Skip to content

Conversation

@retlehs
Copy link
Member

@retlehs retlehs commented Nov 14, 2025

See https://blog.packagist.com/composer-2-9/

Composer now automatically blocks updates to packages with known security advisories.

Note that if you are currently using roave/security-advisories to block packages with known vulnerabilities, this feature replaces it fully and you can remove the dependency on this package.

@retlehs retlehs self-assigned this Nov 14, 2025
@retlehs retlehs merged commit 007f628 into master Nov 14, 2025
8 checks passed
@retlehs retlehs deleted the remove-roave/security-advisories branch November 14, 2025 15:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants