Update dependencies to patch known CVEs
composer audit reported 37 advisories across 15 packages, including high-severity ones in symfony/security-http. Ran composer update within the existing 7.4.* constraints - composer audit now reports zero advisories. Also adds symfony/rate-limiter, needed for login throttling and invite-code rate limiting in the next commit. Flex removed a stale, non-functional sendgrid notifier config left over from before the app switched to Mailgun as part of the sync. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -262,15 +262,6 @@
|
||||
"config/routes/security.yaml"
|
||||
]
|
||||
},
|
||||
"symfony/sendgrid-mailer": {
|
||||
"version": "7.3",
|
||||
"recipe": {
|
||||
"repo": "github.com/symfony/recipes",
|
||||
"branch": "main",
|
||||
"version": "4.4",
|
||||
"ref": "224aedffb66812dc2b0965dabc14d5f800941da6"
|
||||
}
|
||||
},
|
||||
"symfony/stimulus-bundle": {
|
||||
"version": "2.30",
|
||||
"recipe": {
|
||||
|
||||
Reference in New Issue
Block a user