Page MenuHomePhabricator

Upgrade dockerfiles to use composer 2.1.9 per CVE-2021-41116
Closed, ResolvedPublic

Description

They are currently using 2.1.8 (see T279857). They should be upgraded to 2.1.9 in order to fix CVE-2021-41116.

Event Timeline

Noting this CVE is Windows only; https://github.com/composer/composer/commit/ca5e2f8d505fd3bfac6f7c85b82f2740becbc0aa

So it's probably low-ish priority for CI, but in terms of keeping ontop of it, we should get it integrated.

Reedy triaged this task as Low priority.Oct 25 2021, 3:58 PM

Change 771004 had a related patch set uploaded (by Jforrester; author: Jforrester):

[integration/config@master] dockerfiles: [composer-scratch] Upgrade composer to 2.3.3 and cascade

https://gerrit.wikimedia.org/r/771004

Change 771004 merged by jenkins-bot:

[integration/config@master] dockerfiles: [composer-scratch] Upgrade composer to 2.3.3 and cascade

https://gerrit.wikimedia.org/r/771004

Mentioned in SAL (#wikimedia-releng) [2022-04-04T22:43:14Z] <James_F> dockerfiles: [composer-scratch] Upgrade composer to 2.3.3 and cascade for T294260

hashar subscribed.

We first need to finish the deployment of Memcached support which is T300340

Reedy assigned this task to Jdforrester-WMF.