chore(deps): bump league/commonmark 2.9.0 → 2.10.0 (GHSA-8rr7-cvq3-gmfh, WR-1256) - #72
Open
Goosterhof wants to merge 1 commit into
Open
chore(deps): bump league/commonmark 2.9.0 → 2.10.0 (GHSA-8rr7-cvq3-gmfh, WR-1256)#72Goosterhof wants to merge 1 commit into
Goosterhof wants to merge 1 commit into
Conversation
HIGH DoS advisory PKSA-zyf5-hrxv-hrd7, affected >=1.5.0,<2.10.0. commonmark is a PRODUCTION dependency here (illuminate/mail in require), so the audit-gated release lane was blocked. Lockfile-only. WR-1256. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
league/commonmarkGHSA-8rr7-cvq3-gmfh — HIGH, denial of service via distinctly-named attributes; affected>=1.5.0,<2.10.0; reported 2026-09-01. This package was on 2.9.0.commonmark is a production dependency here —
illuminate/mailsits inrequire, so the lock places commonmark inpackages, notpackages-dev— which meanscomposer auditreds even under--no-devand the audit-gated release lane cannot cut a tag until this lands (the WR-0796 shape). Transitive, so Dependabot opens no PR (and security updates are off on the package repos — WR-0819). Found by the 2026-09-07/stack-drain depspass; WR-1256.What
composer.lockonly: commonmark 2.9.0 → 2.10.0. No rule source touched. Deliberately separate from #71.Verified
composer update league/commonmarkresolved as a single-package upgrade (no cascade).composer audit→ No security vulnerability advisories found.🤖 Generated with Claude Code