From d6df6e6118772797425693d2678b91f0eb4abadd Mon Sep 17 00:00:00 2001 From: Georgy Oganisyan Date: Fri, 22 May 2026 23:22:51 +0300 Subject: [PATCH 1/6] Composer audit supports all allowed symfony-php pairs --- .github/workflows/composer.yml | 20 ++++++++++++++++---- 1 file changed, 16 insertions(+), 4 deletions(-) diff --git a/.github/workflows/composer.yml b/.github/workflows/composer.yml index 1fb0158..8966757 100644 --- a/.github/workflows/composer.yml +++ b/.github/workflows/composer.yml @@ -23,17 +23,29 @@ jobs: strategy: matrix: data: [ - { symfony: '5.4.*', php: 7.4 }, - { symfony: '5.4.*', php: 8.0 }, - { symfony: '5.4.*', php: 8.1 }, - { symfony: '5.4.*', php: 8.2 }, + { symfony: '5.3.*', php: 7.4 }, + { symfony: '5.3.*', php: 8.0 }, + { symfony: '5.3.*', php: 8.1 }, + { symfony: '5.3.*', php: 8.2 }, { symfony: '6.4.*', php: 8.1 }, { symfony: '6.4.*', php: 8.2 }, + { symfony: '6.4.*', php: 8.3 }, + + { symfony: '7.0.*', php: 8.2 }, + { symfony: '7.0.*', php: 8.3 }, { symfony: '7.1.*', php: 8.2 }, + { symfony: '7.1.*', php: 8.3 }, { symfony: '7.2.*', php: 8.2 }, + { symfony: '7.2.*', php: 8.3 }, + + { symfony: '7.3.*', php: 8.2 }, + { symfony: '7.3.*', php: 8.3 }, + + { symfony: '7.4.*', php: 8.2 }, + { symfony: '7.4.*', php: 8.3 }, ] steps: From eee07567a16547488511a7e7a089e069133736bb Mon Sep 17 00:00:00 2001 From: Georgy Oganisyan Date: Fri, 22 May 2026 23:38:15 +0300 Subject: [PATCH 2/6] Composer audit supports all allowed symfony-php pairs --- .github/workflows/composer.yml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/composer.yml b/.github/workflows/composer.yml index 8966757..a4a0391 100644 --- a/.github/workflows/composer.yml +++ b/.github/workflows/composer.yml @@ -23,10 +23,10 @@ jobs: strategy: matrix: data: [ - { symfony: '5.3.*', php: 7.4 }, - { symfony: '5.3.*', php: 8.0 }, - { symfony: '5.3.*', php: 8.1 }, - { symfony: '5.3.*', php: 8.2 }, + { symfony: '5.4.*', php: 7.4 }, + { symfony: '5.4.*', php: 8.0 }, + { symfony: '5.4.*', php: 8.1 }, + { symfony: '5.4.*', php: 8.2 }, { symfony: '6.4.*', php: 8.1 }, { symfony: '6.4.*', php: 8.2 }, From 38bad20d6f9da07a72857c6cb1fda687a834cbf4 Mon Sep 17 00:00:00 2001 From: Georgy Oganisyan Date: Fri, 22 May 2026 23:41:07 +0300 Subject: [PATCH 3/6] Skip composer audit for dev dependencies --- .github/workflows/composer.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/composer.yml b/.github/workflows/composer.yml index a4a0391..6f64462 100644 --- a/.github/workflows/composer.yml +++ b/.github/workflows/composer.yml @@ -67,4 +67,4 @@ jobs: dependency-versions: "highest" - name: Run Security Audit - run: composer audit + run: composer audit --no-dev From 6a69cbdc8b69f5d9c6434e64f426c791a8830f30 Mon Sep 17 00:00:00 2001 From: Georgy Oganisyan Date: Fri, 22 May 2026 23:42:43 +0300 Subject: [PATCH 4/6] Removed composer audit ignore --- composer.json | 7 +------ 1 file changed, 1 insertion(+), 6 deletions(-) diff --git a/composer.json b/composer.json index d7f81c3..393166c 100644 --- a/composer.json +++ b/composer.json @@ -54,12 +54,7 @@ }, "audit": { "abandoned": "ignore", - "block-insecure": false, - "ignore":{ - "CVE-2026-45073": "The affected component is not in use.", - "CVE-2026-45065": "The affected component is not in use.", - "CVE-2025-64500": "The affected component is not in use." - } + "block-insecure": false } } } From 52d2cda4de49cf380098ed9f9f53737483d372da Mon Sep 17 00:00:00 2001 From: Georgy Oganisyan Date: Fri, 22 May 2026 23:55:38 +0300 Subject: [PATCH 5/6] Removed symfony 5.4 from composer action --- .github/workflows/composer.yml | 5 ----- 1 file changed, 5 deletions(-) diff --git a/.github/workflows/composer.yml b/.github/workflows/composer.yml index 6f64462..2517f99 100644 --- a/.github/workflows/composer.yml +++ b/.github/workflows/composer.yml @@ -23,11 +23,6 @@ jobs: strategy: matrix: data: [ - { symfony: '5.4.*', php: 7.4 }, - { symfony: '5.4.*', php: 8.0 }, - { symfony: '5.4.*', php: 8.1 }, - { symfony: '5.4.*', php: 8.2 }, - { symfony: '6.4.*', php: 8.1 }, { symfony: '6.4.*', php: 8.2 }, { symfony: '6.4.*', php: 8.3 }, From 56613ca369af0b6ecf2be8ebd4f9c3eafc92b42f Mon Sep 17 00:00:00 2001 From: Georgy Oganisyan Date: Tue, 26 May 2026 12:49:24 +0300 Subject: [PATCH 6/6] Return symfony 5.4 composer audit checks --- .github/workflows/composer.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/composer.yml b/.github/workflows/composer.yml index 2517f99..6f64462 100644 --- a/.github/workflows/composer.yml +++ b/.github/workflows/composer.yml @@ -23,6 +23,11 @@ jobs: strategy: matrix: data: [ + { symfony: '5.4.*', php: 7.4 }, + { symfony: '5.4.*', php: 8.0 }, + { symfony: '5.4.*', php: 8.1 }, + { symfony: '5.4.*', php: 8.2 }, + { symfony: '6.4.*', php: 8.1 }, { symfony: '6.4.*', php: 8.2 }, { symfony: '6.4.*', php: 8.3 },