-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade xmlseclibs to version 3.0.4 #138
Conversation
CHANGELOG.md
Outdated
@@ -1,5 +1,10 @@ | |||
# Next release | |||
|
|||
# 1.2.3 | |||
This is a security release that will harden the application against CVE 2019-3465 | |||
* Implement countermeasures against CVE 2019-3465 #138 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The PR title does not match the actual title, should be: Upgrade xmlseclibs to version 3.0.4 #138
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
composer.lock
Outdated
@@ -1735,16 +1735,16 @@ | |||
}, | |||
{ | |||
"name": "simplesamlphp/saml2", | |||
"version": "v3.3.8", | |||
"version": "v3.4.2", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Consider not updating SAML2 for this release. Or identify this does not harm any current behaviour
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Reverted it and only updated xmlseclibs
This change will apply the countermeasures to harden against CVE 2019-3465 and will effectively bump `robrichards/xmlseclibs` to version 3.0.4.
Ant is no longer installed by default on the Travis platform. An explicit installtion instruction was added to achieve installation.
d4edbd1
to
3ff0fdf
Compare
This change will apply the countermeasures to harden against
CVE 2019-3465 and will effectively bump
robrichards/xmlseclibs
toversion 3.0.4.