Skip to content

Require a patched composer/composer - #690

Draft
samuelpatro wants to merge 1 commit into
octobercms:developfrom
samuelpatro:chore/composer-advisory
Draft

samuelpatro wants to merge 1 commit into
octobercms:developfrom
samuelpatro:chore/composer-advisory

Conversation

@samuelpatro

Copy link
Copy Markdown
Member

Raises the composer/composer minimum to 2.10.3, which fixes CVE-2026-84361 (GHSA-rvx4-ffvw-m9q3, command execution through a package's Perforce source URL). October runs Composer in-process for plugin installs and updates, and ^2.0.0 still allows every affected release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant