|
|
Log in / Subscribe / Register

Fedora alert FEDORA-2026-9b34a78e81 (composer)

From:  updates--- via package-announce <package-announce@lists.fedoraproject.org>
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 44 Update: composer-2.10.1-1.fc44
Date:  Sat, 13 Jun 2026 01:13:08 +0000
Message-ID:  <20260613011308.883BB70BC5@bastion01.rdu3.fedoraproject.org>
Archive-link:  Article

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9b34a78e81 2026-06-13 01:09:32.029641+00:00 -------------------------------------------------------------------------------- Name : composer Product : Fedora 44 Version : 2.10.1 Release : 1.fc44 URL : https://getcomposer.org/ Summary : Dependency Manager for PHP Description : Composer helps you declare, manage and install dependencies of PHP projects, ensuring you have the right stack everywhere. Documentation: https://getcomposer.org/doc/ -------------------------------------------------------------------------------- Update Information: Version 2.10.1 - 2026-06-04 Security: Fixed shell escaping when opening an editor (#12903) Security: Verify backup phar signature before restoring it when using self- update --rollback (#12918) Fixed source-fallback also disabling fallbacks to dist install when source is the preferred install method (#12888) Fixed source -> dist package updates wiping the .git dir without checking for local changes first (#12912) Fixed GitHub token prompt happening multiple times on parallel auth failures (#12913) Fixed warnings from Composer repositories being printed twice in some cases (#12907) Version 2.10.0 Read the Composer 2.10 Release Announcement for more details on the release highlights. Full Changelog BC Break / Security: Disabled automatic fallback to source checkout if dist/zip install fails, we have introduced a new source-fallback config option as a temporary way to restore the old behavior, but if you need this talk to us as we plan to remove it entirely in 2.11 (#12885) BC Break: Minor break for audit consumers, the exit code is now always 0 (success) or 1 if anything failed the audit (#12881) Security: Added dependency policies to block package versions where malware was detected on update/install or report it with audit (#12786) Security: Hardened output filtering of URLs to reduce chances of token leaks (#12882, #12886) Security: Fixed handling of uppercase schemes in URL validation that might have allowed https requirement bypass (#12884) Security: Fixed git credentials remaining in git mirror .git/config after clone or update failed (2bcbfc3) Security: Fixed usage of insecure 3DES ciphers when ext-curl is missing (5e71d77) Security: Enforce allow-plugins even in non-interactive mode for very old pre-2.2 lock files (#12764) Added support for temporary --with constraints with wildcards in the package name for the update command (#12658) Added --strict-psr-autoloader flag to install and update commands (#12647) Added source-fallback config option to disable or enable source fallback on download failure (#12698) Added --require parameter to create-project to add new packages to the project as it gets installed (#12738) Optimized plugin autoloading by avoiding regenerating classmaps for every package per plugin (#12696) Optimized PoolOptimizer memory usage (#12783) Optimized classmap dumping performance Deprecated most of the audit config in favor of the new policy one (#12804, see #12786 for the RFC and upgrade docs) Fixed update --bump-after-update to only bump packages that actually were updated (#12733) Fixed GitHub API authentication errors not being visible to the user (#12737) Fixed error reporting for clarity when a constraint cannot be parsed (#12743) Fixed warning being shown when lock file is disabled (#12760) Fixed inconsistent treatment of SingleCommandApplication script commands wrt autoloading (#12758) Fixed some platform package parsing failing when Composer runs in web SAPIs (#12735) Fixed audit command returning a success code when the vendor dir was not present (#12880) -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 4 2026 Remi Collet <remi@remirepo.net> - 2.10.1-1 - update to 2.10.1 * Thu May 28 2026 Remi Collet <remi@remirepo.net> - 2.10.0-1 - update to 2.10.0 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9b34a78e81' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds