Skip to content

Instantly share code, notes, and snippets.

@jrbeeman
Created August 2, 2018 00:47
Show Gist options
  • Save jrbeeman/2c9e19d20f5500d4baed3fff9b473a1d to your computer and use it in GitHub Desktop.
Save jrbeeman/2c9e19d20f5500d4baed3fff9b473a1d to your computer and use it in GitHub Desktop.
Drupal 8.4.x patch for SA-CORE-2018-005
diff --git a/core/composer.json b/core/composer.json
index 307aefa31d..bb9d0f2736 100644
--- a/core/composer.json
+++ b/core/composer.json
@@ -5,31 +5,31 @@
"license": "GPL-2.0-or-later",
"require": {
"php": ">=5.5.9",
- "symfony/class-loader": "~3.2.8",
- "symfony/console": "~3.2.8",
- "symfony/dependency-injection": "~3.2.8",
- "symfony/event-dispatcher": "~3.2.8",
- "symfony/http-foundation": "~3.2.8",
- "symfony/http-kernel": "~3.2.8",
- "symfony/routing": "~3.2.8",
- "symfony/serializer": "~3.2.8",
- "symfony/translation": "~3.2.8",
- "symfony/validator": "~3.2.8",
- "symfony/process": "~3.2.8",
+ "symfony/class-loader": "~3.3.18",
+ "symfony/console": "~3.3.18",
+ "symfony/dependency-injection": "~3.3.18",
+ "symfony/event-dispatcher": "~3.3.18",
+ "symfony/http-foundation": "~3.3.18",
+ "symfony/http-kernel": "~3.3.18",
+ "symfony/routing": "~3.3.18",
+ "symfony/serializer": "~3.3.18",
+ "symfony/translation": "~3.3.18",
+ "symfony/validator": "~3.3.18",
+ "symfony/process": "~3.3.18",
"symfony/polyfill-iconv": "^1.0",
- "symfony/yaml": "~3.2.8",
+ "symfony/yaml": "~3.3.18",
"twig/twig": "^1.23.1",
"doctrine/common": "^2.5",
"doctrine/annotations": "^1.2",
"guzzlehttp/guzzle": "^6.2.1",
"symfony-cmf/routing": "^1.4",
"easyrdf/easyrdf": "^0.9",
- "zendframework/zend-feed": "^2.4",
+ "zendframework/zend-feed": "^2.10.3",
"stack/builder": "^1.0",
"egulias/email-validator": "^1.2",
"masterminds/html5": "^2.1",
"symfony/psr-http-message-bridge": "^1.0",
- "zendframework/zend-diactoros": "^1.1",
+ "zendframework/zend-diactoros": "^1.8.5",
"composer/semver": "^1.0",
"paragonie/random_compat": "^1.0|^2.0",
"asm89/stack-cors": "^1.1"
@@ -46,8 +46,8 @@
"mikey179/vfsStream": "^1.2",
"phpunit/phpunit": ">=4.8.35 <5",
"phpspec/prophecy": "^1.4",
- "symfony/css-selector": "~3.2.8",
- "symfony/phpunit-bridge": "~3.2.8"
+ "symfony/css-selector": "~3.3.18",
+ "symfony/phpunit-bridge": "~3.3.18"
},
"replace": {
"drupal/action": "self.version",
@jrbeeman
Copy link
Author

jrbeeman commented Aug 2, 2018

NOT THOROUGHLY TESTED

Requires PHP 5.6 or higher. To use, download and apply patch.
Run composer update symfony/* zendframework/* twig/twig

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment