Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
These fixes were originally included in
#1967, but are now to be included in this PR.
Description
BaseControllerProvider.php
: the namespace for theControllerProviderInterface;
interface changed in the latest version of Silex ( fromSilex\ControllerProviderInterface
toSilex\Api\ControllerProviderInterface
).XdmodApplicationFactory.php
:UrlGeneratorServiceProvider
has been changed toRoutingServiceProvider
.app->share
function, you just use an anonymous function.Request $request
argument has been added to the anonymous function called by the$app->error
helperfunction.
composer.json
:v2.3.0
, this resolves the following dependabot alerts:vendor/symfony/http-kernel/HttpCache/Store.php
. Specifically lines49-51
, and228-230
.v4.4.49
is >=3.4.35
.vendor/symfony/http-foundation/File/MimeType/FileBinaryMimeTypeGuesser.php
vendor/symfony/http-foundation/Request.php
vendor/symfony/http-kernel/UriSigner.php
vendor/symfony/http-foundation/Request.php
open_xdmod/modules/xdmod/build.json
SimpleSAMLphp Patches
www/errorreport.php
):open_xdmod/modules/xdmod/assets/simplesamlphp-CVE-2020-5225.patch
open_xdmod/modules/xdmod/assets/simplesamlphp-CVE-2020-5301.patch
isValidURL
already exists inUtils/Http.php
in the version that we're using, that's why only the change topostredirect.php
has been included in the patch file.Motivation and Context
We have a number of Dependabot Alerts that should probably be resolved. The following changes should do that for the
symfony/*
andsimplesamlphp/simplesamlphp
dependencies.Tests performed
All automated tests pass.
Checklist: