You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Updated the squizlabs/php_codesniffer development dependency from 3.13.5 to 3.13.6, resolving GHSA-hmqg-cxww-wqhq (command injection in the gitblame report via a crafted filename).
Bug Fixes
No bug fixes in this release.
Upgrade Notes
No functional changes. The plugin's PHP, its endpoints, its capabilities, and its admin screen are byte-for-byte identical to 2.1.0.
Nothing was exploitable in a released build.squizlabs/php_codesniffer is a require-dev dependency used for coding-standards checks, and build.sh excludes vendor/ from the release zip, so the affected code was never distributed to any site. This release exists so the repository's own tooling and CI run on a patched version.
There are no open Dependabot alerts against this repository as of this release.