Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump DI version due to CVE-2019-10910 #746

Closed
wants to merge 1 commit into from

Conversation

realFlowControl
Copy link
Contributor

No description provided.

@alfredbez
Copy link
Contributor

Composer will use the latest version of v3.4 anyway or am I wrong? See also: https://semver.mwl.be/#!?package=symfony%2Fdependency-injection&version=%5E3.4&minimum-stability=stable

@realFlowControl
Copy link
Contributor Author

That's not granted, another dependency could require an explicit version and as we allow it, it would install. Better save then sorry 😉

@realFlowControl
Copy link
Contributor Author

Additionally one could also use the --prefer-lowest argument with composer install and composer will install the lowest allowed version.

@alfredbez
Copy link
Contributor

I think adding roave/security-advisories is also a good idea:

composer require --dev roave/security-advisories:dev-master

see: https://github.com/Roave/SecurityAdvisories

@Sieg
Copy link
Member

Sieg commented Dec 13, 2019

Hey @flow-control, merged to b-6.2.x and up.

@Sieg Sieg closed this Dec 13, 2019
@realFlowControl realFlowControl deleted the flow-control-patch-2 branch January 9, 2020 13:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
3 participants