Skip to content

Bump composer/composer from 2.10.2 to 2.10.3 - #1230

Merged
veewee merged 1 commit into
v2.xfrom
dependabot/composer/composer/composer-2.10.3
Oct 3, 2026
Merged

veewee merged 1 commit into
v2.xfrom
dependabot/composer/composer/composer-2.10.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Bumps composer/composer from 2.10.2 to 2.10.3.

Release notes

Sourced from composer/composer's releases.

2.10.3

  • Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
  • Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3, CVE-2026-84361)
  • Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
  • Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
  • Fixed PHP 8.6 deprecation warnings (#12967, #13028)
  • Fixed error output when a policy blocks a package version to be clearer (#12993)
  • Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
  • Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
  • Fixed forgejo support to handle empty repositories better (#12968)
  • Fixed FilterListApiClient not forwarding transport options (#13040)

Full Changelog: composer/composer@2.10.2...2.10.3

Changelog

Sourced from composer/composer's changelog.

[2.10.3] 2026-08-27

  • Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
  • Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
  • Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
  • Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
  • Fixed PHP 8.6 deprecation warnings (#12967, #13028)
  • Fixed error output when a policy blocks a package version to be clearer (#12993)
  • Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
  • Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
  • Fixed forgejo support to handle empty repositories better (#12968)
  • Fixed FilterListApiClient not forwarding transport options (#13040)
Commits
  • f0de0bf Release 2.10.3
  • f247758 Update changelog
  • 0aac505 Merge commit from fork
  • 53b8bb4 Merge commit from fork
  • 24e396b Make it possible to pass transport options to FilterListApiClient (#13040)
  • f383d23 Do not use a conflicted content-hash as the autoloader suffix (#13048)
  • ada0055 Mask URL credentials anywhere in a string, not just at its start (#13044)
  • cd19785 Prevent curl SSL version parsing across lines (#13046)
  • eba7baa Fix Url::getOrigin prefix-matching a host against gitlab-domains (#12988)
  • 5e9f655 Include the failed URL in max-file-size and content-length errors (#13041)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update Php code labels Sep 8, 2026
@veewee

veewee commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [composer/composer](https://github.com/composer/composer) from 2.10.2 to 2.10.3.
- [Release notes](https://github.com/composer/composer/releases)
- [Changelog](https://github.com/composer/composer/blob/main/CHANGELOG.md)
- [Commits](composer/composer@2.10.2...2.10.3)

---
updated-dependencies:
- dependency-name: composer/composer
  dependency-version: 2.10.3
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/composer/composer/composer-2.10.3 branch from 3f81b8d to 20efaf9 Compare October 2, 2026 16:54
@veewee
veewee merged commit 1527e25 into v2.x Oct 3, 2026
51 checks passed
@dependabot
dependabot Bot deleted the dependabot/composer/composer/composer-2.10.3 branch October 3, 2026 08:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update Php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant