Skip to content

v1.0.0 — Security updates

Choose a tag to compare

@pstoute pstoute released this 01 Aug 16:36
· 76 commits to main since this release
e3fd138

Security updates

This release incorporates the dependency remediation merged in #2.

  • Updated Composer dependencies to patched releases, including Laravel, Symfony, Guzzle, phpseclib, and CommonMark.
  • Updated pnpm dependencies to patched releases, including Axios, DOMPurify, Vite, Vitest, PostCSS and their vulnerable transitive dependencies.
  • Added a direct esbuild 0.28.1 development dependency to remediate the remaining transitive advisory.
  • Dependency audits after the update report no known npm/pnpm vulnerabilities and no Composer security advisories.

Reliability and CI

  • Restored PostgreSQL/MySQL CI by persisting paused SLA durations as integers.
  • Restored lint/static-analysis checks with formatting cleanup and a path-scoped baseline for pre-existing PHPStan diagnostics.
  • CI now passes on PostgreSQL, MySQL, lint/static analysis, and frontend checks.

Note: Composer continues to report doctrine/annotations as abandoned; it has no listed security advisory in this release.