Unclear behavior for security-only updates, when 2 composer.json files in different folders are used #36507
Unanswered
DanielRuf
asked this question in
Request Help
Replies: 2 comments
-
|
From the renovate output: |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
So why does renovate not skip the major upgrade, since it is not relevant for the security? |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
How are you running Renovate?
Self-hosted Renovate
If you're self-hosting Renovate, tell us which platform (GitHub, GitLab, etc) and which version of Renovate.
Gitea, latest renovate Docker image
Please tell us more about your question or problem
We have a PHP project where multiple folders have a composer.json file.
Interestingly for one of both renovate suggest an upgrade to symfony/process 7.0.0 and tries to change the selector to
^7.0but that makes not much sense.Configuration:
Resulting CVE information: CVE-2024-51736 / GHSA-qq5c-677p-737q
Artifact failure results:
Manual check locally:
We have set the
platformversion for PHP to 8.1.2.So why does renovate try to use symfony/process 7.0.0 and increase the SemVer selector ti the major version instead of staying on 6.x?
Logs (if relevant)
No response
Beta Was this translation helpful? Give feedback.
All reactions