-
Notifications
You must be signed in to change notification settings - Fork 436
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
sensiolabs/security-checker is abandoned and replaced by fabpot/local-php-security-checker #865
Comments
As we dont want to mess around with binaries and want to keep everything inside our composer, we are looking into switching to https://github.com/Roave/SecurityAdvisories It uses the same source repo to check for vulnerabilities as One caveat is that it only runs checks during
|
@ctrl-f5 : Maybe we could make 2 tasks instead? The task takes some configurable options, which won't be possible with the package from roave. So we could change the existing task and extend it with an option to select the executable: |
yup, having both options will be best. I will try and find the time to create a task for the roave package. |
Guys, you can consider the Enlightn Security Checker. No binaries needed, can be pulled in with Composer, no licensing issues (MIT license) and has in-built HTTP caching. |
As @paras-malhotra stated, If there's still interest in using local-php-security-checker, or if their license were to change, you can always reopen #871 (or use it as a starting point). |
Awesome - thanks guys! |
To replace the Symfony Security Checker, the Enlightn Security Checker has been installed, which does the same checks and is already enabled in the GrumPHP configuration. See: phpro/grumphp#865
To replace the Symfony Security Checker, the Enlightn Security Checker has been installed, which does the same checks and is already enabled in the GrumPHP configuration. See: phpro/grumphp#865
To replace the Symfony Security Checker, the Enlightn Security Checker has been installed, which does the same checks and is already enabled in the GrumPHP configuration. See: phpro/grumphp#865
To replace the Symfony Security Checker, the Enlightn Security Checker has been installed, which does the same checks and is already enabled in the GrumPHP configuration. See: phpro/grumphp#865
To replace the Symfony Security Checker, the Enlightn Security Checker has been installed, which does the same checks and is already enabled in the GrumPHP configuration. See: phpro/grumphp#865
sensiolabs/security-checker has been marked as abandoned and the free api at security.symfony.com will be stopped at the end of January 2021.
It has apparently been replaced by fabpot/local-php-security-checker so the securitychecker task may need to be updated to move to use this instead.
The text was updated successfully, but these errors were encountered: