Skip to content

Update laravel-lang/lang to clean post-incident release#3585

Merged
bernardhanna merged 1 commit into
devfrom
feature/grassroots-grants-page
Jun 23, 2026
Merged

Update laravel-lang/lang to clean post-incident release#3585
bernardhanna merged 1 commit into
devfrom
feature/grassroots-grants-page

Conversation

@bernardhanna

Copy link
Copy Markdown
Collaborator

Bumps laravel-lang/lang 12.24.2 -> 12.24.3 (and related deps) to a remediated release after the May 2026 laravel-lang supply-chain incident. Packagist flagged the 12.24.2 version label as malware, breaking composer install on deploy. The new lock entry is verified clean: psr-4-only autoload, no autoload.files/src/helpers.php and no flipboxstudio indicators.

Bumps laravel-lang/lang 12.24.2 -> 12.24.3 (and related deps) to a
remediated release after the May 2026 laravel-lang supply-chain
incident. Packagist flagged the 12.24.2 version label as malware,
breaking composer install on deploy. The new lock entry is verified
clean: psr-4-only autoload, no autoload.files/src/helpers.php and no
flipboxstudio indicators.

Co-authored-by: Cursor <cursoragent@cursor.com>
@bernardhanna bernardhanna merged commit b2f14d0 into dev Jun 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant