Re: Disable PEAR by default

From: Date: Sat, 02 Feb 2019 17:59:57 +0000
Subject: Re: Disable PEAR by default
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-104034@lists.php.net to get a copy of this message
On 02/02/2019 01:08, Alice Wonder wrote:
That version has vulnerability, developer fixed it in newer release, but composer keeps pulling in the older version because that is what composer provides.
Have you seen https://packagist.phpcomposer.com/packages/roave/security-advisories ? It's a very simple composer package which lists packages with known vulnerabilities as incompatible, so that composer will skip them even if it means downgrading to meet the constraints of other packages you've requested. I'm not sure what other solution any package manager could provide, other than allowing you to install any version you liked, even if the authors stated that they were incompatible. Regards, -- Rowan Collins [IMSoP]

« previous php.internals (#104034) next »