5a5ca981228e0e205c2bc7dfb8e24559b60
justinrainbow/json-schema 5.2.12 source url https://github.com/justinrainbow/json-schema.git https://github.com/jsonrainbow/json-schema.git

Settings · Docs · Powered by Private Packagist

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants