Skip to content

Conversation

@Serializator
Copy link

No description provided.

@igorwulff
Copy link

igorwulff commented Apr 28, 2021

Can you also include support for 1.10.22 which fixes an security issue:
https://github.com/composer/composer/releases/tag/1.10.22

Security: Fixed command injection vulnerability in HgDriver/HgDownloader and hardened other VCS drivers and downloaders (GHSA-h5h8-pc6h-jvvx / CVE-2021-29472)

EDIT I see this issue is also already in PR for looser restrictions #25

@pdohogne-magento
Copy link
Contributor

Addressed in #25, released in version 1.1.2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants