Skip to content

Commit 02f50b6

Browse files
committed
Build/Test Tools: Ignore PHPCS Security Advisory CVE-2026-67434
Add an ignore for GHSA-hmqg-cxww-wqhq (CVE-2026-67434), under both its GitHub and Packagist advisory IDs. WordPress tooling does not use the vulnerable `Gitblame`, `Hgblame` or `Svnblame` report formats, so the pinned version poses no practical risk. Merges [63037] to the 7.0 branch. Props johnbillion, joedolson, jonsurrell, sergeybiryukov. Fixes #65822. git-svn-id: https://develop.svn.wordpress.org/branches/7.0@63038 602fd350-edb4-49c9-b593-d223f7449a82
1 parent 1c09d62 commit 02f50b6

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

‎composer.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@
2727
"yoast/phpunit-polyfills": "^1.1.0"
2828
},
2929
"config": {
30-
"audit": { "ignore": [ "GHSA-3pwp-g2mj-5p3v" ] },
30+
"audit": { "ignore": [ "GHSA-3pwp-g2mj-5p3v", "GHSA-hmqg-cxww-wqhq", "PKSA-rdkp-vv9z-mjkg" ] },
3131
"allow-plugins": {
3232
"dealerdirect/phpcodesniffer-composer-installer": true
3333
},

0 commit comments

Comments
 (0)