Skip to content

Conversation

leonhelmus
Copy link
Collaborator

…ve security issues, but will not block

the passing of the testing suite.

…ve security issues, but will not block

  the passing of the testing suite.

## 2.19.2
### Fixed
- Task `Security Enlightn` will now only tell what composer packages have security issues, but will not block
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you share why we don't want this to block anymore?

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I now get the error that magento has a security issue if a new patch is released or if we have clients with older magento versions.
Like this for example:
magento/product-community-edition (2.4.4)


## 2.19.2
### Fixed
- Task `Security Enlightn` will now only tell what composer packages have security issues, but will not block
Copy link
Contributor

@rutgerrademaker rutgerrademaker Dec 9, 2024

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was not broken AFAIK, so to me this feels like a (breaking) change, of which I'm not sure if we want to apply this. To my understanding people can also opt out of this in their local/project configuration
If we want this to happen I think this should be in 3.0 as until now we trust our systems to stop working once a a security issue is found.

I Don't think we should lower our barriers for those that want to run insecure code

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alright than i will close this pr and let people resolve it within their projects.

@leonhelmus leonhelmus closed this Dec 9, 2024
@Anve94
Copy link
Member

Anve94 commented Feb 14, 2025

@rutgerrademaker I will be working on v3 through the DO1 project, let's discuss whether we want to include this commit or not.
cc: @leonhelmus

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants