1
0
Fork 0

Toggle abandoned composer libs #1

Offen
2026-09-07 07:27:45 +00:00 von Oldperl geöffnet · 0 Kommentare
Besitzer

Some libs used with composer are abandoned. We have to switch to newer libs.

composer audit
Found 2 security vulnerability advisories affecting 1 package:
+-------------------+----------------------------------------------------------------------------------+
| Package           | symfony/process                                                                  |
| Severity          | medium                                                                           |
| Advisory ID       | PKSA-rkkf-636k-qjb3                                                              |
| CVE               | CVE-2026-24739                                                                   |
| Title             | Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to           |
|                   | destructive file operations on Windows                                           |
| URL               | https://github.com/advisories/GHSA-r39x-jcww-82v6                                |
| Affected versions | >=8.0,<8.0.5|>=7.4,<7.4.5|>=7.3,<7.3.11|>=6.4,<6.4.33|<5.4.51                    |
| Reported at       | 2026-01-28T21:28:10+00:00                                                        |
+-------------------+----------------------------------------------------------------------------------+
+-------------------+----------------------------------------------------------------------------------+
| Package           | symfony/process                                                                  |
| Severity          | high                                                                             |
| Advisory ID       | PKSA-wws7-mr54-jsny                                                              |
| CVE               | CVE-2024-51736                                                                   |
| Title             | CVE-2024-51736: Command execution hijack on Windows with Process class           |
| URL               | https://symfony.com/cve-2024-51736                                               |
| Affected versions | >=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2 |
|                   | .0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.46|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,< |
|                   | 6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.14|>=7.0.0,<7.1.0|>=7.1.0,<7.1.7               |
| Reported at       | 2024-11-05T08:00:00+00:00                                                        |
+-------------------+----------------------------------------------------------------------------------+
Found 5 abandoned packages:
+-------------------+----------------------------------------------------------------------------------+
| Abandoned Package | Suggested Replacement                                                            |
+-------------------+----------------------------------------------------------------------------------+
| doctrine/cache    | none                                                                             |
| hoa/consistency   | none                                                                             |
| hoa/event         | none                                                                             |
| hoa/exception     | none                                                                             |
| openid/php-openid | none                                                                             |
+-------------------+----------------------------------------------------------------------------------+
Some libs used with composer are abandoned. We have to switch to newer libs. ``` composer audit Found 2 security vulnerability advisories affecting 1 package: +-------------------+----------------------------------------------------------------------------------+ | Package | symfony/process | | Severity | medium | | Advisory ID | PKSA-rkkf-636k-qjb3 | | CVE | CVE-2026-24739 | | Title | Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to | | | destructive file operations on Windows | | URL | https://github.com/advisories/GHSA-r39x-jcww-82v6 | | Affected versions | >=8.0,<8.0.5|>=7.4,<7.4.5|>=7.3,<7.3.11|>=6.4,<6.4.33|<5.4.51 | | Reported at | 2026-01-28T21:28:10+00:00 | +-------------------+----------------------------------------------------------------------------------+ +-------------------+----------------------------------------------------------------------------------+ | Package | symfony/process | | Severity | high | | Advisory ID | PKSA-wws7-mr54-jsny | | CVE | CVE-2024-51736 | | Title | CVE-2024-51736: Command execution hijack on Windows with Process class | | URL | https://symfony.com/cve-2024-51736 | | Affected versions | >=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2 | | | .0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.46|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,< | | | 6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.14|>=7.0.0,<7.1.0|>=7.1.0,<7.1.7 | | Reported at | 2024-11-05T08:00:00+00:00 | +-------------------+----------------------------------------------------------------------------------+ Found 5 abandoned packages: +-------------------+----------------------------------------------------------------------------------+ | Abandoned Package | Suggested Replacement | +-------------------+----------------------------------------------------------------------------------+ | doctrine/cache | none | | hoa/consistency | none | | hoa/event | none | | hoa/exception | none | | openid/php-openid | none | +-------------------+----------------------------------------------------------------------------------+ ```
Oldperl hat dieses Issue 2026-09-07 07:31:31 +00:00 zum Meilenstein v2.2.0 hinzugefügt
Anmelden, um an der Diskussion teilzunehmen.
Kein Meilenstein
Kein Projekt
Niemand zuständig
1 Beteiligter
Benachrichtigungen
Fällig am
Das Fälligkeitsdatum ist ungültig oder außerhalb des zulässigen Bereichs. Bitte verwende das Format „JJJJ-MM-TT“.

Kein Fälligkeitsdatum gesetzt.

Abhängigkeiten

Keine Abhängigkeiten gesetzt.

Referenz
Oldperl/gnu-social#1
Keine Beschreibung angegeben.