laravel-adminpanel
laravel-adminpanel copied to clipboard
Bump composer/composer from 1.10.7 to 1.10.23
Bumps composer/composer from 1.10.7 to 1.10.23.
Release notes
Sourced from composer/composer's releases.
1.10.23
- Security: Fixed command injection vulnerability on Windows (GHSA-frqg-7g38-6gcf / CVE-2021-41116)
1.10.22
- Security: Fixed command injection vulnerability in HgDriver/HgDownloader and hardened other VCS drivers and downloaders (GHSA-h5h8-pc6h-jvvx / CVE-2021-29472)
1.10.21
- Fixed support for new GitHub OAuth token format
- Fixed processes silently ignoring the CWD when it does not exist
1.10.20
- Fixed exclude-from-classmap causing regex issues when having too many paths
- Fixed compatibility issue with Symfony 4/5
1.10.19
- Fixed regression on PHP 8.0
1.10.18
- Allow installation on PHP 8.0
1.10.17
- Fixed Bitbucket API authentication issue
- Fixed parsing of Composer 2 lock files breaking in some rare conditions
1.10.16
- Added warning to
validatecommand for cases where packages provide/replace a package that they also require- Fixed JSON schema validation issue with PHPStorm
- Fixed symlink handling in
archivecommand1.10.15
- Fixed path repo version guessing issue
1.10.14
- Fixed version guesser to look at remote branches as well as local ones
- Fixed path repositories version guessing to handle edge cases where version is different from the VCS-guessed version
- Fixed COMPOSER env var causing issues when combined with the
globalcommand- Fixed a few issues dealing with PHP without openssl extension (not recommended at all but sometimes needed for testing)
1.10.13
- Fixed regressions with old version validation
- Fixed invalid root aliases not being reported
1.10.12
- Fixed regressions with old version validation
1.10.11
- Fixed more PHP 8 compatibility issues
- Fixed regression in handling of CTRL-C when xdebug is loaded
- Fixed
statushandling of broken symlinks
... (truncated)
Changelog
Sourced from composer/composer's changelog.
[1.10.23] 2021-10-05
- Security: Fixed command injection vulnerability on Windows (GHSA-frqg-7g38-6gcf / CVE-2021-41116)
[1.10.22] 2021-04-27
- Security: Fixed command injection vulnerability in HgDriver/HgDownloader and hardened other VCS drivers and downloaders (GHSA-h5h8-pc6h-jvvx / CVE-2021-29472)
[1.10.21] 2021-04-01
- Fixed support for new GitHub OAuth token format
- Fixed processes silently ignoring the CWD when it does not exist
[1.10.20] 2021-01-27
- Fixed exclude-from-classmap causing regex issues when having too many paths
- Fixed compatibility issue with Symfony 4/5
[1.10.19] 2020-12-04
- Fixed regression on PHP 8.0
[1.10.18] 2020-12-03
- Allow installation on PHP 8.0
[1.10.17] 2020-10-30
- Fixed Bitbucket API authentication issue
- Fixed parsing of Composer 2 lock files breaking in some rare conditions
[1.10.16] 2020-10-24
- Added warning to
validatecommand for cases where packages provide/replace a package that they also require- Fixed JSON schema validation issue with PHPStorm
- Fixed symlink handling in
archivecommand[1.10.15] 2020-10-13
- Fixed path repo version guessing issue
[1.10.14] 2020-10-13
- Fixed version guesser to look at remote branches as well as local ones
- Fixed path repositories version guessing to handle edge cases where version is different from the VCS-guessed version
- Fixed COMPOSER env var causing issues when combined with the
globalcommand- Fixed a few issues dealing with PHP without openssl extension (not recommended at all but sometimes needed for testing)
[1.10.13] 2020-09-09
... (truncated)
Commits
eb3bae3Release 1.10.23ca5e2f8Fix escaping issues on Windows which could lead to command injection, fixes G...1a994e4Update deps32eb3b4Update depsa02802bWarn 1.x users when a package is not found that it may be due to our deprecat...cd682f9Update xdebug-handler to latest1cdbacbUpdate changelog083b735Merge pull request from GHSA-h5h8-pc6h-jvvx4dc293bUpdate changelog96acad1Update github token pattern to match their latest updates- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.
SonarCloud Quality Gate failed. 
0 Bugs
0 Vulnerabilities
0 Security Hotspots
0 Code Smells
No Coverage information
19.4% Duplication
A newer version of composer/composer exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.