Skip to content

chore(deps): fix Dependabot security alerts (guzzle, commonmark) - #52

Merged
marianogoldman merged 1 commit into
masterfrom
chore/dependabot-security-updates
Aug 9, 2026
Merged

marianogoldman merged 1 commit into
masterfrom
chore/dependabot-security-updates

Conversation

@marianogoldman

Copy link
Copy Markdown
Contributor

Closes all 12 open Dependabot alerts.

Changes (composer.lock only)

Package From To Alerts
guzzlehttp/guzzle 7.12.3 7.15.3 6 (#31–#36)
league/commonmark 2.8.2 2.9.0 6 (#37–#42)
guzzlehttp/psr7 2.12.3 2.13.0 transitive
guzzlehttp/promises 2.5.0 2.5.2 transitive
nette/utils v4.1.4 v4.1.5 transitive

Both are transitive dependencies of laravel/framework, so no composer.json change was needed — composer update guzzlehttp/guzzle guzzlehttp/psr7 league/commonmark --with-all-dependencies.

Verification

  • composer audit → No security vulnerability advisories found.
  • composer lint (Pint) → passed
  • composer test → 9 tests, 4 errors, 1 skipped — identical before and after the update. The errors are pre-existing and caused by missing PayPal credentials locally (config('paypal.client_id') is null); CI supplies them via secrets.

🤖 Generated with Claude Code

Resolves all 12 open Dependabot alerts:

- guzzlehttp/guzzle 7.12.3 => 7.15.3 (7 advisories: noncanonical host
  bypass, cookie domain/scope issues, Referer fragment disclosure,
  unbounded response cookies, Proxy-Authorization leak)
- league/commonmark 2.8.2 => 2.9.0 (6 advisories: quadratic-time and
  other DoS vectors, unsafe-link filter bypass)

Pulled in as transitive updates: guzzlehttp/promises 2.5.2,
guzzlehttp/psr7 2.13.0, nette/utils v4.1.5.

`composer audit` reports no advisories. Pint passes. Test results are
unchanged (the 4 errors are pre-existing and come from missing PayPal
credentials in the local environment).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@marianogoldman
marianogoldman merged commit 5c30449 into master Aug 9, 2026
1 check passed
@marianogoldman
marianogoldman deleted the chore/dependabot-security-updates branch August 9, 2026 12:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant