Bump PHPUnit to ^9.6.33 to fix CVE-2026-24765 (Dependabot alert #3) - #21
Merged
Merged
Conversation
- app/composer.json pinned phpunit 3.7.* which cannot resolve to any patched release, triggering Dependabot alert #3 (GHSA-vvj3-c3rp-c85p, unsafe deserialization in PHPT code coverage handling). Raise it and the root constraint to ^9.6.33 so only patched 9.6.x can resolve; a fresh install currently resolves to 9.6.36. - Ignore the squizlabs/php_codesniffer 1.x security advisories via config.policy.advisories.ignore: Composer >= 2.9 refuses to install advisory-affected packages, which has broken every CI composer install since Nov 2025. The 1.x line is required by the CakePHP2 coding standard (cakephp-codesniffer 1.x), is dev-only, and is frozen upstream. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
HttpSocketTest::testVerifyPeer connects to https://tv.eurosport.com/ expecting a TLS peer-verification failure, but that hostname no longer resolves, so the SocketException carries a DNS error instead of 'Failed to enable crypto' and the assertion fails on every CI job. Skip on name-resolution failure, in the same style as the existing environmental skip conditions in this test. This was masked until now because CI had been failing at composer install since Nov 2025. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The skeleton pins upstream cakephp/cakephp ~2.9 and php >= 5.3.0, which are incompatible with PHPUnit 9 (upstream CakeTestCase extends the PHPUnit 3 era PHPUnit_Framework_TestCase, and PHPUnit 9.6 requires PHP >= 7.3). The skeleton is not exercised by CI nor by the documented consumption path (the README instructs the VCS-repository method), so the dev dependency is vestigial. Removing it resolves Dependabot alert #3 for this manifest without advertising an impossible install. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Replace the package-wide policy.advisories.ignore for squizlabs/php_codesniffer with ignore-id entries for the two advisories that block resolution (PKSA-6vdd-n4sx-knhy and CVE-2026-67434), scoped with on-audit: false so only install/update blocking is lifted while composer audit keeps reporting them. Verified against Composer 2.10.2: resolution succeeds (php_codesniffer 1.5.6) and both advisories remain visible in composer audit and in the post-install warning. The scoping semantics follow the implementation (AdvisoriesPolicyConfig) and the doc example; the prose in Composer's 06-config.md currently describes on-block/on-audit inverted. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
testVerifyPeer previously depended on an external bad-certificate host (tv.eurosport.com) whose DNS no longer resolves, leaving the test permanently skipped and TLS peer verification without regression coverage. Replace it with a helper (lib/Cake/Test/test_app/tls_server.php) that generates a throwaway self-signed certificate at runtime and serves one TLS connection on 127.0.0.1, so the verification failure is asserted deterministically with no network dependency. An unexpectedly successful request is now a test failure instead of a skip. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
basi
marked this pull request as ready for review
August 26, 2026 09:26
This was referenced Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Resolves Dependabot alert #3: https://github.com/basi/cakephp2-php8/security/dependabot/3
cleanupForCoverage()) deserializes.coveragefiles viaunserializewithout anallowed_classesrestriction. Patched in 9.6.33 (latest 9.6.x is 9.6.36).This repository contains no
*.phpttests and CI collects no coverage, so there is no actual attack surface here — the manifest changes below are what resolve the alert. The PR additionally un-breaks CI (everycomposer installhad been failing since Nov 2025) and restores real TLS peer-verification test coverage. Updated after a code review (3 findings addressed — see "Review response" below), then brought up to date withmain(#23 switched the CI matrix from PHP 8.2 to 8.4), which required one PHP 8.4 test-expectation fix.Changes
app/composer.json: removephpunit/phpunitfromrequire-dev(previously3.7.*, the constraint the alert fired on)cakephp/cakephp ~2.9andphp >= 5.3.0; any modern PHPUnit constraint there would be self-contradictory (upstream 2.xCakeTestCaseextends the PHPUnit 3 eraPHPUnit_Framework_TestCase, and PHPUnit 9.6 requires PHP >= 7.3). The skeleton is not exercised by CI nor by the documented consumption path (README instructs the VCS-repository method), so the dev dependency is vestigial. Removing it resolves the alert without advertising an impossible installcomposer.json:phpunit/phpunit^9.5→^9.6.33— raises the floor to the first patched version (a fresh install resolves to 9.6.36)composer.json: ID-scoped advisory policy to un-break CI. Since Composer 2.9, resolution of advisory-affected packages is blocked by default, andcakephp/cakephp-codesniffer ^1.0.0→squizlabs/php_codesniffer ^1.4made every CIcomposer installfail since Nov 2025 (build(deps): bump actions/checkout from 5 to 6 #19, build(deps): bump actions/cache from 4 to 5 #20).config.policy.advisories.ignore-idnow lists exactly the two blocking advisories —PKSA-6vdd-n4sx-knhy(phpcs 1.x arbitrary shell execution, GHSA-mhfv-8rc9-w38c) andCVE-2026-67434(phpcs OS command injection, PKSA-rdkp-vv9z-mjkg / GHSA-hmqg-cxww-wqhq) — each with"on-audit": falseand a reason, so only install/update blocking is lifted whilecomposer auditand the post-install warning keep reporting both advisorieson-auditsemantics: Composer's06-config.mdprose currently describeson-block/on-auditinverted relative to the implementation. The actual behavior (perAdvisoriesPolicyConfig::getIgnoreIdForOperation()in 2.10.2 and verified empirically) is that the flags scope where the ignore applies:"on-audit": false= ignored for blocking, still reported by auditlib/Cake/Test/Case/Network/Http/HttpSocketTest.php+ newlib/Cake/Test/test_app/tls_server.php:testVerifyPeernow verifies TLS peer rejection against a local TLS server with a runtime-generated self-signed certificate instead of a dead external hosttv.eurosport.comno longer resolves, which had left the test permanently skipped (no regression coverage for peer verification). Nothing is committed to the repository and nothing can expire: the helper generates a throwaway certificate at runtime — CN=127.0.0.1 withsubjectAltName = IP:127.0.0.1,serverAuthEKU andCA:FALSE, built from an explicit OpenSSL config so the fixture does not depend on a systemopenssl.cnfproc_open, no shell escaping); startup is handed back as a JSON line, and the child's stderr is folded into the failure message. Fixture startup problems are test failures, not skips, so environment rot stays visiblessl_allow_self_signed => truemust receive an HTTP 200 from the fixture first (proving the server and certificate genuinely work for 127.0.0.1), then the default-configuration client must be rejected withFailed to enable crypto. The child serves both connections with real HTTP responses, and its exit code 0 and the removal of both temporary files are asserted as welllib/Cake/Test/Case/Utility/DebuggerTest.php: update the expectedhighlight_string()pattern for PHP 8.4 (the<code>element may carry attributes and colors are emitted as 6-digit hex). Needed because the CI matrix now includes PHP 8.4 (see Run CI tests on PHP 8.4 instead of 8.2 #23)Verification
composer validatepasses for both root andapp/(Composer 2.10.2)phpunit/phpunit→ 9.6.36,squizlabs/php_codesniffer→ 1.5.6, zero problems, exit 0Found 2 security vulnerability advisories affecting 1 package.andcomposer auditlists both advisories in full — only the install-time block is liftedmainmerged in, matrix PHP 8.0 × mysql/pgsql/sqlite + PHP 8.4 × mysql): all 4 jobs pass — run 32952486089. The hardenedtestVerifyPeerruns its assertions (not skipped) on every jobReview response
app/composer.jsondeps incompatible with PHPUnit 9 and unverified by CIphpunit/phpunitdev dependency from the skeleton (option 1 of the review); the skeleton reverts to a coherent legacy snapshotignore-identries for exactly the two blocking advisories, scoped to lift blocking only;composer auditkeeps reporting them. Backporting a phpcs fix / migrating the ruleset remains a separate tasktestVerifyPeerpermanently skippedssl_allow_self_signed, child stderr/exit-code propagation, fixture problems fail instead of skip)Out of scope (known separate issues)
cakephp/cakephp ~2.9inapp/composer.json, GHSA-wpvj-hjcr-h3p2): the view path traversal itself is being backported in Backport view path containment check for CVE-2026-48820 #22 (draft); note that the backport alone does not close the manifest-based alert — thecakephp/cakephp ~2.9requirement will still need to be removed/adjusted or the alert dismissedbump-version.ymlduplicate-tag failure (custom_tag: 1.1.0already exists): the update to 1.2.0 is staged in Backport view path containment check for CVE-2026-48820 #22🤖 Generated with Claude Code