#1146066 trixie-pu: package composer/2.8.8-1+deb13u4

#1146066#5
Date:
2026-08-29 14:19:16 UTC
From:
To:
Hi,

I’d like to fix five security issues that are not worth a DSA in the
next point release (four are marked as no-dsa, the fifth one has no CVE
assigned).

[ Tests ]
The test suite has been updated with the code change.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

Thanks in advance for considering.

Regards,

taffit

#1146066#12
Date:
2026-09-02 20:40:08 UTC
From:
To:
Hi David,

The fifth one (GHSA-rvx4-ffvw-m9q3), now has as well a CVE, it is
CVE-2026-84361.

Regards,
Salvatore

#1146066#17
Date:
2026-09-04 11:12:07 UTC
From:
To:
Control: tags -1 + confirmed
[...]

Please go ahead.

Regards,

Adam