Skip to content

Bumped psy/psysh from ^0.10.8 to ^0.11.23 due to security advisory#301

Merged
micszo merged 1 commit into8.3from
bump-psy
Feb 26, 2026
Merged

Bumped psy/psysh from ^0.10.8 to ^0.11.23 due to security advisory#301
micszo merged 1 commit into8.3from
bump-psy

Conversation

@micszo
Copy link
Member

@micszo micszo commented Feb 19, 2026

Related PRs:

Description:

Composer reported:
ezsystems/behatbundle 8.3.x-dev requires psy/psysh ^0.10.8 -> found psy/psysh[v0.10.8, ..., v0.10.12] but these were not loaded, because they are affected by security advisories
in e.g. https://github.com/ibexa/oss/actions/runs/22201685687/job/64215959991#step:10:240.

This PR bumps psy/psysh requirement from ^0.10.8 to ^0.11.23.

The unaffected versions at this moment are:
https://packagist.org/packages/psy/psysh#v0.11.23
https://packagist.org/packages/psy/psysh#v0.12.19
https://packagist.org/packages/psy/psysh#v0.12.20
Ref. https://packagist.org/packages/psy/psysh

CI is red because authentication fails in ezsystems org:
Failed to download recipe: Could not authenticate against github.com.
Ref. https://github.com/ezsystems/BehatBundle/actions/runs/22179961017/job/64138787726?pr=301#step:10:879

Regression builds - all passed:
ibexa/oss#261
ibexa/content#156
ibexa/experience#578
ibexa/commerce#1692

@micszo micszo requested a review from a team February 26, 2026 13:53
@micszo micszo merged commit 79e3d92 into 8.3 Feb 26, 2026
17 of 21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

3 participants