Skip to content

lockrot 0.7.0

Choose a tag to compare

@github-actions github-actions released this 18 Sep 20:05
· 238 commits to main since this release

Added

  • left-behind: a verdict for the branch you are on, not the package. Signal S8 takes the newest stable release on the installed version's release branch (1.x; 0.3.x below 1.0; the patch alone below 0.1 — what a caret constraint stays inside; pre-releases do not count), measures its age against release-warn-years / release-high-years, and fires only when a higher branch has released since and within release-warn-years of today — a package dead on every branch stays S2's. composer outdated --major-only says a newer major exists; S2 sees the package's newest release and stays quiet; this says the branch installed here gets no fixes. The verdict is left-behind at either threshold — between pinned and old-promise in severity, base priority high. The evidence reads branch 1.x last released 2021-08-03 (5.1 years ago); 2.x released v2.12.5 (2026-04-17) — the higher branch whose release is newest, named as the branch fixes land on. A branch whose highest tag the repository leaves undated is not measured: Packagist dates a tag by its commit, and a subtree split (illuminate/*, symfony/*) has undated tags and tags dated years before the release.
  • Security advisories on the finding, with whether a fix is coming. Signal S9 carries the advisories that affect the installed version — the same ones composer audit reports, fetched through Composer's own advisory API from the configured repositories, honouring Composer's ignore lists (config.policy.advisories on 2.10+, config.audit.ignore before) — under data.advisories in --format=json. S9 never decides a verdict. Each advisory is held against the highest stable tag on the installed version's branch and the package's highest stable tag, each only when above the installed version; one out of both ranges is already fixed, and the line says by what (fixed by 6.3.0; 1 fixed by v3.4.47, 3 fixed by v8.1.7 when they differ), with affected_versions, fixed_by and fixed_on_branch on each advisory. On an abandoned, silent or left-behind package the advisories nothing listed fixes — on a left-behind branch, nothing listed on the branch — earn no fix expected (no fix expected on 3.x next to a fix in a higher branch) and the priority goes up one step, critical at most. Advisories on packages the report does not flag stay off the rows and are totalled in the footer: 53 security advisories on 17 packages the report does not flag; see composer audit. On Composer 2.2, under --offline and once the install-time budget is spent the report carries one note instead.

Changed

  • A package on a quiet branch of a living upstream is now left-behind where it was ok, stale or old-promise; --fail-on=left-behind sees it. A baseline holding such a package at stale or old-promise reports it worsened.
  • A priority threshold can trip on a verdict that did not move: an advisory on an abandoned, silent or left-behind package lifts high to critical, so --fail-on=critical now fails on it. left-behind itself starts at high, so a run that passed --fail-on=high can fail on a package that was ok before. The baseline, keyed on the verdict, still calls the finding known.
  • S2 stays quiet when the package's highest non-dev tag carries no release date: "last release" would otherwise date the newest tag the repository dated and say nothing about the undated ones above it.
  • --strict-network covers the advisory request too: every repository that publishes advisories is asked, as composer audit asks them. A private repository that is down fails a strict run where it used to pass unnoticed.
  • The counts, priority and pulled in by: lines fold between their ·-separated items, never between a label and its number, and never wider than the terminal. The install-time block shows up to three notes, one per source that could not answer.
  • The evidence line opens with the signal that decided the verdict, then the rest in signal order, then what the package pulls in. --format=json keeps the signals in signal order.
  • The counts line gained left-behind; the verdict enums in the config and baseline schemas, the SARIF rule list and --fail-on accept it. The JSON schema number stays 1: an added enum value and two new signal ids, nothing removed or renamed.

Verify this release

curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.7.0/lockrot.phar
curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.7.0/lockrot.phar.sha256
sha256sum -c lockrot.phar.sha256
gpg --keyserver hkps://keys.openpgp.org --recv-keys 39ECC3F64AE8D06A9A63FD99AB6F7F52AE513141
curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.7.0/lockrot.phar.asc
gpg --verify lockrot.phar.asc lockrot.phar
gh attestation verify lockrot.phar --repo somework/lockrot

Or rebuild it: check out v0.7.0, run build/build-phar.sh with Composer 2.10.3, and compare the sha256 — see the PHAR page.

Full changelog: CHANGELOG.md.