Mechanism to fix CVEs by the presence of another package (Shopware security plugin) #12628
Replies: 3 comments 2 replies
-
|
This looks like it requests the same as #12616 if I understand it correctly. Does the solution for that issue (see 632d1c3) help? Or is it taking that idea one step further? |
Beta Was this translation helpful? Give feedback.
-
|
This feature request won't work for the new |
Beta Was this translation helpful? Give feedback.
-
That would indeed be the preferable outcome here. Because ignoring all CVEs is now possible but a nasty hack.. And third party packages declaring ignores for CVEs also sounds like a bad idea (beyond the fact that as @stof said it isn't really possible to implement). |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
In the Shopware ecosystem, there is the a security plugin which can be installed / updated via Composer to fix known vulnerabilities if an update of the core packages would be to risky or time consuming at that moment.
So what happens is, that we update the security plugin but
composer updatewould still complain about theshopware/coreCVEs, even they are patched by the plugin.An idea would be that a composer package can provide a audit.fixes list so that CVEs in the core packages are automatically ignored. Currently it's necessary to do this manually in the root
composer.jsonOther options:
Of course this itself is some workaround already and I guess the plugin is meant mostly for stores which are not really fully composer managed and merchants update via the admin panel.
Shopware also could release patched core packages for each minor version, so there would be no need for the security plugin.
I am fully okay with a "won't implement" response, but wanted to bring this discussion on the table.
Beta Was this translation helpful? Give feedback.
All reactions