-
-
Notifications
You must be signed in to change notification settings - Fork 3.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade tecnickcom/tcpdf from version 6.7.4 to 6.7.5 to address the security vulnerability CVE-2024-22640 #14661
Conversation
💖 Thanks for this pull request! 💖 We use semantic commit messages to streamline the release process and easily generate changelogs between versions. Before your pull request can be merged, you should update your pull request title to start with a semantic prefix if it doesn't have one already. Examples of commit messages with semantic prefixes:
Things that will help get your PR across the finish line:
We get a lot of pull requests on this repo, so please be patient and we will get back to you as soon as we can. |
Can you provide a little more info here? Also we should probably lock that version into composer.json |
Thank you for your comment of asking me to provide information of my pull request. We use Snipe-IT to manage our hardware inventory. When we ran
To fix the error, I ran I could confirm the error was fixed by running
Could you accept my pull request for upgrading tecnickcom/tcpdf from 6.7.4 to 6.7.5? Thank you. |
@snipe RE "Also we should probably lock that version into composer.json" are planning to lock all your dependencies? Over in Drupal land we have a locked version of the core dependencies in a separate project https://github.com/drupal/core-recommended/ Is that what kinda what you're going for (not the separate project but the dependency lock down)?
|
Congrats on merging your first pull request! 🎉🎉🎉 |
No description provided.