[1.x] [workflows] fix: peg composer at 2.8.x to avoid security blocking, etc in 2.9 #4294
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Fixes #0000
Changes proposed in this pull request:
Composer now automatically blocks updates to packages with known security advisories. This is a problem for some of
1.x's deps, especially laminas.To prevent CI failures, this pegs composer to
2.8.x(ie before these changes were introduced).The other option is to add
audit.block-insecure: falseincomposer.json, but this would not be helpful for currently released Flarum versions.The changes here are not needed for
2.xMore information: https://blog.packagist.com/composer-2-9/
Reviewers should focus on:
Screenshot
Necessity
Confirmed
composer test).Required changes: