Update the coding-standards tooling off three security advisories
CI / Coding Standards (pull_request) Successful in 16s
CI / No Debug Code (pull_request) Successful in 4s
CI / Tests (PHP 8.3) (pull_request) Successful in 21s
CI / Tests (PHP 8.5) (pull_request) Successful in 22s
CI / Tests (PHP 8.2) (pull_request) Successful in 48s
CI / Tests (PHP 8.1) (pull_request) Successful in 49s
CI / Static Analysis (pull_request) Successful in 57s
CI / Build Plugin Zip (pull_request) Skipped
CI / Coding Standards (pull_request) Successful in 16s
CI / No Debug Code (pull_request) Successful in 4s
CI / Tests (PHP 8.3) (pull_request) Successful in 21s
CI / Tests (PHP 8.5) (pull_request) Successful in 22s
CI / Tests (PHP 8.2) (pull_request) Successful in 48s
CI / Tests (PHP 8.1) (pull_request) Successful in 49s
CI / Static Analysis (pull_request) Successful in 57s
CI / Build Plugin Zip (pull_request) Skipped
composer audit reported three advisories against the PHPCS stack, two rated high: squizlabs/php_codesniffer 3.13.5 -> 3.13.6 CVE-2026-67434, OS command injection wp-coding-standards/wpcs 3.3.0 -> 3.4.1 CVE-2026-45293, arbitrary code execution phpcsstandards/phpcsutils 1.2.2 -> 1.2.3 CVE-2026-65954, arbitrary code execution All three are dev-only and none ship in the plugin — bin/build-zip.sh installs --no-dev — but they execute against repository content on every CI run. The existing ^3.7 and ^3.0 constraints already allowed the fixed releases, so composer.json is unchanged. phpcsextra and the codesniffer installer come along as transitive dependencies. Five packages move, none are added or removed, and the updated standards report no new violations. composer audit is now clean. Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01D9acV1mHktGAb1uyvNmrR2
This commit is contained in:
Generated
+29
-29
@@ -187,16 +187,16 @@
|
||||
},
|
||||
{
|
||||
"name": "dealerdirect/phpcodesniffer-composer-installer",
|
||||
"version": "v1.2.0",
|
||||
"version": "v1.2.1",
|
||||
"source": {
|
||||
"type": "git",
|
||||
"url": "https://github.com/PHPCSStandards/composer-installer.git",
|
||||
"reference": "845eb62303d2ca9b289ef216356568ccc075ffd1"
|
||||
"reference": "963f0c67bffde0eac41b56be71ac0e8ba132f0bd"
|
||||
},
|
||||
"dist": {
|
||||
"type": "zip",
|
||||
"url": "https://api.github.com/repos/PHPCSStandards/composer-installer/zipball/845eb62303d2ca9b289ef216356568ccc075ffd1",
|
||||
"reference": "845eb62303d2ca9b289ef216356568ccc075ffd1",
|
||||
"url": "https://api.github.com/repos/PHPCSStandards/composer-installer/zipball/963f0c67bffde0eac41b56be71ac0e8ba132f0bd",
|
||||
"reference": "963f0c67bffde0eac41b56be71ac0e8ba132f0bd",
|
||||
"shasum": ""
|
||||
},
|
||||
"require": {
|
||||
@@ -279,7 +279,7 @@
|
||||
"type": "thanks_dev"
|
||||
}
|
||||
],
|
||||
"time": "2025-11-11T04:32:07+00:00"
|
||||
"time": "2026-05-06T08:26:05+00:00"
|
||||
},
|
||||
{
|
||||
"name": "hamcrest/hamcrest-php",
|
||||
@@ -705,21 +705,21 @@
|
||||
},
|
||||
{
|
||||
"name": "phpcsstandards/phpcsextra",
|
||||
"version": "1.5.0",
|
||||
"version": "1.5.1",
|
||||
"source": {
|
||||
"type": "git",
|
||||
"url": "https://github.com/PHPCSStandards/PHPCSExtra.git",
|
||||
"reference": "b598aa890815b8df16363271b659d73280129101"
|
||||
"reference": "39467533fdb742446d68c1d10ac33d625ee0311c"
|
||||
},
|
||||
"dist": {
|
||||
"type": "zip",
|
||||
"url": "https://api.github.com/repos/PHPCSStandards/PHPCSExtra/zipball/b598aa890815b8df16363271b659d73280129101",
|
||||
"reference": "b598aa890815b8df16363271b659d73280129101",
|
||||
"url": "https://api.github.com/repos/PHPCSStandards/PHPCSExtra/zipball/39467533fdb742446d68c1d10ac33d625ee0311c",
|
||||
"reference": "39467533fdb742446d68c1d10ac33d625ee0311c",
|
||||
"shasum": ""
|
||||
},
|
||||
"require": {
|
||||
"php": ">=5.4",
|
||||
"phpcsstandards/phpcsutils": "^1.2.0",
|
||||
"phpcsstandards/phpcsutils": "^1.2.3",
|
||||
"squizlabs/php_codesniffer": "^3.13.5 || ^4.0.1"
|
||||
},
|
||||
"require-dev": {
|
||||
@@ -783,20 +783,20 @@
|
||||
"type": "thanks_dev"
|
||||
}
|
||||
],
|
||||
"time": "2025-11-12T23:06:57+00:00"
|
||||
"time": "2026-07-27T11:13:17+00:00"
|
||||
},
|
||||
{
|
||||
"name": "phpcsstandards/phpcsutils",
|
||||
"version": "1.2.2",
|
||||
"version": "1.2.3",
|
||||
"source": {
|
||||
"type": "git",
|
||||
"url": "https://github.com/PHPCSStandards/PHPCSUtils.git",
|
||||
"reference": "c216317e96c8b3f5932808f9b0f1f7a14e3bbf55"
|
||||
"reference": "5f35d9408c54d7b529501f3c688b6eae562aea1f"
|
||||
},
|
||||
"dist": {
|
||||
"type": "zip",
|
||||
"url": "https://api.github.com/repos/PHPCSStandards/PHPCSUtils/zipball/c216317e96c8b3f5932808f9b0f1f7a14e3bbf55",
|
||||
"reference": "c216317e96c8b3f5932808f9b0f1f7a14e3bbf55",
|
||||
"url": "https://api.github.com/repos/PHPCSStandards/PHPCSUtils/zipball/5f35d9408c54d7b529501f3c688b6eae562aea1f",
|
||||
"reference": "5f35d9408c54d7b529501f3c688b6eae562aea1f",
|
||||
"shasum": ""
|
||||
},
|
||||
"require": {
|
||||
@@ -876,7 +876,7 @@
|
||||
"type": "thanks_dev"
|
||||
}
|
||||
],
|
||||
"time": "2025-12-08T14:27:58+00:00"
|
||||
"time": "2026-07-27T10:28:41+00:00"
|
||||
},
|
||||
{
|
||||
"name": "phpstan/phpstan",
|
||||
@@ -2327,16 +2327,16 @@
|
||||
},
|
||||
{
|
||||
"name": "squizlabs/php_codesniffer",
|
||||
"version": "3.13.5",
|
||||
"version": "3.13.6",
|
||||
"source": {
|
||||
"type": "git",
|
||||
"url": "https://github.com/PHPCSStandards/PHP_CodeSniffer.git",
|
||||
"reference": "0ca86845ce43291e8f5692c7356fccf3bcf02bf4"
|
||||
"reference": "4c378e1a528ea066890fc2397cbdd2f94eb2fc91"
|
||||
},
|
||||
"dist": {
|
||||
"type": "zip",
|
||||
"url": "https://api.github.com/repos/PHPCSStandards/PHP_CodeSniffer/zipball/0ca86845ce43291e8f5692c7356fccf3bcf02bf4",
|
||||
"reference": "0ca86845ce43291e8f5692c7356fccf3bcf02bf4",
|
||||
"url": "https://api.github.com/repos/PHPCSStandards/PHP_CodeSniffer/zipball/4c378e1a528ea066890fc2397cbdd2f94eb2fc91",
|
||||
"reference": "4c378e1a528ea066890fc2397cbdd2f94eb2fc91",
|
||||
"shasum": ""
|
||||
},
|
||||
"require": {
|
||||
@@ -2402,7 +2402,7 @@
|
||||
"type": "thanks_dev"
|
||||
}
|
||||
],
|
||||
"time": "2025-11-04T16:30:35+00:00"
|
||||
"time": "2026-08-06T00:17:32+00:00"
|
||||
},
|
||||
{
|
||||
"name": "szepeviktor/phpstan-wordpress",
|
||||
@@ -2519,16 +2519,16 @@
|
||||
},
|
||||
{
|
||||
"name": "wp-coding-standards/wpcs",
|
||||
"version": "3.3.0",
|
||||
"version": "3.4.1",
|
||||
"source": {
|
||||
"type": "git",
|
||||
"url": "https://github.com/WordPress/WordPress-Coding-Standards.git",
|
||||
"reference": "7795ec6fa05663d716a549d0b44e47ffc8b0d4a6"
|
||||
"reference": "ec2ff942335f33683a5957a85d138753876a05cf"
|
||||
},
|
||||
"dist": {
|
||||
"type": "zip",
|
||||
"url": "https://api.github.com/repos/WordPress/WordPress-Coding-Standards/zipball/7795ec6fa05663d716a549d0b44e47ffc8b0d4a6",
|
||||
"reference": "7795ec6fa05663d716a549d0b44e47ffc8b0d4a6",
|
||||
"url": "https://api.github.com/repos/WordPress/WordPress-Coding-Standards/zipball/ec2ff942335f33683a5957a85d138753876a05cf",
|
||||
"reference": "ec2ff942335f33683a5957a85d138753876a05cf",
|
||||
"shasum": ""
|
||||
},
|
||||
"require": {
|
||||
@@ -2537,9 +2537,9 @@
|
||||
"ext-tokenizer": "*",
|
||||
"ext-xmlreader": "*",
|
||||
"php": ">=7.2",
|
||||
"phpcsstandards/phpcsextra": "^1.5.0",
|
||||
"phpcsstandards/phpcsutils": "^1.1.0",
|
||||
"squizlabs/php_codesniffer": "^3.13.4"
|
||||
"phpcsstandards/phpcsextra": "^1.5.1",
|
||||
"phpcsstandards/phpcsutils": "^1.2.3",
|
||||
"squizlabs/php_codesniffer": "^3.13.5"
|
||||
},
|
||||
"require-dev": {
|
||||
"php-parallel-lint/php-console-highlighter": "^1.0.0",
|
||||
@@ -2581,7 +2581,7 @@
|
||||
"type": "custom"
|
||||
}
|
||||
],
|
||||
"time": "2025-11-25T12:08:04+00:00"
|
||||
"time": "2026-07-27T11:53:23+00:00"
|
||||
}
|
||||
],
|
||||
"aliases": [],
|
||||
|
||||
Reference in New Issue
Block a user