Skip to content

Releases: SamJUK/m2-meta-security-patches

2026.08.11 (Aug Isolated Patches)

Choose a tag to compare

@SamJUK SamJUK released this 11 Aug 19:34
Immutable release. Only release title and notes can be modified.

🎉 Introduces the second iteration of Adobe's new Isolated patches ( APSB26-92).

NOTE: These patches ONLY apply to the latest -p releases. If you are out of date, they will skip.

What's Changed

  • add: august isolated security patches by @SamJUK in #5
  • fix: repoint root files in patches at magento2-base to work on fresh installations @SamJUK in #6
  • fix: re-add nginx.conf.sample with repointed base @SamJUK in #6
  • fix: drop vendor/bin/patch-status to prevent patches:redo failures @SamJUK in #6

Full Changelog: 2026.07.14-p1...2026.08.11

Isolated Patch Refs

https://helpx.adobe.com/security/products/magento/apsb26-92.html
https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-40380

2026.07.14-p1

Choose a tag to compare

@SamJUK SamJUK released this 14 Jul 18:29
Immutable release. Only release title and notes can be modified.

🐛 Fixes broken composer install on fresh CI installs

The official distributed patch files bundled in release 2026.07.14
Attempts to patch nginx.conf.sample before the composer plugin
deploys it from the magento-base package, breaking clean/CI installs.

What's Changed

  • drop nginx.sample.conf hunk from July isolated patches by @SamJUK in #4

Full Changelog: 2026.07.14...2026.07.14-p1

2026.07.14 (July Isolated Patches)

Choose a tag to compare

@SamJUK SamJUK released this 14 Jul 16:42
Immutable release. Only release title and notes can be modified.

⚠️ Known issue: this release breaks composer install in CI
A patch hunk targets nginx.conf.sample before Magento deploys it (composer plugin).
Existing installs will patch fine; new/CI installs will fail.
Fixed in 2026.07.14-p1 — upgrade to that instead.

🎉 Introduces the first of Adobe's new Isolated patches ( APSB26-73).
NOTE: These patches ONLY apply to the latest -p releases. If you are out of date, they will skip.

What's Changed

  • add 2026-07-001 isolated CE security patches (2.4.6-p15/2.4.7-p10/2.4.8-p5/2.4.9) by @SamJUK in #3

Full Changelog: 2026.03.19...2026.07.14

2026.03.19

Choose a tag to compare

@SamJUK SamJUK released this 19 Mar 16:06

Introduce a Emergency patch for the Polyshell vulnerability (APSB25-94) - #2

Patch content is derived from Mark's module https://github.com/markshust/magento-polyshell-patch/
Allowing for a single Patch file for all versions, due to the official commit not applying cleanly to older versions

Full Changelog: 2026.02.01...2026.03.19

2026.02.01

Choose a tag to compare

@SamJUK SamJUK released this 01 Feb 21:48

Release 2026.02.01

Initial release

New Patches