An open index of dependabot pull requests across open source projects.

composer/composer

Ecosystem:
packagist
Package URL:
pkg:composer/composer/composer
Total PRs:
217 Dependabot PRs
Latest PR:
21 days ago
Unique Repositories:
128 repositories
Unique Repos (30 days):
4 repositories
Security Advisories
Composer's missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial
GHSA-h5h8-pc6h-jvvx CVE-2021-29472 HIGH published about 5 years ago • updated 5 days ago
URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitized correctly. Specifically crafted URL va...
Composer code execution and possible privilege escalation via compromised InstalledVersions.php or installed.php
GHSA-7c6p-848j-wh5h CVE-2024-24821 HIGH published over 2 years ago • updated 6 days ago
### Impact Several files within the local working directory are included during the invocation of Composer and in the context of the executing use...
Composer Remote Code Execution vulnerability via web-accessible composer.phar
GHSA-jm6m-4632-36hf CVE-2023-43655 HIGH published over 2 years ago • updated 5 days ago
### Impact Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be impacte...
Missing input validation can lead to command execution in composer
GHSA-x7cr-6qr6-2hh6 CVE-2022-24828 HIGH published about 4 years ago • updated 5 days ago
The Composer method `VcsDriver::getFileContent()` with user-controlled `$file` or `$identifier` arguments is susceptible to an argument injection v...
Composer allows cache poisoning from other projects built on the same host
GHSA-725m-w832-q973 CVE-2015-8371 HIGH published over 2 years ago • updated 18 days ago
Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a s...
Recent PRs
Package Details
Name: composer/composer
Ecosystem: packagist
PURL Type: composer
Package URL: pkg:composer/composer/composer
JSON API: View JSON
Security Advisories

12

Active advisories
HIGH 11
LOW 1
View All composer Advisories
Package Information
Description:

Composer helps you declare, manage and install dependencies of PHP projects. It ensures you have the right stack everywhere.

Repository: https://github.com/composer/composer
Homepage: https://getcomposer.org/
Latest Release: 2.8.9
about 1 year ago
Dependent Repos: 35,414
Dependent Packages: 2,610
Downloads: 162,035,323
Ranking: Top 0.0479% by dependent repos Top 0.0457% by downloads Top 0.0156% by dependent pkgs
PR Status
Open 87 (40.1%)
Merged 24 (11.1%)
Closed 90 (41.5%)
PR Types
Major 1 (0.5%)
Minor 75 (34.6%)
Patch 125 (57.6%)