Update dependencies to patch known CVEs
composer audit reported 37 advisories across 15 packages, including high-severity ones in symfony/security-http. Ran composer update within the existing 7.4.* constraints - composer audit now reports zero advisories. Also adds symfony/rate-limiter, needed for login throttling and invite-code rate limiting in the next commit. Flex removed a stale, non-functional sendgrid notifier config left over from before the app switched to Mailgun as part of the sync. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -34,6 +34,7 @@
|
||||
"symfony/process": "7.4.*",
|
||||
"symfony/property-access": "7.4.*",
|
||||
"symfony/property-info": "7.4.*",
|
||||
"symfony/rate-limiter": "7.4.*",
|
||||
"symfony/runtime": "7.4.*",
|
||||
"symfony/security-bundle": "7.4.*",
|
||||
"symfony/serializer": "7.4.*",
|
||||
|
||||
Reference in New Issue
Block a user