Skip to content
This repository has been archived by the owner on Jun 25, 2024. It is now read-only.

Update dependencies #94

Merged
merged 2 commits into from
May 25, 2021
Merged

Update dependencies #94

merged 2 commits into from
May 25, 2021

Conversation

forevermatt
Copy link
Contributor

Fixed

  • Raise supported version of SimpleSAMLphp to non-vulnerable version
  • Switch to official MariaDB image for databases (for local dev/testing)

@@ -13,7 +13,7 @@
"require": {
"php": ">=7.0",
"simplesamlphp/composer-module-installer": "^1.1.5",
"simplesamlphp/simplesamlphp": "~1.17.7 || ~1.18.5",
"simplesamlphp/simplesamlphp": "~1.18.6",
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the inclusion of two versions was to make it easier to build ssp-base. Is 1.17.7 no longer secure?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct. Anything less than 1.18.6 is apparently vulnerable now.

@forevermatt forevermatt merged commit 58c25a4 into develop May 25, 2021
@forevermatt forevermatt deleted the feature/update-dependencies branch May 25, 2021 19:27
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants