Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Drupal Extension #4232

Closed
danepowell opened this issue Aug 27, 2020 · 1 comment
Closed

Update Drupal Extension #4232

danepowell opened this issue Aug 27, 2020 · 1 comment
Labels
11.x Affects or applies to 11.x Enhancement A feature or feature request

Comments

@danepowell
Copy link
Contributor

Is your feature request related to a problem? Please describe.
via Slack, blt-require-dev depends on drupal-extension 3.x, which depends on a version of Drupal Driver with a vulnerability.

Describe the solution you'd like
Updating Drupal Extension to 4.x might also update Drupal Driver and fix the vulnerability, we need to confirm that.

Describe alternatives you've considered
Individual users can stop using blt-require-dev and pull in the dependencies manually, or possibly use Composer aliases to use a newer version of Drupal Driver / Drupal Extension than what BLT requires.

@danepowell danepowell added Enhancement A feature or feature request 11.x Affects or applies to 11.x labels Aug 27, 2020
danepowell added a commit to danepowell/blt that referenced this issue Sep 2, 2020
@danepowell
Copy link
Contributor Author

We already use Drupal Extension 4.x in BLT 12 so I think it's safe to update.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
11.x Affects or applies to 11.x Enhancement A feature or feature request
Projects
None yet
Development

No branches or pull requests

1 participant