-
-
Notifications
You must be signed in to change notification settings - Fork 4.7k
Comparing changes
Open a pull request
base repository: composer/composer
base: 2.9.1
head repository: composer/composer
compare: 2.9.2
- 18 commits
- 40 files changed
- 4 contributors
Commits on Nov 13, 2025
-
Configuration menu - View commit details
-
Copy full SHA for 04f7a81 - Browse repository at this point
Copy the full SHA 04f7a81View commit details
Commits on Nov 14, 2025
-
New flags to disable/configure blocking (#12617)
* Add --no-security-blocking / COMPOSER_NO_SECURITY_BLOCKING env to disable security blocking * Add COMPOSER_SECURITY_BLOCKING_ABANDONED to enable/disable audit.block-abandoned * Move audit/auditFormat Installer configs into AuditConfig object
Configuration menu - View commit details
-
Copy full SHA for eb6eaaf - Browse repository at this point
Copy the full SHA eb6eaafView commit details -
Configuration menu - View commit details
-
Copy full SHA for f5854b1 - Browse repository at this point
Copy the full SHA f5854b1View commit details -
Configuration menu - View commit details
-
Copy full SHA for 8c73247 - Browse repository at this point
Copy the full SHA 8c73247View commit details
Commits on Nov 19, 2025
-
Bump actions/checkout from 5.0.0 to 5.0.1 (#12625)
Bumps [actions/checkout](https://github.com/actions/checkout) from 5.0.0 to 5.0.1. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@08c6903...93cb6ef) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 5.0.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for b18d73b - Browse repository at this point
Copy the full SHA b18d73bView commit details -
Configuration menu - View commit details
-
Copy full SHA for 632d1c3 - Browse repository at this point
Copy the full SHA 632d1c3View commit details -
Configuration menu - View commit details
-
Copy full SHA for 64bc9c9 - Browse repository at this point
Copy the full SHA 64bc9c9View commit details -
Configuration menu - View commit details
-
Copy full SHA for a8c16b6 - Browse repository at this point
Copy the full SHA a8c16b6View commit details -
Configuration menu - View commit details
-
Copy full SHA for e76c43b - Browse repository at this point
Copy the full SHA e76c43bView commit details -
Make block-abandoned a config option for insecure version blocking
It's no longer possible to filter abandoned packages without also filtering insecure versions, this matches env handling and docs.
Configuration menu - View commit details
-
Copy full SHA for b5bf0cf - Browse repository at this point
Copy the full SHA b5bf0cfView commit details -
Configuration menu - View commit details
-
Copy full SHA for e64d1ff - Browse repository at this point
Copy the full SHA e64d1ffView commit details -
Configuration menu - View commit details
-
Copy full SHA for 5b2692e - Browse repository at this point
Copy the full SHA 5b2692eView commit details -
Merge pull request #12618 from Seldaek/block_edits
Add a way to configure block- and audit-specific ignores in audit.ignore, audit.ignore-abandoned and audit.ignore-severity Fixes #12612
Configuration menu - View commit details
-
Copy full SHA for bfc0e31 - Browse repository at this point
Copy the full SHA bfc0e31View commit details -
Fix ignoring of CVE ids in security blocking
Also adds Advisory IDs in output of audit command Fixes #12624
Configuration menu - View commit details
-
Copy full SHA for 59eb8e7 - Browse repository at this point
Copy the full SHA 59eb8e7View commit details -
Merge pull request #12627 from Seldaek/audit_fix
Fix ignoring of CVE ids in security blocking
Configuration menu - View commit details
-
Copy full SHA for f85f82d - Browse repository at this point
Copy the full SHA f85f82dView commit details -
Fix partial updates failing when a locked package has security adviso…
…ries (#12626) Fixes #12620 --------- Co-authored-by: Nils Adermann <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 98861c6 - Browse repository at this point
Copy the full SHA 98861c6View commit details -
Configuration menu - View commit details
-
Copy full SHA for a4fa0b5 - Browse repository at this point
Copy the full SHA a4fa0b5View commit details -
Configuration menu - View commit details
-
Copy full SHA for 8d5358f - Browse repository at this point
Copy the full SHA 8d5358fView commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff 2.9.1...2.9.2