Skip to content

Ignore CVE-2026-24765 in Composer's audit#7300

Closed
derrabus wants to merge 1 commit intodoctrine:4.4.xfrom
derrabus:chore/ignore-phpt-deserialization-vuln
Closed

Ignore CVE-2026-24765 in Composer's audit#7300
derrabus wants to merge 1 commit intodoctrine:4.4.xfrom
derrabus:chore/ignore-phpt-deserialization-vuln

Conversation

@derrabus
Copy link
Member

Q A
Type chore
Fixed issues #7297

Summary

Composer complains about the PHPUnit version in use because a vulnerability has been discovered (GHSA-vvj3-c3rp-c85p). However, upgrading is complicated for us at the moment (see #7190). Also, I'm pretty certain that this vulnerability does not affect us. Therefore, I'd like to ignore this report in order to unblock the CI for us.

@greg0ire
Copy link
Member

However, upgrading is complicated for us at the moment

What's complicated about ac48e86 ?

@derrabus
Copy link
Member Author

Seems to do the trick. 🤔 Great, thanks for fixing this. 🥳

@derrabus derrabus closed this Jan 30, 2026
@derrabus derrabus deleted the chore/ignore-phpt-deserialization-vuln branch January 30, 2026 08:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants