Skip to content

chore(deps): bump league/commonmark 2.9.0 → 2.10.0 (GHSA-8rr7-cvq3-gmfh, WR-1256) - #72

Open
Goosterhof wants to merge 1 commit into
mainfrom
chore/commonmark-2.10-ghsa-8rr7
Open

chore(deps): bump league/commonmark 2.9.0 → 2.10.0 (GHSA-8rr7-cvq3-gmfh, WR-1256)#72
Goosterhof wants to merge 1 commit into
mainfrom
chore/commonmark-2.10-ghsa-8rr7

Conversation

@Goosterhof

Copy link
Copy Markdown
Contributor

Why

league/commonmark GHSA-8rr7-cvq3-gmfh — HIGH, denial of service via distinctly-named attributes; affected >=1.5.0,<2.10.0; reported 2026-09-01. This package was on 2.9.0.

commonmark is a production dependency here — illuminate/mail sits in require, so the lock places commonmark in packages, not packages-dev — which means composer audit reds even under --no-dev and the audit-gated release lane cannot cut a tag until this lands (the WR-0796 shape). Transitive, so Dependabot opens no PR (and security updates are off on the package repos — WR-0819). Found by the 2026-09-07 /stack-drain deps pass; WR-1256.

What

composer.lock only: commonmark 2.9.0 → 2.10.0. No rule source touched. Deliberately separate from #71.

Verified

  • composer update league/commonmark resolved as a single-package upgrade (no cascade).
  • composer auditNo security vulnerability advisories found.
  • Local pre-commit + pre-push gates green.

🤖 Generated with Claude Code

HIGH DoS advisory PKSA-zyf5-hrxv-hrd7, affected >=1.5.0,<2.10.0. commonmark is a PRODUCTION dependency here (illuminate/mail in require), so the audit-gated release lane was blocked. Lockfile-only. WR-1256.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Agent Review Requested Requesting review of specialized AI review agents.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant