Skip to content

Releases: composer/composer

2.3.8

01 Jul 10:26
f69e632
Compare
Choose a tag to compare
  • Fixed support for cache-read-only where the filesystem is not writable (#10906)
  • Fixed type error when using allow-plugins: true (#10909)
  • Fixed @putenv scripts receiving arguments passed to the command (#10846)
  • Fixed support for spaces in paths with binary proxies on Windows (#10836)
  • Fixed type error in GitDownloader if branches cannot be listed (#10888)
  • Fixed RootPackageInterface issue on PHP 5.3.3 (#10895)
  • Fixed type errors (#10904, #10897)

2.2.15

01 Jul 10:26
509dcbd
Compare
Choose a tag to compare
  • Fixed support for cache-read-only where the filesystem is not writable (#10906)
  • Fixed type error when using allow-plugins: true (#10909)
  • Fixed @putenv scripts receiving arguments passed to the command (#10846)
  • Fixed support for spaces in paths with binary proxies on Windows (#10836)
  • Fixed type error in GitDownloader if branches cannot be listed (#10888)
  • Fixed RootPackageInterface issue on PHP 5.3.3 (#10895)

2.3.7

06 Jun 14:51
10cd375
Compare
Choose a tag to compare
  • Fixed a few PHPStan ConfigReturnTypeExtension bugs
  • Fixed Config default for auth configs to be empty arrays instead of null, fixes issues with diagnose command (#10814)
  • Fixed handling of broken symlinks when checking whether a package is still installed (#6708)
  • Fixed bin proxies to allow a proxy to include another one safely (#10823)
  • Fixed openssl 3.x version parsing as it is now semver compliant
  • Fixed type error when a json file cannot be read (#10818)
  • Fixed parsing of multi-line arrays in funding.yml (#10784)

2.2.14

06 Jun 14:51
8c7a2d2
Compare
Choose a tag to compare
  • Fixed handling of broken symlinks when checking whether a package is still installed (#6708)
  • Fixed name validation regex in schema causing issues with JS IDEs like VS Code (#10811)
  • Fixed bin proxies to allow a proxy to include another one safely (#10823)
  • Fixed gitlab-token JSON schema definition (#10800)
  • Fixed openssl 3.x version parsing as it is now semver compliant
  • Fixed type error when a json file cannot be read (#10818)
  • Fixed parsing of multi-line arrays in funding.yml (#10784)

2.3.6

01 Jun 20:11
0f43aa1
Compare
Choose a tag to compare
  • Added Composer\PHPStan\ConfigReturnTypeExtension to improve return types of Config::get() which you can also use in plugins CI (#10635)
  • Fixed name validation regex in schema causing issues with JS IDEs like VS Code (#10811)
  • Fixed unnecessary HTTP request in BitbucketDriver (#10729)
  • Fixed invalid credentials loop when setting up GitLab token (#10748)
  • Fixed PHP 8.2 deprecations (#10766)
  • Fixed lock file changes being output even when the lock file creation is disabled
  • Fixed race condition when multiple requests asking for auth on the same hostname fired concurrently (#10763)
  • Fixed quoting of commas on Windows (#10775)
  • Fixed issue installing path repos with a disabled symlink function (#10786)
  • Fixed various type errors (#10753, #10739, #10751)

2.2.13

25 May 19:49
de11c98
Compare
Choose a tag to compare
  • Fixed invalid credentials loop when setting up GitLab token (#10748)
  • Fixed PHP 8.2 deprecations (#10766)
  • Fixed lock file changes being output even when the lock file creation is disabled
  • Fixed race condition when multiple requests asking for auth on the same hostname fired concurrently (#10763)
  • Fixed quoting of commas on Windows (#10775)
  • Fixed issue installing path repos with a disabled symlink function (#10786)

2.3.5

13 Apr 14:56
50c47b1
Compare
Choose a tag to compare
  • Security: Fixed command injection vulnerability in HgDriver/GitDriver (GHSA-x7cr-6qr6-2hh6 / CVE-2022-24828)
  • Added warning when downloading a file with verify_peer[_name] disabled (#10722)
  • Fixed curl downloader not retrying when a DNS resolution failure occurs (#10716)
  • Fixed composer.lock file still being used/read when the lock config option is disabled (#10726)
  • Fixed validate command checking the lock file even if the lock option is disabled (#10723)
  • Fixed detection of default branch name when it changed since a git repo was mirrored in cache dir (#10701)

2.2.12

13 Apr 14:56
ba61e76
Compare
Choose a tag to compare
  • Security: Fixed command injection vulnerability in HgDriver/GitDriver (GHSA-x7cr-6qr6-2hh6 / CVE-2022-24828)
  • Fixed curl downloader not retrying when a DNS resolution failure occurs (#10716)
  • Fixed composer.lock file still being used/read when the lock config option is disabled (#10726)
  • Fixed validate command checking the lock file even if the lock option is disabled (#10723)

1.10.26

13 Apr 14:56
3e19613
Compare
Choose a tag to compare

2.3.4

07 Apr 19:29
b7a0413
Compare
Choose a tag to compare
  • Fixed the generated autoload.php to support running on PHP 5.6+ (down from 7.0+) and warn clearly on older PHP versions (#10714)
  • Fixed run-script --list flag regression (#10710)
  • Fixed curl downloader handling of DNS resolution failures to do an automatic retry (#10716)
  • Fixed script handling of external commands not setting the Path env correctly on windows (#10700)
  • Fixed various type errors (#10694, #10696, #10702, #10712, #10703)