PHP Composer
Notes
Dependency Manager for PHP
Release notes
v2.2.30
· today
- Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
- Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
- Security: Sanitize URL-embedded usernames/token in a few more places (#13045)
- Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#13042)
Full Changelog: https://github.com/composer/composer/compare/2.2.29...2.2.30