Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

{composer1, composer2}: bumps #299

Merged
merged 2 commits into from
Oct 17, 2023
Merged

{composer1, composer2}: bumps #299

merged 2 commits into from
Oct 17, 2023

Conversation

drupol
Copy link
Collaborator

@drupol drupol commented Sep 29, 2023

Security releases!

Changelogs in commit log messages.

Security release: Fixed possible remote code execution vulnerability if composer.phar is publicly accessible, executable as PHP, and register_argc_argv is enabled in php.ini (GHSA-jm6m-4632-36hf / CVE-2023-43655)

Changelog: https://github.com/composer/composer/releases/tag/1.10.27
Security release: Fixed possible remote code execution vulnerability if composer.phar is publicly accessible, executable as PHP, and register_argc_argv is enabled in php.ini (GHSA-jm6m-4632-36hf / CVE-2023-43655)

Changelog: https://github.com/composer/composer/releases/tag/2.2.22
@drupol
Copy link
Collaborator Author

drupol commented Oct 17, 2023

@jtojnar ?

@jtojnar
Copy link
Member

jtojnar commented Oct 17, 2023

Actually, looks like the second commit message is off.

@drupol drupol merged commit 9a596be into master Oct 17, 2023
21 checks passed
@drupol drupol deleted the php/composer/bumps branch October 17, 2023 19:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants