UnicornGlobal / vault

Secure Document Storage
MIT License
2 stars 2 forks source link

[Security] Bump symfony/http-kernel from 4.3.8 to 4.4.25 #28

Closed dependabot-preview[bot] closed 3 years ago

dependabot-preview[bot] commented 3 years ago

Bumps symfony/http-kernel from 4.3.8 to 4.4.25. This update includes a security fix.

Vulnerabilities fixed

Sourced from The PHP Security Advisories Database.

CVE-2020-15094: Prevent RCE when calling untrusted remote with CachingHttpClient

Affected versions: >=4.3.0, =5.1.0, <5.1.5

Release notes

Sourced from symfony/http-kernel's releases.

v4.4.25

Changelog (https://github.com/symfony/http-kernel/compare/v4.4.24...v4.4.25)

  • no significant changes

v4.4.24

Changelog (https://github.com/symfony/http-kernel/compare/v4.4.23...v4.4.24)

  • bug #41240 Fixed deprecation warnings about passing null as parameter (derrabus)

v4.4.23

Changelog (https://github.com/symfony/http-kernel/compare/v4.4.22...v4.4.23)

  • no significant changes

v4.4.22

Changelog (https://github.com/symfony/http-kernel/compare/v4.4.21...v4.4.22)

  • no significant changes

v4.4.21

Changelog (https://github.com/symfony/http-kernel/compare/v4.4.20...v4.4.21)

  • bug #40535 ConfigDataCollector to return known data without the need of a Kernel (topikito)

v4.4.20

Changelog (https://github.com/symfony/http-kernel/compare/v4.4.19...v4.4.20)

  • bug #40231 Configure session.cookie_secure earlier (tamcy)
  • bug #40104 Silence failed deprecations logs writes (fancyweb)

v4.4.19

Changelog (https://github.com/symfony/http-kernel/compare/v4.4.18...v4.4.19)

  • bug #39944 Configure the ErrorHandler even when it is overriden (nicolas-grekas)
  • bug #39797 Dont allow unserializing classes with a destructor (jderusse)

v4.4.18

Changelog (https://github.com/symfony/http-kernel/compare/v4.4.17...v4.4.18)

  • bug #39220 Fix bug with whitespace in Kernel::stripComments() (ausi)

v4.4.17

Changelog (https://github.com/symfony/http-kernel/compare/v4.4.16...v4.4.17)

  • bug #38910 Fix session initialized several times (jderusse)
  • bug #38894 Remove Symfony 3 compatibility code (derrabus)

v4.4.16

Changelog (https://github.com/symfony/http-kernel/compare/v4.4.15...v4.4.16)

... (truncated)

Changelog

Sourced from symfony/http-kernel's changelog.

CHANGELOG

5.3

  • Deprecate ArgumentInterface
  • Add ArgumentMetadata::getAttributes()
  • Deprecate ArgumentMetadata::getAttribute(), use getAttributes() instead
  • Mark the class Symfony\Component\HttpKernel\EventListener\DebugHandlersListener as internal
  • Deprecate returning a ContainerBuilder from KernelInterface::registerContainerConfiguration()
  • Deprecate HttpKernelInterface::MASTER_REQUEST and add HttpKernelInterface::MAIN_REQUEST as replacement
  • Deprecate KernelEvent::isMasterRequest() and add isMainRequest() as replacement
  • Add #[AsController] attribute for declaring standalone controllers on PHP 8
  • Add FragmentUriGeneratorInterface and FragmentUriGenerator to generate the URI of a fragment

5.2.0

  • added session usage
  • made the public http_cache service handle requests when available
  • allowed enabling trusted hosts and proxies using new kernel.trusted_hosts, kernel.trusted_proxies and kernel.trusted_headers parameters
  • content of request parameter _password is now also hidden in the request profiler raw content section
  • Allowed adding attributes on controller arguments that will be passed to argument resolvers.
  • kernels implementing the ExtensionInterface will now be auto-registered to the container
  • added parameter kernel.runtime_environment, defined as %env(default:kernel.environment:APP_RUNTIME_ENV)%
  • do not set a default Accept HTTP header when using HttpKernelBrowser

5.1.0

  • allowed to use a specific logger channel for deprecations
  • made WarmableInterface::warmUp() return a list of classes or files to preload on PHP 7.4+; not returning an array is deprecated
  • made kernels implementing WarmableInterface be part of the cache warmup stage
  • deprecated support for service:action syntax to reference controllers, use serviceOrFqcn::method instead
  • allowed using public aliases to reference controllers
  • added session usage reporting when the _stateless attribute of the request is set to true
  • added AbstractSessionListener::onSessionUsage() to report when the session is used while a request is stateless

5.0.0

  • removed support for getting the container from a non-booted kernel
  • removed the first and second constructor argument of ConfigDataCollector
  • removed ConfigDataCollector::getApplicationName()
  • removed ConfigDataCollector::getApplicationVersion()
  • removed support for Symfony\Component\Templating\EngineInterface in HIncludeFragmentRenderer, use a Twig\Environment only

... (truncated)

Commits
  • 3795165 Update VERSION for 4.4.25
  • 3225e62 minor #41412 [HttpKernel] Fixes file_get_content in HttpCache's Store for PHP...
  • a0d8fd7 Fix markdown
  • 3879d23 [HttpKernel] Fixes tests for PHP7.4+
  • f287ea9 Bump Symfony version to 4.4.25
  • 59925ee Update VERSION for 4.4.24
  • 46e66e8 Fixed deprecation warnings about passing null as parameter
  • 0cc7b69 Bump Symfony version to 4.4.24
  • 95bb423 Update VERSION for 4.4.23
  • 62d7cd9 Bump Symfony version to 4.4.23
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language - `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com): - Update frequency (including time of day and day of week) - Pull request limits (per update run and/or open at any time) - Automerge options (never/patch/minor, and dev/runtime dependencies) - Out-of-range updates (receive only lockfile updates, if desired) - Security updates (receive only security updates, if desired)
codecov[bot] commented 3 years ago

Codecov Report

Merging #28 (46ddc36) into dev (e64f544) will not change coverage. The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##              dev      #28   +/-   ##
=======================================
  Coverage   38.46%   38.46%           
=======================================
  Files          22       22           
  Lines         247      247           
=======================================
  Hits           95       95           
  Misses        152      152           

Continue to review full report at Codecov.

Legend - Click here to learn more Δ = absolute <relative> (impact), ø = not affected, ? = missing data Powered by Codecov. Last update e64f544...46ddc36. Read the comment docs.

dependabot-preview[bot] commented 3 years ago

Superseded by #29.