-
-
Notifications
You must be signed in to change notification settings - Fork 3.7k
Bump php-saml to solve vulnerability #18380
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: develop
Are you sure you want to change the base?
Conversation
|
I'm not sure what went wrong here: I've enforced the dependency on 3.8.1, but 3.8.0 is taken anyway? 🤔 EDIT: Ok, I was missing the |
ec3b6c1 to
f983919
Compare
|
Hi there - thanks for this! Can you please re-target this PR to point to the You don't need to close and re-open. After you create a pull request, you can modify the base branch so that the changes in the pull request are compared against a different branch. By changing the base branch of your original pull request rather than opening a new one with the correct base branch, you’ll be able to keep valuable work and discussion. Thanks! |
|
I did that from mobile, but now this requires a rebase. I'll do it ASAP. |
f983919 to
eba3361
Compare
| "nunomaduro/collision": "^8.1", | ||
| "okvpn/clock-lts": "^1.0", | ||
| "onelogin/php-saml": "^3.4", | ||
| "onelogin/php-saml": "^3.8.1", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
You probably don't need to make this change as it is implied in the semver (at least I wouldn't, but maybe the maintainers would). 2¢
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes, I know. However, I don't see why I should skip it and risk someone downgrading it. Hence the bump.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Totally fair. This is more a personal quirk of mine than a strong opinion. I tend to normalize to ^3.0 since it makes diffs a bit easier to scan across projects, but I see where you're coming from.

Bumping php-saml to 3.8.1 due to GHSA-5j8p-438x-rgg5.
I took a look at your implementation and I've found no breaking change in the php-saml CHANGELOG.