Skip to content

Upgrade PHPUnit due to vulnerability

Low
glye published GHSA-pjj2-77xr-wwr7 Jul 29, 2022

Package

composer ibexa/templated-uri-bundle (Composer)

Affected versions

v2.1.*, v3.3.*

Patched versions

v2.1.0.2, v3.3.2.2

Description

This is only low priority in Ibexa DXP because 1) we use it in dev installs only (which should never be live), 2) we don't expose the vendor folder, and 3) due to higher requirements of other dependencies we don't install the affected phpunit versions in any case. So the main goal of this is just to close a Dependabot warning.

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs