aboutsummaryrefslogtreecommitdiffhomepage
diff options
context:
space:
mode:
authorVirtualTam <virtualtam@flibidi.net>2019-01-18 21:35:11 +0100
committerVirtualTam <virtualtam@flibidi.net>2019-01-18 21:35:13 +0100
commit8f4e9624e6b512b5377faa5504b9710809b59ce6 (patch)
tree082bdef0fe1f7fdf8f872da34e509b8962a5f49c
parentff3b5dc5542ec150f0d9b447394364a15e9156d0 (diff)
downloadShaarli-8f4e9624e6b512b5377faa5504b9710809b59ce6.tar.gz
Shaarli-8f4e9624e6b512b5377faa5504b9710809b59ce6.tar.zst
Shaarli-8f4e9624e6b512b5377faa5504b9710809b59ce6.zip
composer: enforce PHP security advisories
This adds roave/security-advisories to prevent installing PHP packages with known vulnerabilities with Composer. See: - https://github.com/FriendsOfPHP/security-advisories - https://github.com/Roave/SecurityAdvisories Signed-off-by: VirtualTam <virtualtam@flibidi.net>
-rw-r--r--composer.json1
-rw-r--r--composer.lock219
2 files changed, 213 insertions, 7 deletions
diff --git a/composer.json b/composer.json
index a52b5f78..c23b8252 100644
--- a/composer.json
+++ b/composer.json
@@ -26,6 +26,7 @@
26 "gettext/gettext": "^4.4" 26 "gettext/gettext": "^4.4"
27 }, 27 },
28 "require-dev": { 28 "require-dev": {
29 "roave/security-advisories": "dev-master",
29 "phpunit/phpcov": "*", 30 "phpunit/phpcov": "*",
30 "phpunit/phpunit": "^5.0", 31 "phpunit/phpunit": "^5.0",
31 "squizlabs/php_codesniffer": "2.*" 32 "squizlabs/php_codesniffer": "2.*"
diff --git a/composer.lock b/composer.lock
index 53fb2175..5cbcbc4a 100644
--- a/composer.lock
+++ b/composer.lock
@@ -4,7 +4,7 @@
4 "Read more about it at https://getcomposer.org/doc/01-basic-usage.md#installing-dependencies", 4 "Read more about it at https://getcomposer.org/doc/01-basic-usage.md#installing-dependencies",
5 "This file is @generated automatically" 5 "This file is @generated automatically"
6 ], 6 ],
7 "content-hash": "f8965821c946c2a1271c3f8c7e8c6eea", 7 "content-hash": "432005c9db3e890f42fde27036d2a70f",
8 "packages": [ 8 "packages": [
9 { 9 {
10 "name": "arthurhoaro/web-thumbnailer", 10 "name": "arthurhoaro/web-thumbnailer",
@@ -689,16 +689,16 @@
689 }, 689 },
690 { 690 {
691 "name": "slim/slim", 691 "name": "slim/slim",
692 "version": "3.11.0", 692 "version": "3.12.0",
693 "source": { 693 "source": {
694 "type": "git", 694 "type": "git",
695 "url": "https://github.com/slimphp/Slim.git", 695 "url": "https://github.com/slimphp/Slim.git",
696 "reference": "d378e70431e78ee92ee32ddde61ecc72edf5dc0a" 696 "reference": "f4947cc900b6e51cbfda58b9f1247bca2f76f9f0"
697 }, 697 },
698 "dist": { 698 "dist": {
699 "type": "zip", 699 "type": "zip",
700 "url": "https://api.github.com/repos/slimphp/Slim/zipball/d378e70431e78ee92ee32ddde61ecc72edf5dc0a", 700 "url": "https://api.github.com/repos/slimphp/Slim/zipball/f4947cc900b6e51cbfda58b9f1247bca2f76f9f0",
701 "reference": "d378e70431e78ee92ee32ddde61ecc72edf5dc0a", 701 "reference": "f4947cc900b6e51cbfda58b9f1247bca2f76f9f0",
702 "shasum": "" 702 "shasum": ""
703 }, 703 },
704 "require": { 704 "require": {
@@ -756,7 +756,7 @@
756 "micro", 756 "micro",
757 "router" 757 "router"
758 ], 758 ],
759 "time": "2018-09-16T10:54:21+00:00" 759 "time": "2019-01-15T13:21:25+00:00"
760 } 760 }
761 ], 761 ],
762 "packages-dev": [ 762 "packages-dev": [
@@ -1470,6 +1470,210 @@
1470 "time": "2017-06-30T09:13:00+00:00" 1470 "time": "2017-06-30T09:13:00+00:00"
1471 }, 1471 },
1472 { 1472 {
1473 "name": "roave/security-advisories",
1474 "version": "dev-master",
1475 "source": {
1476 "type": "git",
1477 "url": "https://github.com/Roave/SecurityAdvisories.git",
1478 "reference": "d155baccb43ba2542941fbcba258b85ce7786419"
1479 },
1480 "dist": {
1481 "type": "zip",
1482 "url": "https://api.github.com/repos/Roave/SecurityAdvisories/zipball/d155baccb43ba2542941fbcba258b85ce7786419",
1483 "reference": "d155baccb43ba2542941fbcba258b85ce7786419",
1484 "shasum": ""
1485 },
1486 "conflict": {
1487 "3f/pygmentize": "<1.2",
1488 "adodb/adodb-php": "<5.20.12",
1489 "alterphp/easyadmin-extension-bundle": ">=1.2,<1.2.11|>=1.3,<1.3.1",
1490 "amphp/artax": "<1.0.6|>=2,<2.0.6",
1491 "amphp/http": "<1.0.1",
1492 "api-platform/core": ">=2.2,<2.2.10|>=2.3,<2.3.6",
1493 "asymmetricrypt/asymmetricrypt": ">=0,<9.9.99",
1494 "aws/aws-sdk-php": ">=3,<3.2.1",
1495 "brightlocal/phpwhois": "<=4.2.5",
1496 "bugsnag/bugsnag-laravel": ">=2,<2.0.2",
1497 "cakephp/cakephp": ">=1.3,<1.3.18|>=2,<2.4.99|>=2.5,<2.5.99|>=2.6,<2.6.12|>=2.7,<2.7.6|>=3,<3.0.15|>=3.1,<3.1.4|>=3.4,<3.4.14|>=3.5,<3.5.17|>=3.6,<3.6.4",
1498 "cart2quote/module-quotation": ">=4.1.6,<=4.4.5|>=5,<5.4.4",
1499 "cartalyst/sentry": "<=2.1.6",
1500 "codeigniter/framework": "<=3.0.6",
1501 "composer/composer": "<=1.0.0-alpha11",
1502 "contao-components/mediaelement": ">=2.14.2,<2.21.1",
1503 "contao/core": ">=2,<3.5.35",
1504 "contao/core-bundle": ">=4,<4.4.18|>=4.5,<4.5.8",
1505 "contao/listing-bundle": ">=4,<4.4.8",
1506 "contao/newsletter-bundle": ">=4,<4.1",
1507 "david-garcia/phpwhois": "<=4.3.1",
1508 "doctrine/annotations": ">=1,<1.2.7",
1509 "doctrine/cache": ">=1,<1.3.2|>=1.4,<1.4.2",
1510 "doctrine/common": ">=2,<2.4.3|>=2.5,<2.5.1",
1511 "doctrine/dbal": ">=2,<2.0.8|>=2.1,<2.1.2",
1512 "doctrine/doctrine-bundle": "<1.5.2",
1513 "doctrine/doctrine-module": "<=0.7.1",
1514 "doctrine/mongodb-odm": ">=1,<1.0.2",
1515 "doctrine/mongodb-odm-bundle": ">=2,<3.0.1",
1516 "doctrine/orm": ">=2,<2.4.8|>=2.5,<2.5.1",
1517 "dompdf/dompdf": ">=0.6,<0.6.2",
1518 "drupal/core": ">=7,<7.60|>=8,<8.5.8|>=8.6,<8.6.2",
1519 "drupal/drupal": ">=7,<7.60|>=8,<8.5.8|>=8.6,<8.6.2",
1520 "erusev/parsedown": "<1.7",
1521 "ezsystems/ezpublish-kernel": ">=5.3,<5.3.12.1|>=5.4,<5.4.13.1|>=6,<6.7.9.1|>=6.8,<6.13.5.1|>=7,<7.2.4.1|>=7.3,<7.3.2.1",
1522 "ezsystems/ezpublish-legacy": ">=5.3,<5.3.12.6|>=5.4,<5.4.12.3|>=2011,<2017.12.4.3|>=2018.6,<2018.6.1.4|>=2018.9,<2018.9.1.3",
1523 "ezsystems/repository-forms": ">=2.3,<2.3.2.1",
1524 "ezyang/htmlpurifier": "<4.1.1",
1525 "firebase/php-jwt": "<2",
1526 "fooman/tcpdf": "<6.2.22",
1527 "fossar/tcpdf-parser": "<6.2.22",
1528 "friendsofsymfony/rest-bundle": ">=1.2,<1.2.2",
1529 "friendsofsymfony/user-bundle": ">=1.2,<1.3.5",
1530 "fuel/core": "<1.8.1",
1531 "gree/jose": "<=2.2",
1532 "gregwar/rst": "<1.0.3",
1533 "guzzlehttp/guzzle": ">=6,<6.2.1|>=4.0.0-rc2,<4.2.4|>=5,<5.3.1",
1534 "illuminate/auth": ">=4,<4.0.99|>=4.1,<=4.1.31|>=4.2,<=4.2.22|>=5,<=5.0.35|>=5.1,<=5.1.46|>=5.2,<=5.2.45|>=5.3,<=5.3.31|>=5.4,<=5.4.36|>=5.5,<5.5.10",
1535 "illuminate/cookie": ">=4,<=4.0.11|>=4.1,<=4.1.31|>=4.2,<=4.2.22|>=5,<=5.0.35|>=5.1,<=5.1.46|>=5.2,<=5.2.45|>=5.3,<=5.3.31|>=5.4,<=5.4.36|>=5.5,<5.5.42|>=5.6,<5.6.30",
1536 "illuminate/database": ">=4,<4.0.99|>=4.1,<4.1.29",
1537 "illuminate/encryption": ">=4,<=4.0.11|>=4.1,<=4.1.31|>=4.2,<=4.2.22|>=5,<=5.0.35|>=5.1,<=5.1.46|>=5.2,<=5.2.45|>=5.3,<=5.3.31|>=5.4,<=5.4.36|>=5.5,<5.5.40|>=5.6,<5.6.15",
1538 "ivankristianto/phpwhois": "<=4.3",
1539 "james-heinrich/getid3": "<1.9.9",
1540 "joomla/session": "<1.3.1",
1541 "jsmitty12/phpwhois": "<5.1",
1542 "kazist/phpwhois": "<=4.2.6",
1543 "kreait/firebase-php": ">=3.2,<3.8.1",
1544 "la-haute-societe/tcpdf": "<6.2.22",
1545 "laravel/framework": ">=4,<4.0.99|>=4.1,<=4.1.31|>=4.2,<=4.2.22|>=5,<=5.0.35|>=5.1,<=5.1.46|>=5.2,<=5.2.45|>=5.3,<=5.3.31|>=5.4,<=5.4.36|>=5.5,<5.5.42|>=5.6,<5.6.30",
1546 "laravel/socialite": ">=1,<1.0.99|>=2,<2.0.10",
1547 "league/commonmark": ">=0.15.6,<0.18.1",
1548 "magento/magento1ce": "<1.9.4",
1549 "magento/magento1ee": ">=1.9,<1.14.4",
1550 "magento/product-community-edition": ">=2,<2.2.7",
1551 "monolog/monolog": ">=1.8,<1.12",
1552 "namshi/jose": "<2.2",
1553 "onelogin/php-saml": "<2.10.4",
1554 "openid/php-openid": "<2.3",
1555 "oro/crm": ">=1.7,<1.7.4",
1556 "oro/platform": ">=1.7,<1.7.4",
1557 "padraic/humbug_get_contents": "<1.1.2",
1558 "pagarme/pagarme-php": ">=0,<3",
1559 "paragonie/random_compat": "<2",
1560 "paypal/merchant-sdk-php": "<3.12",
1561 "pear/archive_tar": "<1.4.4",
1562 "phpmailer/phpmailer": ">=5,<5.2.27|>=6,<6.0.6",
1563 "phpoffice/phpexcel": "<=1.8.1",
1564 "phpoffice/phpspreadsheet": "<=1.5",
1565 "phpunit/phpunit": ">=4.8.19,<4.8.28|>=5.0.10,<5.6.3",
1566 "phpwhois/phpwhois": "<=4.2.5",
1567 "phpxmlrpc/extras": "<0.6.1",
1568 "propel/propel": ">=2.0.0-alpha1,<=2.0.0-alpha7",
1569 "propel/propel1": ">=1,<=1.7.1",
1570 "pusher/pusher-php-server": "<2.2.1",
1571 "robrichards/xmlseclibs": ">=1,<3.0.2",
1572 "sabre/dav": ">=1.6,<1.6.99|>=1.7,<1.7.11|>=1.8,<1.8.9",
1573 "sensiolabs/connect": "<4.2.3",
1574 "serluck/phpwhois": "<=4.2.6",
1575 "shopware/shopware": "<5.3.7",
1576 "silverstripe/cms": ">=3,<=3.0.11|>=3.1,<3.1.11",
1577 "silverstripe/forum": "<=0.6.1|>=0.7,<=0.7.3",
1578 "silverstripe/framework": ">=3,<3.3",
1579 "silverstripe/userforms": "<3",
1580 "simple-updates/phpwhois": "<=1",
1581 "simplesamlphp/saml2": "<1.10.6|>=2,<2.3.8|>=3,<3.1.4",
1582 "simplesamlphp/simplesamlphp": "<1.16.3",
1583 "simplesamlphp/simplesamlphp-module-infocard": "<1.0.1",
1584 "slim/slim": "<2.6",
1585 "smarty/smarty": "<3.1.33",
1586 "socalnick/scn-social-auth": "<1.15.2",
1587 "spoonity/tcpdf": "<6.2.22",
1588 "squizlabs/php_codesniffer": ">=1,<2.8.1|>=3,<3.0.1",
1589 "stormpath/sdk": ">=0,<9.9.99",
1590 "swiftmailer/swiftmailer": ">=4,<5.4.5",
1591 "sylius/admin-bundle": ">=1,<1.0.17|>=1.1,<1.1.9|>=1.2,<1.2.2",
1592 "sylius/sylius": ">=1,<1.0.17|>=1.1,<1.1.9|>=1.2,<1.2.2",
1593 "symfony/dependency-injection": ">=2,<2.0.17",
1594 "symfony/form": ">=2.3,<2.3.35|>=2.4,<2.6.12|>=2.7,<2.7.50|>=2.8,<2.8.49|>=3,<3.4.20|>=4,<4.0.15|>=4.1,<4.1.9|>=4.2,<4.2.1",
1595 "symfony/framework-bundle": ">=2,<2.3.18|>=2.4,<2.4.8|>=2.5,<2.5.2",
1596 "symfony/http-foundation": ">=2,<2.7.49|>=2.8,<2.8.44|>=3,<3.3.18|>=3.4,<3.4.14|>=4,<4.0.14|>=4.1,<4.1.3",
1597 "symfony/http-kernel": ">=2,<2.3.29|>=2.4,<2.5.12|>=2.6,<2.6.8",
1598 "symfony/intl": ">=2.7,<2.7.38|>=2.8,<2.8.31|>=3,<3.2.14|>=3.3,<3.3.13",
1599 "symfony/polyfill": ">=1,<1.10",
1600 "symfony/polyfill-php55": ">=1,<1.10",
1601 "symfony/routing": ">=2,<2.0.19",
1602 "symfony/security": ">=2,<2.7.50|>=2.8,<2.8.49|>=3,<3.4.19|>=4,<4.0.15|>=4.1,<4.1.9|>=4.2,<4.2.1",
1603 "symfony/security-bundle": ">=2,<2.7.48|>=2.8,<2.8.41|>=3,<3.3.17|>=3.4,<3.4.11|>=4,<4.0.11",
1604 "symfony/security-core": ">=2.4,<2.6.13|>=2.7,<2.7.9|>=2.7.30,<2.7.32|>=2.8,<2.8.37|>=3,<3.3.17|>=3.4,<3.4.7|>=4,<4.0.7",
1605 "symfony/security-csrf": ">=2.4,<2.7.48|>=2.8,<2.8.41|>=3,<3.3.17|>=3.4,<3.4.11|>=4,<4.0.11",
1606 "symfony/security-guard": ">=2.8,<2.8.41|>=3,<3.3.17|>=3.4,<3.4.11|>=4,<4.0.11",
1607 "symfony/security-http": ">=2.3,<2.3.41|>=2.4,<2.7.50|>=2.8,<2.8.49|>=3,<3.4.20|>=4,<4.0.15|>=4.1,<4.1.9|>=4.2,<4.2.1",
1608 "symfony/serializer": ">=2,<2.0.11",
1609 "symfony/symfony": ">=2,<2.7.50|>=2.8,<2.8.49|>=3,<3.4.20|>=4,<4.0.15|>=4.1,<4.1.9|>=4.2,<4.2.1",
1610 "symfony/translation": ">=2,<2.0.17",
1611 "symfony/validator": ">=2,<2.0.24|>=2.1,<2.1.12|>=2.2,<2.2.5|>=2.3,<2.3.3",
1612 "symfony/web-profiler-bundle": ">=2,<2.3.19|>=2.4,<2.4.9|>=2.5,<2.5.4",
1613 "symfony/yaml": ">=2,<2.0.22|>=2.1,<2.1.7",
1614 "tecnickcom/tcpdf": "<6.2.22",
1615 "thelia/backoffice-default-template": ">=2.1,<2.1.2",
1616 "thelia/thelia": ">=2.1.0-beta1,<2.1.3|>=2.1,<2.1.2",
1617 "theonedemon/phpwhois": "<=4.2.5",
1618 "titon/framework": ">=0,<9.9.99",
1619 "truckersmp/phpwhois": "<=4.3.1",
1620 "twig/twig": "<1.20",
1621 "typo3/cms": ">=6.2,<6.2.30|>=7,<7.6.32|>=8,<8.7.21|>=9,<9.5.2",
1622 "typo3/cms-core": ">=8,<8.7.21|>=9,<9.5.2",
1623 "typo3/flow": ">=1,<1.0.4|>=1.1,<1.1.1|>=2,<2.0.1|>=2.3,<2.3.16|>=3,<3.0.10|>=3.1,<3.1.7|>=3.2,<3.2.7|>=3.3,<3.3.5",
1624 "typo3/neos": ">=1.1,<1.1.3|>=1.2,<1.2.13|>=2,<2.0.4",
1625 "ua-parser/uap-php": "<3.8",
1626 "wallabag/tcpdf": "<6.2.22",
1627 "willdurand/js-translation-bundle": "<2.1.1",
1628 "yiisoft/yii": ">=1.1.14,<1.1.15",
1629 "yiisoft/yii2": "<2.0.15",
1630 "yiisoft/yii2-bootstrap": "<2.0.4",
1631 "yiisoft/yii2-dev": "<2.0.15",
1632 "yiisoft/yii2-elasticsearch": "<2.0.5",
1633 "yiisoft/yii2-gii": "<2.0.4",
1634 "yiisoft/yii2-jui": "<2.0.4",
1635 "yiisoft/yii2-redis": "<2.0.8",
1636 "zendframework/zend-cache": ">=2.4,<2.4.8|>=2.5,<2.5.3",
1637 "zendframework/zend-captcha": ">=2,<2.4.9|>=2.5,<2.5.2",
1638 "zendframework/zend-crypt": ">=2,<2.4.9|>=2.5,<2.5.2",
1639 "zendframework/zend-db": ">=2,<2.0.99|>=2.1,<2.1.99|>=2.2,<2.2.10|>=2.3,<2.3.5",
1640 "zendframework/zend-diactoros": ">=1,<1.8.4",
1641 "zendframework/zend-feed": ">=1,<2.10.3",
1642 "zendframework/zend-form": ">=2,<2.2.7|>=2.3,<2.3.1",
1643 "zendframework/zend-http": ">=1,<2.8.1",
1644 "zendframework/zend-json": ">=2.1,<2.1.6|>=2.2,<2.2.6",
1645 "zendframework/zend-ldap": ">=2,<2.0.99|>=2.1,<2.1.99|>=2.2,<2.2.8|>=2.3,<2.3.3",
1646 "zendframework/zend-mail": ">=2,<2.4.11|>=2.5,<2.7.2",
1647 "zendframework/zend-navigation": ">=2,<2.2.7|>=2.3,<2.3.1",
1648 "zendframework/zend-session": ">=2,<2.0.99|>=2.1,<2.1.99|>=2.2,<2.2.9|>=2.3,<2.3.4",
1649 "zendframework/zend-validator": ">=2.3,<2.3.6",
1650 "zendframework/zend-view": ">=2,<2.2.7|>=2.3,<2.3.1",
1651 "zendframework/zend-xmlrpc": ">=2.1,<2.1.6|>=2.2,<2.2.6",
1652 "zendframework/zendframework": "<2.5.1",
1653 "zendframework/zendframework1": "<1.12.20",
1654 "zendframework/zendopenid": ">=2,<2.0.2",
1655 "zendframework/zendxml": ">=1,<1.0.1",
1656 "zetacomponents/mail": "<1.8.2",
1657 "zf-commons/zfc-user": "<1.2.2",
1658 "zfcampus/zf-apigility-doctrine": ">=1,<1.0.3",
1659 "zfr/zfr-oauth2-server-module": "<0.1.2"
1660 },
1661 "type": "metapackage",
1662 "notification-url": "https://packagist.org/downloads/",
1663 "license": [
1664 "MIT"
1665 ],
1666 "authors": [
1667 {
1668 "name": "Marco Pivetta",
1669 "email": "ocramius@gmail.com",
1670 "role": "maintainer"
1671 }
1672 ],
1673 "description": "Prevents installation of composer packages with known security vulnerabilities: no API, simply require it",
1674 "time": "2019-01-15T19:39:37+00:00"
1675 },
1676 {
1473 "name": "sebastian/code-unit-reverse-lookup", 1677 "name": "sebastian/code-unit-reverse-lookup",
1474 "version": "1.0.1", 1678 "version": "1.0.1",
1475 "source": { 1679 "source": {
@@ -2544,7 +2748,8 @@
2544 "aliases": [], 2748 "aliases": [],
2545 "minimum-stability": "stable", 2749 "minimum-stability": "stable",
2546 "stability-flags": { 2750 "stability-flags": {
2547 "pubsubhubbub/publisher": 20 2751 "pubsubhubbub/publisher": 20,
2752 "roave/security-advisories": 20
2548 }, 2753 },
2549 "prefer-stable": false, 2754 "prefer-stable": false,
2550 "prefer-lowest": false, 2755 "prefer-lowest": false,