Composer Dependency Changed PR-5.0-dev Pending

User tests: Successful: Unsuccessful:

avatar SniperSister
SniperSister
5 Dec 2023

Summary of Changes

Update phpseclib to 3.0.34 to fix https://nvd.nist.gov/vuln/detail/CVE-2023-49316.

Testing Instructions

Code review.

avatar SniperSister SniperSister - open - 5 Dec 2023
avatar SniperSister SniperSister - change - 5 Dec 2023
Status New Pending
avatar joomla-cms-bot joomla-cms-bot - change - 5 Dec 2023
Category External Library Composer Change
avatar richard67
richard67 - comment - 20 Dec 2023

This will also fix issue #42142 . See also my PR #42190 for that issue, which I've just closed in favour of this one here.

avatar richard67 richard67 - test_item - 20 Dec 2023 - Tested successfully
avatar richard67
richard67 - comment - 20 Dec 2023

I have tested this item ✅ successfully on 674f372

Tested by code review + verified that the URL is correct.

There is an additional change from "plugin-api-version": "2.6.0" to "plugin-api-version": "2.3.0", but that doesn't really matter, so I'm ok with it as it is, but would also be ok with reverting that change.


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/42469.

avatar richard67
richard67 - comment - 29 Dec 2023

@SniperSister Meanwhile there is a new release 3.0.35 available. Changelog see https://github.com/phpseclib/phpseclib/releases/tag/3.0.35 . Would it make sense to update this PR to that release?

avatar bembelimen bembelimen - change - 30 Dec 2023
Labels Added: Composer Dependency Changed PR-5.0-dev
avatar bembelimen bembelimen - change - 31 Dec 2023
Status Pending Fixed in Code Base
Closed_Date 0000-00-00 00:00:00 2023-12-31 08:09:34
Closed_By bembelimen
avatar bembelimen bembelimen - close - 31 Dec 2023
avatar bembelimen bembelimen - merge - 31 Dec 2023
avatar bembelimen
bembelimen - comment - 31 Dec 2023

Thx

Add a Comment

Login with GitHub to post a comment