Skip to content

FOUR-33162 - Fix High Security Vulnerabilities - #9053

Open
nolanpro wants to merge 3 commits into
developfrom
FOUR-33162
Open

FOUR-33162 - Fix High Security Vulnerabilities#9053
nolanpro wants to merge 3 commits into
developfrom
FOUR-33162

Conversation

@nolanpro

Copy link
Copy Markdown
Contributor

Summary

  • Ensure league/commonmark 2.10.0 in lockfile (fixes 4 high-severity GHSA advisories)
  • Builds on FOUR-33066 branch
  • Skipped: swagger-ui npm transitive deps (brace-expansion, immutable in vendor lockfile), theiconic/name-parser transitive guzzle/phpunit, swaggest/json-schema symfony/yaml, frankenphp grpc — require upstream or infra changes

Test plan

  • composer install succeeds
  • composer audit reports no advisories
  • Application tests pass

Made with Cursor

nolanpro and others added 3 commits September 3, 2026 17:01
Package is being deleted.

Co-authored-by: Cursor <cursoragent@cursor.com>
…VE fixes.

Co-authored-by: Cursor <cursoragent@cursor.com>
@decisions-sonarqube

Copy link
Copy Markdown

Quality Gate passed Quality Gate passed

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
No data about Duplication

See analysis details on SonarQube

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 7f4f59d. Configure here.

Comment thread composer.json
"package-irisbank": "dev-fall",
"package-pinnacle": "1.0.9",
"package-esign": "dev-fall",
"package-thermofisher": "dev-fall",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thermo Fisher package catalog entry removed

Medium Severity

package-thermofisher was dropped from extra.processmaker.custom in a security-only lockfile bump. LicensedPackageManifest builds its known-package list from that catalog, so this package is no longer license-gated or discoverable as a custom package, and any install pipeline that reads this list stops shipping it.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 7f4f59d. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant