v0.10.0
Security
-
A repository URL no longer carries its credentials into a report. A private Composer source is routinely configured with a token in the URL —
https://gitlab-ci-token:$CI_JOB_TOKEN@…is how GitLab CI hands a job access to one, and Bitbucket app passwords take the same shape — and Composer keeps it in the lock because it has to fetch with it.--explainprinted that value verbatim: in the text output as thesourceline, and in--format=jsonaslock.repository. A pasted terminal buffer, an uploaded CI artifact or a report attached to a ticket therefore carried a working token to everyone who could read it. Every repository URL lockrot prints now has its userinfo removed and its host kept (Lockrot\Data\Repository\RepositoryUrl).Affects 0.8.0 and 0.9.0, where
--explainwas the only path to it — a run that never asked for an explanation was never affected. If you have published an--explainoutput from either release for a project with a token in a repository URL, treat that token as disclosed and rotate it.
Added
-
--format=html: the whole run as one self-contained page. It carries the report, the release branches behind every finding, the advisories and the baseline comparison inside a single file, so it opens fromfile://, uploads as one CI artifact and attaches to a ticket — no server, no network, no fonts or scripts fetched from anywhere.What a stream cannot show: one line per signal instead of one sentence with four semicolons in it, every release branch on a time axis with the installed one marked, advisories grouped by whether the fix is a patch on your own branch or a move to another, and what is new or worsened since the baseline. Filters and the open package live in the URL hash, the query understands
verdict:,priority:,signal:,severity:,cve:,direct:anddev:, and?opens a glossary of every verdict and signal.A report is usually read by someone who did not run it, so the page closes with the two commands that produce the same page for their own lock. The payload's
reportkey is what--format=jsonwrites, envelope included, so it validates against the published report schema.--allputs every package in the page at roughly 4 KB each; without it a 100-package lock lands around 250 KB. The page carries a description and an Open Graph card so a shared link says what was found, and norobotsdirective: whether a published report may be indexed is the publisher's call, made in their robots.txt, not this file's.See CI and reports.
-
The report says what it was decided against. Every verdict depends on settings the document did not record: the thresholds separate
stalefromsilent, the target PHP decides whether a release predates it. Until now--format=jsonnamed the target in exactly one place — inside the data of an S5 signal — so a run where S5 never fired left no trace of what it aimed at, and the thresholds left none at all. Two people comparing two reports could not tell whether they differ because the locks do or because the settings do.The report now carries a
runblock: the project's own name from composer.json — until now nothing in a report said which project it was about, every lock being calledcomposer.lock— the target PHP, the thresholds, thefail-on, the name of the lock (never its path, which carries the account and often the client's directory) andflagged_verdicts, the verdicts the run counted as findings.extra.lockrot.projectoverrides the name where the manifest has none, or where its name is not the one to publish: a package inside a monorepo names itself after the package, and a private project names itself after the client.Each finding also carries
baseline, where it stands against the baseline file —known,neworworsened, with the verdict the baseline accepted — beside the totals thebaselineblock already gave.Both are optional in the published schema, so documents written by 0.9.0 still validate, and
lockrot.schemastays1.
Verifying this release
sha256sum -c lockrot.phar.sha256
gpg --verify lockrot.phar.asc lockrot.phar # key 39EC C3F6 4AE8 D06A 9A63 FD99 AB6F 7F52 AE51 3141
gh attestation verify lockrot.phar --repo somework/lockrotsha256sum is GNU; on macOS use shasum -a 256 -c. What each check proves, and how to fetch
the key, is on the PHAR page.
See the full changelog.