Bug 263264 - devel/php-composer: Update to latest version, includes security fix
Summary: devel/php-composer: Update to latest version, includes security fix
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Only Me
Assignee: Guido Falsi
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-04-13 19:00 UTC by Guido Falsi
Modified: 2022-04-13 19:34 UTC (History)
1 user (show)

See Also:
cyberbotx: maintainer-feedback+
madpilot: merge-quarterly+


Attachments
UPdate patch (1.92 KB, patch)
2022-04-13 19:00 UTC, Guido Falsi
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Guido Falsi freebsd_committer freebsd_triage 2022-04-13 19:00:32 UTC
Created attachment 233203 [details]
UPdate patch

Hi,

I've crated patches to update the composer ports to the latest version. (both 1.x and 2.3.x)

This update includes an important security fix:

https://github.com/composer/composer/security/advisories/GHSA-x7cr-6qr6-2hh6


I have already created a vuxml entry for this:

https://cgit.freebsd.org/ports/commit/?id=b899d08f05c491e3ee4f9584030981d63acb385d

Can you approve the patch?

Thanks in advance.
Comment 1 Guido Falsi freebsd_committer freebsd_triage 2022-04-13 19:00:59 UTC
I also intend to merge this to quarterly, obviously.
Comment 2 Naram Qashat 2022-04-13 19:09:09 UTC
Looks good to me.
Comment 3 commit-hook freebsd_committer freebsd_triage 2022-04-13 19:28:52 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=c4cee6e9be1b069f16529cc11d10a6212d8f3640

commit c4cee6e9be1b069f16529cc11d10a6212d8f3640
Author:     Guido Falsi <madpilot@FreeBSD.org>
AuthorDate: 2022-04-13 19:25:05 +0000
Commit:     Guido Falsi <madpilot@FreeBSD.org>
CommitDate: 2022-04-13 19:25:05 +0000

    devel/php-composer: Update to 1.10.26

    PR:             263264
    Approved by:    Naram Qashat <cyberbotx@cyberbotx.com> (maintainer)
    MFH:            2022Q2
    Security:       24a9bd2b-bb43-11ec-af81-0897988a1c07

 devel/php-composer/Makefile | 2 +-
 devel/php-composer/distinfo | 6 +++---
 2 files changed, 4 insertions(+), 4 deletions(-)
Comment 4 commit-hook freebsd_committer freebsd_triage 2022-04-13 19:28:52 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=ee4ff44b36358acda3b9298dc1dcc1e646ea134d

commit ee4ff44b36358acda3b9298dc1dcc1e646ea134d
Author:     Guido Falsi <madpilot@FreeBSD.org>
AuthorDate: 2022-04-13 19:27:15 +0000
Commit:     Guido Falsi <madpilot@FreeBSD.org>
CommitDate: 2022-04-13 19:27:15 +0000

    devel/php-composer2: Update to 2.3.5

    PR:             263264
    Approved by:    Naram Qashat <cyberbotx@cyberbotx.com> (maintainer)
    MFH:            2022Q2
    Security:       24a9bd2b-bb43-11ec-af81-0897988a1c07

 devel/php-composer2/Makefile | 2 +-
 devel/php-composer2/distinfo | 6 +++---
 2 files changed, 4 insertions(+), 4 deletions(-)
Comment 5 commit-hook freebsd_committer freebsd_triage 2022-04-13 19:32:53 UTC
A commit in branch 2022Q2 references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=8a7c8d4fe93912676521c2e8eea89db638c7e599

commit 8a7c8d4fe93912676521c2e8eea89db638c7e599
Author:     Guido Falsi <madpilot@FreeBSD.org>
AuthorDate: 2022-04-13 19:27:15 +0000
Commit:     Guido Falsi <madpilot@FreeBSD.org>
CommitDate: 2022-04-13 19:31:29 +0000

    devel/php-composer2: Update to 2.3.5

    PR:             263264
    Approved by:    Naram Qashat <cyberbotx@cyberbotx.com> (maintainer)
    MFH:            2022Q2
    Security:       24a9bd2b-bb43-11ec-af81-0897988a1c07

    (cherry picked from commit ee4ff44b36358acda3b9298dc1dcc1e646ea134d)

 devel/php-composer2/Makefile | 2 +-
 devel/php-composer2/distinfo | 6 +++---
 2 files changed, 4 insertions(+), 4 deletions(-)
Comment 6 commit-hook freebsd_committer freebsd_triage 2022-04-13 19:32:56 UTC
A commit in branch 2022Q2 references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=3420140bf3a20bb9e4181550684bc5102276a18f

commit 3420140bf3a20bb9e4181550684bc5102276a18f
Author:     Guido Falsi <madpilot@FreeBSD.org>
AuthorDate: 2022-04-13 19:25:05 +0000
Commit:     Guido Falsi <madpilot@FreeBSD.org>
CommitDate: 2022-04-13 19:30:08 +0000

    devel/php-composer: Update to 1.10.26

    PR:             263264
    Approved by:    Naram Qashat <cyberbotx@cyberbotx.com> (maintainer)
    MFH:            2022Q2
    Security:       24a9bd2b-bb43-11ec-af81-0897988a1c07

    (cherry picked from commit c4cee6e9be1b069f16529cc11d10a6212d8f3640)

 devel/php-composer/Makefile | 2 +-
 devel/php-composer/distinfo | 6 +++---
 2 files changed, 4 insertions(+), 4 deletions(-)
Comment 7 Guido Falsi freebsd_committer freebsd_triage 2022-04-13 19:34:18 UTC
Committed and merged to quarterly. Thanks!