Skip to content

Require patched Guzzle and PHPUnit versions, and prepare 3.0.1 - #13

Open
MudassarTariq wants to merge 2 commits into
masterfrom
fix/security-dependencies
Open

MudassarTariq wants to merge 2 commits into
masterfrom
fix/security-dependencies

Conversation

@MudassarTariq

Copy link
Copy Markdown
Member

What

This raises the minimum versions of two dependencies so installs can no longer pick releases with known security vulnerabilities. It also prepares release 3.0.1.

Package Constraint
guzzlehttp/guzzle ^7.8 → ^7.15.2
phpunit/phpunit (dev) ^10.5 → ^10.5.62
  • No code changes. The release commit bumps Version::VERSION (used in the User-Agent) to 3.0.1 and adds a CHANGELOG entry.
  • php ^8.1 is unchanged. Guzzle 7.15.2 supports PHP 7.2.5+ and 8.x, and PHPUnit 10.5.62 supports PHP 8.1+.

Security

No functional change: verification

Check Before After
composer validate valid valid
Fresh composer update (70 packages) guzzle 7.15.5, phpunit 10.5.65 same 70 package versions
phpunit --exclude-group live (latest dependencies) OK, 24 tests OK, 24 tests
composer update --prefer-lowest + unit tests OK, 24 tests on guzzle 7.15.2 and phpunit 10.5.62
composer audit no advisories no advisories

Because a fresh install resolves exactly the same packages as before, and the SDK code is unchanged, the runtime behavior is identical. The only difference in 3.0.1 is the User-Agent version string (3.0.0 → 3.0.1).

The CI matrix (PHP 8.1, 8.2 and 8.3) runs on this PR. Locally I tested on PHP 8.5.

Raises the minimum guzzlehttp/guzzle from 7.8 to 7.15.2 and the dev dependency phpunit/phpunit from 10.5 to 10.5.62. Guzzle releases below 7.15.2 have up to 9 security advisories (CVE-2026-55568, CVE-2026-55767, CVE-2026-59883, CVE-2026-67339, CVE-2026-67353, CVE-2026-67354, CVE-2026-67355, CVE-2026-69245, CVE-2026-69246), and PHPUnit below 10.5.62 has CVE-2026-24765. Fresh installs already resolve the same package versions as before. No code changes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant