pantheon-systems / drops-8

Pantheon Upstream for Drupal 8 Sites. Deprecated; please see https://github.com/pantheon-upstreams/drupal-composer-managed
GNU General Public License v2.0
80 stars 117 forks source link

Update to Drupal 9.5.3. For more information, see https://www.drupal.org/project/drupal/releases/9.5.3 #423

Closed pantheon-upstream closed 1 year ago

pantheon-upstream commented 1 year ago

Update from Drupal 9.1.0 to Drupal 9.5.3.

This is experimental. Do not merge.

guardrails[bot] commented 1 year ago

:warning: We detected 9 security issues in this pull request:

Hard-Coded Secrets (1)
Docs | Details ----- | -------- [:bulb:](https://docs.guardrails.io/docs/en/vulnerabilities/general/hard-coded_secrets.html?utm_source=ghpr#) | Title: **Secret Keyword**, Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/abb2c1f4ee11d845ab3fd72b359dbe4331f7bad4/core/modules/user/config/install/user.mail.yml#L34 More info on how to fix Hard-Coded Secrets in [General](https://docs.guardrails.io/docs/en/vulnerabilities/general/hard-coded_secrets.html?utm_source=ghpr#). ---
Insecure Use of Regular Expressions (7)
Docs | Details ----- | -------- [:bulb:](https://docs.guardrails.io/docs/en/vulnerabilities/javascript/insecure_use_of_regular_expressions.html?utm_source=ghpr#) | Title: **Regex DOS (ReDOS)**, Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/abb2c1f4ee11d845ab3fd72b359dbe4331f7bad4/core/misc/position.es6.js#L30 [:bulb:](https://docs.guardrails.io/docs/en/vulnerabilities/javascript/insecure_use_of_regular_expressions.html?utm_source=ghpr#) | Title: **Regex DOS (ReDOS)**, Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/abb2c1f4ee11d845ab3fd72b359dbe4331f7bad4/core/misc/position.js#L13 [:bulb:](https://docs.guardrails.io/docs/en/vulnerabilities/javascript/insecure_use_of_regular_expressions.html?utm_source=ghpr#) | Title: **Regex DOS (ReDOS)**, Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/abb2c1f4ee11d845ab3fd72b359dbe4331f7bad4/core/scripts/js/ckeditor5-types-documentation.js#L30 [:bulb:](https://docs.guardrails.io/docs/en/vulnerabilities/javascript/insecure_use_of_regular_expressions.html?utm_source=ghpr#) | Title: **Regex DOS (ReDOS)**, Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/abb2c1f4ee11d845ab3fd72b359dbe4331f7bad4/core/scripts/js/vendor-update.js#L34 [:bulb:](https://docs.guardrails.io/docs/en/vulnerabilities/javascript/insecure_use_of_regular_expressions.html?utm_source=ghpr#) | Title: **Regex DOS (ReDOS)**, Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/abb2c1f4ee11d845ab3fd72b359dbe4331f7bad4/core/misc/position.es6.js#L38 [:bulb:](https://docs.guardrails.io/docs/en/vulnerabilities/javascript/insecure_use_of_regular_expressions.html?utm_source=ghpr#) | Title: **Regex DOS (ReDOS)**, Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/abb2c1f4ee11d845ab3fd72b359dbe4331f7bad4/core/misc/position.es6.js#L40 [:bulb:](https://docs.guardrails.io/docs/en/vulnerabilities/javascript/insecure_use_of_regular_expressions.html?utm_source=ghpr#) | Title: **Regex DOS (ReDOS)**, Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/abb2c1f4ee11d845ab3fd72b359dbe4331f7bad4/core/misc/position.js#L18 More info on how to fix Insecure Use of Regular Expressions in [JavaScript](https://docs.guardrails.io/docs/en/vulnerabilities/javascript/insecure_use_of_regular_expressions.html?utm_source=ghpr#). ---
Insecure Processing of Data (1)
Docs | Details ----- | -------- [:bulb:](https://docs.guardrails.io/docs/en/vulnerabilities/php/insecure_processing_of_data.html?utm_source=ghpr#) | Title: **Insecure HTTP redirect**, Severity: Low
https://github.com/pantheon-systems/drops-8/blob/abb2c1f4ee11d845ab3fd72b359dbe4331f7bad4/.ht.router.php#L29 More info on how to fix Insecure Processing of Data in [PHP](https://docs.guardrails.io/docs/en/vulnerabilities/php/insecure_processing_of_data.html?utm_source=ghpr#).

👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

pantheon-upstream commented 1 year ago

Superseeded by #425.