View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0036860 | mantisbt | tools | public | 2026-01-30 08:14 | 2026-02-03 17:11 |
| Reporter | dregad | Assigned To | dregad | ||
| Priority | normal | Severity | major | Reproducibility | have not tried |
| Status | resolved | Resolution | fixed | ||
| Target Version | 2.28.1 | Fixed in Version | 2.28.1 | ||
| Summary | 0036860: Update PHPUnit to 9.6.34 | ||||
| Description | According to PHPUnit release notes, a security issue in earlier versions allows Poisoned Pipeline Execution (PPE) attacks using prepared .coverage files in pull requests. Dependabot PR https://github.com/mantisbt/mantisbt/pull/2172 for 9.6.33 Going straight to 9.6.34, which includes a fix for a regression issue. | ||||
| Tags | No tags attached. | ||||
|
MantisBT: master-2.28 3a3c7a8b 2026-01-30 08:18 Details Diff |
Bump phpunit/phpunit from 9.6.31 to 9.6.34 Also increase minimum versions in composer.json. Fixes 0036860, PR https://github.com/mantisbt/mantisbt/pull/2172 |
Affected Issues 0036860 |
|
| mod - composer.json | Diff File | ||
| mod - composer.lock | Diff File | ||