Skip to content

fix(deps): bump league/commonmark to 2.10.0 (Dependabot security alerts) - #54

Merged
marianogoldman merged 1 commit into
mainfrom
fix/commonmark-security-advisories
Sep 2, 2026
Merged

marianogoldman merged 1 commit into
mainfrom
fix/commonmark-security-advisories

Conversation

@marianogoldman

Copy link
Copy Markdown
Contributor

What

Bumps league/commonmark 2.9.0 → 2.10.0 (plus nette/schema v1.3.5 → v1.3.6, pulled along by --with-all-dependencies).

composer.lock only — no composer.json change.

Alerts closed

All four open Dependabot alerts on the repo, all high severity, all league/commonmark:

# Vulnerable range First patched
46 >= 0.6.0, < 2.9.1 2.9.1
45 >= 1.5.0, < 2.10.0 2.10.0
44 >= 1.5.0, < 2.9.1 2.9.1
43 >= 2.7.0, < 2.9.1 2.9.1

Highest first_patched_version across the group is 2.10.0, so one bump clears all four.

Exposure

Transitive, and inert in practice:

  • composer why league/commonmark → laravel/framework v13.17.0 requires league/commonmark (^2.8.1)
  • It sits in the packages section of the lock, not packages-dev, because laravel/framework declares replace of illuminate/support and satisfies our production require. So "dev-only" would have been the wrong call here.
  • Nothing in src/, config/ or tests/ references CommonMark or Markdown rendering.

Why lock-only

This is a published library. Consumers resolve their own dependencies and never use our lock, so adding a require for a transitive package we don't use would push a constraint onto them for no benefit. If we ever needed to force consumers off a bad version, the right tool is conflict, not require.

Verification

  • composer audit → No security vulnerability advisories found.
  • composer lint → {"tool":"pint","result":"passed"}
  • composer test → Tests: 9, Assertions: 4, Errors: 4, Skipped: 1

The 4 errors are PayPalApiClient::__construct(): Argument #1 ($apiClientKey) must be of type string, null given — missing local PayPal credentials. Verified via git stash that main produces the identical result (Tests: 9, Assertions: 4, Errors: 4, Skipped: 1), so this is pre-existing and unrelated to the bump.

.github/workflows/php.yml supplies PAYPAL_API_CLIENT_ID / PAYPAL_API_CLIENT_SECRET, so CI is the real gate for the suite.

Closes Dependabot alerts #43, #44, #45 and #46 (all high severity,
league/commonmark). The highest first_patched_version across the four
advisories is 2.10.0, so a single bump clears all of them.

commonmark is a purely transitive dependency: laravel/framework requires
it (^2.8.1) and it lands in the production `packages` section of the lock
because laravel/framework replaces illuminate/support. No code in src/,
config/ or tests/ touches CommonMark, so the vulnerability is inert here.

Lock-only change on purpose: this is a published library, consumers do
not use our lock, and adding a require for a transitive package we do not
use would impose a constraint on them for no benefit.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@marianogoldman
marianogoldman merged commit e101901 into main Sep 2, 2026
1 check passed
@marianogoldman
marianogoldman deleted the fix/commonmark-security-advisories branch September 2, 2026 22:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant