Commit 85a718c
Update dev dependencies for three security advisories
composer audit --locked failed on three development dependencies whose
advisories were published after the last green run:
- squizlabs/php_codesniffer 3.13.5 to 3.13.6 (CVE-2026-67434, OS command
injection, high)
- wp-coding-standards/wpcs 3.4.0 to 3.4.1 (CVE-2026-45293, arbitrary code
execution, high)
- phpcsstandards/phpcsutils 1.2.2 to 1.2.3 (CVE-2026-65954, arbitrary code
execution)
phpcsstandards/phpcsextra moved 1.5.0 to 1.5.1 as a dependency of that set.
All four resolve inside the existing composer.json constraints against the
declared PHP 7.4 platform, so no constraint changed.
Every affected package is require-dev and none is installed by the
production build, so the release archive is unchanged. lint, lint:php,
analyse, and unit stay green on the newer PHP_CodeSniffer and WPCS.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>1 parent 046be65 commit 85a718c
1 file changed
Lines changed: 23 additions & 23 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments