Composer Dependency Changed ? Pending

User tests: Successful: Unsuccessful:

avatar PhilETaylor
PhilETaylor
17 Dec 2021

Composer 2.2 brings with it new security features, one of these is to disable composer plugins for security with allow-plugins

Composer 2.2 will be a LTS Version

Use composer self-update --preview to try the latest prerelease version to test this PR.
Use composer self-update --stable to go back to stable releases..

https://github.com/composer/composer/releases/tag/2.2.0-RC1
https://getcomposer.org/doc/06-config.md#allow-plugins

When installing Joomla 4 using composer 2.2 you will get this:

Screenshot 2021-12-17 at 16 31 31

Composer plugins should be disabled by default, unless there is a compelling reason for them to run.

Unless this PR is merged, you will be asked each time if you want to run this plugin or not.

avatar PhilETaylor PhilETaylor - open - 17 Dec 2021
avatar PhilETaylor PhilETaylor - change - 17 Dec 2021
Status New Pending
avatar joomla-cms-bot joomla-cms-bot - change - 17 Dec 2021
Category External Library Composer Change
avatar PhilETaylor PhilETaylor - change - 18 Dec 2021
Title
[4.1] Disable Composer plugins - dealerdirect/phpcodesniffer-composer-installer
[4.1] Enable Composer plugins - dealerdirect/phpcodesniffer-composer-installer
avatar PhilETaylor PhilETaylor - edited - 18 Dec 2021
avatar PhilETaylor PhilETaylor - change - 18 Dec 2021
Labels Added: Composer Dependency Changed ?
avatar PhilETaylor
PhilETaylor - comment - 22 Dec 2021

Composer 2.2 has now been released

https://blog.packagist.com/composer-2-2/

avatar HLeithner
HLeithner - comment - 28 Dec 2021

can you redo this for 4.0 or should I do it by my self?

avatar Quy
Quy - comment - 8 Jan 2022

This will be upmerged from 43a8fb0. Thanks!

avatar Quy Quy - change - 8 Jan 2022
Status Pending Closed
Closed_Date 0000-00-00 00:00:00 2022-01-08 22:43:32
Closed_By Quy
avatar Quy Quy - close - 8 Jan 2022

Add a Comment

Login with GitHub to post a comment