You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Security
Require wp-coding-standards/wpcs^3.4.1 (was ^3.4) to fix GHSA-3pwp-g2mj-5p3v
(CVSS 8.6, high). The WordPress.WP.EnqueuedResourceParameters
sniff reconstructed function arguments and passed them to eval(), so scanning untrusted PHP — CI on pull requests,
third-party code review — could execute arbitrary commands on
the scanning host. WPCS 0.14.1 through 3.4.0 were affected via
the WordPress and WordPress-Extra rulesets; Apermo
references WordPress, so it was in the affected set. The floor
is raised rather than only the lockfile refreshed, so consuming
projects cannot resolve back to a vulnerable version. No ruleset
changes.