Security: Fixed code execution and possible privilege escalation via compromised vendor dir contents (GHSA-7c6p-848j-wh5h / CVE-2024-24821)
2.2.22
Security: Fixed possible remote code execution vulnerability if composer.phar is publicly accessible, executable as PHP, and register_argc_argv is enabled in php.ini (GHSA-jm6m-4632-36hf / CVE-2023-43655)
Fixed authentication issue when downloading several files from private Bitbucket in parallel (#11464)
Fixed handling of broken junctions on windows (#11550)
Fixed loading of root aliases on path repo packages when doing partial updates (#11632)
Fixed parsing of lib-curl-openssl version with OSX SecureTransport (#11534)
Fixed binary proxies not being transparent when included by another PHP process and returning a value (#11454)
Fixed support for plugin classes being marked as readonly (#11404)
Security: Fixed code execution and possible privilege escalation via compromised vendor dir contents (GHSA-7c6p-848j-wh5h / CVE-2024-24821)
Changed the default of the audit.abandoned config setting to fail, set it to report or ignore if you do not want this, or set it via COMPOSER_AUDIT_ABANDONED env var (#11643)
Added --minimal-changes (-m) flag to update/require/remove commands to perform partial update with --with-dependencies while changing only what is absolutely necessary in transitive dependencies (#11665)
Added --sort-by-age (-A) flag to outdated/show commands to allow sorting by and displaying the release date (most outdated first) (#11762)
Added support for --self combined with --installed or --locked in show command, to add the root package to the package list being output (#11785)
Added severity information to audit command output (#11702)
Added scripts-aliases top level key in composer.json to define aliases for custom scripts you defined (#11666)
Added IPv4 fallback on connection timeout, as well as a COMPOSER_IPRESOLVE env var to force IPv4 or IPv6, set it to 4 or 6 (#11791)
Added support for wildcards in outdated's --ignore arg (#11831)
Added support for bump command bumping * to >=current version (#11694)
Added detection of constraints that cannot possibly match anything to validate command (#11829)
Added package source information to the output of install when running in very verbose (-vv) mode (#11763)
Added audit of Composer's own bundled dependencies in diagnose command (#11761)
Added GitHub token expiration date to diagnose command output (#11688)
Added non-zero status code to why/why-not commands (#11796)
Added error when calling show --direct <package> with an indirect/transitive dependency (#11728)
Added COMPOSER_FUND=0 env var to hide calls for funding (#11779)
Fixed bump command not bumping packages required with a v prefix (#11764)
Fixed automatic disabling of plugins when running non-interactive as root
Fixed update --lock not keeping the dist reference/url/checksum pinned (#11787)
Fixed require command crashing at the end if no lock file is present (#11814)
Fixed root aliases causing problems when auditing locked dependencies (#11771)
Fixed handling of versions with 4 components in require command (#11716)
Fixed compatibility issues with Symfony 7
Fixed composer.json remaining behind after a --dry-run of the require command (#11747)
Fixed warnings being shown incorrectly under some circumstances (#11786, #11760, #11803)
[2.6.6] 2023-12-08
Fixed symfony/console requirement to exclude 7.x as Composer 2.6 is not compatible, 2.7 will be (#11741)
Fixed libpq parsing to use the global constant if available (#11684)
Fixed error output when updating with a temporary constraint fails (#11692)
[2.6.5] 2023-10-06
Fixed error when vendor dir contains broken symlinks (#11670)
Fixed composer.lock missing from Composer's zip archives (#11674)
Fixed AutoloadGenerator::dump() non-BC signature change in 2.6.4 (cb363b0e8)
[2.6.4] 2023-09-29
Security: Fixed possible remote code execution vulnerability if composer.phar is publicly accessible, executable as PHP, and register_argc_argv is enabled in php.ini (GHSA-jm6m-4632-36hf / CVE-2023-43655)
Fixed json output of abandoned packages in audit command (#11647)
Performance improvement in pool optimization step (#11638)
Performance improvement in show -a <packagename> (#11659)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/WeareJH/m2-module-import/network/alerts).
Bumps composer/composer from 2.2.17 to 2.2.23.
Release notes
Sourced from composer/composer's releases.
Changelog
Sourced from composer/composer's changelog.
... (truncated)
Commits
d1542e8
Release 2.2.23ff14762
Fix php5.3 syntax6263586
Remove php8 CIb534407
Remove platform config before selecting phpunit bridge version69fa55d
CI fixes7418b52
Remove return type77e3982
Merge pull request from GHSA-7c6p-848j-wh5hc6e09b3
Update deps6a69018
Reverting release version changesfedc76e
Release 2.2.22Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show