Skip to content

Unblock Dependabot security updates by moving leafs/auth to JWT 7-compatible release - #7

Draft
ibnsultan with Copilot wants to merge 2 commits into
mainfrom
copilot/fix-dependabot-job-failure
Draft

ibnsultan with Copilot wants to merge 2 commits into
mainfrom
copilot/fix-dependabot-job-failure

Conversation

Copilot AI commented Jun 6, 2026 •

Copy link
Copy Markdown

Dependabot’s security update job for firebase/php-jwt failed with security_update_not_possible because the dependency graph could only resolve 6.x, while the first non-vulnerable line is 7.0.0+. This change updates the project constraints so Dependabot can resolve and propose secure JWT upgrades.

  • Root cause addressed

    • leafs/auth v3.4 (selected by *) constrained firebase/php-jwt to ^6.10, preventing a security upgrade to 7.x.
  • Dependency constraint changes

    • Pinned leafs/auth in composer.json from wildcard to a JWT 7-compatible major:
      • leafs/auth: "^5.0"
  • Lockfile resolution updates

    • Regenerated lockfile to reflect the new constraint:
      • leafs/auth v3.4 → v5.0
      • firebase/php-jwt v6.10.2 → v7.0.5
      • Required transitive package updates to satisfy the new graph
// composer.json
"require": {
  "leafs/auth": "^5.0"
}

Copilot AI changed the title [WIP] Fix failing GitHub Actions job Dependabot Unblock Dependabot security updates by moving leafs/auth to JWT 7-compatible release Jun 6, 2026
Copilot AI requested a review from ibnsultan June 6, 2026 07:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants