Skip to content

chore(deps): exclude vulnerable PHPUnit versions - #243

Merged
DASPRiD merged 1 commit into
Bacon:mainfrom
ricande:chore/phpunit-security-minimums
Sep 16, 2026
Merged

DASPRiD merged 1 commit into
Bacon:mainfrom
ricande:chore/phpunit-security-minimums

Conversation

@ricande

@ricande ricande commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Summary

require-dev currently allows PHPUnit versions covered by GHSA-vvj3-c3rp-c85p / CVE-2026-24765:

"phpunit/phpunit": "^10.5.11 || ^11.0.4"

Those ranges include PHPUnit 10 < 10.5.62 and PHPUnit 11 < 11.5.50.

This change only raises the minima inside the already-supported majors:

"phpunit/phpunit": "^10.5.63 || ^11.5.50"
  • PHPUnit 11.5.50 is the first patched 11.x release.
  • PHPUnit 10.5.63 is the published 10.x release that includes the fix (advisory lists 10.5.62 as the first patched 10.x version).
  • The PHPUnit 10 alternative is kept so the library can still run tests on PHP 8.1.

No runtime / production dependencies change. There is no lockfile in this repository, and this PR does not add one.

Scope of the vulnerability

The advisory is in PHPUnit's PHPT code-coverage handling (cleanupForCoverage() deserializes a pre-existing .coverage file). It is not a vulnerability in BaconQrCode QR generation, and this change does not claim that BaconQrCode (or any storefront that uses it) is exploitable through QR output.

Validation

  • composer validate --strict — ./composer.json is valid
  • Library tests were already run on an earlier checkout of this same one-line change (d169414e262c65b909f4430f634cb8834b7d28cd):
    • PHP 8.3.6 + PHPUnit 11.5.56 — 175 tests / 79782 assertions (pixelmatch)
    • PHP 8.1.34 + PHPUnit 10.5.64 — 175 tests / 79782 assertions (pixelmatch)

This environment only has PHP 8.5.4, so those PHP 8.1 / 8.3 suites were not re-run here. Upstream CI on this PR covers PHP 8.1–8.5.

Exclude PHPUnit versions covered by GHSA-vvj3-c3rp-c85p
within the already-supported 10 and 11 majors.
@DASPRiD
DASPRiD merged commit c0c9671 into Bacon:main Sep 16, 2026
7 checks passed
@codecov

codecov Bot commented Sep 16, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 71.72%. Comparing base (4da2233) to head (df2baee).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff            @@
##               main     #243   +/-   ##
=========================================
  Coverage     71.72%   71.72%           
  Complexity      999      999           
=========================================
  Files            49       49           
  Lines          3158     3158           
=========================================
  Hits           2265     2265           
  Misses          893      893           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants