Skip to content

Fix: Bump Composer dependencies to fix security issues#2340

Open
krishana7911 wants to merge 2 commits into
developfrom
fix/dependabot-alerts-june
Open

Fix: Bump Composer dependencies to fix security issues#2340
krishana7911 wants to merge 2 commits into
developfrom
fix/dependabot-alerts-june

Conversation

@krishana7911

@krishana7911 krishana7911 commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Summary

Bumps guzzlehttp/psr7, symfony/yaml, and symfony/dom-crawler in tests/codeception/composer.lock to resolve the open Dependabot security alerts.

Changes

  • guzzlehttp/psr7: 2.8.02.12.0
  • symfony/yaml: 5.4.455.4.52
  • symfony/dom-crawler: 5.4.485.4.52

Verification

Ran composer audit locally after the bump — all previously flagged advisories are resolved:

No security vulnerability advisories found.
Found 1 abandoned package:
codeception/phpunit-wrapper (no replacement suggested)

The codeception/phpunit-wrapper notice is unrelated to this fix — it's an abandoned-package notice, not a security advisory, and isn't part of the alerts this PR addresses.

Scope note

These are dev/test-only dependencies (tests/codeception/composer.lock), isolated from the plugin's runtime code — they're never loaded on a live site running rtMedia, only when the test suite is executed locally or in CI.

Resolves

Closes:

@krishana7911 krishana7911 self-assigned this Jun 18, 2026
@krishana7911 krishana7911 marked this pull request as ready for review June 18, 2026 07:29
@krishana7911 krishana7911 requested a review from Pradeep1308 June 18, 2026 11:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants