2.2.30 - released 2026-08-27
Changelog
- Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
- Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3, CVE-2026-84361)
- Security: Sanitize URL-embedded usernames/token in a few more places (#13045)
- Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#13042)
Full Changelog: https://github.com/composer/composer/compare/2.2.29...2.2.30
Home