They are currently using 2.1.8 (see T279857). They should be upgraded to 2.1.9 in order to fix CVE-2021-41116.
Description
Description
Details
Details
Related Changes in Gerrit:
| Subject | Repo | Branch | Lines +/- | |
|---|---|---|---|---|
| dockerfiles: [composer-scratch] Upgrade composer to 2.3.3 and cascade | integration/config | master | +246 -2 |
| Status | Subtype | Assigned | Task | ||
|---|---|---|---|---|---|
| Resolved | Jdforrester-WMF | T294260 Upgrade dockerfiles to use composer 2.1.9 per CVE-2021-41116 | |||
| Resolved | kostajh | T300340 Use Memcached with Quibble | |||
| Resolved | hashar | T304147 jenkis CI wikibase-repo-docker failing with new quibble version |
Event Timeline
Comment Actions
Noting this CVE is Windows only; https://github.com/composer/composer/commit/ca5e2f8d505fd3bfac6f7c85b82f2740becbc0aa
So it's probably low-ish priority for CI, but in terms of keeping ontop of it, we should get it integrated.
Comment Actions
Change 771004 had a related patch set uploaded (by Jforrester; author: Jforrester):
[integration/config@master] dockerfiles: [composer-scratch] Upgrade composer to 2.3.3 and cascade
Comment Actions
Change 771004 merged by jenkins-bot:
[integration/config@master] dockerfiles: [composer-scratch] Upgrade composer to 2.3.3 and cascade
Comment Actions
Mentioned in SAL (#wikimedia-releng) [2022-04-04T22:43:14Z] <James_F> dockerfiles: [composer-scratch] Upgrade composer to 2.3.3 and cascade for T294260