Skip to content

Conversation

@rootpd
Copy link
Contributor

@rootpd rootpd commented Dec 31, 2025

The v6 is required by composer/composer library since v2.8.7 and causes dependency issues.

All recent releases of composer/composer were flagged as vulnerable. The fix is included in v2.9.3 which requires justinrainbow/json-schema v6 which is incompatible with the current version of Nette API.

I've checked the v6 changes and they seem to be compatible for use in this library and therefore it should be OK to allow v5 OR v6 installation - see https://github.com/jsonrainbow/json-schema/releases/tag/6.0.0.

If possible, please cherry pick this also for v2 tag so that it could be used with 2.12 version.

The v6 is required by composer/composer library since v2.8.7
and causes dependency issues.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant