Skip to content

fix(VUL-26736): bump squizlabs/php_codesniffer to 3.13.6 - #15

Merged
pwtyler merged 1 commit into
mainfrom
vuln-VUL-26736
Aug 11, 2026
Merged

fix(VUL-26736): bump squizlabs/php_codesniffer to 3.13.6#15
pwtyler merged 1 commit into
mainfrom
vuln-VUL-26736

Conversation

@samwise-service

@samwise-service samwise-service Bot commented Aug 9, 2026

Copy link
Copy Markdown
Contributor

Bumps squizlabs/php_codesniffer from 3.7.2 to 3.13.6 to address a high-severity CVE. This is a direct dev-only dependency; the version constraint in composer.json (^3.7) already permits 3.13.6, so only composer.lock was regenerated — no manifest change needed.

Jira Tickets Resolved

CVEs Fixed

Package CVE Severity Description Fixed in
squizlabs/php_codesniffer CVE-2026-67434 High gitblame report command injection via crafted filename 3.13.6

Changes

  • Ran composer update squizlabs/php_codesniffer to regenerate composer.lock, pulling in 3.13.6.
  • composer.json unchanged — the existing ^3.7 constraint already allows this version.

Risk assessment

Undetermined — the service-maturity skill was not available in this environment to produce the maturity scoring table. This is a dev-only dependency (php_codesniffer is required-dev, used for linting), not shipped in production code paths.

Addresses CVEs fixed in squizlabs/php_codesniffer v3.13.6:
- CVE-2026-67434: gitblame report command injection via crafted filename
@samwise-service
samwise-service Bot requested review from a team as code owners August 9, 2026 02:36
@github-actions

github-actions Bot commented Aug 9, 2026

Copy link
Copy Markdown
Composer Changes
Dev Packages Operation Base Target
squizlabs/php_codesniffer Upgraded 3.7.2 3.13.6

@pwtyler
pwtyler merged commit 6daae45 into main Aug 11, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant