-
Notifications
You must be signed in to change notification settings - Fork 0
π¨ [security] [php] Update symfony/http-foundation 7.3.5 β 7.3.7 (patch) #338
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. Weβll occasionally send you account related emails.
Already on GitHub? Sign in to your account
π¨ [security] [php] Update symfony/http-foundation 7.3.5 β 7.3.7 (patch) #338
Conversation
π Hi there!Everything looks good!
|
Please double check the following review of the pull request:
Changes in the diff
Identified IssuesNo code changes were provided in the diff, so no issues could be identified. Since the diff is empty, no code changes were made in this pull request. The title indicates an update of symfony/http-foundation from version 7.3.5 to 7.3.7 for security reasons, but no actual code or dependency file modifications are shown here. Recommendations:
No further review or tests can be generated without code changes. Summon me to re-review when updated! Yours, Gooroo.dev |
Potential issues, bugs, and flaws that can introduce unwanted behavior:
Code suggestions and improvements for better exception handling, logic, standardization, and consistency:
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the Comment |
|
Here's the code health analysis summary for commits Analysis Summary
Code Coverage Report
|
guibranco
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Automatically approved by gstraccini[bot]
|
@depfu merge |
|



π¨ Your current dependencies have known security vulnerabilities π¨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
Security Advisories π¨
π¨ Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
Release Notes
7.3.7
7.3.6
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 7 commits:
Merge branch '6.4' into 7.3Merge branch '5.4' into 6.4Merge branch '6.4' into 7.3[HttpFoundation] Fix parsing hosts and schemes in URLs[HttpFoundation] Fix parsing pathinfo with no leading slashMerge branch '6.4' into 7.3[HttpFoundation] Allow Request::setFormat() to override predefined formatsDepfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands