Skip to content

chore(deps): update dependency php-pie to v1.4.5#780

Merged
paxuclus merged 1 commit into
mainfrom
renovate/php-pie-1.x
Jun 10, 2026
Merged

chore(deps): update dependency php-pie to v1.4.5#780
paxuclus merged 1 commit into
mainfrom
renovate/php-pie-1.x

Conversation

@netlogix-bot

@netlogix-bot netlogix-bot commented May 26, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Update Change
php-pie patch 1.4.41.4.5

Release Notes

php/pie (php-pie)

v1.4.5

Compare Source

This release contains vulnerability fixes for the following security advisories:

  • GHSA-h842-vjwg-pxxx - Sudo-elevated arbitrary file deletion via extra.pie-installed-binary metadata in UninstallUsingUnlink
  • GHSA-pm6p-666q-hvj5 - Sudo-elevated root code execution via TOCTOU between self-update verify and write
  • GHSA-f67f-c344-cqqr - PIE self-update accepts any historically-attested pie.phar (rollback gap)
  • GHSA-vcv4-gmjc-mxvq - php-ext.build-path traversal escapes PIE's vendor extract directory
  • GHSA-8xmh-xrvp-hwrf - WindowsInstall::copyExtraFile lacks destination containment check (Windows-only path traversal)
  • GHSA-p4j8-36rr-gjfq - Self-update attestation verification is scoped to --owner=php, not --repo=php/pie

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@netlogix-bot netlogix-bot requested a review from a team as a code owner May 26, 2026 16:08
@paxuclus paxuclus merged commit 27a3fbd into main Jun 10, 2026
20 checks passed
@paxuclus paxuclus deleted the renovate/php-pie-1.x branch June 10, 2026 06:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants