Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SECURITY] Update composer and psr7 to unaffected versions #129

Closed
wants to merge 2 commits into from

Conversation

mteu
Copy link
Collaborator

@mteu mteu commented Apr 30, 2024

This PR narrows the range of composer/composer to fix two vulnerabilities:

  1. CVE-2024-24821 (high)
  2. CVE-2023-43655 (high)

It also bumps nyholm/psr to an unaffected version starting from^1.5.1:

  1. CVE-2023-29197 (high)

@mteu mteu added the security Contains security fixes label Apr 30, 2024
@mteu mteu closed this Sep 10, 2024
@mteu mteu deleted the security/update-nyholm-psr7 branch September 10, 2024 06:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Contains security fixes
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant