Skip to content

chore(dep): bump vulnerable PHP dependencies#5519

Merged
elzody merged 2 commits intomainfrom
fix/commonmark-dep
Mar 25, 2026
Merged

chore(dep): bump vulnerable PHP dependencies#5519
elzody merged 2 commits intomainfrom
fix/commonmark-dep

Conversation

@elzody
Copy link
Collaborator

@elzody elzody commented Mar 25, 2026

Updates PHP dependencies that were flagged as vulnerable by roave/security-advisories and caused static analysis to fail:

  • league/commonmark v2.8.1 => v2.8.2
  • phpseclib/phpseclib v3.0.49 => v3.0.50

Signed-off-by: Elizabeth Danzberger <elizabeth@elzody.dev>
@elzody elzody self-assigned this Mar 25, 2026
@elzody elzody requested a review from juliusknorr as a code owner March 25, 2026 20:54
@elzody elzody added the 3. to review Ready to be reviewed label Mar 25, 2026
Signed-off-by: Elizabeth Danzberger <elizabeth@elzody.dev>
@elzody elzody changed the title chore(dep): bump league/commonmark to 2.8.2 chore(dep): bump vulnerable PHP dependencies Mar 25, 2026
@elzody
Copy link
Collaborator Author

elzody commented Mar 25, 2026

/backport to stable33 please

@elzody elzody merged commit 2ac7f4a into main Mar 25, 2026
112 of 118 checks passed
@elzody elzody deleted the fix/commonmark-dep branch March 25, 2026 21:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Ready to be reviewed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants