diff options
author | Thomas Gerbet <thomas.gerbet@enalean.com> | 2024-06-11 09:20:39 +0200 |
---|---|---|
committer | Thomas Gerbet <thomas.gerbet@enalean.com> | 2024-06-11 09:20:39 +0200 |
commit | 316dd70bd2a9d0a4e19592874bb59fc7168b41ae (patch) | |
tree | 2599d2b2e83086a69e0ad321d967dc7d7ee75b7d /pkgs | |
parent | 43edb077162f6c326586719c3713ff90d311439b (diff) |
phpPackages.composer: 2.7.6 -> 2.7.7
Fixes CVE-2024-35241 and CVE-2024-35242. Changes: https://github.com/composer/composer/releases/tag/2.7.7
Diffstat (limited to 'pkgs')
-rw-r--r-- | pkgs/development/php-packages/composer/default.nix | 8 |
1 files changed, 4 insertions, 4 deletions
diff --git a/pkgs/development/php-packages/composer/default.nix b/pkgs/development/php-packages/composer/default.nix index 334edbb7d1ac1..0b36ab32439bf 100644 --- a/pkgs/development/php-packages/composer/default.nix +++ b/pkgs/development/php-packages/composer/default.nix @@ -16,7 +16,7 @@ php.buildComposerProject (finalAttrs: { # use together with the version from this package to keep the # bootstrap phar file up-to-date together with the end user composer # package. - passthru.pharHash = "sha256-KdyaGe8zU12wYbMRgLKoM6fPjSz0FFszovg1BId7ugg="; + passthru.pharHash = "sha256-qrlAzVPShaVMUEZYIKIID8txgqS6Hl95Wr+xBBSktL4="; composer = callPackage ../../../build-support/php/pkgs/composer-phar.nix { inherit (finalAttrs) version; @@ -24,13 +24,13 @@ php.buildComposerProject (finalAttrs: { }; pname = "composer"; - version = "2.7.6"; + version = "2.7.7"; src = fetchFromGitHub { owner = "composer"; repo = "composer"; rev = finalAttrs.version; - hash = "sha256-LZwg3PR3zl07Nb6MS8oKkRfjLgqtT/c4sfUOzWE4S+U="; + hash = "sha256-N8el4oyz3ZGIXN2qmpf6Df0SIjuc1GjyuMuQCcR/xN4="; }; nativeBuildInputs = [ makeBinaryWrapper ]; @@ -40,7 +40,7 @@ php.buildComposerProject (finalAttrs: { --prefix PATH : ${lib.makeBinPath [ _7zz cacert curl git unzip xz ]} ''; - vendorHash = "sha256-dNNV9fTyGyRoGeDV/vBjn0aMgkaUMsrKQv5AOoiYokQ="; + vendorHash = "sha256-4EyMtf4i7GqL/8eGZqBuk0Afagzo/2EbpcWekc7iHDU="; meta = { changelog = "https://github.com/composer/composer/releases/tag/${finalAttrs.version}"; |