Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade composer DEV dependencies #894

Merged
merged 1 commit into from
Apr 30, 2021
Merged

Conversation

veewee
Copy link
Contributor

@veewee veewee commented Apr 30, 2021

Q A
Branch master
Bug fix? no
New feature? no
BC breaks? no
Deprecations? no
Documented? no
Fixed tickets

This upgrades composer dev dependencies to latest versions that don't include the CVE.
https://blog.packagist.com/composer-command-injection-vulnerability/

Since this is a dev dependency, GrumPHP is not impacted by this.

@veewee veewee added this to the 1.3.2 milestone Apr 30, 2021
@veewee veewee merged commit 244c871 into phpro:master Apr 30, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant