Skip to content

IBX-11797: Added missing twig/* advisories & included PHP 8.0 #97

Merged
alongosz merged 2 commits into
mainfrom
ibx-11797-fix-twig-advisories-allow-list
May 21, 2026
Merged

IBX-11797: Added missing twig/* advisories & included PHP 8.0 #97
alongosz merged 2 commits into
mainfrom
ibx-11797-fix-twig-advisories-allow-list

Conversation

@alongosz
Copy link
Copy Markdown
Member

@alongosz alongosz commented May 21, 2026

Caution

  • Drop TMP commit before merging
🎫 Issue IBX-11797

Related PRs:

Description:

I missed the fact that twig/* advisories apply to both PHP 7.4 and 8.0, because twig/*:v3.26.0 supports PHP >=8.1

Also added PKSA-fs5b-x5k4-1h39 for twig/cssinliner-extra, which I initially missed.

Now it should include all 19 advisories as declared in the Symfony blog post.

For QA:

No QA required - applies to Backend CI jobs.

@alongosz alongosz force-pushed the ibx-11797-fix-twig-advisories-allow-list branch from 51a067b to 541c222 Compare May 21, 2026 10:16
@sonarqubecloud
Copy link
Copy Markdown

@alongosz alongosz merged commit 0ca9d8c into main May 21, 2026
3 checks passed
@alongosz alongosz deleted the ibx-11797-fix-twig-advisories-allow-list branch May 21, 2026 10:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants