-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 30 Dec 2025 16:00:43 +0100
Source: composer
Architecture: source
Version: 2.9.3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian PHP PEAR Maintainers <pkg-php-pear@lists.alioth.debian.org>
Changed-By: David Prévot <taffit@debian.org>
Changes:
composer (2.9.3-1) unstable; urgency=medium
.
* Security: Fixed ANSI sequence injection [CVE-2025-67746]
.
[ Jordi Boggiano ]
* Remove requirement that a full Composer instance be passed to
EventDispatcher (#12629)
* Fix update --lock / update mirrors not working when locked packages
contain vulnerabilities, fixes #12634 (#12645)
* Retry on curl timeouts (28) (#12662)
* Use git rev-list instead of log to avoid issues with
log.showSignature being enabled (#12666)
* Fix regression in showing reasons for ignoring advisories (#12668)
* Fix no-security-blocking / COMPOSER_NO_SECURITY_BLOCKING not working
on updates done via the install command
* Validate php-ext schema in ValidatingArrayLoader (#12694)
* Fix support for securetransport + libressl
* Release 2.9.3
.
[ ಠ_ಠ ]
* fix crash bumping version with composer update and disabled lockfile
.
[ Ilia Urvachev ]
* fix(AuthHelper): misplaced `username` and `password` (#12667)
.
[ David Prévot ]
* Update Standards-Version to 4.7.3
* Convert d/watch to version 5
Checksums-Sha1:
ae7765ba1e91445474270d474f660248ee068d8b 2299 composer_2.9.3-1.dsc
15470d9d3fdf83fb07d96c18190c8ff7fce1757d 715496 composer_2.9.3.orig.tar.xz
4cf52ce54496694d967ce1df6a47f8c1ab3176ca 52056 composer_2.9.3-1.debian.tar.xz
2273cb7de2c18871785791ad3539c2be09b45ccc 9657 composer_2.9.3-1_amd64.buildinfo
Checksums-Sha256:
b647be13dfd719bdc369b96a2a592eff2fe9c570aaae86ef486c627b8804b509 2299 composer_2.9.3-1.dsc
3c416bd929754278832e814c4bc0ef1de9f95cf1484c407a9388c0a5a448cb5f 715496 composer_2.9.3.orig.tar.xz
0bc5bffe8f741920d8ca2c552b36c9f44bab2c3b513817f50bbb6a6f28fea9ac 52056 composer_2.9.3-1.debian.tar.xz
054842804e696c63992fb8525ce285b7b0225f0ab59dc0a9373bc0af40ee6e1f 9657 composer_2.9.3-1_amd64.buildinfo
Files:
6d4ef047ab19356cd1b2f5d2c7aed97a 2299 php optional composer_2.9.3-1.dsc
5d8d00be2b512325890fd99e594ed1df 715496 php optional composer_2.9.3.orig.tar.xz
24f58adc11fbbc32d8cc66001aaac19b 52056 php optional composer_2.9.3-1.debian.tar.xz
a87bca6a32b710aa8c7e7e0ee6a0f6b2 9657 php optional composer_2.9.3-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQFGBAEBCgAwFiEEeHVNB7wJXHRI941mBYwc+UT2vTwFAmlT7uASHHRhZmZpdEBk
ZWJpYW4ub3JnAAoJEAWMHPlE9r08s6UH/iC5B0sQEZDulM+ckodHTpXifHt/jEui
1sx3yKlKkWp7WksR+oIkdFijoGhr3x4enwAIK5cS5AVjHREnE8Fwrtdg18eG4O0B
quDFpPV7KwiO2f/AP90lAEVYBl4w4XofprpHKgl2MZoOk/fS97MWckfVmSZWEQ0J
e2ygXdGqmcleRRZOY8UZcMJZ9MAT5vKoTa2nicdyq9UVxtFySQITYwixY60dVxMj
hUQXBYUSIOK1zG+BeR4sQIynlNAVx0llZ84r6e3FkDXA7zRK4zeX43s1MrR8VGGh
lF66ebtSTBy4lLtZgXLC4jf8MT/TvVU2sZAiC04uff8SSwso3r4mhQ8=
=sn41
-----END PGP SIGNATURE-----