From f24db035124ef5a7694e5431b0cf0b9adf6a1df9 Mon Sep 17 00:00:00 2001 From: basi Date: Tue, 29 Sep 2026 20:22:41 +0900 Subject: [PATCH] build(deps): drop cakephp/cakephp from the app skeleton composer.json The skeleton requires cakephp/cakephp ~2.9 from Packagist, which is upstream CakePHP 2.10.x. It does not support PHP 8, and Composer now refuses to load 2.9.0-2.10.24 because of security advisories. CakePHP advisories without a lower bound keep raising Dependabot alerts on this manifest (alerts 1, 2, 6 and 7) with no 2.x fix, and each one makes the "composer in /app" security update job fail with dependency_file_not_resolvable. The in-repo app loads lib/Cake from the repository root, CI installs only the root composer.json, and the README documents the VCS repository method, so the requirement is unused. This is the same rationale as 5bff587af, which dropped phpunit from this skeleton. Co-Authored-By: Claude Opus 5.5 --- app/composer.json | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/app/composer.json b/app/composer.json index 197bb66b06..488eeb9671 100644 --- a/app/composer.json +++ b/app/composer.json @@ -19,8 +19,7 @@ }, "require": { "php": ">=5.3.0", - "ext-mcrypt": "*", - "cakephp/cakephp": "~2.9" + "ext-mcrypt": "*" }, "suggest": { "cakephp/cakephp-codesniffer": "Easily check code formatting against the CakePHP coding standards."