SecurityAdvisories

:closed_lock_with_key: Security advisories as a simple composer exclusion list, regularly updated

Github星跟踪图

Roave Security Advisories

Build Status
Downloads

This package ensures that your application doesn't have installed dependencies with known security vulnerabilities.

Installation

composer require --dev roave/security-advisories:dev-master

Usage

This package does not provide any API or usable classes: its only purpose is to prevent installation of software
with known and documented security issues.
Simply add "roave/security-advisories": "dev-master" to your composer.json "require-dev" section and you will
not be able to harm yourself with software with known security vulnerabilities.

For example, try following:

composer require --dev roave/security-advisories:dev-master
# following commands will fail:
composer require symfony/symfony:2.5.2
composer require zendframework/zendframework:2.3.1 

The checks are only executed when adding a new dependency via composer require or when running composer update:
deploying an application with a valid composer.lock and via composer install won't trigger any security versions
checking.

You can manually trigger a version check by using the --dry-run switch on an update while not doing anything. Running composer update --dry-run roave/security-advisories is an effective way to manually trigger a security version check.

roave/security-advisories for enterprise

Available as part of the Tidelift Subscription.

The maintainers of roave/security-advisories and thousands of other packages are working with Tidelift to deliver commercial support and maintenance for the open source dependencies you use to build your applications. Save time, reduce risk, and improve code health, while paying the maintainers of the exact dependencies you use. Learn more..

You can also contact us at team@roave.com for looking into security issues in your own project.

Stability

This package can only be required in its dev-master version: there will never be stable/tagged versions because of
the nature of the problem being targeted. Security issues are in fact a moving target, and locking your project to a
specific tagged version of the package would not make any sense.

This package is therefore only suited for installation in the root of your deployable project.

Sources

This package extracts information about existing security issues in various composer projects from
the FriendsOfPHP/security-advisories repository.

主要指标

概览
名称与所有者Roave/SecurityAdvisories
主编程语言
编程语言 (语言数: 0)
平台
许可证MIT License
所有者活动
创建于2014-11-05 14:34:26
推送于2025-06-02 17:06:16
最后一次提交2025-06-02 17:06:15
发布数0
用户参与
星数2.8k
关注者数73
派生数109
提交数1.9k
已启用问题?
问题数91
打开的问题数0
拉请求数29
打开的拉请求数1
关闭的拉请求数20
项目设置
已启用Wiki?
已存档?
是复刻?
已锁定?
是镜像?
是私有?