From 50b3f22792b3efa209ab90572381171852bf9ff6 Mon Sep 17 00:00:00 2001 From: Riddhesh Sanghvi Date: Wed, 30 Sep 2026 12:20:13 +0530 Subject: [PATCH] build(composer): ignore the flysystem 1.x path-normalizer advisory site-command requires league/flysystem 1.1.4, and Composer now blocks it because of advisory PKSA-w9tt-7782-78jx (CVE-2026-102601, GHSA-cxf4-7mrp-vvpr). Every composer update fails, so develop and PR builds can't resolve dependencies. No 1.x release fixes it, and the fixed 3.35.3 needs PHP 8.0.2, while EasyEngine still supports PHP 7.4. flysystem only stores ACME certificates under acme-conf, with paths built from root-supplied site names, so the bypass isn't reachable. The ID is ignored under config.policy.advisories (Composer 2.10) and config.audit.ignore (Composer 2.9). Replacing flysystem in site-command is planned, after which the ignore can be dropped. --- composer.json | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/composer.json b/composer.json index 4cbe3f75e..5382aab7e 100644 --- a/composer.json +++ b/composer.json @@ -22,6 +22,18 @@ "sort-packages": true, "allow-plugins": { "dealerdirect/phpcodesniffer-composer-installer": true + }, + "audit": { + "ignore": { + "PKSA-w9tt-7782-78jx": "league/flysystem 1.x has no fixed release (the fix, 3.35.3, needs PHP 8); it only stores ACME certs under acme-conf with root-supplied paths, so the bypass is not reachable." + } + }, + "policy": { + "advisories": { + "ignore-id": { + "PKSA-w9tt-7782-78jx": "league/flysystem 1.x has no fixed release (the fix, 3.35.3, needs PHP 8); it only stores ACME certs under acme-conf with root-supplied paths, so the bypass is not reachable." + } + } } }, "minimum-stability": "dev",