Skip to content

build(composer): ignore the flysystem 1.x path-normalizer advisory - #1941

Merged
mrrobot47 merged 1 commit into
EasyEngine:developfrom
mrrobot47:fix/ignore-flysystem-advisory
Sep 30, 2026
Merged

mrrobot47 merged 1 commit into
EasyEngine:developfrom
mrrobot47:fix/ignore-flysystem-advisory

Conversation

@mrrobot47

Copy link
Copy Markdown
Member

Composer now blocks league/flysystem 1.1.4 (required by site-command) because of advisory PKSA-w9tt-7782-78jx (CVE-2026-102601). Every composer update fails, including the develop nightly build and PR builds.

  • There is no fixed 1.x release; the fix (3.35.3) needs PHP 8.0.2, and EasyEngine still supports PHP 7.4.
  • flysystem is only used as the local ACME certificate store under acme-conf, with paths built from root-supplied site names, so the bypass isn't reachable.
  • This ignores the ID in config.policy.advisories.ignore-id (Composer 2.10) and config.audit.ignore (Composer 2.9). The lock is unchanged, and so is the built phar.

Replacing flysystem in site-command is planned as a follow-up, after which this ignore can be removed.

site-command requires league/flysystem 1.1.4, and Composer now blocks it because of advisory PKSA-w9tt-7782-78jx (CVE-2026-102601, GHSA-cxf4-7mrp-vvpr). Every composer update fails, so develop and PR builds can't resolve dependencies. No 1.x release fixes it, and the fixed 3.35.3 needs PHP 8.0.2, while EasyEngine still supports PHP 7.4. flysystem only stores ACME certificates under acme-conf, with paths built from root-supplied site names, so the bypass isn't reachable.

The ID is ignored under config.policy.advisories (Composer 2.10) and config.audit.ignore (Composer 2.9). Replacing flysystem in site-command is planned, after which the ignore can be dropped.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The exception also suppresses audit reporting and should be scoped only to dependency blocking.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds a temporary Composer advisory exception for Flysystem 1.x to restore dependency updates on supported PHP versions.

Changes:

  • Adds Composer 2.9 and 2.10 advisory-ignore configurations.
  • Documents why the advisory is considered unreachable.
File Description
composer.json Configures the advisory exception across supported Composer versions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread composer.json
@mrrobot47
mrrobot47 merged commit 446c76e into EasyEngine:develop Sep 30, 2026
11 checks passed
@mrrobot47
mrrobot47 deleted the fix/ignore-flysystem-advisory branch September 30, 2026 07:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants