Skip to content

phpunit <12 still marked as vulnerable #150

@uuf6429

Description

@uuf6429

The fix in 7d0034b is not correct. PHPUnit <12 is still marked as vulnerable, when in fact only two specific versions were vulnerable (one in v12 and one in v13). See also: github/advisory-database#7430

AFAIK the advisory in Composer/Packagist looks more correct as it takes into consideration other vulnerabilities: https://packagist.org/packages/phpunit/phpunit/advisories

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions