Skip to content

Composer dependency is ^1.10.22 - security vulnerability #2551

@gravelld

Description

@gravelld

Thanks for your work on this library.

Due to GHSA-frqg-7g38-6gcf the minimum version for the 1.x version of composer should be 1.10.23. This means the entry in composer.json should be:

"composer/composer": "^1.10.23"

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions