Repository navigation
fix(deps): bump league/commonmark to 2.10.0 (Dependabot security alerts) - #54
Merged
Merged
Conversation
Closes Dependabot alerts #43, #44, #45 and #46 (all high severity, league/commonmark). The highest first_patched_version across the four advisories is 2.10.0, so a single bump clears all of them. commonmark is a purely transitive dependency: laravel/framework requires it (^2.8.1) and it lands in the production `packages` section of the lock because laravel/framework replaces illuminate/support. No code in src/, config/ or tests/ touches CommonMark, so the vulnerability is inert here. Lock-only change on purpose: this is a published library, consumers do not use our lock, and adding a require for a transitive package we do not use would impose a constraint on them for no benefit. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Bumps
league/commonmark2.9.0 → 2.10.0 (plusnette/schemav1.3.5 → v1.3.6, pulled along by--with-all-dependencies).composer.lockonly — nocomposer.jsonchange.Alerts closed
All four open Dependabot alerts on the repo, all high severity, all
league/commonmark:>= 0.6.0, < 2.9.1>= 1.5.0, < 2.10.0>= 1.5.0, < 2.9.1>= 2.7.0, < 2.9.1Highest
first_patched_versionacross the group is 2.10.0, so one bump clears all four.Exposure
Transitive, and inert in practice:
composer why league/commonmark→laravel/framework v13.17.0 requires league/commonmark (^2.8.1)packagessection of the lock, notpackages-dev, becauselaravel/frameworkdeclaresreplaceofilluminate/supportand satisfies our production require. So "dev-only" would have been the wrong call here.src/,config/ortests/references CommonMark or Markdown rendering.Why lock-only
This is a published library. Consumers resolve their own dependencies and never use our lock, so adding a
requirefor a transitive package we don't use would push a constraint onto them for no benefit. If we ever needed to force consumers off a bad version, the right tool isconflict, notrequire.Verification
composer audit→ No security vulnerability advisories found.composer lint→{"tool":"pint","result":"passed"}composer test→Tests: 9, Assertions: 4, Errors: 4, Skipped: 1The 4 errors are
PayPalApiClient::__construct(): Argument #1 ($apiClientKey) must be of type string, null given— missing local PayPal credentials. Verified viagit stashthat main produces the identical result (Tests: 9, Assertions: 4, Errors: 4, Skipped: 1), so this is pre-existing and unrelated to the bump..github/workflows/php.ymlsuppliesPAYPAL_API_CLIENT_ID/PAYPAL_API_CLIENT_SECRET, so CI is the real gate for the suite.