Security
GrumPHP passed repository files to external tools as plain arguments, so a file whose name starts with - could be read as an option, such as --config, instead of a path. Paths starting with - are now prefixed with ./, and the git_blacklist task matches file names literally. See GHSA-fmpp-rfr9-jgpg for details.
Thanks to @jf0x3a for reporting this responsibly.
What's Changed
- Prevent file paths from being parsed as tool options by @veewee in #1234
- Bump composer/composer from 2.10.2 to 2.10.3 by @dependabot[bot] in #1230
Full Changelog: v2.24.0...v2.25.0