User tests: Successful: Unsuccessful:
Update phpseclib to 3.0.34 to fix https://nvd.nist.gov/vuln/detail/CVE-2023-49316.
Code review.
Status | New | ⇒ | Pending |
Category | ⇒ | External Library Composer Change |
I have tested this item ✅ successfully on 674f372
Tested by code review + verified that the URL is correct.
There is an additional change from "plugin-api-version": "2.6.0"
to "plugin-api-version": "2.3.0"
, but that doesn't really matter, so I'm ok with it as it is, but would also be ok with reverting that change.
@SniperSister Meanwhile there is a new release 3.0.35 available. Changelog see https://github.com/phpseclib/phpseclib/releases/tag/3.0.35 . Would it make sense to update this PR to that release?
Labels |
Added:
Composer Dependency Changed
PR-5.0-dev
|
Status | Pending | ⇒ | Fixed in Code Base |
Closed_Date | 0000-00-00 00:00:00 | ⇒ | 2023-12-31 08:09:34 |
Closed_By | ⇒ | bembelimen |
Thx
This will also fix issue #42142 . See also my PR #42190 for that issue, which I've just closed in favour of this one here.