forked from pool/php-composer2
This branch is 11 commits behind pool/php-composer2:factory
- version update to 2.7.7
2.7.7 2024-06-10
Security: Fixed command injection via malicious git branch name (GHSA-47f6-5gq3-vx9c / CVE-2024-35241)
Security: Fixed multiple command injections via malicious git/hg branch names (GHSA-v9qv-c7wm-wgmf / CVE-2024-35242)
Fixed PSR violations for classes not matching the namespace of a rule being hidden, this may lead to new violations being shown (#11957)
Fixed UX when a plugin is still in vendor dir but is not required nor allowed anymore after changing branches (#12000)
Fixed new platform requirements from composer.json not being checked if the lock file is outdated (#12001)
Fixed secure-http checks that could be bypassed by using malformed URL formats (fa3b9582c)
Fixed Filesystem::isLocalPath including windows-specific checks on linux (3c37a67c)
Fixed perforce argument escaping (3773f775)
Fixed handling of zip bombs when extracting archives (de5f7e32)
Fixed Windows command parameter escaping to prevent abuse of unicode characters with best fit encoding conversion (3130a7455, 04a63b324)
Fixed ability for config command to remove autoload keys (#11967)
Fixed empty type support in init command (#11999)
Fixed git clone errors when safe.bareRepository is set to strict in the git config (#11969)
Fixed regression showing network errors on PHP <8.1 (#11974)
Fixed some color bleed from a few warnings (#11972)
2.7.6 2024-05-04
Fixed regression when script handlers add an autoloader which uses a private callback (#11960)
2.7.5 2024-05-03
Added uninstall alias to remove command (#11951)
Added workaround for broken curl versions 8.7.0/8.7.1 causing transport exceptions (#11913)
Fixed root usage warnings showing up within Podman containers (#11946)
Fixed config command not handling objects correctly in some conditions (#11945)
Fixed binary proxies not containing the correct path if the project dir is a symlink (#11947)
Fixed Composer autoloader being overruled by project autoloaders when they are loaded by event handlers (scripts/plugins) (#11955)
Fixed TransportException (http failures) not having a distinct exit code, should now exit with 100 as code (#11954)
2.7.4 2024-04-22
Fixed regression (Call to undefined method ProxyManager::needsTransitionWarning()) with projects requiring composer/composer in an pre-2.7.3 version (#11943, #11940)
2.7.3 2024-04-19
OBS-URL: https://build.opensuse.org/request/show/1179900
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/php-composer2?expand=0&rev=27
Description
No description provided
Languages
RPM Spec
100%